Last updated: 26 August 2026. This page applies only to the Chrome / Chromium extension listed as “Community” (GriGsi). It does not describe SENDi!, Fresh and Now, or other GriGsi websites, except where the extension opens those sites in a normal browser tab.
Single purpose. The extension is a browsing trust layer: it checks domains and identifiers you type or paste, shows community trust signals and notices on websites, and can optionally connect this browser to a GriGsi group or Space.
In-product consent
On first install (and after an update if you have not yet agreed), the extension shows a privacy notice in its own UI. It does not scan pages or send data to GriGsi until you click I agree and continue. A privacy policy or Chrome Web Store listing is not a substitute for that button. You can uninstall at any time.
What the extension reads on your device
After you agree, content scripts run on http(s) pages (including iframes) so trust prompts work in compose boxes such as webmail:
- The URL / domain of pages you navigate to (to show domain trust UI and, if you choose, intercept unknown domains).
- Text you type or paste when it looks like a domain, email, phone number, or IBAN.
- Settings, votes, licence state, and allow-lists in
chrome.storage.local. Allow-lists include the plaintext values you accepted, not only hashes, so similarity checks can run locally.
The extension does not request camera, microphone, location, photos, or contacts. It does not read your clipboard except to write when you trigger Copy.
What is sent off the device (after you agree)
Traffic goes to GriGsi over HTTPS / WSS (https://grigsi.com). Every HTTPS request also exposes your IP address to our host. We use that for abuse limits; for votes we store a truncated hash of the IP, a coarse country signal, and a hash of the User-Agent, not the raw IP string.
- Install / heartbeat: a random install identifier (hash of a local random value), browser family, extension version, and
navigator.language. Heartbeats are about every six hours.
- Trust votes and checks: a truncated SHA-256 hash of the normalized value (domain, email, phone, IBAN, or text), vote (+1/−1), an opaque client id, timestamp, and optional tab id. Hashes of emails, phones, IBANs, and domains are still treated as user data. They are not a promise that the value cannot be related to you.
- Operational counts: tab id, ad/paid mode, and timestamp when a domain is allowed (
/report-tab); ad-play acknowledgements.
- Community notices / ads (free mode): the extension keeps a WebSocket to receive live notices, watermarks, or ads. Image/video URLs in those messages are loaded as media, not as executable scripts. Ads are not built by selling your browsing history to third-party ad networks. A fallback ads host
ads.grigsi.com may be used if the main ads list is empty.
- Licence: if you paste a licence key, the key, extension id, and install identifier are sent to verify the seat. Checkout itself happens on grigsi.com with the payment provider; that is website activity, not the extension reading card numbers.
- LieCheck / Space (optional): claim text and merged snippets pass through our WebSocket. The extension may fetch public HTML from DuckDuckGo using the claim as the query.
- Group / Space (optional, extra notice): if you join a group after ticking the browsing-share box, we send each visited domain in plaintext plus a group client id to the group admin. Organisation Spaces with screen activity enabled may send the active tab URL and title.
- GSI wallet display (popup): a public wallet id and balance may sync via Gun relays (
gun-manhattan.herokuapp.com, gun-us.herokuapp.com).
Uninstall opens extension-uninstalled.html. If you type feedback there, that is a website contact submission, not a running extension.
What we do not do
- We do not sell personal data.
- We do not use your browsing data to sell third-party interest-based ads.
- We do not download and execute remote JavaScript. Logic ships in the extension package. Network responses are treated as data (JSON, images, video).
- We do not require a name/email account for normal use.
Permissions (why they exist)
- storage — settings, allow-lists, hashes, install id.
- tabs and webNavigation — current URL, domain trust intercept, optional group visit reports.
- activeTab — actions on the tab you use with the extension.
- host access (all http/https pages) — trust UI and notices on pages you visit, including compose iframes.
- alarms — heartbeat and retries.
- notifications — occasional status notices.
- clipboardWrite — copy when you click Copy.
- tts — optional spoken live notices.
Retention and operators
Operational extension records (install heartbeats, vote metadata, tab-mode counts) are deleted after 90 days unless a shorter abuse or legal hold applies. Contact/uninstall feedback on the website follows the same default window.
Limited Use (Chrome Web Store)
We use the data described here only to provide and operate this extension’s disclosed purpose (trust checks, community notices, optional groups/Spaces, licence). We do not transfer it except to our host, to DuckDuckGo when LieCheck searches, to Gun relays for the optional wallet display, to a group/Space admin you joined, or as required by law. Humans at GriGsi do not read your page content except if you send it in a support message, or as needed for security, law, or aggregated internal stats.
Your controls
- Refuse the first-run notice — the extension stays idle (no scans, no server traffic).
- Options: turn off mail check, link check, LieCheck, or deactivate.
- Do not join a group/Space if you do not want domain (or URL/title) sharing.
- Uninstall removes local extension storage.
Contact
Privacy questions: use Get in Touch on grigsi.com and mention “Chrome extension privacy”.
Website and other GriGsi products: grigsi.com/privacy.html.