opensources.dev

Security

After a wave of browser extensions caught stealing AI chats, we think you deserve to know exactly how ours work.

Extensions

  • Say activates only on the tab where you press the shortcut — it has no standing access to your browsing.
  • No remote code: everything that runs is in the reviewed package on the Chrome Web Store.
  • No analytics or tracking scripts inside the extensions.
  • Your API access tokens live in the browser's extension storage and expire in 15 minutes; refresh tokens rotate on every use and a stolen one is detected and revoked automatically.

Your data

  • Voice recordings and dictated text are processed in memory and never stored.
  • Passwords don't exist: you sign in with Google or a one-time email code.
  • Sessions and tokens are stored only as hashes. Payment details never touch our servers (Paddle.com handles them).
  • You can see and disconnect every connected browser from your account, download your data, or delete your account in one click.

Infrastructure

  • Hosted on Cloudflare with HTTPS everywhere, HSTS, and a strict Content Security Policy.
  • Webhooks are signature-verified; all changes are code-reviewed and tested before deployment.

Report a vulnerability

Email security@opensources.dev. We respond within 72 hours and won't take legal action against good-faith research. See also security.txt.