Chrome Extension Privacy Policy
Last updated: September 1, 2026
This policy covers the Jess: Your AI Teammate Chrome extension, operated by JESS AI LLC ("Jess", "we", "us"). The extension is a companion to a Jess account and is governed by our full Privacy Policy; this page describes specifically what the extension collects, how it is used, stored, and shared, and how to delete it.
1. Data the extension collects
- Messages and files you send to Jess in the side panel. These are transmitted over HTTPS to our servers at tryjess.com to generate a reply and carry out the work you ask for, exactly like a message sent to Jess in Slack or Telegram. Conversations are stored in your account so Jess has context in later sessions.
- Your email address, if you sign up or sign in through the side panel. We use it to send a one-time 6-digit verification code, to create or locate your account, and for the account communications described in the full Privacy Policy. Verification codes are stored hashed, are single-use, and expire after 10 minutes.
- An authentication token. After pairing (by email code, or a one-time code from your dashboard), the extension stores a scoped access token in
chrome.storage.localon your device. It identifies your Jess account to our servers and nothing else. - A desktop notification subscription, if you enable notifications, so we can tell you when Jess has finished something for you. The subscription identifies your browser to the push service; it contains no browsing data.
- Basic request metadata received server-side with any web request (IP address, browser user agent), used for security, rate limiting, and abuse prevention as described in the full Privacy Policy.
- A one-time install ping. When the extension is first installed it sends a single, empty request to tryjess.com so we can count installs. It contains no identifiers, no account information, and no browsing data, and it never repeats.
2. Data the extension does not collect
- It does not read, track, or transmit the content of web pages you visit, your browsing history, tabs, bookmarks, cookies, or form data.
- It does not inject scripts into web pages. The side panel is an isolated interface.
- It communicates with one host only: tryjess.com. No data is sent anywhere else by the extension.
- It contains no analytics, advertising, or tracking libraries.
3. How data is used
Data collected through the extension is used only to provide the service: generating Jess's replies, doing the work you ask for, maintaining your account's memory and knowledge base, sending the notifications you enabled, securing the service, and billing usage against your plan. We do not sell personal data, do not use it for advertising, and do not use the content of your conversations to train our own or any third party's AI models.
4. How data is stored
- On your device: only the authentication token and unread-notification state, in
chrome.storage.local. Nothing else is stored locally. - On our servers: your conversations, account data, and anything Jess produces for you are stored in your isolated account, hosted in the United States, as described in the full Privacy Policy. Credentials for any third-party tools you connect are encrypted at rest.
5. How data is shared
We share data only with the service providers required to operate the service (for example our AI model provider, hosting provider, and email delivery provider), each processing it on our behalf and only as needed for their function. The full list of provider categories, and everything they receive, is in Section 6 of the full Privacy Policy. A complete subprocessor list is available on request. We may also disclose data where required by law. We never sell it.
6. Retention and deletion
- Local data: disconnecting inside the extension, or uninstalling it, deletes the token and local state from your browser.
- Server data: retained while your account is active, per the full Privacy Policy. You can export everything or permanently delete your account (which also revokes every connected app) self-serve, from your dashboard's Your data section at tryjess.com.
- Verification codes expire in 10 minutes; pairing codes are single-use and short-lived.
7. Security
All traffic between the extension and our servers uses HTTPS. Access tokens are scoped to the extension, signed, and tied to your account only. Public endpoints are rate limited, sign-in codes are stored hashed with limited attempts, and each account's data is isolated from every other account.
8. Extension permissions, and why
- storage: keep you signed in between browser sessions (the token above).
- notifications: show a desktop notification when Jess has a message for you.
- sidePanel: display the chat interface in Chrome's side panel.
- Host access to tryjess.com: the only server the extension talks to.
9. Changes and contact
If we change what the extension collects, we will update this page and the extension's store listing. Questions or requests, including data export and deletion help: josh@tryjess.com.