Research Assistant Pro
Privacy policy
Effective July 20, 2026
Research Assistant Pro is designed to research the page you choose without sending its content to Needly Labs.
Information the extension handles
When you click Summarize this page, the extension temporarily reads the visible text, title, and URL of the active web page. For a directly opened PDF, it retrieves that exact active PDF and extracts its text locally. It also handles the questions you enter and the summaries, answers, comparisons, and evidence snippets Chrome generates.
This information is used only for the visible summarization, key-point, contextual question-and-answer, project, comparison, and export features.
Storage and deletion
Active source text, generated briefs, and questions stay in the open side panel's memory unless you explicitly save a Pro project, copy, or download an export. Full page or PDF text is never stored in a project.
Summary length, output language, license state, and the encrypted Pro library are stored in chrome.storage.local. The library may contain project names and templates, source titles and URLs, generated briefs and comparisons, short evidence snippets, timestamps, and local identifiers. AES-256-GCM encryption uses a key derived from your passphrase; the passphrase and derived key are not stored. Needly Labs cannot recover a forgotten passphrase.
You can export or delete projects and delete the complete encrypted library. Removing the extension or clearing its Chrome data also removes preferences, license state, and the encrypted library.
Data transfer
Research Assistant Pro does not send page content, PDF text, questions, summaries, answers, usage information, or identifiers to Needly Labs. Chrome supplies and manages the built-in AI model. Chrome documents that the initial model may be downloaded and that inference then runs locally without sending prompt data to Google or another third party.
For a PDF, the extension may request that exact document URL so it can parse the file. The request goes to the document's existing host and may use your browser's current access; it is not routed through Needly Labs or an AI provider.
Copying or downloading a Markdown brief is an explicit action. After export, you control where that clipboard content or file is shared.
License and checkout information
Paddle processes checkout, customer, tax, and payment information on the separate Needly Labs checkout page. The extension never receives card details. Paddle receives no research content.
Paddle sends signed subscription events to a stateless Needly Labs fulfillment Worker hosted by Cloudflare. These may contain Paddle customer, subscription, transaction, price, status, and billing-period identifiers. The Worker verifies the signature, stores no database, intentionally logs no payload, ignores unrelated fields, and sends only provider identifiers, state, timestamps, entitlement expiry, and the generated license key to Keygen. Names, email addresses, postal addresses, and card details are not sent to Keygen.
The checkout success page sends the unguessable Paddle transaction reference from its URL fragment to the Worker to retrieve the matching license, then removes the fragment after success. Cloudflare processes ordinary request metadata as the Worker host. No page, PDF, question, brief, evidence, project, passphrase, or installation fingerprint is sent to the Worker.
When you explicitly activate, check, or deactivate a license, the extension asks for optional access to api.keygen.sh and sends only the license key, compiled product ID, and a random installation fingerprint. It locally stores the license and machine IDs, fingerprint, product ID, validation timestamps, and expiry for a 30-day offline window.
Chrome permissions
activeTabtemporarily accesses only the tab where you invoke the extension.scriptingruns the packaged readable-text extractor in that active tab after your action.sidePanelprovides the research interface.storagesaves preferences, provider entitlement state, and the encrypted project library locally.- Optional
https://api.keygen.sh/*is requested only when you start a license action.
The extension requests no permanent general website host permissions and does not read browsing history.
Limited Use
Information received from Chrome APIs is used only to provide the extension's prominent research features. It is not used for advertising, profiling, credit decisions, or unrelated purposes, is not sold, and is not made available for humans to read.
Security and AI output
All executable code is packaged with the Manifest V3 extension. The extension does not load remote executable code and never changes or submits the active page. AI output can be inaccurate, so important information should be verified against the source.
Seller contact information
Needly Labs is the trading name of an individual trader. Seller address and telephone details are published in the terms of service before paid checkout opens. Email needlylabs@gmail.com for privacy or support questions.
Questions
Email needlylabs@gmail.com. Do not include private source text, questions, or exported briefs in a support request.