This policy covers the Workbench Chrome extension, an optional connected Workbench Library, and Google sign-in to a Workbench account.
Chrome extension information
The extension handles text you intentionally add, the source page title and address, skill names and drafts, saved excerpts, comments, locks, markers and removal marks. This may include personal communications or other personal and user-generated content you choose to add.
On ChatGPT, Claude, Perplexity and Gemini, and on another HTTP(S) page after you activate Workbench there, the packaged capture script temporarily reads page text in your browser to identify selectable passages, locate exact saved passages and display your source annotations. It stores only content you intentionally add, together with the source information and annotations needed for those features. A tab identifier and page address may be kept temporarily in Chrome session storage while a source action is active.
Local storage and optional Library transfer
Skill drafts, source references and annotations are stored locally in Chrome extension storage. Local capture, editing, reading and export do not require a Workbench account.
When you choose Connect Library, the extension stores the exact Workbench origin and its stable account identifier, then verifies the same-origin Workbench session and compatibility endpoints. No skill content is sent during this connection check. A hosted Library requires an active Workbench session; Google is one possible Workbench sign-in method, not a requirement of the extension.
Only when you choose Save skill does the extension send the finished skill title and compiled clean text to that connected Library. Source addresses, comments, marks and other working-draft metadata are not included in that save. The extension contains no AI improvement service and sends no content to an AI model.
Google sign-in and Workbench accounts
Workbench requests only Google identity and email permissions (openid and email). A verified email address is used to match an existing private Workbench account explicitly configured by the service operator. Workbench stores Google's stable account identifier, email address and verification status to maintain that account link. Google sign-in does not create a new Workbench account. Workbench does not receive your Google password, access Google Drive or Gmail, or send Library content to Google. Technical Google tokens are processed temporarily to verify sign-in; Workbench does not store Google access, identity or refresh tokens.
A private Workbench browser session can last up to 7 days. A terminal connection grants read-only Library access for up to 90 days and can be revoked under “Manage your connections.” Library content is private by default; connecting does not publish it.
Use, sharing and security
Information is used only for the visible collection, editing, annotation, source-return, reading, export, account and explicit Library features. Workbench does not sell data or use it for advertising, profiling or credit decisions. A connected Workbench service and its hosting and database providers process the account identifier and any finished skill you explicitly save there. Human access to user content is not part of normal operation.
All extension code is packaged with the extension; it does not execute remotely hosted code. Hosted Workbench transfers use HTTPS. HTTP is accepted only for the loopback addresses localhost and 127.0.0.1 that you explicitly connect for local development or testing.
The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
Your control and support
You can edit or remove local drafts and annotations. Local data remains until you remove it or uninstall the extension. Uninstalling removes Chrome-managed extension storage. Signing out does not delete saved Library content; account access or deletion requests require support handling.
See Workbench support or email lirazgershon148@gmail.com for troubleshooting, account-access and data-deletion requests.