ZoExt Privacy Policy
How the Write&Cite ZoExt browser extension collects, uses and shares data.
1.Summary
- ZoExt saves web pages and papers to your Zotero library. It talks to Zotero directly from your browser.
- There is no server of ours in between. The developer of ZoExt does not receive, see or store anything you save.
- Your Zotero API key stays on your device and is sent only to Zotero.
- A page is read only when you click the ZoExt icon.
- ZoExt has no analytics, tracking or advertising, and your data is never sold.
2.Data ZoExt collects and how it is used
ZoExt handles the following data for one purpose: saving the page or work you choose into your Zotero library.
Signs you in to your own Zotero account so ZoExt can list your libraries, groups and collections, save items to them, and create collections when you ask it to.
Kept on your device. The key is sent only to api.zotero.org. The user ID and username are used to address your library and to show which account is connected.
Remembers Web or App mode, whether to link a PDF, and where you last saved, so the popup opens ready to use.
Kept on your device only. Never sent anywhere.
Builds the reference. Read only when you click the toolbar icon, and only from the tab you clicked on.
Turned into a Zotero item and sent to api.zotero.org, or to the Zotero desktop app on your own computer in App mode, when you press Save. Before that it stays inside the extension.
Lets you select a DOI, arXiv ID or ISBN on the page and have it used instead of the page’s own metadata.
Used inside the extension. It leaves your device only if it is a DOI, arXiv ID or ISBN, and then only as described in the next row.
Fetches the title, authors, journal and other details of the work.
Sent to Crossref, doi.org, DataCite, arXiv or Open Library. Only the identifier is sent. The address of the page you are on is not.
Warns you if the same item is already in the library you chose.
Sent to api.zotero.org as a search of your own library.
Adds a link to the PDF under the saved item when that setting is on. No file is downloaded or uploaded.
Sent to api.zotero.org as part of the item.
Like any web request, a request to Zotero or to a lookup service reveals your IP address to that service. ZoExt does not collect health, financial, payment, location or communications data, and it does not record clicks, keystrokes or the list of pages you visit.
3.Who data is shared with
Your data goes only to the following parties, and only when you save an item, create a collection or look up an identifier.
- Zotero (Corporation for Digital Scholarship), api.zotero.org. Receives your API key, and the items, tags and destinations you save, plus the name and location of any collection you create. This is your own Zotero account, and Zotero’s privacy policy governs what it does with that data.
- The Zotero desktop app on your computer, 127.0.0.1. Used only in App mode. The request goes to your own machine and never leaves it.
- Crossref, doi.org and DataCite. Receive a DOI so they can return the details of the work.
- arXiv. Receives an arXiv ID so it can return the details of the paper.
- Open Library (Internet Archive). Receives an ISBN so it can return the details of the book.
These services are run by other organisations and handle data under their own privacy policies. The developer of ZoExt is not among the recipients and receives none of this data.
4.What ZoExt does not do
- It does not sell your data, or transfer it to anyone outside the parties listed above.
- It does not use or transfer your data for anything unrelated to saving items to Zotero.
- It does not use or transfer your data to judge creditworthiness or for lending.
- It does not run analytics, crash reporting, advertising or tracking of any kind.
- It does not read pages in the background, or any tab you have not clicked the icon on.
- It does not build profiles or keep a record of your browsing.
- It does not load or run remotely hosted code. Everything it runs ships inside the extension.
5.Storage, retention and your control
- Settings, your key and your cached destinations are kept in your browser's local extension storage. They are not synced through your browser account.
- Choose Disconnect in the ZoExt settings to remove your key and account details from the extension. Removing the extension deletes everything it stored.
- You can revoke the key itself at any time from your key settings on zotero.org. Items you have saved and collections you have created stay in your Zotero library until you delete them there.
- Because the developer never receives your data, no copy exists to access, correct or delete. Data held by Zotero and the lookup services is managed with them.
6.Security
Every request to Zotero and the lookup services uses HTTPS. The only request that does not is the one to the Zotero desktop app, which goes to your own computer at 127.0.0.1. Your key is never included in a lookup request and is never written to your browser's synced storage. Use a Zotero key with only the permissions you need.
7.Chrome Web Store user data policy
The use and transfer of information received through browser APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The data described above is used only to provide ZoExt's single purpose of saving sources to your Zotero library.
8.Changes to this policy
If ZoExt's handling of data changes, this page and its date will be updated before the change takes effect.