Chrome Extension Privacy
Privacy Policy for HField AI Assistant
HField AI Assistant lets signed-in brokers send selected webpage text to HField AI, review AI responses, and use HField broker login features.
Last updated: June 28, 2026
Information the extension collects or handles
The extension handles the following information only when needed to provide its features:
- Selected webpage text: text you select and choose to send through the extension context menu.
- AI responses: responses returned by the HField AI service, including any response URL detected by the extension.
- Broker login information: your broker email address, one-time login code, access token, refresh token, token metadata, and basic user details returned by the HField login service.
- Gmail login-code content: if you choose the optional Gmail login flow, the extension searches an open Gmail tab for HField one-time-code emails from
no-reply@hfield.netand reads the code needed to complete broker login. - Extension settings and status: theme, display preferences, history limits, connection status, timestamps, generated item IDs, and thread IDs used to match selections with AI responses.
How information is used
The extension uses this information to:
- authenticate you with HField broker services;
- send selected text to HField AI and display the resulting response;
- keep a local history of recent selections and AI responses in the extension popup;
- open and search Gmail for a HField one-time login code only when you explicitly choose the Gmail login option and grant Gmail access;
- save your preferences and show extension status messages.
Information shared with external services
The extension communicates with HField-operated services to provide its core functionality:
wss://ai.hfield.net/ws/hfield-platform-agentreceives selected text and a generated thread ID so HField AI can process the request and return a response.https://services.hfield.net/webreceives broker login requests, email addresses, one-time codes, refresh tokens, and logout requests needed for authentication.
The extension does not sell personal information, does not use information for advertising, and does not include analytics or tracking scripts.
Local storage and retention
The extension stores data in chrome.storage.local on your browser. This may include recent selected text, AI responses, broker email, broker authentication tokens, pending login state, settings, and status messages.
You can clear recent selections and AI responses from the extension popup. You can also sign out of broker authentication from the popup. Removing the extension from Chrome deletes its locally stored extension data.
Chrome permissions
The extension requests these permissions for the following purposes:
- activeTab: to work with the active tab when you send selected text.
- contextMenus: to add the right-click option for sending selected text.
- storage: to save settings, recent activity, status, and broker login state locally.
- scripting: to show the optional selection editor and, with permission, read the HField one-time code from an open Gmail tab.
- https://services.hfield.net/*: optional host permission used for HField broker login API requests.
- https://mail.google.com/*: optional host permission used only for the Gmail one-time-code login flow.
Gmail access
Gmail access is optional. The extension requests Gmail permission only when you choose the "Use Gmail" login option. It searches for HField login-code emails, extracts the one-time code, and clears the Gmail search field afterward when possible. The extension does not use Gmail for advertising, analytics, or unrelated email processing.
Data security
The extension uses HTTPS and secure WebSocket endpoints for communication with HField services. Authentication tokens are stored locally by Chrome extension storage. You should sign out from the extension and remove it from Chrome if you no longer want its local data retained.
Changes to this policy
This policy may be updated when the extension changes. The updated version will be posted in this file with a new "Last updated" date.
Contact
For privacy questions, contact HField at info@hfield.net.