Research Assistant Pro

Privacy policy

Public version 0.2.2 · updated August 17, 2026

Research Assistant Pro is designed to research the source you choose without sending its content to Needly Labs.

Information the extension handles

When you start research, the extension temporarily reads either the visible text of the active web page or only the passage you selected, together with the page title and URL. For a directly opened PDF, it retrieves that exact active PDF and extracts its text locally. If you choose Paste text, it handles only the title and text you explicitly enter in the side panel.

The extension can create an instant extractive brief from source sentences using packaged local code. On a compatible device, you may instead use Chrome's built-in on-device model for richer summaries, key points, output languages, questions, comparisons, and evidence. This information is used only for those visible research and export features.

Storage and deletion

Active page, PDF, selection, or pasted source text; generated briefs; and questions stay in the open side panel's memory unless you explicitly save a Pro project, copy, or download an export. Full source text is never stored in a project.

Summary length, output language, license state, and the encrypted Pro library are stored in chrome.storage.local. The library may contain project names and templates, source titles and URLs, generated briefs and comparisons, short evidence snippets, timestamps, and local identifiers. AES-256-GCM encryption uses a key derived from your passphrase; the passphrase and derived key are not stored. Needly Labs cannot recover a forgotten passphrase.

You can export or delete projects, download a full encrypted vault backup, restore that encrypted backup into an empty vault, and delete the complete encrypted library. The backup contains the encrypted vault record rather than readable project content. After download, you control where the backup file is stored or shared. Removing the extension or clearing its Chrome data also removes preferences, license state, and the encrypted library.

Data transfer

Research Assistant Pro does not send page content, PDF text, selected or pasted text, questions, summaries, answers, usage information, or device or research-workflow identifiers to Needly Labs. The instant extractive brief runs entirely in packaged extension code. For richer AI features, Chrome supplies and manages the built-in model. Chrome documents that the initial model may be downloaded and that inference then runs locally without sending prompt data to Google or another third party.

For a PDF, the extension may request that exact document URL so it can parse the file. The request goes to the document's existing host and may use your browser's current access; it is not routed through Needly Labs or an AI provider.

Copying or downloading a brief, or exporting a Pro project as Markdown, CSV, or JSON, is an explicit action. After export, you control where that clipboard content or file is shared.

License and checkout information

Paddle processes checkout, customer, tax, and payment information on the separate Needly Labs checkout page. The extension never receives card details. Paddle receives no research content.

Paddle sends signed subscription events to a stateless Needly Labs fulfillment Worker hosted by Cloudflare. These may contain Paddle customer, subscription, transaction, price, status, and billing-period identifiers. The Worker verifies the signature, stores no database, intentionally logs no payload, ignores unrelated fields, and sends only provider identifiers, state, timestamps, entitlement expiry, and the generated license key to Keygen. Names, email addresses, postal addresses, and card details are not sent to Keygen.

The checkout success page sends the unguessable Paddle transaction reference from its URL fragment to the Worker to retrieve the matching license, then removes the fragment after success. Cloudflare processes ordinary request metadata as the Worker host. No page, PDF, selection, pasted text, question, brief, evidence, project, passphrase, or installation fingerprint is sent to the Worker.

When you explicitly activate, check, or deactivate a license, the extension asks for optional access to api.keygen.sh and sends only the license key, compiled product ID, and a random installation fingerprint. It locally stores the license and machine IDs, fingerprint, product ID, validation timestamps, and expiry for a 30-day offline window.

Chrome permissions

  • activeTab temporarily accesses only the tab where you invoke the extension.
  • scripting runs the packaged readable-text extractor in that active tab after your action.
  • sidePanel provides the research interface.
  • storage saves preferences, provider entitlement state, and the encrypted project library locally.
  • Optional https://api.keygen.sh/* is requested only when you start a license action.

The extension requests no permanent general website host permissions and does not read browsing history.

Limited Use

Information received from Chrome APIs is used only to provide the extension's prominent research features. It is not used for advertising, profiling, credit decisions, or unrelated purposes, is not sold, and is not made available for humans to read.

Security and AI output

All executable code is packaged with the Manifest V3 extension. The extension does not load remote executable code and never changes or submits the active page. AI output can be inaccurate, so important information should be verified against the source.

Contact

Email needlylabs@gmail.com for privacy or support questions.

Questions

Email needlylabs@gmail.com. Do not include private source text, questions, or exported briefs in a support request.

← Back to Research Assistant Pro