Browser Extension — Privacy Policy
Last updated: July 2, 2026
The Records Labs browser extension (“the extension”) is a companion to the Records Labs knowledge platform. It is used with your own Records Labs account. This policy explains what the extension accesses, where that data goes, and the controls you have. The platform itself is covered by the Records Labs Privacy Policy.
The short version
- The extension only acts when you ask it to (capture a page, ask a question, draft a reply, run a task).
- The page content it processes is sent only to your own Records Labs organization — the account your API key belongs to. We do not sell it, and it is never sent to any third party.
- Your Records Labs API key and settings are stored locally on your device and are never synced or shared.
- Your website logins and passwords are never read or stored — the extension works because you are already signed in.
What the extension accesses, and when
The extension does nothing in the background. It accesses data only in response to an action you take:
- When you capture a page— it reads that page’s text, and the URLs of images/PDFs and any video transcript on it, and sends them to your Records Labs organization to add to your knowledge base (as a draft for review).
- When you ask a question or draft a reply— it sends your question (and, only if you turn on “Use this page”, a copy of the current page’s text) to your Records Labs organization to generate a cited answer.
- When you run a Tool or a Drive task — it reads the current page (its interactive elements and, only if you enable it, a screenshot) so the task can decide what to do, and reports the result back to you. Drive actions on a site require your consent.
Data we store on your device
- Your Records Labs API key — stored in
chrome.storage.local, used only as the authorization header for requests to the Records Labs API. Never synced. - Your settings and site policy — stored locally.
- A local activity log — metadata only (site, action type, a one-line detail, and how many items were redacted). It never includes page content and never leaves your device.
Where data goes
Page content and questions are transmitted only to the Records Labs API (the Records Labs API URL configured for your deployment) and are attributed to your organization by your API key. From your perspective this is first-party: it is your own Records Labs account. We do not sell your data, and we do not share it with third parties for advertising or any purpose unrelated to providing the feature.
Once received by Records Labs, data is handled under the Records Labs platform privacy terms and your organization’s own retention and access controls.
Privacy protections built into the extension
- Edge redaction (on by default) — emails, phone numbers, card numbers, national ID numbers, and secret-shaped tokens are removed from text in your browser before anything is sent.
- Site policy — you can allow, ask before, or block the extension per site, and maintain a hard-block list of sensitive sites (banking, health, login pages) the extension will never touch.
- Consent for actions — anything that changes a page (Drive, inserting a draft) asks before acting when your policy requires it.
Permissions
The extension requests broad host access (http/https) so that you can choose to use it on any site. This access is exercised only on the specific tab and action you invoke, and is constrained by your site policy. See the store listing for a per-permission breakdown.
Children
The extension is a workplace tool and is not directed to children under 13.
Changes
We may update this policy; material changes will be reflected here with a new date.
Contact
Questions about this policy or your data: privacy@recordslabs.ai.