Proofkit Privacy Policy
Last updated: 14 September 2026
This policy explains how Proofkit — the Chrome extension ("the extension") and the Google Docs add-on
("the add-on") — handles your information.
1. The short version
Proofkit has no server. Nothing is sent to, or stored on, any server run by the developer.
With the extension, the text you check and the settings you save are processed inside your own browser.
With the add-on, your document is processed inside Google Apps Script under your own Google account.
Proofkit does not use your Google user data with any AI or machine-learning model.
2. What the extension stores on your device
The following is kept in the browser's extension storage (chrome.storage) and is not sent anywhere.
| Stored | Contents | Where |
|---|---|---|
| Settings | Client presets (style guides), spelling dictionary, snippets, source URL format | On your device (local) |
| AI settings | The AI service you chose, the model name, your API key | On your device (local) |
| Copy of the text from before | The article text from immediately before you pressed "Apply all suggestions" (the most recent one only) | On your device (local) |
| Diagnostic log | Your last 20 actions and errors, and the hostname of the site you were working on | On your device (local) |
| Licence information | Paid licence key, expiry date, activation ID | Browser sync storage (sync) |
| Install record | First install date, version | Browser sync storage (sync) |
- The copy of the text from before can be deleted at any time with the "Discard" button in the side panel.
- The diagnostic log can be deleted from the settings screen with "Clear the log".
- Anything in sync storage is synchronised to your other devices through your own Google account if you have Chrome sync turned on. The developer cannot see it.
- Uninstalling the extension deletes all of the above.
3. When the extension sends something outside your device
The extension communicates with the outside world only when you take one of the following actions.
There is no other network traffic.
(1) When you run AI proofreading
Only when you press the "AI proofreading" button, the text being checked and the API key you
configured are sent to the AI service you selected. The destination is always shown on the settings screen.
- The destination depends on your choice (Anthropic, OpenAI, Google Gemini, Groq, or any OpenAI-compatible server)
- If you choose a model running on your own computer, such as Ollama or LM Studio, the text never leaves your machine
- What each service does with the text is governed by that service's own terms and privacy policy. Please read them before use
- The developer is not in the path and never receives the content — it goes from your browser straight to the service
(2) When you run source URL formatting
The pages behind the URLs you pasted are read in order to pick up the site name, article title and so on.
- Only the URLs you pasted yourself are fetched
- These requests send no cookies (
credentials: "omit"), so pages that require a login cannot be read - What is retrieved is displayed in the side panel only. It is not stored or sent anywhere
(3) When you register or verify a paid licence key
The licence key you entered and your device's activation ID are sent to the licence verification
API of Polar (polar.sh), the payment provider. No text, API key or personal information is sent.
The key may be re-verified automatically as the expiry date approaches.
4. The Google Docs add-on
(1) What the add-on accesses
- The add-on uses the
documents.currentonlypermission: it can reach only the document you have open
when you use it. It has no permission to list, open or read other files in your Google Drive - When you press "Check this document", it reads the text of the body, header and footer to find
inconsistent spellings and style-rule violations. It changes the document only at the spots you choose
to apply - The check runs inside Google Apps Script. The document text is not stored and is not sent anywhere;
nothing from the document is kept once the check has finished
(2) What the add-on stores
The following is kept in Apps Script's per-user storage (User Properties) under your Google account.
| Stored | Contents |
|---|---|
| Settings | Client presets, spelling dictionary, snippets, working language (the same items as a settings file exported from the extension) |
| Licence information | Paid licence key, expiry date, activation ID |
| First-use record | The date you first used the add-on |
- API keys are never stored by the add-on. AI proofreading is not available in the add-on, and settings
files exported from the extension never contain API keys or licence keys - This storage can be read only by the add-on when it runs for you. Other people working on the same document,
and the developer, cannot read it
(3) What the add-on sends outside Google
Only when you register or verify a paid licence key, a request is sent to two fixed addresses onapi.polar.sh (/validate and /activate). It carries only the licence key you entered, the
developer's own Polar organisation ID, and a device label such as "Proofkit (Windows)".
Document text and information about your Google account are never sent, and no other host is contacted.
(4) Google API Services User Data Policy (Limited Use)
Proofkit's use and transfer of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. The use of raw or derived user data received from Google Workspace
APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular:
- Google user data (the content of your document) is used only to provide the checks and replacements you ask for
- It is not transferred to anyone, including Polar, and is not sold
- It is not used for advertising, including personalised, retargeted or interest-based advertising
- No person reads it. The developer has no access to your documents; the only exception is text you
choose to send us yourself, for example in a support email - It is not used to develop, improve or train generalised or non-personalised AI or machine-learning
models, and the add-on does not run any AI or machine-learning model on your documents
5. How your data is protected
- No copy is held by the developer. Proofkit has no server or database of its own, so your text,
documents, settings and keys are not collected into any place where the developer could lose or leak them - Encrypted in transit. Requests to Polar and to the built-in AI services (Anthropic, OpenAI,
Google Gemini, Groq) are made over HTTPS (TLS). Local models such as Ollama and LM Studio are reached
inside your own computer (localhost). If you type in a server address yourself, the connection goes to
that address as entered, so use anhttps://address - Least privilege. The add-on can reach only the document that is open, not your Drive. The licence
requests in the add-on can go only to the two fixed Polar addresses; any other address is refused - Secrets stay where they belong. Your AI API key is kept only in the extension's local storage on your
device: it is not synchronised, not included in exported settings files, and sent only to the AI service
you selected. Licence keys are not included in exported settings files either - Separated per user. The add-on's storage is separate for each Google account and is protected by
Google's own security for Apps Script - Payment details are never seen by the developer. Payment is handled by Polar; card details are
entered on Polar's checkout and are not passed to the developer - Revoking access. You can remove the add-on from Google Docs (Extensions > Add-ons > Manage add-ons),
or revoke its access at any time at myaccount.google.com/permissions
6. What is never collected
Proofkit does not collect or transmit any of the following.
- Browsing history, or the URL of the page you are on (the diagnostic log records the hostname and nothing more)
- Personal information such as your name or email address, including those of your Google account
- Location, health, or financial and payment information
- Usage analytics (no analytics or telemetry of any kind is built in)
As a result, the developer has no way of knowing how you use Proofkit. Please report problems
using the address below.
7. Sharing with third parties
Your information is never sold, rented or handed to third parties.
Each of the transmissions in sections 3 and 4 goes to a recipient you chose yourself, and only carries what
that feature needs in order to work.
8. Information you send when you contact support
If you report a problem or otherwise get in touch, we keep what you wrote and your contact details
(your email address). It is used only to answer you and to fix and improve Proofkit, and for
nothing else.
- We may ask you to paste in the diagnostic information so we can narrow a problem down. It does not contain your article text, and you can read it on screen before you send it
- Your enquiry will never be published in a form that identifies you
9. Children
Proofkit is a tool for professional work and is not intended for anyone under 13. No information
is collected from children.
10. Changes to this policy
If a new feature changes what information is handled, this policy is updated and the date at the top is
revised. Significant changes — a new destination data is sent to, for example — are also announced in
the extension's own help page.
11. Provider and contact
Affect Inc.
Contact: support@proofkit.jp