Privacy — Locus browser extension
Last updated 10 September 2026
This covers what the browser extension reads and sends, in every browser it runs on. The terms you use it under are in its terms of use, and the web app is covered by the Locus privacy policy.
What it reads, and when
Nothing happens on a publisher’s site until you click the Locus icon. The extension runs on no article page by itself and observes no browsing.
It has exactly one content script, and it runs only on joinlocus.ai/extension/connect — the page where you connect your account. Its only job is to carry your Locus sign-in from that page into the extension, which the page cannot do by itself. It runs on no other address.
When you click it on an article page, it reads from that page only:
- The title and DOI, from the
citation_*metadata publishers publish for search engines. - Links that look like the PDF, so it knows what to download.
- The page URL, stored with the paper so you can get back to where it came from.
What it sends
When you press Add: the PDF, the title, the DOI, the page URL, and the project you picked. They go to Locus and nowhere else. Nothing is sent to any third party, and there is no analytics, tracking, or advertising code in the extension.
The download runs in your browser using the access you already have. Locus never receives your institutional credentials, your publisher cookies, or your library login — those stay in your browser, and our servers hold no credentials at any publisher.
What it stores on your machine
- Your Locus sign-in tokens, so it can add papers to your account without asking you to sign in repeatedly.
- The last project you added to, so the picker defaults sensibly.
Both live in the extension’s own local storage on your computer. Disconnect in the popup erases them, and removing the extension erases them with it.
Why it asks for the permissions it does
- activeTab and scripting — to read the article page you are on, and to run the download from inside that tab, where your access applies. Granted for that one tab, at the moment you click, and not before.
- storage — the two items above.
- joinlocus.ai — to talk to your Locus library, and to notice which project you have open so the picker can default to it.
- All sites, optional — only requested when a PDF is hosted somewhere other than the page you are on, and only at the moment that happens. Declining it costs you that one fallback; everything else keeps working.
What it never does
- Collect browsing history, or record which pages you visit.
- Run on any page you have not clicked it on, apart from the Locus connect page described above.
- Download in bulk, crawl, or fetch anything you did not ask for — one paper, on the page you are looking at.
- Sell, share, or transfer your data to anyone. It is not used for advertising, credit assessment, or any purpose unrelated to adding papers to your library.
- Contain or load remote code. Everything it runs ships in the package.
Contact
Questions, or a request to delete anything: support@joinlocus.ai.