Start here
The free tool below runs entirely in this browser — no account, nothing stored or transmitted. Redact anything you would not want kept before you type it.
Open the companion tool →Why 'read page content' is the permission that matters
A summarizer that only sees the page you clicked is different from one with access to all sites. The first is a tool; the second sees your banking tab, your email, and your work systems, whether or not it is asked about them.
Send-to-server is the second half of the question. An assistant that processes text on your device and one that uploads it to a vendor are different exposures, and the extension's own description or privacy page says which one it is.
The protocol
- Open your browser's extension list and read the access line for each item: 'on click', 'on specific sites', or 'on all sites'.
- Remove anything you do not actively use. Extension counts grow silently, and old ones keep their access.
- For the ones you keep, check whether the assistant sends page text to a server, and whether there is an on-device or local-processing option.
- Turn off auto-apply or automatic page reading where the tool offers it, so it acts only when you invoke it.
- Consider keeping financial, health, and work accounts in a separate browser profile with no extensions, or in a browser without them.
What the tool does
Walk through your installed browser AI tools: what each can read, whether content leaves your device, and what to remove or restrict. It runs in this browser; nothing is sent or stored.
Limit first: This is an access-review aid, not a security audit. It cannot see your extensions or your accounts, and permissions change when an extension updates.
Open the companion tool →One human next step
If an extension you removed had access to work systems, tell your IT or security contact — vendor access to internal pages is something they need to know about. For personal accounts, change the passwords for anything that was visible in a browser you shared.
Research log and safety checks
AI-assist path: not used for a verdict. Extension permissions are listed by the browser itself, which is a better source than any model's recollection of an extension's behavior. §6.10: not a frontier-pace topic.
§0.5 protection result: category is data-privacy-exposure; crisis-adjacent: no; fear/urgency/scarcity toolkit used: no. The protective function is free and the paid feature is convenience only.