Security
After a wave of browser extensions caught stealing AI chats, we think you deserve to know exactly how ours work.
Extensions
- Say activates only on the tab where you press the shortcut — it has no standing access to your browsing.
- No remote code: everything that runs is in the reviewed package on the Chrome Web Store.
- No analytics or tracking scripts inside the extensions.
- Your API access tokens live in the browser's extension storage and expire in 15 minutes; refresh tokens rotate on every use and a stolen one is detected and revoked automatically.
Your data
- Voice recordings and dictated text are processed in memory and never stored.
- Passwords don't exist: you sign in with Google or a one-time email code.
- Sessions and tokens are stored only as hashes. Payment details never touch our servers (Paddle.com handles them).
- You can see and disconnect every connected browser from your account, download your data, or delete your account in one click.
Infrastructure
- Hosted on Cloudflare with HTTPS everywhere, HSTS, and a strict Content Security Policy.
- Webhooks are signature-verified; all changes are code-reviewed and tested before deployment.
Report a vulnerability
Email security@opensources.dev. We respond within 72 hours and won't take legal action against good-faith research. See also security.txt.