Chrome Web Store data disclosures
GRN Waypoint handles the following Chrome Web Store data categories, including information kept only on your device:
- Personally identifiable information: the GRN Gateway associates a linked-device session with your existing GRN account ID. The extension itself does not receive or store your name, email address, or GRN user ID.
- Authentication information: short-lived authorization data and opaque, scoped access and refresh credentials.
- Location: Supabase automatically records request IP addresses and network-derived geographic metadata in GRN Gateway operational logs. This is used for delivery, security, abuse prevention, and reliability, and is retained for up to seven days under the current provider configuration.
- Web history: URLs and titles of open or explicitly recovered pages for local tab finding and recovery. This stays on your device unless you deliberately start a GRN source action, when only the bounded source information described below is sent.
- Website content: allowlisted citation metadata after Check source or Capture passage, plus the passage you explicitly select and any note you enter. If you separately enable a research-site feature, the extension reads only the allowlisted result metadata described below to show its badges and to check one identifier per page.
Waypoint does not handle health information, financial or payment information, personal communications, or general user-activity telemetry as Chrome Web Store data categories. A medical research article is website content, not your personal health information. Waypoint does not record clicks, keystrokes, mouse movement, scrolling, or general interaction analytics. Enabling a research-site feature, Research Memory, or Research Intelligence adds no new data category; each only changes what is described here, and each is off by default.
Data stored on this device
GRN Waypoint may store:
- Normal-window tab IDs, URLs, titles, window placement, pinned state, and user-assigned local labels needed for search or explicit recovery.
- Explicit safe-close recovery records for up to seven days.
- Legacy projects, saved-window recovery sets, and user notes created by older versions, until you delete them.
- Local Trail rows for recognized DOI, PubMed, and PMC URLs: source class and identifier, an identity-derived query-free canonical URL, normalized title, first and last day, count, and a 30-day expiry.
- Local deletion markers needed to prevent old snapshots from recreating deleted recovery data.
- One pending passage deliberately selected through the context menu, with reviewed provenance and a draft note, in session-only storage for no more than 15 minutes.
- When you turn on session recording and deliberately start a session: the session's start and end times and end reason, and for each recognized DOI, PubMed, or PMC source seen while recording, or each explicit Check, Save, or Capture, only its identifier, evidence type, sequence number and time, plus the GRN saved-reference, passage, and project IDs for explicit actions. The only text a session can hold is an optional name you type for it. No page title, URL, search query, page text, quote, or note is kept. At most 500 entries and 4 hours per session and 50 sessions; each session is deleted 30 days after it ends.
- When Research Memory is independently enabled, unsent canonical-source encounters in session-only storage for no more than 48 hours, containing only a GRN source ID and class, UTC day, random deduplication key and expiry.
The pending passage is cleared on cancel, successful save, logout, source-page navigation or closure, or browser restart. The session-only Research Memory queue is cleared on browser restart, logout, disable, or expiry.
Waypoint does not store remote favicon URLs. It does not capture arbitrary page contents, clipboard contents, passwords, form values, cookies, screenshots, general browser history, or incognito data.
Optional research-site features (Google Scholar, PubMed, PMC)
These features are off by default and independent. Each becomes active only when you grant that exact site's optional host permission and switch on the matching consent; disabling the consent, removing the permission, or logging out turns it off and unregisters the site's script immediately. Private (incognito) windows are never observed.
On Google Scholar, nothing is read or sent until you click the injected “Check this page in GRN” control on a visible tab. Hiding the tab stops it, and returning requires a fresh click. On PubMed and PMC, once the feature is on, the extension reads only the page's own identifier (PMID or PMCID) when a matching article page loads, to show a factual badge and check that one identifier; it does not read the page body, and it sends no query, title, or free text.
When a check is sent, it contains only the feature key and the single bounded identifier, plus the minimum values described under “Explicit source and passage actions” when you act yourself. Saving results requires a separate review and confirmation in an extension page, and nothing is saved until you confirm there.
Optional Research Memory
Research Memory is a separate, default-off GRN consent. In an already permitted recognition context, it sends only a durable canonical source ID and class, UTC day, a random deduplication key, and a collection epoch. GRN derives the account and device from the scoped session. It does not send an arbitrary URL, query, page body, precise visit time, client-supplied count, or browsing chronology.
GRN stores one private aggregate per account and source: first and last UTC day, distinct accepted device and day count, and source class. It expires 90 days after the last accepted day. Turning Memory off immediately clears the session-only queue and stops future collection; it does not replay pre-consent browsing. Export and delete remain available while collection is off. Per-source or delete-all advances a collection epoch so stale clients cannot recreate removed data. Memory deletion does not delete saved Desk sources, projects, passages, or notes. User-created export files are outside the extension's control and must be deleted by you when no longer wanted.
Research Intelligence controls
Research Intelligence is a separate, default-off contribution control. In this version it is unavailable: every event remains blocked pending per-event product and privacy approval, so operational use and Research Memory transmit no learning events.
If a later approved release enables a listed event, Waypoint may send only the event type, app and adapter version, source class, fixed outcome, and an allowed confidence value. An explicitly previewed unsupported-domain report may also send the registrable domain, a fixed page type, and three metadata-present booleans. It never includes source IDs, titles, URLs or paths, project IDs, queries, notes, passages, page content, cookies, or user identity. There is no durable local learning queue: a currently authorized event is sent immediately or dropped.
Attributable raw events expire within 30 days and attributable aggregate buckets within 90 days. Review, export, and delete remain available while contribution is off. Delete immediately blocks further collection, removes raw events and every aggregate bucket attributable to the account, and creates a server recovery job. User-created export files remain under your control.
Intentional research sessions
Research sessions are optional and off by default. Turning session recording on does not record anything; a session starts only when you press Start, and a red REC badge on the toolbar button plus a “Recording research session” bar with a Stop button in the popup and side panel show it throughout. Stop takes effect immediately and does not need a network connection. A session also ends automatically after 4 hours or 500 entries, and it ends — and never resumes — if the browser or extension restarts or the recording indicator cannot be confirmed.
While recording, Waypoint looks at the address of pages in normal windows only to recognize DOI, PubMed, and PMC pages; every other address is discarded immediately and is never stored, counted, or sent. Private (incognito) windows are never observed. It records each recognized source once per session as “visited”. The browser cannot reliably report which page led to which, so Waypoint does not record how you moved between sources, and the session review says so. Explicit Check source, Save to GRN, and Capture passage actions are added with their GRN IDs only; a captured quote or note never enters a session.
Sessions stay on this device. Session recording does not need a GRN account and makes no network request. Uploading sessions to GRN is a separate consent that is not available in this version. Turning recording off ends any active session; existing sessions remain until deleted. Each session can be reviewed and deleted in the Library, or all can be deleted at once; deleted session IDs are remembered until the session's latest possible expiry so no stale copy can recreate them. Research Memory and Research Intelligence neither start nor feed sessions, and sessions neither imply nor enable them.
Returning to a past session
A retained session can be reviewed in the Library. The review shows only what was recorded: the sources recognized during the session, the explicit GRN actions, the counts, when the session ran, and when it will be deleted. Waypoint does not summarize, score, rank, or interpret a session, does not infer why a source was opened, and does not present the order in which sources were recorded as a navigation path. A session can be given a name you type; it is optional, can be changed or cleared, stays on this device, and is never generated from a page you visited.
Resume reopens research sources you choose from a past session. It happens only when you ask for it: nothing is reopened when the browser starts, when Waypoint is opened, when a session is selected, or after an update or reconnect. Opening several sources shows a preview of exactly what will open first and waits for confirmation. A source already open is focused rather than opened again, and only the canonical doi.org, PubMed, or PMC address of a recorded source can be opened. Resuming does not start a recording.
Export writes one session to a file on your device, as Markdown or versioned JSON. It is created locally and sent nowhere; Waypoint does not upload an export and does not pass it to any AI service. An export contains only that session's recorded evidence, never other browsing, page text, credentials, or internal state. Once a file has been exported or copied, it is outside Waypoint: deleting the session here cannot change or delete a copy already saved or pasted elsewhere, and the export screen says so.
Local Trail controls
Local Trail recognition is disclosed in the extension Library. Pausing stops new recognized-source updates. Clearing removes Local Trail rows and copies but does not delete legacy recovery sets. Deleting legacy recovery is a separate action.
Recovery, backups, and deletion
Waypoint preserves existing saved projects and sets only as local recovery. Users can restore, export, or delete legacy recovery. New extension-owned recovery snapshots are limited to 20 and expire after seven days.
Deletion purges matching records from extension-owned snapshots and leaves a deletion marker so stale backups do not recreate them. Exported JSON files are user-controlled; Waypoint cannot delete copies saved outside browser storage.
Network and permissions
Waypoint has no history, web-navigation, alarm, or clipboard permission, no cookies permission, and no content script that runs by default on every page. Fonts and icons are bundled, and there are no remote font or image loads.
It uses identity for Connect; contextMenus for the user-invoked passage action; activeTab plus scripting for a one-time, top-level provenance extraction after Check source or Capture passage; and scripting again to dynamically register a bounded content script for Google Scholar, PubMed, or PMC only after you grant that exact site's optional host permission and enable the matching feature consent. Disabling the consent, removing the permission, or logging out unregisters it. At Connect it requests only the exact approved GRN authentication and Gateway origins; the Scholar, PubMed, and PMC optional host permissions are requested separately, per site, only when you turn on that specific enhancement.
Connecting permits authentication, a random device ID and label, version and platform information, consent flags and revisions, and security or revocation operations. Connecting leaves every research-sharing grant off. The release package's connect-src limits outbound network connections to the two exact reviewed GRN origins.
Explicit source and passage actions
After you press Check source or choose Capture passage, Waypoint reads only allowlisted citation metadata, the canonical link, a title fallback, and the current top-level URL needed to reject unsafe page classes.
It sends the strongest needed identity only: normalized DOI, PMID, PMCID, supported canonical identity, or a bounded hash plus minimum bibliography. It does not send raw HTML, unselected page text, clipboard data, search URLs, other tabs, cookies, or Local Trail.
A selected passage stays in session-only storage while the confirmation page shows provenance, project, and note controls. Only after Save passage to GRN does Waypoint send the reviewed passage (up to 400 Unicode characters), the optional note (up to 1,000), the resolved or confirmed source, and an optional owned GRN project. Cancel sends no passage or note. Failed or offline actions are not queued or replayed automatically.
GRN records
Confirmed sources, projects, passages, and notes are authoritative GRN Desk records, not extension storage. They remain under the existing Desk lifecycle until you remove the passage or reference, or delete the account, subject to GRN retention and backup policy.
Clearing Local Trail or disconnecting does not delete Desk records. Waypoint does not place passage or note content in analytics or diagnostics.
Credentials and disconnection
GRN returns opaque, scoped credentials rather than a broad database session. Credentials are restricted to trusted extension contexts in session-only browser storage and are cleared on browser restart or extension reload.
Disconnect blocks connected work and clears credentials locally before attempting remote revocation. While offline, Waypoint reports that remote revocation is unconfirmed. The GRN Linked devices screen can revoke the device independently.
Human access
Waypoint developers cannot access local browser data because local features do not transmit it. GRN operators do not routinely read user content. Human access to server-side account, device, consent, security, or explicitly confirmed GRN records is limited to user-requested support with explicit consent, security or abuse investigation, legal obligations, or aggregated and anonymized internal operations. Unrelated browsing remains local.
If you intentionally share an exported recovery or session file, its recipient can read the URLs, titles, labels, notes, and recorded evidence in that file.
Limited Use commitment
GRN Waypoint's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Cloudzzy:
- does not sell user data or transfer it to third parties except where necessary to provide or improve Waypoint's disclosed single purpose, comply with law, protect against abuse or security threats, or complete a merger or acquisition with the required consent;
- does not use or transfer user data for purposes unrelated to Waypoint's disclosed single purpose;
- does not use or transfer user data for personalized advertising; and
- does not use or transfer user data to determine creditworthiness or for lending purposes.
Contact
Questions about this policy or requests concerning GRN Waypoint can be sent to nihal@cloudzzy.co.uk.