Security & Privacy

Ask Screen is designed so that the content you share with AI stays between you and the AI provider you choose. This page explains what the extension can access, what it never accesses, and how we keep your account and subscription safe.

This page is maintained by Ask Screen to answer common security and privacy questions. It describes our current practices and is not a certification.

Security Overview

Ask Screen is a Chrome extension and supporting backend that lets you ask AI about anything on your screen. The extension only acts when you ask it to. Selected text and screenshots are sent directly to the AI provider you pick (such as ChatGPT, Claude, Gemini, or Grok) — not stored on Ask Screen servers.

Account-level data (your email, plan, usage counters) is stored securely in our backend and protected by row-level security so that one user can never read another user's data.

What Ask Screen Can Access

  • The page you are currently viewing, only when you trigger the highlight bubble, click Open Ask Screen, or press the capture shortcut.
  • The text you explicitly select.
  • The screen region you explicitly draw with the capture tool.
  • Your AI provider preference and language, stored locally in the browser.
  • Your authenticated session token, so the backend can verify your subscription before opening the AI.

What Ask Screen Does Not Access

Ask Screen does not read your passwords, emails, browsing history, bookmarks, downloads, or personal files.

  • We do not scan pages in the background.
  • We do not read your clipboard.
  • We do not track which tabs you open or close.
  • We do not access other browser profiles or extensions.
  • We do not collect form input, passwords, or autofill data.

Screen Capture Privacy

Screen captures happen only after you press Alt + Shift + S or click the capture button and draw a region with your mouse. The resulting image is placed on your clipboard so you can paste it into the AI tab that opens.

The image is not uploaded to Ask Screen servers. Once you paste it into the AI provider's chat, it is governed by that provider's own privacy policy.

Selected Text Privacy

When you highlight text on a page, a small Ask Screen bubble appears. Clicking it copies the selection into the AI chat tab. Until you click, nothing is sent anywhere.

Selected text is not stored on Ask Screen servers and is not included in usage logs.

Chrome Extension Permissions

The Ask Screen Chrome extension requests only the permissions it actually needs. Each one is listed below with the reason it is required and what we do not use it for.

PermissionWhy we need itNot used for
activeTabLets the extension read the page you are currently looking at, but only when you click the Ask Screen icon or trigger a capture.Reading other tabs in the background or tracking your browsing.
scriptingInjects the highlight bubble, capture overlay, and AI paste helper into the page when you ask for them.Modifying pages without your action or running code on unrelated sites.
clipboardWriteCopies your selected text or captured image to the clipboard so it can be pasted into the AI chat tab.Reading the contents of your clipboard or capturing what you have copied from other apps.
contextMenusAdds the right-click "Open Ask Screen" menu entry.Tracking right-clicks or sending menu activity off-device.
storageStores your preferences locally in the browser — for example, your chosen AI provider and language.Storing your prompts, screenshots, or selected text.
tabsOpens or focuses the correct AI tab (ChatGPT, Claude, Gemini, Grok, or your custom AI) after you ask a question.Reading the URLs or content of unrelated tabs.
alarmsSchedules lightweight background tasks such as refreshing your session.Polling external servers or sending data while you are idle.
system.displayMeasures your screen so the capture overlay aligns correctly on multi-monitor setups.Reading what is on your other screens.
host_permissions: <all_urls>Required so the highlight bubble and capture shortcut can work on any website you visit.Scraping pages, harvesting form data, or sending page content anywhere without your explicit action.

The authoritative permission list is the extension's manifest.json, shipped with each release.

Login and License Security

  • Sign-in uses Google OAuth through our authenticated backend. Passwords are never seen by Ask Screen.
  • Your subscription and daily usage limits are checked on the server before the AI panel opens, so paid features stay protected.
  • Every permission check is recorded so abuse and abnormal usage can be detected and stopped.
  • Rate limits (per minute and per hour) protect your account from being misused if a token is stolen.

Your subscription and usage limits are securely verified on our servers before paid features open.

Payments and Billing Security

  • Payments are processed by trusted providers (Paddle, Stripe, or PayPal). Ask Screen never sees or stores your full card number, CVV, or bank credentials.
  • Billing webhooks from these providers are verified with cryptographic signatures before any subscription change is applied.
  • Duplicate webhook deliveries are detected and ignored, so the same payment cannot be counted twice.
  • Subscription status (active, past due, canceled, refunded) is synced from the payment provider and used to grant or revoke access in real time.

Data We Do Not Store

Ask Screen does not store, log, or sell:

  • Selected text from web pages
  • Screenshots or captured screen regions
  • AI prompts you send
  • AI responses you receive
  • Passwords, browsing history, bookmarks, or downloads
  • Full payment card details

We only retain what we need to operate your account: your email, plan, anonymous usage counts, security events (such as denied permission checks), and billing records required for compliance.

Responsible Disclosure

If you believe you have found a security vulnerability in Ask Screen, please report it to support@askscreen.com.

  • Please do not include sensitive personal data (passwords, payment details, other users' information) in your report.
  • Please give us a reasonable opportunity to investigate and resolve the issue before public disclosure.
  • We review reports as quickly as possible and will follow up by email.

Contact

For general questions, see our Support page. For privacy questions, see our Privacy Policy. For security reports, email support@askscreen.com.