Last updated: 8 September 2026
Who we are and scope
ONEKIN is a research group at the University of the Basque Country (UPV/EHU), Spain. This policy explains how user data is handled by browser extensions developed and published by ONEKIN that link to this page, including AnnotateGPT, and by our website, https://onekin.org. For privacy questions or requests, contact xabier.garmendiad@ehu.eus.
Our extensions provide different functions. The sections below apply when the corresponding function is present in the extension you use. Its store listing, settings and in-product notices identify its functions and connected services. Any additional data processing or recipient must be disclosed before that processing begins; this policy does not authorize undisclosed collection or sharing.
Data handled by our extensions and why
Documents and website content. Annotation, analysis and web-augmentation features access the documents or pages on which they operate. This can include PDF text, selected passages, titles, document identifiers, URLs or local file references, and content you add. These data are used to display and associate annotations, analyse content, and produce the results you request. In AnnotateGPT, this includes manuscripts, review criteria, prompts, comments, highlights and generated assessments. Content submitted for AI analysis can include the full extracted document text, not just a selected passage.
Preferences and credentials. Extensions store settings needed to operate, such as review models, custom prompts, selected AI models, service endpoint addresses, API keys and, for integrations that require them, authorization tokens. Credentials authenticate requests to the relevant service. Saving an AI endpoint can itself contact that endpoint to retrieve its available models.
Work products and interactions. Extensions can retain annotations, generated responses, maps, feedback and records of interactions needed for features such as revisiting an exploration or exporting work. For example, ChatInVis stores interaction and feedback records in browser storage to support its exploration features.
Support. If you contact us, we receive your email address, message and any files or diagnostic information you choose to send. We use them to answer your request and investigate the reported issue. Please do not include API keys or confidential manuscripts in support messages.
Local storage and browser synchronization
Data stored locally remain in the browser profile unless a feature sends them to a connected service or you export or share them. AnnotateGPT stores its annotation database locally. Local processing and storage are still forms of handling user data.
Some settings use Chrome storage synchronization. In AnnotateGPT this includes endpoint configuration and API keys, selected models and custom prompts. When Chrome synchronization is enabled, Google may store and synchronize those data across browsers signed in to your account, according to your Chrome settings and Google’s Privacy Policy. Such settings should not be treated as exclusively device-local. ONEKIN does not receive a copy simply because Chrome synchronizes them.
External services and recipients
AI services. When you request an AI feature, the service receiving the request processes the prompt and the document, annotation, question or map content included as context, together with authentication and connection information such as your IP address. It returns generated results to the extension. Recipients depend on the selected integration: AnnotateGPT offers OpenAI, Google Gemini, Groq, OpenRouter, DeepSeek, Mistral AI and Together AI, as well as a custom OpenAI-compatible endpoint, including a local or self-hosted server. Other ONEKIN integrations, such as ChatInVis, also support Anthropic. Only the services used by the relevant feature receive its requests. Where you configure a custom endpoint, its operator is the recipient. If you use a routing service such as OpenRouter, the underlying model provider may also receive the request.
AnnotateGPT fallback processing. Its current implementation also contains an OpenAI embedding fallback after an AI rate-limit error. This route can send document chunks and a query to OpenAI using the configured API key, even when the main endpoint is different. Selecting a custom or local endpoint therefore does not, by itself, guarantee that every attempted request remains local.
Connected applications. For extensions that integrate with MindMeister, such as Chatin and ChatInVis, MindMeister receives the map content and requests needed to read, create or update your maps, using your authorization. Maps are retained in your MindMeister account and are subject to its sharing settings. Document metadata lookup features can send a document DOI to doi.org and its resolution destination to retrieve bibliographic information.
People you share with. Exporting creates files under your control. If you send an exported review, annotation file or map to another person or service, they receive its contents, which may include document references, quotations and comments. Exported files are not deleted when you uninstall the extension.
Third-party services have their own retention, security and data-use practices, which can vary by account, API offering, model and region. Consult the selected provider’s privacy terms before sending content. Their processing may occur outside your country, including outside the European Economic Area. ONEKIN cannot erase data directly from an independently operated provider account or promise that a provider will not retain or use submissions. For confidential or unpublished manuscripts, use only services and account settings permitted by the document owner and the applicable publication or review rules.
Limited use of extension data
ONEKIN’s use of data obtained through browser extensions is limited to providing and supporting their disclosed user-facing functions, in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell extension user data, use it for personalized advertising, or use browsing activity for unrelated profiling. Transfers are limited to providing the disclosed functions, complying with applicable law, or protecting security.
We do not allow human access to extension user data except with your consent to review specific data, where necessary for security or legal compliance, or for internal operations using aggregated and anonymized data as permitted by the Chrome Web Store policy. Participation in a research study requires its own information and consent process; installing an extension does not by itself enroll you in a study or authorize researchers to receive your documents.
Retention, deletion and your choices
Local work and settings are kept until you delete them using the extension’s controls or remove the associated browser storage. You can delete annotations and configured endpoints through the available settings, remove the extension, and manage synchronized data through Chrome. Clearing local data alone may not remove synchronized copies or data held by external services. Revoke API keys and connected-application permissions at their provider if you want to prevent further access.
Data sent to AI providers or saved in connected applications follow those providers’ retention and deletion rules. Use their account controls or contact them to request deletion. Delete exported files separately wherever you stored or shared them. We retain support correspondence only as needed to handle the request and any necessary follow-up, subject to applicable legal obligations.
You can restrict site and file access in the browser’s extension settings, avoid optional integrations, or disable or uninstall an extension to stop its future processing. Features requiring revoked permissions will no longer work. Where we hold personal data about you, you may contact us to request access, correction or deletion, and, where applicable, restriction, portability or objection to processing. You may withdraw consent for consent-based processing without affecting prior lawful processing, and may complain to the competent data-protection authority. Identify the extension and the request without sending passwords or API keys.
Security
Access to documents and services depends on the browser permissions and credentials granted to the extension. Use HTTPS for remote API endpoints and keep your browser and extensions updated. Browser storage is not a dedicated encrypted secrets vault: protect your device, browser profile and synchronized account. No storage or transmission method can be guaranteed completely secure.
Visiting the ONEKIN website
Website handling is separate from extension processing. Web requests expose technical connection information, including IP address and browser information, to the website infrastructure so it can deliver pages and protect the service. WordPress uses cookies for login sessions and account preferences; these are not extension tracking cookies.
If you submit a website comment, the submitted information and associated IP address and browser information are used to display and moderate it. Approved comments are public. Where Gravatar is used, an email-derived hash is sent to Automattic to obtain an avatar; see Automattic’s Privacy Policy. Comments and their metadata are retained while published and for moderation, unless removed. Website account information remains while the account is maintained, subject to deletion requests and necessary legal or security retention.
External links and embedded content are operated by their respective providers. Loading embedded content can disclose your IP address and browser information to that provider and permit its cookies. Contact us using the address above for requests concerning website data.
Changes to this policy
We update this page when our practices change and show the latest revision date above. Material changes in an extension’s data handling must also be explained through its relevant notices, with consent requested where required, before the new processing takes place.
