Privacy statement

ATHEXIS AI browser extension

What the extension can read, what leaves your browser, where it goes, and how long it is kept.

Last updated 10 September 2026

What this statement covers

This statement covers the ATHEXIS AI extension for Google Chrome — the assistant that runs in the browser side panel, beside the ATHEXIS app. It is a separate product from the ATHEXIS web application and the ATHEXIS mobile app, which are covered by the privacy statement for the service.

The extension is distributed to organisations that already use ATHEXIS. It is not a general-purpose browser assistant and it does not work anywhere else.

Where the extension can act

The extension is confined to your organisation's ATHEXIS app. Chrome grants it standing access to the ATHEXIS web addresses the build was made for, and to no other site. That list is fixed when the extension is built, not chosen afterwards in a settings screen, and Chrome — not the extension — is what enforces it.

One permission is worth naming, because a reviewer will see it in the list below. Chrome's activeTab permission lets it hand the extension the tab you are looking at when you invoke it, whatever site that is. The extension declines it: every path that reads or screenshots a page checks the address first, and a page that is not part of the ATHEXIS app is refused by name before anything is read. So on every other page you open — your bank, your email, an intranet — it reads nothing, sends nothing, and changes nothing.

What the extension can read

Chrome shows you a list of permissions when you install an extension. These are the eight this one asks for, and why each is there.

storage
Keeps your conversations, settings and workspace state in Chrome's own extension storage on this computer. Nothing is written to a third party.
unlimitedStorage
Conversation transcripts and generated files are larger than Chrome's small default allowance. They are held on this computer and cleared after seven days.
activeTab
Takes a picture of the ATHEXIS tab you are looking at, when you ask the assistant what is on screen. Chrome requires this permission for a screenshot; site access alone is not enough.
sidePanel
Draws the assistant in Chrome's side panel. The extension has no pop-up and adds nothing to the page itself.
userScripts
Reads the ATHEXIS page you are on, so the assistant can answer questions about what is in front of you and fill a form when you ask it to. Confined to the ATHEXIS addresses above.
tabGroups
Reads which tab group an ATHEXIS tab belongs to, so the panel can tell you where it went.
webNavigation
Waits for an ATHEXIS page to finish loading before reading it, and re-checks that the tab is still the one you approved before every read.
favicon
Draws site icons in the panel from Chrome's own local icon store, instead of fetching them from the network.

It does not ask for, and Chrome has not granted it, access to all sites, the Chrome debugger, or the ability to inject scripts into arbitrary pages. Those three were removed from this edition before release, and the packaged extension is checked against the list above on every build.

What leaves your browser

Only what you give the assistant, and only when you use it:

  • the message you type, and the earlier messages in that conversation;
  • what the assistant read from the ATHEXIS page you are on, when you asked it to look;
  • the lookups it makes against your own ATHEXIS data to answer you.

Nothing else goes to the platform. The extension sends no analytics and no usage tracking, it has no advertising identifier, and it does not sell or share anything with anyone. There is one other thing it can send, to one other place — the extension's own crash reports, described below.

Where it goes

To one place: your organisation's own ATHEXIS platform. The extension holds no account with a language-model provider and has no way to reach one directly — it carries no key for one, and Chrome grants it access to no address other than the ATHEXIS ones above.

Your messages reach the language model through the platform, which holds the credential, applies your organisation's spending limits before the call, and records what it cost. Where your organisation's data must remain in Australia, the platform routes the request to a model in an Australian region — and if it cannot, it refuses the request rather than sending it offshore.

If the extension itself crashes

When the extension's own code fails — not your work, the software — it can send a crash report, so that a broken install is something we find rather than something you have to tell us about days later.

Those reports go to Sentry (Functional Software, Inc.), in Sentry's European data region. It is the only third party the extension talks to, and it is used for nothing else.

A report is built field by field rather than collected, and it carries:

  • what failed and where — the error's type, a redacted one-line message, and the stack frames that are the extension's own files;
  • which build it was — the version shown on Chrome's extensions page;
  • which half of the extension failed — the side panel, or its background worker;
  • a random report number and the time.

It carries none of your data. No page content, no page address, no tab title. No name, no email address, no account or organisation identifier, and no cookies. Stack frames from anything that is not the extension's own files are dropped rather than shortened, because on this extension a frame from somewhere else is one of your pages. The message is redacted before it is sent — quoted values, figures, email addresses and web addresses are all replaced — and the redaction errs towards destroying the meaning of a message rather than risk carrying yours.

It is bounded: at most twenty reports in a session, and a repeat of one already sent is not sent again. And it is configuration, not a default — a build with no reporting destination configured sends nothing at all.

This is the one thing the Manual setting does not switch off. An organisation whose extension is broken has to be able to say so, and an assistant that has been turned off is exactly the situation in which nobody would notice.

What is kept, and for how long

In your browser. Conversations and generated files stay in Chrome's extension storage on this computer for seven days. After that they stop being readable and are cleared — whether the extension has been opened in the meantime or not. Signing out clears them straight away, along with the sign-in token, which is never written to disk and does not outlive the browser session.

On the platform. What a call cost, charged against your organisation's own budget. Where the assistant used one of the platform's tools, a record of that call as well — which tool, which model, how much it consumed, how long it took, and a one-way fingerprint of what went in and what came out, so the action can be audited afterwards. The conversation itself is not stored on the platform.

What your organisation controls

Your organisation chooses how much of the assistant runs. The extension reads that setting from the platform each time it starts — it never assumes one:

Manual
The assistant is switched off. No message and no page content leaves the browser; the panel says so instead of pretending to work. Two exceptions, both named above: it still asks the platform which setting is in force, and a crash in the extension itself is still reported.
Assist
The assistant reads and answers. Anything that would change a record waits for a person to approve it, and the approval is recorded on the platform before the change is made.
Automate
The assistant may act without asking each time. Every action it takes is shown in the panel as it happens and recorded on the platform.

Today the platform serves the extension read-only tools, so the assistant can look things up but cannot change your records through them.

Who to contact

Questions about this statement, or about what the extension did in your organisation:

We answer questions about the extension at this address. Requests about the workforce records themselves go to your own organisation's administrator first — they hold the data, and we hold the platform it runs on.