LabKick Connector — Privacy Policy
Last updated July 31, 2026. Covers the LabKick Connector browser extension. Written to describe exactly what the extension does — no more, no less.
What the extension is for
One thing: saving the scholarly paper you are looking at — its bibliographic metadata and, where available, its PDF — into your own LabKick library on a LabKick server you choose. It does nothing in the background; every capture is started by you (a toolbar click, the popup's Save button, or the right-click “Save to LabKick” menu).
What the extension reads
- The page you capture. When (and only when) you start a capture, the extension reads the current tab to extract bibliographic metadata — title, authors, journal, DOI/PMID/PMCID/arXiv id, abstract, and PDF links. The extension's script is present on web pages so this works on any journal site, but it is inert until you act.
- The PDF, if you can see it. The extension fetches the article PDF in the page's own context, so a PDF you can access (institutional login, EZProxy, or open access) is saved with the reference. This reuses the page's own cookies in place; the extension never reads, copies, or stores those cookies.
- An optional page snapshot. Off by default. If you enable “Save a page snapshot” in the extension options, a copy of the page HTML is attached to the capture.
Where captured data goes
- To your LabKick server, and nowhere else. The metadata, attachments, and page URL are sent to the LabKick server you configured (default: app.bramantebio.com), authenticated by a personal LabKick API token you created and pasted into the extension's options page (see “What is stored” below). The token is sent only to that server, and to no other destination.
- Identifier lookups to public scholarly APIs. To clean up metadata, the extension queries up to four public bibliographic services with the paper's identifier or title only: Crossref (api.crossref.org), OpenAlex (api.openalex.org), NCBI E-utilities (eutils.ncbi.nlm.nih.gov), DataCite (api.datacite.org). These requests are sent without cookies or credentials and carry no information about you. Per those APIs' guidelines they include a fixed developer contact address (connector@bramantebio.com) and the tool name — identifying the extension's developers, not you.
What is stored, and where
- Your LabKick API token (Chrome local storage). The extension authenticates to your LabKick server with a personal API token that you create in LabKick under Settings → API tokens and paste into the extension's options page. The token grants exactly what your LabKick account can already do — no more. It is stored only on this device (never synced across devices or through your Google account), it is sent only to the LabKick server you configured — never to any other site, service, or third party — and you can revoke it at any time on that same API tokens page. Revoking it immediately cuts off the extension.
- Non-secret preferences (Chrome sync storage): the LabKick server URL you chose, your last-used lab and project, and two on/off settings (debug logging, snapshot). No passwords, no history — and never the API token.
- On your LabKick server: the references you chose to save, under your LabKick account.
- Nowhere else. The extension has no servers of its own.
What is NOT collected
- No browsing history — nothing is recorded about pages you don't capture.
- No analytics, telemetry, crash reporting, or tracking of any kind.
- No cookies read or stored by the extension.
- No data sold, shared with advertisers, or used to build profiles.
- No keystrokes, form contents, or page contents outside a capture you start.
Limited Use disclosure
The extension's use of data obtained through browser permissions adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: that data is used only to provide the single user-facing feature described above, is never sold, never used for advertising, and never transferred except to the LabKick server you configured and the public metadata APIs listed above.
Changes and contact
Material changes to this policy ship with a new extension version and update this page. Questions: connector@bramantebio.com.