Privacy Policy

The privacy policy for the Cordy for Chrome extension — what data it handles, where it is stored, where it is sent, and how you stay in control. No server, no analytics, no telemetry.

Effective date: 2026-07-15 · Last updated: 2026-09-16 · Contact: dsdev.cn@gmail.com

This is the public hosted copy of the privacy policy bundled with Cordy 2.5.4, with its effective date and contact preserved. The English text is authoritative; a Chinese translation is available by switching the site language.

Summary

Cordy is a local-first AI browsing assistant. We operate no Cordy server and collect no analytics or telemetry. We do not sell your data or use it for advertising. Data is stored locally; transmission is limited to the user-requested features described below, including requests to your chosen AI provider or configured runtime.

What data Cordy handles, and where it goes

DataWhere it is storedWhere it is sent
Chat messages and conversation historyLocally, in your browser (IndexedDB)To the AI provider you configured, only after you accept the one-time data-use confirmation
Web page content (text you select, or page text you explicitly reference with @-mentions or AI tools)Processed in memory; referenced excerpts are kept with the conversation locallySame as above — only as part of a request you initiate, only after consent
API keys for AI providers or configured runtimesEncrypted locally, in browser secure storage (IndexedDB, non-extractable encryption key). Never synced, never uploaded to usOnly to the corresponding configured provider or runtime, as authentication for user-requested features, including provider configuration and model discovery
Settings, tabs metadata, saved content, and bookmark data used for local display/organizationLocally (IndexedDB / browser extension storage)Local browsing, organization, and search alone do not send this data to an AI provider
Tab and bookmark titles and URLs; history titles, URLs, and visit times included in context attached with @ references or retrieved by AI browser tools for your requestBrowser APIs and local extension storage; referenced context may be retained with the conversationTo your chosen provider or configured runtime as part of your AI request; cloud AI content requests require data-use consent
Text spoken aloud with a cloud TTS voice (if you select one)Not stored beyond playbackTo the cloud TTS provider you selected, gated by the same consent
Text spoken with local TTS (Kokoro / your browser's Web Speech)Processed entirely on-deviceNowhere
Bookmark URLs checked by dead-link detection, only when you press the check buttonNot stored beyond the result listTo the bookmarked site itself, and only for sites you have granted access to — never to Cordy or any server of ours. Sites without a grant are skipped without any request

Third-party AI providers

Requests go directly from your browser to the provider or runtime endpoint you configured (for example OpenRouter, Volcano Ark, a custom OpenAI-compatible endpoint, or a model runtime). There is no intermediary server operated by Cordy. Each provider processes your content under its own privacy policy, which you should review.

Browser on-device models and Chrome's built-in AI run inference on your device without sending inference content to a cloud provider. Runtime requests go to the endpoint you configure; only a runtime running on your machine provides same-device processing. Cloud AI content requests require consent. API-key authentication for provider configuration and model discovery is separate from sending chat content.

Model and language-pack downloads

When you enable optional on-device models (for example local TTS or a local chat model), Cordy downloads static model files from public hosting such as Hugging Face. The host receives normal request metadata, such as your IP address and browser headers, but Cordy does not attach chat, page, bookmark, or browsing-history content to the model-file request. Downloaded files are cached locally.

  • The first time a content request would go to a cloud AI service, Cordy shows a confirmation dialog. That content is not sent unless you accept.
  • You can revoke consent at any time in Settings → Data & Privacy. After revocation, cloud requests are blocked again until you re-consent.
  • You can export a backup from the dashboard and clear application data in Data Management. Both full and selective cleanup preserve your bookmarks; manage individual bookmarks in the bookmark manager. API-key deletion is a separate choice.
  • The in-page text-selection assistant can be turned off in Settings.

Browser permissions

Cordy requests only a small set of permissions at install and asks for the rest at first use. A plain-language guide to every permission, and how to revoke each one, is on the Privacy & permissions page.

What Cordy does NOT do

  • No analytics or telemetry of any kind.
  • No sale of user data or use for advertising. Data transmission is limited to the user-requested features described above.
  • No remote configuration or remote code.
  • No collection of browsing history for any purpose other than the features you explicitly invoke.

Changes

If this policy changes materially, this page and the copy bundled with the extension will be updated with a new effective date.