A consultant can answer exactly what Docognito touches, because Chrome discloses its one permission before install. It requests only storage, and its source contains no network interception code at all, so nothing about a client's own traffic passes through it either.
The question that actually matters on a client machine
Working on or near a client's device, or under an NDA that names exactly what you are allowed to touch, changes what "is this extension fine to install" actually means. It stops being a matter of taste and becomes a matter of being able to answer a direct question precisely: what does this tool touch, and can that claim be checked rather than taken on faith. A consultant who cannot answer that specifically is not in a position to install anything on or near a client's environment, disguise extension or otherwise.
This is a different bar from most personal privacy questions, and it is the one this page is actually built to answer.
What Chrome's install prompt already answers
one browser permission, storage. That is not a description written by Docognito's own marketing, it is the line Chrome itself generates from the manifest and shows before the extension is ever added, the same way it does for any extension a client might ask about. A consultant can open that prompt in front of a client, or describe it accurately beforehand, and the claim holds up because it was not authored by the party making it.
This is the part worth being precise about. Saying an extension is lightweight or minimal is a description. Saying it requests one named permission, storage, and nothing else, is a claim a client can verify themselves in under a minute on their own machine if they choose to.
Why no network interception code is the second half of the answer
The permission list covers what the extension can reach inside the browser. It says nothing on its own about network traffic, which is usually the sharper concern on a client machine or under an NDA. Docognito's source contains no call to webRequest, to declarativeNetRequest, or to any proxy API, anywhere. That is a specific, checkable absence, not a general assurance. Nothing about a client's own browsing, their other tabs, or any traffic on their network passes through the extension, because there is no code path in it capable of touching any of that.
Two separate claims, both checkable
What an extension can reach inside the browser and what it can see on the network are two different questions. Docognito answers the first with one disclosed permission and the second with an absence of any network facing API in its source.
What this looks like when a client actually asks
The honest answer to "what is that" is short: a browser extension that redraws the page you are looking at, requesting one permission that Chrome already showed on install, with no code that touches network traffic at all. That answer does not require defending a broader claim about privacy in general, and it does not require the client to trust a description rather than a disclosed fact. It is the kind of answer that closes a question rather than inviting a follow up one.
Under an NDA, precision replaces concealment as the goal
An NDA usually names categories of access rather than naming every tool by brand, which puts the burden on you to describe accurately what something touches when it comes up. A narrow, disclosed permission list is what makes that description possible without guessing. The goal under an NDA is never hiding that a tool is installed. It is being able to state exactly what it does the moment somebody asks, and a single named permission is a much easier thing to state precisely than a longer list would be.
What none of this changes
the address bar, which still reads claude.ai or chatgpt.com stays exactly as it is, regardless of the permission list or the absence of network code, and the conversation itself, which OpenAI and Anthropic still receive and store the same way it always does. This page is about being able to name what the extension touches accurately. It is not a claim that the underlying conversation becomes invisible to anyone, and it should never be presented to a client as one.
The two facts worth leading with under an NDA
If a client or an NDA requires you to state precisely what a tool touches, lead with the two facts that are actually checkable: one disclosed permission, storage, and no code path that reaches network traffic. Keep the shortcut ready if you need the real interface mid call, covered in the dedicated guide rather than here, and never describe the disguise itself as something that changes what a client's own traffic exposes.