The short version. Pidgey Assist is a bring-your-own-key (BYOK) extension. Your API keys, your chat history, and your notes are stored on your own computer and are never sent to us. We run no analytics, no trackers, and no advertising. We do not sell or share your data with anyone.
The only time the extension contacts a Pidgey server is to validate a Phoenix licence code, and only if you have entered one.
This policy explains what the Pidgey Assist browser extension (“the extension”) does with your information. It is published by Ultimate Faux LLC (“we”, “us”), North Las Vegas, Nevada, USA.
1. What we do not collect
We want to be specific, because “we value your privacy” means nothing on its own. The extension contains no analytics SDK, no telemetry, no advertising or marketing pixels, and no error-reporting service. We do not operate an account system, so we have no name, email address, or password for you. We do not collect, log, or store:
- your API keys;
- your conversations with the AI, or anything the AI returns;
- the pages you visit, their contents, or your browsing history;
- your notes, saved files, or research history;
- your IP address, location, or device fingerprint.
2. What is stored on your device
The extension saves your settings and your work using the browser’s own
chrome.storage.local area. This is local storage on your computer. It is not synced to a
Pidgey account, and we have no ability to read it.
| What | Why it is stored |
|---|---|
| API keys | So you do not have to paste your provider key on every use. Includes your AI provider key and, if you use web search, your Tavily key. |
| Chat history | So a conversation survives closing the side panel. |
| Preferences | Chosen provider, model, image model, and interface settings. |
| Saved work | Notes, folders, and research history you create inside the extension. |
| Device ID | A random string generated on your device (for example pid_k3f9q2…).
It contains no personal information and is not derived from your hardware. It is used
only for Phoenix licence validation, described in section 5. |
3. What happens when you use the AI
When you ask Pidgey a question, the extension sends your prompt — and, when you ask it to work with the current page, that page’s text — directly from your browser to the AI provider you chose, authenticated with your own API key. That traffic does not pass through any Pidgey server. We never see it.
This means your data is handled under the privacy policy and data-retention terms of whichever provider you have configured. That is your choice to make, and it is worth reading their terms:
If you point the extension at a local model (for example Ollama on localhost), nothing leaves
your machine at all.
4. Other services the extension can call
Certain features reach out to third-party services, and only when you actively use that feature. Each one receives only what it needs to answer — a search query, or the address of a page you asked Pidgey to read.
| Service | Used for |
|---|---|
| Tavily | Web search, using your own Tavily key |
| Jina Reader / DuckDuckGo | Fetching and reading a page you asked about |
| YouTube | Retrieving a video transcript you asked to summarise |
| Yahoo Finance, CoinGecko, DexScreener | Market and token lookups in the finance tools |
5. Phoenix licence validation
Phoenix is the paid tier. If, and only if, you have entered a Phoenix code, the extension
periodically contacts pidgeyassist.com (or pidgeypost.io) to confirm the code
is still valid. That request sends three things: your Phoenix code, your randomly generated device ID,
and a session token. It carries no chat content, no page content, and no API keys.
We use this solely to stop a single licence being shared across unlimited machines. If you never enter a Phoenix code, the extension never contacts our servers.
6. Permissions, and why each one exists
| Permission | Why |
|---|---|
sidePanel |
Pidgey lives in the browser’s side panel. |
activeTab, scripting |
To read the page you are on, when you ask Pidgey to summarise or work with it. |
storage |
To save your keys, settings, and history on your device. |
tabs |
To know which tab is active and to compare information across tabs. |
contextMenus |
The right-click “ask Pidgey” shortcut. |
alarms |
Scheduling periodic background checks. |
| Per-site access | Granted one website at a time, by you, and revocable at any time. See below. |
Pidgey never asks for access to every website. When it needs to read or capture a page it has not been allowed on, it stops and shows you a single button — “Allow Pidgey on example.com”. Nothing is requested until you press it, and pressing it grants that one site and nothing else.
Settings lists every site you have allowed, each with its own Remove button, so you can take access back whenever you like. There is no “allow all websites” option, by design.
7. Limited use
Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use your data for advertising, credit assessment, or any purpose unrelated to running the extension’s features. We do not use it to train any model.
8. Keeping and deleting your data
Because your data lives on your own machine, you control it. You can clear your keys and history from the extension’s settings at any time. Uninstalling Pidgey Assist removes everything the extension stored.
The only record we hold is Phoenix licence status, and only for licence holders. To have that deleted, email us at the address below.
9. Children
Pidgey Assist is not directed at children under 13, and we do not knowingly collect information from them.
10. Changes to this policy
If this policy changes materially, we will update the date at the top of this page and note the change in the extension’s release notes. Continuing to use the extension after a change means you accept the revised policy.
11. Contact
Questions, deletion requests, or anything about this policy: pidgey@pidgeyassist.com.