| Chrome permissions |
alarms | Wakes StudyChime every five minutes for a local monitoring connection health check. | The check only targets an already-open Prolific studies page and sends no request to Prolific. |
notifications | Shows Chrome browser notifications for matching studies. | Only fires when notifications are enabled. |
offscreen | Allows StudyChime to play alert sounds in the background. | Used for alert audio only, not screen recording or page capture. |
scripting | Restores StudyChime's monitoring script if Chrome has disconnected it. | Limited to the exact Prolific studies page, runs in Chrome's isolated world, and never downloads remote code. |
storage | Saves settings, Quick Start completion, quota state, and Milestone progress, licence status, filters, schedules, customisation, and local Study Trends. | Most extension data remains in Chrome storage on your device; Milestones use extension storage and Trends uses local IndexedDB when Premium is available. |
| Required website access |
https://app.prolific.com/* | Lets StudyChime monitor your open Prolific studies page, detect matching studies, and recover its local content script when needed. | Recovery targets only https://app.prolific.com/studies. It does not refresh, navigate, or modify the page. |
StudyChime licence service | Handles licence activation, signed entitlements, trials, and the free limit of 15 external alerts per rolling 24-hour period. | It does not receive health-check messages, destination credentials, alert contents, Prolific passwords, cookies, or local trends. |
| Optional destination access |
https://discord.com/* | Sends Discord alerts to webhook URLs you configure. | Chrome asks for this permission only when Discord is configured or tested and can remove it when disabled. |
https://api.telegram.org/* | Sends Telegram alerts using the bot token and chat ID you configure. | Chrome asks for this permission only when Telegram is configured or tested and can remove it when disabled. |
https://api.pushover.net/* | Sends Pushover alerts using the app token and user key you configure. | Chrome asks for this permission only when Pushover is configured or tested and can remove it when disabled. |