Privacy & Security

What StudyChime can access, store, and send.

Browser extensions deserve extra scrutiny. This page explains StudyChime’s permissions, storage, network requests, and monetisation boundaries in plain English.

No passwordsNo cookie permissionsNo ad trackingNo telemetryLocal settings

Permissions explained

Privacy and security, in plain English.

StudyChime needs enough access to monitor your open Prolific studies page and send the alerts you configure. It is personal and local-first, not account-based. It is not designed to read unrelated websites, collect passwords, or build advertising profiles.

Prolific page access

StudyChime has required website access only to Prolific and the StudyChime licence service. It passively observes changes to your open studies page to detect matches and apply your alert settings.

  • Reads study details visible on the Prolific studies page
  • Uses that information to match your alert settings
  • Does not reserve, accept, or submit studies for you
  • Does not automatically refresh Prolific

Monitoring recovery

Every five minutes, Chrome can wake StudyChime for a local health check. If Chrome has disconnected the monitoring script, StudyChime can restore it, only on the exact https://app.prolific.com/studies page.

  • Does not refresh, navigate, or modify the Prolific page
  • Health checks do not send requests to Prolific or transmit personal data
  • Runs bundled code in Chrome's isolated extension environment
  • No remote code is downloaded or executed

Local browser storage

StudyChime stores settings, destination details, Quick Start completion, and Milestone progress locally in Chrome.

Premium settings also stay local, while Trends keeps up to 12 months of data.

  • Alert destinations and settings
  • Quick Start completion status
  • Milestone totals and permanent local unlocks
  • Filters, schedules, and customisation
  • Local Trends data contains no titles, researcher names, descriptions, or URLs
  • Schedule coverage is estimated locally from existing anonymised Trends records
  • Destination credentials stay in extension storage
  • Non-sensitive JSON backups can preserve settings and Milestones, but exclude credentials, licences, installation identifiers, and notification mappings

Notifications and alert services

If you configure external alerts, StudyChime sends matching study alerts to the services you choose, such as Discord, Telegram, or Pushover.

  • Only sends alerts to destinations you configure
  • Alert messages may contain study title, reward, time, and link
  • You control which services are enabled
  • Chrome asks for destination access only when you configure or test it

Licence, trial, and quota checks

StudyChime may contact the StudyChime licence service to check quota status, trial status and Premium licence status. These checks are separate from your Prolific account.

  • Checks whether Premium or trial licence is active
  • Checks remaining quota
  • Does not send your Prolific password or browser cookies

No password or cookie permissions

StudyChime does not ask for your Prolific login details and does not request Chrome cookie permissions. You sign in to Prolific normally in your browser.

  • No Prolific password requested
  • No Chrome cookie permission requested
  • No attempt to bypass Prolific login

No tracking or telemetry

StudyChime is not an advertising product. It does not show ads, collect behavioural telemetry, build advertising profiles, add tracking pixels, or sell user data.

  • No ads inside the extension
  • No behavioural telemetry
  • No behavioural advertising profiles
  • No sale of user data

Network requests

What leaves your browser?

StudyChime only sends data when it needs to deliver an alert, check your licence, trial or quota status, or call a service you configured. Help and feedback only leave your device if you choose to send the email draft.

Alert services

If enabled, matching study alerts are sent to Discord, Telegram, or Pushover. Alert content may include the study title, reward, estimated time, and link.

Free users can send up to 15 external alerts in any rolling 24-hour period; old quota events and expired rate-limit records are deleted during daily cleanup.

StudyChime licence service

Installation and activation IDs, licence details, signed entitlements, quota events, rate-limit records, trial redemptions, and the extension version may be processed by the StudyChime licence service. Prolific passwords and browser cookies are not sent.

Email drafts

Help and feedback actions open a draft in your email application. Nothing is submitted automatically; if you send it, your email provider processes the message and StudyChime support receives it.

Nothing else by default

StudyChime does not send unrelated browsing history, behavioural telemetry, ad tracking data, or behavioural profiles.

Data

Where information lives.

Most StudyChime data stays in Chrome storage on your device. Data only leaves your browser when you configure an alert provider, start a trial, activate Premium, check licence or quota status, or complete a purchase through Lemon Squeezy.

  • Local browser: settings, Quick Start completion, destination credentials, cached quota state, Milestone totals and unlocks, Premium settings, entitlements, and Trends observations.
  • Prolific: StudyChime reads the normal studies page your browser is already signed into.
  • Alert providers: matching alert text and the credentials needed to deliver it are sent only to the destination you enable.
  • StudyChime licence service: licence keys, installation and activation IDs, extension version, signed entitlements, quota events, rate limits, and trial redemption records.
  • Lemon Squeezy: handles checkout and payment data. Its verified webhook events update licence and order state in the StudyChime licence service; StudyChime stores only a keyed hash of customer email addresses.

Integrations

Provider integrations.

Each integration is optional. You can use browser notifications and sound only, or enable one or more external alert providers.

Discord

Discord alerts use a webhook URL you create. StudyChime sends matching study alert text to that webhook only when Discord alerts are enabled.

Telegram

Telegram alerts use a bot token and chat ID. The bot token is sensitive, so the setup guide tells users to treat it like a password and revoke it if exposed.

Pushover

Pushover alerts use a user key and app token. Pushover may apply its own message limits or account requirements separately from StudyChime.

Chrome permissions

Chrome permissions explained.

Chrome permissions can sound broad when they are listed in the Web Store. This table explains why each permission or allowed service is needed.

PermissionWhy it is neededTrust note
Chrome permissions
alarmsWakes StudyChime every five minutes for a local monitoring connection health check.The check only targets an already-open Prolific studies page and sends no request to Prolific.
notificationsShows Chrome browser notifications for matching studies.Only fires when notifications are enabled.
offscreenAllows StudyChime to play alert sounds in the background.Used for alert audio only, not screen recording or page capture.
scriptingRestores StudyChime's monitoring script if Chrome has disconnected it.Limited to the exact Prolific studies page, runs in Chrome's isolated world, and never downloads remote code.
storageSaves settings, Quick Start completion, quota state, and Milestone progress, licence status, filters, schedules, customisation, and local Study Trends.Most extension data remains in Chrome storage on your device; Milestones use extension storage and Trends uses local IndexedDB when Premium is available.
Required website access
https://app.prolific.com/*Lets StudyChime monitor your open Prolific studies page, detect matching studies, and recover its local content script when needed.Recovery targets only https://app.prolific.com/studies. It does not refresh, navigate, or modify the page.
StudyChime licence serviceHandles licence activation, signed entitlements, trials, and the free limit of 15 external alerts per rolling 24-hour period.It does not receive health-check messages, destination credentials, alert contents, Prolific passwords, cookies, or local trends.
Optional destination access
https://discord.com/*Sends Discord alerts to webhook URLs you configure.Chrome asks for this permission only when Discord is configured or tested and can remove it when disabled.
https://api.telegram.org/*Sends Telegram alerts using the bot token and chat ID you configure.Chrome asks for this permission only when Telegram is configured or tested and can remove it when disabled.
https://api.pushover.net/*Sends Pushover alerts using the app token and user key you configure.Chrome asks for this permission only when Pushover is configured or tested and can remove it when disabled.

Trust summary

Plain promises.

These are the boundaries StudyChime is designed around. The permissions, screenshots, and privacy policy should all line up with these claims.

  • No Prolific password collection.
  • No study reservation, acceptance, completion, or submission.
  • No behavioural telemetry, ad tracking, tracking pixels, or behavioural ad profiles.
  • No reading unrelated websites.
  • No broad Chrome tabs permission.
  • No central StudyChime analytics database of your study trends.
  • Milestones keep totals and unlocks locally, not an activity timeline or extra study details.
  • No study titles, researcher names, descriptions, or URLs stored in Trends.
  • No schedule or study data sent for the local schedule-coverage estimate.
  • No support or feedback message sent until you review and send the email draft.
  • No payment card handling inside the extension.
  • No public StudyChime study feed or shared community database.