Privacy isn't a promise here.
It's the architecture.
SubChat has no chat backend and no analytics. Questions and user-approved drafting context go directly to the AI provider you choose. Web Mind is optional, off by default, encrypted on this device, and controlled from the dashboard.
At a glance
- No SubChat servers — nothing to send data to
- No analytics, tracking, or telemetry
- No account or sign-up required
- Web Mind is optional and off by default
- Requests run on your own logged-in AI session
- Payments handled by a merchant of record
01 What SubChat sends, and where
When you highlight text and ask a follow-up, your question — plus any context you chose to include — goes directly to the AI provider. It never passes through a server operated by SubChat, because none exists.
- On claude.ai, chatgpt.com, gemini.google.com — the request is made from within the page over your existing session cookies, exactly like the site's own interface. No API key, no separate login.
- On any other website (a Pro feature, only when you invoke it) — the request is relayed inside your own claude.ai or Gemini tab, still on your session; or, if you saved an API key, sent directly to that provider (Anthropic, OpenAI, or Google) in the fallback order you set.
What a request can contain: the text you highlighted and your typed question. With a wider context mode (Pro), it can also include nearby turns or the whole of the Claude conversation you're reading — fetched from your own Claude account — or the visible text of the current page. Context is only ever part of the prompt you send, and only to the provider answering it.
If you explicitly attach files, they are sent only to the answering AI: extractable text, code, PDF, and DOCX content is included in the request; binary or scanned files supported by Claude can upload to your own Claude account. If you enable web search, the answering provider runs its own search tool. Neither files nor search activity pass through a SubChat server.
If Web Mind supplies context, SubChat first retrieves a bounded, source-labelled set of relevant memories or local document excerpts. That context is sent only after you explicitly ask a question or choose Draft, Improve, Shorten, or Research. Ambient observation and ordinary background consolidation do not trigger an AI request. A separate off-by-default AI-assisted consolidation control changes this: only after explicit consent, an idle maintenance pass may send a bounded set of local episode summaries to your selected AI provider to propose durable memories. Returned candidates are filtered into the reviewable Inbox with provenance, not silently treated as direct facts.
When a user-triggered form suggestion references a selected public software repository, SubChat may retrieve public metadata from GitHub, npm, Visual Studio Marketplace, and a Chrome Web Store metric endpoint provided by Shields.io, such as stars, forks, contributors, release downloads, package downloads, extension installs, and current users. Those lookups use only public repository, package, or extension identifiers—not Web Mind records or unrelated form values.
On pages where SubChat is present but Web Mind is off and you do not invoke the widget, it reads or sends nothing for personalization. When Web Mind is enabled, only the sensors shown in Data controls run, and their output remains local.
02 What's stored on your device
Everything SubChat keeps lives in your browser profile. Web Mind records use extension-origin IndexedDB with record-level AES-256-GCM encryption. Store-specific keys derive from a random device key in the same browser profile; this protects database records at rest but does not replace operating-system or browser-profile security.
- Preferences — optional instruction text, widget size, theme, Claude model, and engine order.
- Connection indicator — a local flag for whether your last visit to each AI site was signed in, so the dashboard can show a status dot. No message content.
- Free-plan usage counter — a local count of subchats started today, used only to apply the free daily limit.
- Pro license key & validation state — stored with a random install id used to protect the record from tampering. It identifies your purchase, not you.
- API key (optional) — if you add one, it is stored locally and sent only to the provider it belongs to.
- Saved history (Pro) — transcripts of your subchats, so the dashboard can search and reopen them. Never uploaded; deletable per-entry or all at once.
- Web Mind (optional) — encrypted memories, episodes, source-labelled graph records, document chunks, approved field corrections, and an action audit ledger.
- Sources — files you add in the dashboard and, if “Remember attached documents” is enabled, supported documents you attach to a SubChat. Text is scrubbed for secrets, deduplicated, chunked, and indexed locally. Embedded HTTP(S) links in document text, PDF annotations, and DOCX relationships are extracted locally, stripped of query/hash data, and kept with the source.
- Chat History Builder — provider export files, saved SubChats, or messages visible in open AI chat tabs only when you start an import or enable visible-chat indexing. Closed provider history is not silently fetched.
Web Mind capture levels: Off remembers nothing new; Manual records explicit Remember/source actions; Assisted learns durable context from SubChat side-chats; Ambient also learns from supported visible AI conversations; Full Sentinel can additionally process reading activity, coarse navigation, and text you send or publish. Assisted, Ambient, and Full Sentinel are Pro features.
Local identity inference: authored statements and labelled, non-sensitive form values are converted into short typed claims such as Name, Education, Role, or Goal instead of being saved as chat fragments. SubChat can connect matching claims across documents, forms, and conversations, but it only confirms an inferred identity claim when at least two independent local sources agree and no exclusive identity claim conflicts. One-source hypotheses are not saved as confirmed memories. This deterministic process runs on-device and never triggers an AI-provider request.
Utility filtering and automatic curation: before authored web text is persisted, an on-device gate rejects short, casual, repetitive, or otherwise low-information chatter unless it contains a durable claim, decision, project detail, structured form value, or reference. Local maintenance applies the same gate to older events. By default, deterministic curation can promote high-confidence or reinforced candidates, expire stale low-confidence candidates, and archive low-quality records. Changes are recorded in the local audit ledger, remain reviewable/reversible, and automatic curation can be disabled.
Hard exclusions: password, payment, OTP, government-identity fields, incognito pages, sensitive hosts, and user-blocked sites are excluded. Secrets and high-entropy tokens are redacted before persistence. Observation can be paused at any time.
Backups: Persona Passport export files use passphrase-wrapped AES-256-GCM. Uninstalling removes local extension data, so export a Passport first if you want a backup. Cloud sync is not included in v5.2.0.
03 Data handling summary
A precise view of what is handled and where it goes. This mirrors the disclosures on the Chrome Web Store listing.
| Data | Stored | Sent to developer | Sent elsewhere |
|---|---|---|---|
| Preferences | Your browser | No | No |
| Free-plan usage count | Your browser | No | No |
| Saved history (Pro) | Your browser | No | No |
| Web Mind memories & signals | Encrypted in your browser | No | Only bounded context to your chosen AI after your action |
| Vault documents & imported chats | Encrypted in your browser | No | Relevant excerpts only after your question/draft action |
| License key | Your browser | No | To Dodo Payments, to validate |
| API key (optional) | Your browser | No | Only to the provider it belongs to |
| Your question & context | Not stored by us | No | To the AI provider you chose |
| Card / payment details | Never handled by us | No | Entered on Dodo's checkout only |
| Analytics / telemetry | Not collected | No | — |
04 Payments & license keys
Pro is sold through Dodo Payments, our merchant of record. Checkout happens on Dodo's site — they process your payment and email you a license key. We never see your card details.
When you activate the key, the extension sends it (with a short device label, e.g. your platform name) to dodopayments.com to confirm it's genuine, and re-checks it periodically. Separate user-triggered public repository research may contact the public software/catalog services described above. Dodo's handling of payment data is governed by Dodo's privacy policy. You can cancel anytime from the Dodo customer portal.
05 Analytics & tracking
None. No analytics, no tracking pixels, no fingerprinting, not even anonymous usage pings. There is nothing to opt out of, because nothing is collected.
06 Permissions, and why each exists
- storage / unlimitedStorage — preferences, license state, saved history, and encrypted Web Mind/Vault records. User-added documents and history can outgrow the default quota.
- contextMenus — the right-click “Ask SubChat” entry.
- scripting — ensures the packaged widget is present after a context-menu action and loads packaged Web Mind modules only after the worker verifies enabled, unpaused consent. It never loads remote code.
- alarms + idle — schedules housekeeping and defers persona consolidation until the browser is idle. Consolidation stays local unless you separately opt in to AI-assisted consolidation, which may send bounded episode summaries to your selected provider.
- offscreen — hosts the packaged local embedding worker without adding processing to web pages. No remote code is loaded.
- webNavigation (optional) — requested only when you enable the navigation sensor. It stores a coarse encrypted host/path event locally and is removed when that sensor is disabled.
- Access to claude.ai / gemini.google.com — where the widget runs natively on your session, and where web-mode requests are relayed.
- Access to the AI providers' API hosts — used only for the optional bring-your-own-key mode.
- Access to public software/catalog API hosts — used only after a repository-related Suggest or Research click to retrieve public GitHub, npm, VS Marketplace, or Chrome Web Store reach evidence using public identifiers.
- Presence on other websites — lets the chip and widget appear where you use them. Web Mind is separately off by default; if enabled, only disclosed sensors process local signals. Password, payment, OTP, identity fields, incognito pages, and blocked sites are excluded.
07 What SubChat does not do
- No data is sent to the developer — ever. There is no SubChat server.
- No selling or sharing of user data. No advertising.
- No remote code: everything that runs ships inside the reviewed extension package.
- Your AI accounts remain governed by their own terms (Anthropic, OpenAI, Google); SubChat is not affiliated with any of them.
08 Children
SubChat is not directed at children under 13 and does not knowingly collect information from them.
09 Changes
If this policy changes, the “last updated” date and the version note above change with it. Material changes will be reflected here before a new version that relies on them is published.
10 Contact
Questions about this policy? Reach the developer through the Chrome Web Store listing.