Habeas by David Marín Carreño
Reclaim your own personal data from services that lock it behind non-automatable walls — within your own session.
Available on Firefox for Android™Available on Firefox for Android™
Scan the QR code to open this extension in Firefox for Android
Extension Metadata
Screenshots
About this extension
Habeas — reclaim your own data, in your own session
Many services hold data that is yours — receipts, invoices, card, bank or investment movements — behind walls you can't automate (Cloudflare, Akamai…), with neither an API nor an export. Habeas gives it back to you.
Unlike server-side scraping, Habeas runs inside your real browser, in your already signed-in session. Because of that:
It's the opposite of how aggregators like Plaid or Tink operate.
Your archive, made visual
Everything you recover lands in your Archive: a clear view of your documents, laid out in a source → account tree, with cards grouped by month or category, amounts, and status. Search, filter by account, and open any saved document. The toolbar popup is a fast launcher into your Archive.
You decide where your archive lives
By default, your archive is stored locally in this browser. With one click you can move it to the cloud to reach it from several devices — we recommend Dropbox, and it also supports Google Drive, WebDAV, S3, or a local folder. You can also send specific documents to destinations: download, local folder, Dropbox, Drive, WebDAV, S3, or an HTTP endpoint. Nothing leaves your
browser until you choose a destination.
Sources are data, not code
Sources are declarative definitions (no remotely-hosted code, honoring MV3's rules). There are audited first-party sources and a growing community catalog covering supermarkets, retail, cards and banking, energy, telecom, and more. Missing a service? Record mode watches the site's own API as you browse and drafts the source for you — no coding — and you can share it
with the community.
Privacy and control, by design
Your right, your data
Habeas rests on your right to data portability (GDPR, Art. 20) and the principle of habeas data: it's your own data, in your own session, through free software you run yourself. Habeas is not a PSD2-regulated actor (it initiates no payments). Each site's terms of service may restrict automated access; complying with them is your responsibility.
No telemetry · no accounts · no stored passwords.
Many services hold data that is yours — receipts, invoices, card, bank or investment movements — behind walls you can't automate (Cloudflare, Akamai…), with neither an API nor an export. Habeas gives it back to you.
Unlike server-side scraping, Habeas runs inside your real browser, in your already signed-in session. Because of that:
- It never fights anti-bot systems: it inherits your valid session.
- It never stores your passwords. You log in yourself; the token lives only in memory and is cleared when you close the browser.
- You solve MFA/OTP live, exactly as you always do.
It's the opposite of how aggregators like Plaid or Tink operate.
Your archive, made visual
Everything you recover lands in your Archive: a clear view of your documents, laid out in a source → account tree, with cards grouped by month or category, amounts, and status. Search, filter by account, and open any saved document. The toolbar popup is a fast launcher into your Archive.
You decide where your archive lives
By default, your archive is stored locally in this browser. With one click you can move it to the cloud to reach it from several devices — we recommend Dropbox, and it also supports Google Drive, WebDAV, S3, or a local folder. You can also send specific documents to destinations: download, local folder, Dropbox, Drive, WebDAV, S3, or an HTTP endpoint. Nothing leaves your
browser until you choose a destination.
Sources are data, not code
Sources are declarative definitions (no remotely-hosted code, honoring MV3's rules). There are audited first-party sources and a growing community catalog covering supermarkets, retail, cards and banking, energy, telecom, and more. Missing a service? Record mode watches the site's own API as you browse and drafts the source for you — no coding — and you can share it
with the community.
Privacy and control, by design
- Local-first and open source (AGPL-3.0): you can audit exactly what it does.
- Domain-bound trust boundary: a source's captured session can only ever be replayed to its own service; crossing domains requires an explicit allow-list and a consent screen.
- Integrations on your terms: a website can propose a data flow, but nothing runs until you approve it — and only back to that same site. Revocable anytime.
Your right, your data
Habeas rests on your right to data portability (GDPR, Art. 20) and the principle of habeas data: it's your own data, in your own session, through free software you run yourself. Habeas is not a PSD2-regulated actor (it initiates no payments). Each site's terms of service may restrict automated access; complying with them is your responsibility.
No telemetry · no accounts · no stored passwords.
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Display notifications to you
- Access your data for all websites
Optional permissions:
- Access your data for www.carrefour.es
- Access your data for pro.api.carrefour.es
- Access your data for www.googleapis.com
- Access your data for oauth2.googleapis.com
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 0.8.1
- Size
- 654.37 KB
- Last updated
- 14 hours ago (Jul 24, 2026)
- Related Categories
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection
The developer of this extension asks that you help support its continued development by making a small contribution.