Skip to content

Answering exactly what an extension touches, for a client

Last checked

A consultant can answer exactly what Docognito touches, because Chrome discloses its one permission before install. It requests only storage, and its source contains no network interception code at all, so nothing about a client's own traffic passes through it either.

The question that actually matters on a client machine

Working on or near a client's device, or under an NDA that names exactly what you are allowed to touch, changes what "is this extension fine to install" actually means. It stops being a matter of taste and becomes a matter of being able to answer a direct question precisely: what does this tool touch, and can that claim be checked rather than taken on faith. A consultant who cannot answer that specifically is not in a position to install anything on or near a client's environment, disguise extension or otherwise.

This is a different bar from most personal privacy questions, and it is the one this page is actually built to answer.

What Chrome's install prompt already answers

one browser permission, storage. That is not a description written by Docognito's own marketing, it is the line Chrome itself generates from the manifest and shows before the extension is ever added, the same way it does for any extension a client might ask about. A consultant can open that prompt in front of a client, or describe it accurately beforehand, and the claim holds up because it was not authored by the party making it.

This is the part worth being precise about. Saying an extension is lightweight or minimal is a description. Saying it requests one named permission, storage, and nothing else, is a claim a client can verify themselves in under a minute on their own machine if they choose to.

Why no network interception code is the second half of the answer

The permission list covers what the extension can reach inside the browser. It says nothing on its own about network traffic, which is usually the sharper concern on a client machine or under an NDA. Docognito's source contains no call to webRequest, to declarativeNetRequest, or to any proxy API, anywhere. That is a specific, checkable absence, not a general assurance. Nothing about a client's own browsing, their other tabs, or any traffic on their network passes through the extension, because there is no code path in it capable of touching any of that.

Two separate claims, both checkable

What an extension can reach inside the browser and what it can see on the network are two different questions. Docognito answers the first with one disclosed permission and the second with an absence of any network facing API in its source.

What this looks like when a client actually asks

The honest answer to "what is that" is short: a browser extension that redraws the page you are looking at, requesting one permission that Chrome already showed on install, with no code that touches network traffic at all. That answer does not require defending a broader claim about privacy in general, and it does not require the client to trust a description rather than a disclosed fact. It is the kind of answer that closes a question rather than inviting a follow up one.

Under an NDA, precision replaces concealment as the goal

An NDA usually names categories of access rather than naming every tool by brand, which puts the burden on you to describe accurately what something touches when it comes up. A narrow, disclosed permission list is what makes that description possible without guessing. The goal under an NDA is never hiding that a tool is installed. It is being able to state exactly what it does the moment somebody asks, and a single named permission is a much easier thing to state precisely than a longer list would be.

What none of this changes

the address bar, which still reads claude.ai or chatgpt.com stays exactly as it is, regardless of the permission list or the absence of network code, and the conversation itself, which OpenAI and Anthropic still receive and store the same way it always does. This page is about being able to name what the extension touches accurately. It is not a claim that the underlying conversation becomes invisible to anyone, and it should never be presented to a client as one.

The two facts worth leading with under an NDA

If a client or an NDA requires you to state precisely what a tool touches, lead with the two facts that are actually checkable: one disclosed permission, storage, and no code path that reaches network traffic. Keep the shortcut ready if you need the real interface mid call, covered in the dedicated guide rather than here, and never describe the disguise itself as something that changes what a client's own traffic exposes.

Common questions

What can I actually tell a client who asks what this extension does?

That it requests exactly one browser permission, storage, and Chrome discloses that on the install prompt itself. It is a claim you can point the client at directly, not one you are asking them to take on trust.

Does the extension see or intercept any of the client traffic on the call?

No. Its source contains no call to webRequest, declarativeNetRequest, or any proxy API, so nothing about network traffic passes through it. It changes what is drawn on a page, not what moves across a connection.

Working under an NDA, is installing any browser extension automatically a problem?

Not automatically. What actually matters under an NDA is being able to state precisely what a tool touches rather than describe it vaguely, and a narrow, Chrome disclosed permission list is exactly what makes that possible.

Can I still reach the real interface briefly if a client question needs it?

Yes, with the same shortcut either direction. The mechanics of switching back mid call are covered in the dedicated shortcut guide rather than repeated here.

Hide AI on your screenFree Chrome extension

Add to Chrome