ShroomPenAdd to Chrome

How ShroomPen handles your data

ShroomPen sends text only when you ask it to write something, and only to the AI provider you set up. The request goes straight from your browser to that provider: OpenRouter, OpenAI, Google Gemini, Anthropic, or a server on your own computer such as Ollama or LM Studio. There is no ShroomPen account, no ShroomPen server in between and no telemetry from the extension. Your API keys and settings stay in Chrome’s extension storage on your device.

Published

The short version

  • Nothing is read or sent until you have seen a disclosure inside the extension and chosen “Enable ShroomPen”.
  • Page, field, selection and tab text is read only when you switch that source on for a request.
  • Your instruction, the context you switched on and your API key go directly from your browser to the provider endpoint you configured. ShroomPen runs no backend, hosts no model and has no user accounts.
  • The extension sends no analytics, usage data or telemetry.
  • Remote providers must use HTTPS. Plain HTTP is accepted only for loopback addresses on your own computer.

The legal version is the privacy policy. This page says the same things in a table, so you can check them quickly.

Before it does anything: consent

The first time you open ShroomPen it shows a disclosure: what it reads, where that data goes, what it stores and how it connects. Until you tick the box and choose “Enable ShroomPen”, the overlay shows only that disclosure, the Input Helper does not attach to any text field, and the extension’s background worker refuses to generate text, test or save providers, list your tabs or read them. Choosing “Not now” stores nothing. If the disclosure changes in a way that matters, ShroomPen asks again.

What it reads, where it goes, what it keeps

DataWhen ShroomPen reads itWhere it goesStored?
Your instructionWhen you send a requestYour providerIn session Recents only (see below)
Current field textWhen “Current field” is on for the requestYour providerNo, held in memory for the session
Current page textWhen “Current page” is on. Visible text, capped at 12,000 charactersYour providerNo
Selected textWhen you use it as contextYour providerNo
Other tabsThe tab picker lists open tabs’ titles and addresses. A tab’s text is read only when you pick that tabYour provider, for picked tabs onlyNo, unless you choose “Save context to Workspace”
PDF tabsWhen you pick a PDF tab. ShroomPen asks for permission to reach that site, downloads the PDF from the tab’s own address and parses it inside the extension (up to 40,000 characters or 80 pages)The extracted text goes to your provider. The PDF itself is never uploaded for parsingNo, unless saved to a Workspace
Google DocsWhen you read the current page or pick a Docs tab. ShroomPen asks docs.google.com for the plain-text export, using your existing Google sign-inYour providerNo, unless saved to a Workspace
Workspaces (instructions, notes, imported .txt or .md, saved tab snapshots)When the Workspace is active or a source is switched onYour provider, when included in a requestYes, in local extension storage. Saved page text is capped at 12,000 characters
API keys and provider settingsWhen you add a providerOnly to that provider, with its requestsYes, in local extension storage, without extra encryption
Recents (your prompts and results)After each requestNowhereSession storage, up to 40 conversations per window. Cleared when the browser restarts or the extension reloads. The raw page, field or tab context is not copied into Recents
OpenRouter sign-inWhen you choose to sign in with OpenRouteropenrouter.aiTemporary sign-in state in session storage, removed when sign-in ends. The returned key is stored locally
Rating-request counterAfter each successful Insert or ReplaceNowhereYes, in local extension storage: counts, dates and flags only, no text or site names. Used to show a one-line request to rate ShroomPen at most twice

What your provider receives

When you ask for a draft, the provider gets your instruction, the context sources you switched on, the active Workspace’s instructions, any earlier turns of the conversation you kept, and the API key for that provider. A connection test sends the key, the model name and a short fixed test prompt. Loading the model list may also send the key.

Requests to OpenRouter also carry headers that name the app: HTTP-Referer: https://shroompen.com, X-OpenRouter-Title: ShroomPen and the older X-Title: ShroomPen. OpenRouter uses them to credit usage to ShroomPen on its public app pages. They contain no information about you.

You can see exactly what will be sent: the overlay can show the composed request before it goes out, with your API key hidden. What the provider does with the request after that is governed by its own privacy policy and terms.

What ShroomPen never collects

  • No extension analytics, usage events, crash reports or telemetry.
  • No ShroomPen account, identity profile or cloud conversation history.
  • No passive browsing history. Tab titles and addresses are read only to show the tab picker you opened.
  • No sensitive fields. Password inputs, and fields whose name, label or autocomplete hint points to one-time codes, card numbers, security codes, PINs, account or routing numbers, IBANs or social security numbers, are skipped.
  • No remote code. All extension code ships in the package, and provider replies are treated as text, never run.

Page text is also treated as untrusted. The prompt tells the model to use page, field, tab and PDF text as reference material and to ignore any instructions hidden inside it.

Local models keep everything on your computer

If you connect a local server such as Ollama or LM Studio at http://localhost or http://127.0.0.1, requests go to that server on your own machine and nowhere else. ShroomPen accepts plain HTTP only for loopback addresses (localhost and its subdomains, 127.0.0.1 and ::1). Any other address, including your local network, must use HTTPS. The check runs before a provider is saved, before every connection test and model lookup, and before every request. Setup guides: local LLM browser extensions and LM Studio in Chrome.

Permissions it asks Chrome for

PermissionWhy
storageProvider settings, keys, Workspaces (local) and Recents (session)
tabsThe tab picker, so you can choose other tabs as context
contextMenusThe “Open ShroomPen” right-click item
identityOne-click OpenRouter sign-in
offscreenA short-lived hidden extension page that parses PDFs locally
openrouter.ai site accessDeclared up front, for OpenRouter
Other sites (optional)Asked at runtime, one exact address at a time: the provider you configured, or the site of a PDF tab you picked. Chrome asks you to confirm. Local PDF files need a separate one-time grant plus Chrome’s “Allow access to file URLs” switch

ShroomPen does not request activeTab. Its content script runs on normal http and https pages so the Input Helper and overlay are available, but running there does not send anything anywhere. You can turn ShroomPen off for specific sites in its settings.

Deleting your data

Settings, Clear local data removes provider settings and keys, Workspaces and their sources, per-site defaults, disabled sites, your shortcut, the rating-request counter and your consent record, which sends you back to the disclosure. It does not clear session Recents (a browser restart does), revoke keys at the provider, remove Chrome site permissions you granted, or delete anything your provider already logged. Revoke keys on the provider’s site and site access at chrome://extensions. Uninstalling the extension removes everything it stored.

The website is separate

This website, shroompen.com, counts page views with Vercel Web Analytics: page address, referrer, rough location, browser, operating system and device type, with no cookies. The extension sends no data to the website. The only connection is that a fresh install opens the welcome page once, as a plain page load with nothing added to the address. The welcome page and the privacy policy do not load analytics. Details are in the privacy policy.

Related

Questions

Does ShroomPen see my API key?

The key is stored in the extension’s local storage in your Chrome profile and is sent only to the provider it belongs to, with each request to that provider. There is no ShroomPen server for it to be sent to. ShroomPen does not add its own encryption on top of Chrome’s storage, so anyone with access to your browser profile could read it.

Does ShroomPen train AI models on my writing?

No. ShroomPen has no model and no server that receives your text. Whether your provider trains on your requests depends on that provider’s own terms, so check them, or use a local model if the text must not leave your computer.

Is ShroomPen open source?

No, the extension is closed source. You can still watch every request it makes: open chrome://extensions, turn on Developer mode, click “service worker” under ShroomPen and use the Network tab.

Does ShroomPen read password fields?

No. Password fields and fields that look like one-time codes, card numbers, security codes, account or routing numbers and similar secrets are skipped when ShroomPen collects the current field or page text.

Can ShroomPen work without sending anything to the internet?

Yes, if you connect a local server such as Ollama or LM Studio on localhost. Requests to a loopback address stay on your computer. Opening a PDF tab or a Google Doc as context still downloads that file from its own site.

How do I delete what ShroomPen stored?

Open ShroomPen settings and use Clear local data. It removes provider settings and keys, Workspaces, disabled sites, your shortcut, the rating-request counter and your consent record. Session-only Recents are cleared when the browser restarts or the extension reloads. Uninstalling removes everything the extension stored.