Form ReDraft Documentation

Published: October 4, 2026 by Andrew Apell

Getting Started

Form ReDraft runs entirely inside Chrome. There is no account to create, no server to register with and nothing to configure before it starts working.

It also records nothing until you say where it may. On first run, click the Form ReDraft icon and answer one question:

  • Only on sites I choose. The default. Nothing is recorded until you press Start saving here on a site. Form ReDraft asks this first because a tool that reads what you type should not begin doing so without being told.
  • On every site. Records on all sites except the blocked list. Choose this if the occasional loss is what worries you more than the archive.

You can change that answer at any time from the settings page or from the switch in the popup footer.

Form ReDraft asks for three permissions. The storage permission holds your drafts, alarms runs the hourly cleanup, and activeTab lets the popup send a restore to the page you are looking at. Form ReDraft requests no host permissions, which means it cannot read a page you are not on.

Sites Form ReDraft Never Records

Form ReDraft ships with a list of domains it will not record on, covering banking, payment, email, identity and developer console sites. The list is a starting point rather than a rule, and it is yours to edit: remove any line you disagree with and it stays removed. A button in the settings restores the shipped list if you want it back.

Two things the blocked list deliberately does not include. Writing tools such as Notion and Google Docs are absent, because those are the sites where you lose the most work. And the list is not a security boundary on its own: a site you add by hand is recorded like any other.

For a field level guarantee that does not depend on any list, see what is never saved.

How Form ReDraft Records Your Typing

Form ReDraft attaches to text inputs, textareas and contenteditable surfaces. A MutationObserver watches the page so fields added later are picked up too, including fields inside open shadow roots in web components and inside iframes on the same page.

Each field is identified by a hash of the page address and the field identity. The identity prefers a stable identifier such as id or name, then the visible label, then the placeholder, and only falls back to a structural path through the page when nothing else is available.

When you type, Form ReDraft waits for a short pause of about 400 milliseconds after the last keystroke. That pause becomes a write: the text is filtered, encrypted and stored. Leaving the field flushes it immediately, so switching tabs does not cost you anything. A hard crash costs at most the text typed in the last 400 milliseconds.

Each field also gets a baseline value when Form ReDraft first sees it, and a draft is only written when the value has actually moved away from that baseline. This is why clicking around a page, skipping a video or tabbing through controls does not create drafts: nothing you did not type gets stored.

How the Restore Works

When Form ReDraft finds an empty field that it has a draft for, it places a badge next to the field. The badge shows how many words were kept and when the text was written. Clicking it opens a small panel with a restore button.

The restore step is where most extensions fail. Assigning element.value changes what you see but leaves the framework that owns the field holding its old value, so the next render wipes your text. Form ReDraft writes through the native property setter taken from the element prototype and then dispatches a bubbling input event followed by a change event. React, Vue and Angular read that event, update their own state and keep the text.

For contenteditable surfaces Form ReDraft writes the text into the element and dispatches the same events, which is what rich text editors listen for.

The test is simple. If the restore fills the box but the word count on the page does not change, the framework state was never updated.

What Is Never Saved

Some fields are refused outright and no draft is created for them. There is no setting to turn this off, because a setting is exactly what a password manager should not have.

  • Any input of type password or hidden.
  • Any field whose autocomplete token covers a card, a security code, a one-time code or a password.
  • Any field whose id, name, class, aria-label, placeholder or label contains a word such as password, passcode, cvv, security code, social security, pin, token or secret.

Matching is done on whole words after splitting camel case and punctuation, so a field called shipping is not mistaken for a PIN field.

Values that are ordinary text can still contain a secret. Before anything is written, Form ReDraft scrubs the value and replaces anything that looks like a payment card number passing the Luhn check, a social security number, a private key block, a JSON web token, a bearer token, a Stripe key, an Amazon Web Services key, a Google API key, a long hexadecimal key or a high entropy token. Each match becomes [redacted] and the rest of your sentence survives. If redaction leaves nothing behind, no draft is created at all.

There is one limit worth stating plainly. A password typed into a password field is never recorded, because the field itself is blocked before anything is read. A short password typed into an ordinary text field, such as a note saying your code is hunter2, cannot be told apart from an ordinary word, so it is kept like any other text. ReDraft removes values it can recognise as secrets, not values you happen to have typed somewhere unwise.

Rich Text Editors

Notion, Zendesk, Salesforce, Draft.js and TipTap do not use a textarea. They render a contenteditable surface and manage their own document model. Form ReDraft detects these automatically because they all expose a contenteditable region.

Text is stored as plain text. When restored into a formatted document, it arrives as unformatted text. Form ReDraft does not attempt to recreate your bold, headings or lists, because guessing at formatting usually produces something worse than plain text.

Code editors built on Monaco, including the editor embedded in some developer tools and dashboards, are out of scope. They keep their own undo history, and restoring text into one without its model API produces inconsistent results.

Single Page Apps

A single page app swaps screens without loading a new document. Two things follow from that, and Form ReDraft handles both.

First, the page address changes without a reload, so Form ReDraft watches pushState and replaceState as well as the back button, then re-checks the page for recoverable fields.

Second, some apps generate a fresh id for every field on every render. An identifier that changes on every keystroke is useless for matching, so Form ReDraft falls back to the visible label of the field. That fallback is why Form ReDraft can offer a draft on sites where other tools fail silently.

Settings Reference

Open the settings from the gear icon in the Form ReDraft popup. Every change applies immediately, without restarting Chrome.

Setting Default What it does
Where Form ReDraft records Only on sites I turn on Either only on the sites you have turned on, or on every site except the list of sites it never records. Asked on first run and changeable here.
Sites where you have turned Form ReDraft on None One domain per line, subdomains included. Only used when recording is set to only the sites you turn on.
Sites Form ReDraft never records Banking, payment, email, identity and developer console sites One domain per line. Editable, and removing a line is permanent unless you restore the shipped list.
Keep drafts at all On Master switch. When off, nothing is recorded anywhere.
Show the restore badge on empty fields On Shows the badge beside an empty field that has a draft.
Keep drafts in private browsing windows Off Allows recording inside private windows. Off by default, because drafts in a window that disappears are easy to forget.
Delete drafts older than (hours, 0 keeps everything) 24 hours Retention window in hours. Set 0 to keep drafts until you delete them.
Maximum drafts per site 200 Upper bound for one domain. Set 0 for no limit.
Maximum drafts in total 2000 Upper bound across every site. Set 0 for no limit.
Maximum storage used (MB) 4 MB Upper bound on what the drafts occupy. The oldest go first once it is reached. Set 0 for no limit.
Clean up every (minutes) 60 minutes How often the limits above are applied. Cleanup also runs the moment storage fills up.
Extra field names to never save None One case-insensitive regular expression per line, matched against the field id, name, class, label, placeholder and accessible label. Patterns that could hang the page are refused. The built-in blocks always apply.

Storage and Encryption

Drafts live in chrome.storage.local on your device. Each value is encrypted with AES-GCM before it is written, using a random 256-bit key generated when Form ReDraft is installed.

The key is stored alongside the drafts rather than in chrome.storage.session. That is deliberate. Chrome clears session storage when the browser restarts, so a key held there would leave every draft permanently unreadable after a single restart, which is the exact situation Form ReDraft exists to protect you from.

Be clear about what this does and does not achieve. It keeps stored values out of plain sight in browser storage, backups and disk artefacts. It does not protect against malware or anyone who already has administrative access to your profile, because the key has to be readable by the extension to decrypt anything.

Troubleshooting

No badge appears on a field I typed into

Work through these in order. Confirm the field is not a password or card field, since those are never saved. Confirm recording is not off for that site. Confirm the draft has not passed the retention window. Then confirm the site is one Form ReDraft is allowed to record on, either armed by you or covered by the record-everywhere setting.

The badge restores text but the page does not keep it

This happens on editors that virtualise their content or re-render from a remote model. Form ReDraft writes the text and fires the events the framework listens for, but an editor that overwrites the surface from its own server state will win. Plain fields, including React controlled inputs, are handled.

The popup says a draft could not be decrypted

This appears when the stored drafts and the device key no longer match, which happens if you copy a profile folder between machines or restore a backup from a different install. Form ReDraft cannot recover from this, because the key is the only thing that can read the drafts. Delete everything from the settings page to start clean.

Storage fills up

Lower the retention window, or lower the per-site and total caps. The settings page shows the current size, and the clean up button applies the limits immediately.

FAQ

Does Form ReDraft send my typing anywhere?

No. Form ReDraft contains no network code at all. There is no fetch call, no upload and no analytics inside the extension. Drafts are written to your own browser storage.

Can Form ReDraft see my passwords?

It refuses to record password fields, card fields and one-time code fields before reading them, and it never requests permission to see anything on a page you are not visiting.

Is this the same as Chrome autofill?

No. Chrome autofill stores short, structured answers for its own form filling, and extensions cannot read that store. Form ReDraft keeps the long text you write, which autofill has no field for.

Does Form ReDraft work in Firefox or Edge?

Form ReDraft is built for Chrome and uses Chrome extension interfaces. The same WebExtension interfaces exist in Edge, so it may load there unofficially, but it is tested in Chrome only.

Can I move my drafts to another computer?

Use the export button in the settings page. It writes a readable JSON file. Importing is not automated, because the encryption key is tied to the install.

Keep what you write

Form ReDraft is free, private and makes no network requests. It records text you type into forms, and refuses to record anything that looks like a credential.

Read the recovery guide
Project Slidecut