Privacy policy
Last updated: September 7, 2026
AlienMcp collects nothing, transmits nothing, and stores nothing about you. It has
no backend. Its only network destination is a WebSocket on
ws://localhost:7888 to 7899, which is the MCP server you
started on your own machine. The extension manifest pins
connect-src to localhost, so reaching anywhere else is not a policy we
promise to keep, it is something the browser will not permit.
Only while your own MCP client issues a tool call, and only for a tab you put in the AlienMcp tab group:
localStorage and sessionStorage for that siteAll of it is returned over the loopback socket to the client on your machine, and nothing is written to disk by the extension.
| Permission | Why |
|---|---|
| tabs | List, open, activate and close tabs, and read a tab title and URL |
| scripting | Run the extension bundled functions in a page to click, fill, read or scroll |
| debugger | Chrome DevTools Protocol: screenshots, PDF export, console capture, network inspection, trusted keyboard and mouse input |
| cookies | Read or clear a cookie when you ask whether you are still signed in to a site |
| storage | The extension own connection state: the generated instance id that lets the local MCP server tell two Chrome profiles apart |
| alarms | Keepalive so the Manifest V3 service worker does not drop the local connection |
| tabGroups | Scope every tool to a tab group you create, so tabs outside it are invisible |
| <all_urls> | Operate on whichever site you point your assistant at |
The extension declares no content scripts, so it injects nothing into pages you are merely browsing. Code runs in a tab only when a tool call names that tab.
As of version 1.2.0 the activeTab, webRequest and
offscreen permissions were removed: they were declared but never used.
Nothing is persisted. Captured network requests and console messages are held in memory and cleared when the extension reloads or Chrome restarts.
None. No analytics, no error reporting, no update server of ours, no bundled SDK. The source is MIT and readable, with no obfuscation and no minified vendor blobs.
Changes to this policy are noted here and in the repository changelog. Questions go to an issue on GitHub.