The Art of the Possible

NEUROWEB Privacy

NEUROWEB has no analytics, telemetry, tracking pixels or behaviour profiling. This page describes every piece of data the extension stores or sends, and when. Last updated 2026-09-25 for version 0.5.0.

What stays in your browser

Focus Strip, Visual Calm, Hyperfocus, the Cognitive Load Score, the reading profiles (Dyslexia, ADHD, Autism, Dyscalculia: spacing, number twins, plain idioms, the pace reader, the load governor), Task Re-Entry breadcrumbs, Read Aloud with Chrome's own voices, the campus week map and the "Hecho en el campus" tap all run entirely inside your browser. They read the page you are looking at to change how it is shown to you. They send nothing anywhere.

By default, Read aloud uses the browser's own voices. When an optional NEUROWEB voice is available and selected, the processing described below applies instead; the sentence being read is marked on the page with a CSS highlight, which changes nothing in the page's text. The plain-idiom list (English and Spanish) and every "what would this do on this page" count shown in the popup are computed in your browser. The text size (A, A+, A++) is a setting that scales NEUROWEB's own surfaces and, under Visual Calm, the page's reading; it sends nothing.

Entregas (Moodle): on a course page the extension fetches each assignment and quiz page of that course with your own campus session, at most once an hour per activity, reads its state in your browser (open, closed, not started, in progress, submitted, graded, attempts, the grade shown) and stores it with the course on this device. The pages are not sent anywhere and nothing is written to the campus.

What is sent when you ask for a model

Some features need a language model. NEUROWEB then sends text to the NEUROWEB spine at spine-production-d838.up.railway.app, which forwards it to the model provider configured on the spine (today Google Gemini, model gemini-2.5-flash-lite; the spine can also be configured for Anthropic Claude). Only when you press the button, and only the text named here:

The request carries your sign-in token when you are signed in, or a random install id when you are not, so the spine can count the call against a daily limit. The spine keeps a receipt for each call: your account id, the date, which feature, how many characters in and out, the model name, the response time, and a SHA-256 fingerprint of the input text. The text, the file and the audio are not stored by the spine. The model provider's handling of inputs is governed by its own commercial terms (Google: Gemini API terms; Anthropic: commercial terms).

On sensitive financial and healthcare sites (a fixed hostname list in src/content/privacy-detector.ts) the AI buttons are blocked and no text is captured.

Optional NEUROWEB voices

When an optional NEUROWEB voice is available and you choose it, each sentence or short paragraph (at most 600 characters) is sent through the spine to Microsoft Azure Speech to generate audio. The selected voice and reading speed are sent with it. The provider key stays on the server. The extension says this once, under the voice picker, the first time a NEUROWEB voice is picked, and the computer's voices stay listed as the offline choice. The audio is played by an extension page Chrome keeps off screen (the offscreen permission); nothing of it is stored in the extension. If the spine refuses a sentence (the voice is off, the account is not active, the daily limit), the reading carries on with the computer's voice and the popup says why.

The spine temporarily keeps generated audio in a bounded memory cache for up to 24 hours, or less if it is evicted or the service restarts. The cache is indexed by a fingerprint of the text, voice, speed and audio format, not by your account. This does not make the content anonymous: the audio contains the words being read. The input sentence is not written to server logs or permanent storage. Authentication and subscription checks still apply each time audio is requested, including cached audio.

A separate daily usage budget records a hashed account or install identifier, the UTC date, request count and generated-character count. These records can relate to your requests; they are not an anonymous analytics dataset. They contain neither the sentence nor audio and old daily rows are pruned when the next budget check occurs. Microsoft Azure's handling of synthesis input is governed by its service terms. Transcription audio described above is separate and is not stored in this voice cache.

Account and subscription

The reading tools and the profiles need no account. For the model features you sign in at neuroweb.app with Google (through Supabase). The extension then keeps your session token and your account status (email, trial or subscription, its end date, whether the subscription can be managed) on this device, refreshes that status once a day, on sign-in and after the spine refuses a call, and stops the model features when the spine says the subscription is required and yours is not active. The subscription is a 7-day trial with a card, then a monthly or yearly plan, paid on Stripe's pages opened from neuroweb.app. "Manage subscription" in the popup asks the spine for a Stripe billing portal link and opens it; the extension never sees card details, and no payment data passes through it.

The optional page-context feed (off by default)

NEUROWEB can send a small page-context signal to the spine to power Return To Task. This is off unless you turn on "Send page context" in Settings. With it on, each signal carries the page address, the page title, the cognitive-load score and its factors, and the privacy mode. No page text, no selected text and no summary is sent. The spine stores those fields against your account id in the neuro_context table and deletes anything older than 30 days.

What is stored in Chrome

What is never collected

Browsing history, clickstream, passwords or form fields, banking or healthcare page content, advertising identifiers, crash reports.

Permissions

storage remembers your settings. activeTab and tabs let the extension act on the page you are looking at, count open tabs as one input to the load score, find the tab to return to for Return To Task, and follow the active tab in the side panel. sidePanel is where Mr. Phocuz lives. tts is Read Aloud with Chrome's voices. offscreen opens an unseen extension page that plays a NEUROWEB voice's audio when you picked one, so the reading carries on after the popup closes; it plays nothing else. tabCapture records the audio of the current tab when you press "This tab's audio" in Record a class or Video in the side panel, and only then. contextMenus adds "Study this file with NEUROWEB" to the right-click menu on links to files. alarms schedules the once-a-day account check. The page transforms also run inside embedded frames on the page (course players, H5P and Lumi lessons), so the lesson gets the same treatment as the page around it; the frames send nothing anywhere. Host permission on all sites is required for a tool whose purpose is to work on any page and any campus; it is never used to read pages you are not looking at.

Questions: johan@theartofthepossible.io