ATHEXIS AI browser extension
What the extension can read, what leaves your browser, where it goes, and how long it is kept.
What this statement covers
This statement covers the ATHEXIS AI extension for Google Chrome — the assistant that runs in the browser side panel, beside the ATHEXIS app. It is a separate product from the ATHEXIS web application and the ATHEXIS mobile app, which are covered by the privacy statement for the service.
The extension is distributed to organisations that already use ATHEXIS. It is not a general-purpose browser assistant and it does not work anywhere else.
Where the extension can act
The extension is confined to your organisation's ATHEXIS app. Chrome grants it standing access to the ATHEXIS web addresses the build was made for, and to no other site. That list is fixed when the extension is built, not chosen afterwards in a settings screen, and Chrome — not the extension — is what enforces it.
One permission is worth naming, because a reviewer will see it in the list below. Chrome's activeTab permission lets it hand the extension the tab you are looking at when you invoke it, whatever site that is. The extension declines it: every path that reads or screenshots a page checks the address first, and a page that is not part of the ATHEXIS app is refused by name before anything is read. So on every other page you open — your bank, your email, an intranet — it reads nothing, sends nothing, and changes nothing.
What the extension can read
Chrome shows you a list of permissions when you install an extension. These are the eight this one asks for, and why each is there.
It does not ask for, and Chrome has not granted it, access to all sites, the Chrome debugger, or the ability to inject scripts into arbitrary pages. Those three were removed from this edition before release, and the packaged extension is checked against the list above on every build.
What leaves your browser
Only what you give the assistant, and only when you use it:
- the message you type, and the earlier messages in that conversation;
- what the assistant read from the ATHEXIS page you are on, when you asked it to look;
- the lookups it makes against your own ATHEXIS data to answer you.
Nothing else goes to the platform. The extension sends no analytics and no usage tracking, it has no advertising identifier, and it does not sell or share anything with anyone. There is one other thing it can send, to one other place — the extension's own crash reports, described below.
Where it goes
To one place: your organisation's own ATHEXIS platform. The extension holds no account with a language-model provider and has no way to reach one directly — it carries no key for one, and Chrome grants it access to no address other than the ATHEXIS ones above.
Your messages reach the language model through the platform, which holds the credential, applies your organisation's spending limits before the call, and records what it cost. Where your organisation's data must remain in Australia, the platform routes the request to a model in an Australian region — and if it cannot, it refuses the request rather than sending it offshore.
If the extension itself crashes
When the extension's own code fails — not your work, the software — it can send a crash report, so that a broken install is something we find rather than something you have to tell us about days later.
Those reports go to Sentry (Functional Software, Inc.), in Sentry's European data region. It is the only third party the extension talks to, and it is used for nothing else.
A report is built field by field rather than collected, and it carries:
- what failed and where — the error's type, a redacted one-line message, and the stack frames that are the extension's own files;
- which build it was — the version shown on Chrome's extensions page;
- which half of the extension failed — the side panel, or its background worker;
- a random report number and the time.
It carries none of your data. No page content, no page address, no tab title. No name, no email address, no account or organisation identifier, and no cookies. Stack frames from anything that is not the extension's own files are dropped rather than shortened, because on this extension a frame from somewhere else is one of your pages. The message is redacted before it is sent — quoted values, figures, email addresses and web addresses are all replaced — and the redaction errs towards destroying the meaning of a message rather than risk carrying yours.
It is bounded: at most twenty reports in a session, and a repeat of one already sent is not sent again. And it is configuration, not a default — a build with no reporting destination configured sends nothing at all.
This is the one thing the Manual setting does not switch off. An organisation whose extension is broken has to be able to say so, and an assistant that has been turned off is exactly the situation in which nobody would notice.
What is kept, and for how long
In your browser. Conversations and generated files stay in Chrome's extension storage on this computer for seven days. After that they stop being readable and are cleared — whether the extension has been opened in the meantime or not. Signing out clears them straight away, along with the sign-in token, which is never written to disk and does not outlive the browser session.
On the platform. What a call cost, charged against your organisation's own budget. Where the assistant used one of the platform's tools, a record of that call as well — which tool, which model, how much it consumed, how long it took, and a one-way fingerprint of what went in and what came out, so the action can be audited afterwards. The conversation itself is not stored on the platform.
What your organisation controls
Your organisation chooses how much of the assistant runs. The extension reads that setting from the platform each time it starts — it never assumes one:
Today the platform serves the extension read-only tools, so the assistant can look things up but cannot change your records through them.
Who to contact
Questions about this statement, or about what the extension did in your organisation: