Privacy Policy — Sitebulb Labs Chrome Extension

Last updated: September 29, 2026
Published by: Sitebulb Limited (sitebulb.com)

The Sitebulb Labs Chrome extension checks how well the site you are viewing works for AI agents and crawlers. This page explains what the extension reads, what it stores, and who receives any data. You can reach us at the address below if you have a question.

1. What the extension is for

The extension audits the site in your active tab for AI-agent readiness: whether agents can find, access, and read it. It gives the site a score and suggests what to improve. That audit is the reason for the browser permissions listed below.

2. Summary

  • While the side panel is open, the extension reads the URL of your active tab.
  • Your browser fetches public pages and files from that site, and from another host only where that site names it as its own agent endpoint. Those requests do not go through Sitebulb servers.
  • Audit results are cached temporarily using chrome.storage.session and cleared when your browser session ends.
  • Your text size and choice to include emerging-standard checks are saved on your device usingchrome.storage.local. Your theme choice is saved in the extension'slocalStorage. No browsing data or audit results are kept between sessions.
  • If you enable emerging checks, the extension sends the audited site's hostname to Cloudflare for a DNS lookup. It does not send Cloudflare your full tab URL or audit results.
  • We do not receive your browsing activity or audit results, and we do not sell user data.

3. What the extension reads

The active tab's URL. The extension uses it to work out which site to audit. The side panel can run a new audit when you switch tabs or move to another page.

Public content on that site. Your browser requests files such asrobots.txt, XML sitemaps, llms.txt, and /.well-known/descriptors. The extension also reads markup on the page you have open, including structured data and <link> and <meta> tags. It makes these requests without credentials and does not access private or password-protected content.

4. What an audit checks

Chrome grants the extension access to all sites so it can audit whichever one you choose. While the side panel is open, an audit:

  • reads the active tab's URL;
  • requests public paths from that site: its homepage,/robots.txt, XML sitemaps, /llms.txt and its section-scoped variants,/.well-known/ descriptors, a Markdown version of the page such as/page.md, common about, contact, andprivacy paths, and a path that does not exist to check the site's 404 response. These requests do not include credentials. You can see the current list in the extension's source code;
  • checks up to eight links in that site's /llms.txt, but only if they point to the same site. Links to other domains appear in the results without being fetched;
  • requests an address on another host only when the site publishes it as its own agent endpoint, in its agent catalog (/.well-known/ard.json or/.well-known/ai-catalog.json) or, if emerging checks are enabled, in a DNS-AID record. The extension requests that address once, without credentials and without following redirects, to see whether an MCP server or agent card is there. It never requests an address on your local network, such as your router, unless the site being audited is on your local network too. Links in the page and sitemaps hosted on other domains are not fetched;
  • reads public markup on the open page, including structured data,<link> and <meta> tags, and signs of an agent interface;
  • if emerging checks are enabled, looks up the site's hostname using Cloudflare's DNS-over-HTTPS service. SeeCloudflare DNS lookup below.

The extension does not audit other tabs or keep running on sites after you close the side panel. It does not request access to your bookmarks, browsing history, or passwords.

5. Browser permissions

PermissionWhat it is for
scripting Reads public signals on the page and makes audit requests from that page.
storageCaches results for the browser session and saves two preferences on your device: text size and whether to include emerging-standard checks. The theme preference uses thelocalStorage.
sidePanelShows audit results beside the page in Chrome's side panel.
host_permissions
(http://*/*, https://*/*)
Lets the extension read the active tab's URL and public resources from whichever site you audit, without asking again each time you move to another site. More on this below.

Why it asks for access to all sites

You can audit any site you visit, so we cannot list its domain in advance. Chrome does not offer a permission for "whichever site is in the active tab" that would also let the side panel continue working as you browse.

We tried two narrower approaches:

  • Asking for each domain separately. Chrome still requires us to declare the all-sites scope as optional. This also adds a permission prompt for every new domain, which gets in the way when you audit several sites.
  • Using activeTab. That permission ends when the tab navigates. The side panel follows you when you change pages or tabs, so you would have to click the extension icon again on every page.

6. What stays on your device

Audit results. The extension caches them in chrome.storage.session. Chrome clears this cache when the browser session ends. Results are not synced to a Sitebulb account, a cloud service, or another device.

Your settings.chrome.storage.local keeps your chosen text size and whether you include emerging-standard checks, even after you close Chrome. The theme choice is stored separately in the extension'slocalStorage. These preferences contain no URLs, site names, or audit results.

7. How we use your data

  • The extension does not send your browsing activity, tab URLs, or audit results to Sitebulb.
  • We do not sell, rent, or trade data the extension reads or produces.
  • We do not use data from the extension for advertising.
  • We do not build a browsing history or profile from the sites you audit.

8. Cloudflare DNS lookup

When emerging checks are enabled, the extension sends DNS queries for the audited site's hostname and its _agent subdomain to Cloudflare's public resolver (cloudflare-dns.com). Browsers cannot make raw DNS queries. These requests do not include the full page URL, audit results, or data from another tab. Cloudflare handles the queries under its own privacy commitments. Other audit requests go directly to the site being audited, or to an agent endpoint it declares as described in section 4.

9. Chrome Web Store data rules

The extension follows theChrome Web Store User Data Policy, including theLimited Use requirements. Under those rules:

  • We use the extension's access and data only to provide and improve the audit of the site you are viewing.
  • Aside from requests to the site being audited, to agent endpoints that site declares, and the optional Cloudflare DNS lookup described above, the extension does not send audit results or browsing activity to third parties during a normal audit.
  • We do not use or transfer it for advertising.
  • No one at Sitebulb reads this data during a normal audit because it stays in your browser. Exceptions would require your explicit consent, a legal requirement, or a security need.

10. Children's privacy

The extension is for website owners, developers, and SEO practitioners. It is not aimed at children, and we do not knowingly collect data from anyone who uses it.

11. Changes to this policy

If we change how the extension handles data in a material way, we will update this page and its "Last updated" date.

12. Contact

Sitebulb Limited develops and publishes the extension. The company is registered in England and Wales and is the data controller for the limited data covered by this policy.

Questions about this policy or how the Extension handles data can be sent to:

labs@sitebulb.com

Sitebulb Limited
Hill View, Bell Lane, Biddenden, Kent TN27 8LD, United Kingdom
Company registration number: 12125600