LokiVeil is an experimental Chrome extension that covers chosen fields on a web page with opaque boxes, for rehearsing screen-share demos on fictional pages. It is a visual mask for test data, not a privacy tool.
You want to rehearse a product demo on a fictional test page and see how selected fields can be covered, and the whole page curtained, while you share your screen.

On https://perunlight.com/lokiveil/, click Download synthetic-data demo; you can compare the file with the SHA-256 shown on that page. Extract the ZIP and read INSTALL.md and PRIVACY.md.
Open chrome://extensions, turn on Developer mode, click Load unpacked and select the extracted extension folder (not the ZIP). LokiVeil asks for no site access when installed.
Open your fictional test page over http(s). Before you authorise it, the LokiVeil popup shows NOT PROTECTED: “This site is not authorised, so nothing is masked here.”
Click the LokiVeil toolbar icon, click Authorise this site and accept Chrome's permission prompt. The tab reloads, because the curtain has to start before the page paints. You can also use Authorise an origin in Options.
Click Options. Under Import and export, use Import a profile bundle (.json); or under New profile enter Profile id, Allowed origin, Path pattern and Rules (Selector, Min, Max) and click Save profile. Each rule's match count must stay between Min and Max, or the page is reported as not ready.
Reload the page, open the popup and click Re-check. Use the page for a demo only when the badge says DEMO READY; pages that do not match their profile stay curtained.
Force curtain covers the whole page at once (CURTAIN DOWN). Pick fields reveals the page so you can click fields to capture selectors. Use it only with fictional data, and click Stop picker before you share your screen.
Click Revoke in the popup (or remove the site in Options) and reload open tabs. Options → Delete all LokiVeil data removes profiles, settings and picks; it does not revoke site access, so do both.
Input: examples/lokiveil/fictional-crm-demo.html (a fictional customer record) and examples/lokiveil/fictional-crm-profile.json (a profile for http://localhost:8000/fictional-crm-demo.html covering the name, email, phone and two account numbers).
Expected: Options confirms “Imported 1 profile(s) in merge mode; 1 stored.” and lists the profile fictional-crm with 4 rules. After the reload, the popup should report DEMO READY with the expected matches (1, 1, 1 and 2), and the customer name, email, phone and both account numbers are covered. Force curtain covers the whole page. After Revoke and a reload, LokiVeil no longer runs on the page.
The profile does not match the page. Check that Allowed origin and Path pattern match the address exactly (for example http://localhost:8000, not 127.0.0.1) and that each selector finds the expected number of elements (see the Rules table in the popup). Click Re-check after changes.
Serve the page from a local web server, such as python3 -m http.server 8000, instead of opening the file directly.
Reload the tab: authorising and revoking only take effect after a reload. NOT RUNNING means the site is authorised but LokiVeil has not started in that tab yet.
Select the extracted extension folder that contains manifest.json, not the ZIP or the folder above it.
Ignore it. This build has no paid tier and no checkout, and it does not check keys.
Guide and examples: 30 September 2026. Examples are fictional or synthetic. Online guide · Support