Chrome Extension Permission Information
Last updated: August 2026
This page explains what the Content Swarm Chrome extension can access, what it sends, and where that data goes.
Declared permissions
| Permission | Why we use it |
|---|---|
| tabs | Opens the LinkedIn sign in and help pages, watches the sign in tab for completion, finds the active tab, and closes the temporary sign in tab |
| storage | Stores your Content Swarm session ID, CSRF token, selected swarm, cached account details and analytics state in Chrome local storage |
| cookies | Maintains your authenticated Content Swarm session, and removes session cookies when you sign out |
| https://www.linkedin.com/* | Runs the Content Swarm controls on LinkedIn. Used to find visible posts and comment boxes, read post text and post links, insert generated text, and add the Add to Swarm control |
| https://api.contentswarm.io/* | Calls the Content Swarm API and completes the sign in flow |
What the extension does not do
- It does not read your direct messages
- It does not scrape your connections or contact list
- It does not run on any website other than LinkedIn and our own API
- It does not access your browsing history, camera, microphone, location or downloads
- It does not collect data in the background when you are not using it
- It declares no optional permissions
What is sent, and where
| Action | Data | Destination |
|---|---|---|
| Generate a comment | Visible LinkedIn post text, selected tone and length, optional example comment | Content Swarm API. The backend sends the prompt and input to OpenAI. Usage events go to PostHog |
| Select or post a generated comment | Selected comment, selected swarm, edit and click events | Comment text and team are recorded by Content Swarm when you click LinkedIn’s post button. Product analytics go to PostHog. LinkedIn receives the comment through its own page |
| Add to Swarm | LinkedIn post URL and selected swarm | Content Swarm API. Usage events go to PostHog |
| Sign in and choose a swarm | Session and CSRF tokens, user ID, email, first and last name, swarm IDs and names | Content Swarm API. Account identity and product events go to PostHog |
What stays on your device
Chrome local storage holds your session ID, CSRF token, selected swarm, cached account details and analytics state.
Generated suggestions are held in memory while you review them and are not stored locally.
Signing out removes your session ID, CSRF token and selected swarm from the extension.
If you have automatic reconnect enabled, your LinkedIn connection is kept so that the service continues to work when you sign back in. To remove that connection, disconnect LinkedIn in your Content Swarm account settings or revoke access from your LinkedIn account.
Enterprise deployment
The extension can be deployed and allowlisted through Chrome Enterprise policy. Contact support@contentswarm.io for the extension ID and deployment guidance.
Legal and privacy information
Content Swarm Limited, 727-729 High Road, London N12 0BP, United Kingdom. Contact support@contentswarm.io.