Legal
Privacy Policy
Updated 23 September 2026
In short: the extensions run in your browser and work on your device by default. One feature is different, and it is the one worth reading about: if you turn on the PI Labs AI engine, the text you are working on is sent to our server and passed to a model provider to answer. We do not keep it.
This policy covers the PI Labs website at pilabs.space and the browser extensions published by PI Labs (“we”, “us”, “our”):
- PI Prompts · Prompt Library for LLM platforms
- PI Fix Grammar
- PI Summarize
- PI Answer
- Aviary · Gamify your X journey
It replaces the earlier Joelbooks extensions privacy policy for these products. Where this policy and any general Joelbooks policy differ, this one governs.
The short version. We do not sell your data and we do not use it for advertising. Your settings stay in your browser’s local storage. Extensions can, at your choice, send text you select to a third-party AI provider, or sync your data to your own Google Drive. One route does go through us: the PI Labs AI engine, which members can turn on instead of bringing an API key. Text sent that way reaches a PI Labs server, is passed to our model provider to be answered, and is not stored by us. Apart from that we hold your account, your subscription status and a record of what your energy was spent on. Each case is described below.
1. What the website collects
You can install and use every free feature without ever visiting the website or creating an account. An account exists for one reason: so premium can follow you between machines.
When you sign in with Google
We receive and store:
- your Google account identifier (the stable
subvalue Google issues), - your email address,
- your display name and profile picture URL, as Google provides them.
We use these only to recognise you when you return, to link your subscription to you, and to answer you if you contact support. We do not receive your Google password, and we cannot read anything else in your Google account.
When you use the PI Labs AI engine
This is the one feature where the text you are working on reaches us, so it is worth being exact. When an extension asks our engine for an answer, the request carries what that tool needs to answer it: for PI Fix Grammar the text you are correcting; for PI Answer the post you are replying to, up to four posts above it in the thread, and your draft.
We pass that straight to our model provider, OpenRouter, which routes it to whichever model is answering at the time, and we return the answer to your browser. We do not store the text. It is not written to our database, and we do not keep it after the request has been answered. How OpenRouter and the model provider handle it is governed by OpenRouter’s privacy policy.
What we do keep is one usage record per call, so the energy on your account adds up and you can check it on your account page: which tool asked, what kind of work it was, when, which model answered, and what it cost. Those records hold no part of your text. They are kept for 90 days and then deleted; the running totals behind your monthly allowance stay for as long as your account does.
The engine is never the only option. Every extension that offers it also runs on Chrome’s built-in on-device model or on an API key of your own, and the extension names which engine answered so you can see which applied.
When you connect an extension
Connecting an extension to your account creates a key for that extension. We store only its SHA-256 hash, along with which tool it belongs to and when it was last used, so your account page can list your connected extensions and let you disconnect any of them.
When you subscribe
Payments are handled entirely by our payment providers. We never see or store your card number, bank details, or wallet keys. What we store is your subscription status, the plan, the current period end date, and the provider’s reference for your subscription. That is enough to answer the only question the extensions ask, which is whether premium is currently active for your account.
- Card, Apple Pay and Google Pay are processed by Dodo Payments, who act as merchant of record. They collect the billing details and tax information required to invoice you, under their own privacy policy.
- USDC payments are processed by Rendben. On-chain payments are public by nature: the transaction and the wallet address you pay from are recorded on a public blockchain and cannot be deleted by us or by anyone else.
When you send an idea or report a bug
The feedback button on every page stores what you send: the product it is about, your message, the page you were on, your browser’s user agent, and a screenshot if you attach one. If you are signed in we link it to your account so we can reply; if not, we keep an email address only if you choose to leave one. To stop spam we keep a one-way, salted hash of your IP address, never the address itself.
We use reports only to fix bugs and decide what to build. We may copy the text of a report into our private issue tracker on GitHub; the screenshot and your email are never copied there and stay in our own database. Ask us and we will delete a report.
When you just visit
The site is hosted on Vercel, which records standard server request logs (IP address, user agent, requested page) for security and reliability. We do not run advertising trackers, we do not set marketing cookies, and we do not build a profile of your browsing.
Analytics, only if you allow it
The first time you visit, we ask whether we may use Google Analytics. Its tag is on every page, but until you say yes it runs in Google’s restricted consent mode: it sets no cookies, stores no identifiers, and sends only anonymous, cookieless signals that cannot be tied to you or to a later visit. If you say yes, it sets its cookies and we use it to count visits and to see which pages are read and where visitors came from.
- It sets first-party cookies named
_gaand_ga_followed by an ID, which last up to two years. - Google receives details of the visit: the pages you view, the site that sent you, your approximate location, and your device and browser type. Google Analytics 4 does not log or store IP addresses.
- Google’s advertising features are switched off. Analytics data is not used for ads and is not shared for advertising.
- You can change your mind at any time from Cookie settings in the footer of every page. Choosing no there returns the tag to its restricted mode straight away and deletes those cookies.
Your choice is remembered in your browser’s local storage for a year, and then we ask again. Signing in sets one session cookie, which is strictly necessary for your account to work and so does not need consent.
2. What the extensions collect
We do not collect, receive, or store the content you work on in the extensions. Each one keeps what it needs in your own browser using Chrome’s storage API, or, only when you choose, in your own Google Drive account.
Depending on the extension, the data held locally may include:
- your settings and preferences (summary length, chosen AI provider, keyboard shortcuts, your answering style);
- content you act on, such as text you select to summarize or correct, prompts you save, or replies you draft;
- for Aviary, the public analytics figures shown on your own X pages, used to display your progress;
- any API key you personally enter for an optional AI provider.
This information is stored on your device. Uninstalling the extension, or clearing its storage, removes it.
3. How each extension handles data
PI Prompts: optional Google sign-in to sync to your own Drive
A prompt library that inserts saved prompts into LLM websites such as ChatGPT, Claude, Gemini, Grok, DeepSeek, Mistral, Qwen and others. Your prompts are stored in your browser.
Optionally, you can sign in with Google so your library syncs across devices. Sync uses a private application folder in your own Google Drive, a hidden folder only this extension can reach. Signing in reads your basic Google profile (name and email) to identify your account.
- Data used: your saved prompts and settings; if you sign in, your Google account email and profile name.
- Where it goes: prompts stay in your browser unless you sign in, in which case they sync to your own Google Drive app folder. We never receive your prompts; the sync is between your browser and your Google account.
- Permissions: identity, storage, tabs, scripting, activeTab, contextMenus, and access to supported LLM sites so it can insert prompts. Drive access is limited to the
drive.appdatascope, which is the private app folder only, plus your basic profile.
PI Fix Grammar: on-device by default, optional cloud fallback
Corrects grammar in a text field. By default it uses Chrome’s built-in on-device AI (Gemini Nano), which runs entirely on your computer, so your text never leaves your device.
As an optional fallback you may enter your own API key for a cloud provider (Groq, OpenRouter, or Google Gemini). If you enable this, the text you correct is sent directly to the provider you configured.
The PI Labs AI engine. If you sign in and have an active plan, you can use our hosted engine instead of bringing a key. When that engine answers, the text you asked it to correct is sent to a PI Labs server at pilabs.space, which passes it straight to our model provider (OpenRouter) and returns the correction. We do not store the text, and nothing about it is written to our database. What we do record is that a correction happened: the tool, the time, the model that answered and what it cost, so your energy balance adds up. This engine is off unless you sign in and choose it.
- Data used: the text you ask it to correct; any API key you enter; your settings.
- Where it goes: by default, nowhere, because processing happens on your device. If you enable a cloud provider with your own key, your text goes only to that provider and is governed by their privacy policy; your key is stored locally in your browser profile and is only ever sent to that provider. If you use the PI Labs engine, your text goes to a PI Labs server and on to OpenRouter, and is not stored by us.
- Permissions: contextMenus, scripting, activeTab, storage, identity (only to sign you in to PI Labs, when you ask), and access to the enabled provider’s API endpoint.
PI Summarize: sends selected text to an AI provider you choose
Adds a right-click Summarize option. When you use it, the extension opens your chosen AI chat service (ChatGPT, Gemini or Claude) and places the text you selected into that service’s chat box.
- Data used: the text you select and choose to summarize; your settings.
- Where it goes: the selected text is handed to the AI service you pick, in a normal browser tab, and is then subject to that provider’s privacy policy. It does not pass through any PI Labs server.
- Permissions: contextMenus, scripting, activeTab, storage, and access to the current page so it can read your selection. The management permission is used only to check whether PI Prompts is installed.
PI Answer: on-device by default, optional cloud fallback
Drafts a reply to a post on X. Like PI Fix Grammar it uses Chrome’s built-in on-device AI first, so by default nothing leaves your computer. You may optionally supply your own key for Groq, Google Gemini or OpenRouter as a fallback.
To write a reply it reads the post you are replying to, whatever you have already typed in the reply box, and, when the post sits in a thread, up to four posts above it so the draft answers the conversation rather than one line of it. All of that is passed to the model as data, wrapped in markers, with an explicit instruction not to follow anything it says.
The PI Labs AI engine. PI Answer is a members-only tool, and its default engine is ours. When it answers, the post, the thread context above it and your draft are sent to a PI Labs server at pilabs.space, which passes them straight to our model provider (OpenRouter) and returns the draft. We do not store any of it, and nothing about it is written to our database. What we do record is that a draft happened: the tool, the time, the model that answered and what it cost, so your energy balance adds up. You can switch to Chrome’s on-device model or your own API key in Options, and then nothing goes to us at all.
- Data used: the text of the post you are replying to; up to four posts above it in the same thread; your draft reply; your answering-style settings; any API key you enter.
- Where it goes: to whichever engine you are using. With the PI Labs engine, to a PI Labs server and on to OpenRouter. With your own key, to that provider only. With Chrome’s on-device model, nowhere. The extension names which engine answered after each draft, so you can always see which of these applied.
- Premium check: PI Answer is available to premium members. On launch it asks PI Labs whether your account is active. That request carries your Google identity and nothing about the posts you read or the replies you write.
- Permissions: storage, identity (only to sign you in to PI Labs), and access to x.com so it can read the post and fill the reply box.
Aviary: runs locally, no data sent out
Turns your own X analytics and creator-rewards figures into a daily flight progress view. It reads the figures already shown on the X pages you visit and stores your progress in your browser.
- Data used: public analytics numbers displayed on your X pages; your streak and progress; your Super Friends list.
- Where it goes: nowhere. All of it stays in your browser’s local storage.
- Permissions: storage, plus access to x.com so it can read the page you are on.
4. Summary of data flows
- PI Labs website: yes. Your Google identity and subscription status are stored by us; payment details go to Dodo Payments or Rendben, never to us. Visit details go to Google Analytics only if you allow it.
- PI Prompts: only if you sign in to sync, and then only to your own Google Drive account.
- PI Fix Grammar: no by default. Yes to the provider you configure, using your own key; or, if you choose the PI Labs engine, to us and on to OpenRouter.
- PI Summarize: only when you summarize, to the AI provider you choose.
- PI Answer: yes, to us and on to OpenRouter, because the PI Labs engine is its default. No, if you switch it to Chrome’s on-device model; or to your own provider if you configure a key. Separately, a membership check carries your account identity to PI Labs and nothing about what you are writing.
- Aviary: no.
The only content that reaches a PI Labs server is what you send through the PI Labs AI engine, and only while it is being answered: we pass it to our model provider and return the answer without storing it. We keep a usage record for each of those calls (which tool, when, which model, what it cost) so your energy balance is auditable, and that record holds no part of your text. Everything else stays away from us: the prompts you save, the pages you summarize, your Aviary progress, and anything you send to a provider with your own key.
5. Third-party services
When you choose a feature that involves a third party, that party’s own privacy policy applies to how they handle it:
- OpenRouter: the model provider behind the PI Labs AI engine. Unlike the others in this list, we send to it on your behalf when you use that engine, rather than you configuring it yourself.
- OpenAI (ChatGPT)
- Google (Gemini, Google Drive, Google sign-in, and Google Analytics if you allow it)
- Anthropic (Claude)
- Groq
- OpenRouter
- Dodo Payments, merchant of record for card payments
- Rendben, USDC payments
- Vercel, website hosting
6. How we use data
The extensions use locally stored data only to provide their features to you. The website uses your account data only to sign you in, to keep your subscription working, and to contact you about that subscription. We do not:
- sell, rent, or trade your data;
- use your data for advertising or profiling;
- transfer your data to third parties except as you direct, or as needed to take your payment;
- track your browsing across sites.
7. Retention and deletion
Locally stored data stays in your browser until you remove it. You can:
- clear the extension’s data or delete saved items inside the extension;
- uninstall the extension, which removes its local storage;
- for PI Prompts, sign out and delete the app-folder data from your Google Drive;
- for PI Fix Grammar and PI Answer, remove any API key you entered in the extension’s options.
For your PI Labs account: write to us and we will delete it. Deleting your account ends premium access. We keep the minimum billing and tax records our payment providers and the law require, and on-chain USDC transactions remain public on the blockchain regardless.
8. Your rights
If you are in the UK, EU, or another region with similar law, you have the right to ask what we hold about you, to have it corrected, to have it deleted, and to receive a copy. Because we hold so little, just your Google identity and your subscription status, these requests are quick to answer. Write to hello@pilabs.space.
9. Children
These products are not directed to children under 16, and we do not knowingly collect personal information from children.
10. Security
Data stored by the extensions is protected by your browser’s and operating system’s security. Data you send to a third-party AI provider, to Google Drive, or to us travels over encrypted (HTTPS) connections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Updated” date above. Material changes may also be reflected in the extensions’ store listings.
12. Contact
Questions about this policy or your data: hello@pilabs.space.
© 2026 PI Labs. This policy covers pilabs.space and the browser extensions listed above.