Introduction
This Privacy Policy explains how Intake AI (“Intake AI,” “we,” “us,” or “our”) collects, uses, processes, stores, shares, and protects information when you use the Intake AI Chrome Extension (the “Extension”).
The Extension is designed to assist authorized clinical research users with building, configuring, and verifying study workflows within supported browser-based clinical research systems.
The Extension can analyze the structure and content of a supported clinical research application, identify relevant controls and fields, assist with entering authorized study configuration information, verify the resulting entries, and provide users with visibility and control over the workflow.
This policy applies specifically to information processed through the Extension. Information collected through the broader Intake AI platform, website, connectors, or other products is also subject to the Intake AI Privacy Policy.
By installing and using the Extension, you acknowledge the practices described in this Privacy Policy.
What Data the Extension Collects
Because the Extension must understand and interact with browser-based clinical research systems to perform its disclosed functionality, it may collect and process the following categories of information.
Account and Authentication Information
The Extension may process account identifiers, organization or site identifiers, authentication tokens, session information, and other information necessary to verify that you are an authorized Intake AI user.
We do not intentionally collect your passwords through the Extension.
Supported Webpage Content
When the Extension is used on a supported clinical research system, it may access information from the relevant browser page, including:
- page structure and DOM information;
- URLs and domains of supported applications;
- visible text;
- form names;
- field names and labels;
- selectable options;
- field values where required to perform or verify the requested workflow;
- accessible names and element roles;
- structural relationships between page elements;
- element location and bounding-box information; and
- other page information necessary to identify, map, complete, or verify the applicable clinical research workflow.
The Extension is not designed to collect your general browsing history or webpage content from unrelated websites.
Screenshots of Supported Pages
The Extension may capture screenshots of the visible portion of the active supported browser tab.
Screenshots are used together with structured page information to help Intake AI understand complex application interfaces, identify the correct forms and fields, and verify workflow execution.
The Extension does not intentionally capture other applications on your computer or unrelated browser tabs.
Study and Workflow Information
The Extension may process study configuration information and workflow instructions necessary to perform the requested build.
This may include study names or identifiers, visits, forms, fields, field types, units, coded values, ranges, required-field settings, edit checks, skip logic, source-document information, mappings, and other structured study information.
User Actions, Corrections, and Approvals
We may collect information about actions you take in the Extension, including workflow initiation, confirmations, approvals, pauses, corrections, overrides, mapping decisions, and other feedback.
We may also record the results of actions performed by the Extension, including whether a field was successfully entered and the value read back from the target system for verification.
Session, Diagnostic, and Audit Information
We may collect technical information necessary to operate, secure, troubleshoot, and improve the Extension, including:
- session identifiers;
- timestamps;
- workflow status;
- checkpoints;
- platform type;
- structural fingerprints;
- mapping and grounding results;
- confidence information;
- error information;
- performance information;
- connection status;
- model or workflow outcomes; and
- audit and event records.
Certain diagnostic or audit records may reference separately stored artifacts such as screenshots or structured page snapshots.
Sensitive and Clinical Information
Because the Extension operates within clinical research systems, relevant webpage content may contain personal information, sensitive information, clinical research information, or protected health information (“PHI”).
The Extension processes such information only as necessary to perform the requested functionality and subject to applicable Customer agreements, permissions, and legal requirements.
Users should only use the Extension on systems and data they are authorized to access.
When the Extension Accesses Data
The Extension is designed to process substantive webpage content and screenshots in connection with authenticated Intake AI functionality on supported clinical research systems.
A user initiates and controls the relevant Intake AI workflow through the Extension interface.
During an active workflow, the Extension may inspect the supported page, capture the visible target tab, interact with authorized page elements, and verify resulting values as necessary to complete the workflow.
The Extension may maintain technical session information while a workflow is active in order to support connection continuity, recovery, status reporting, and verification.
The Extension is not designed to monitor unrelated websites or collect general browsing activity for advertising, profiling, or unrelated purposes.
Why We Collect This Data
Information collected through the Extension is used to provide and improve the Extension’s disclosed purpose.
Specifically, we may use Extension data to:
- identify the clinical research system and relevant workflow;
- understand the structure of supported pages;
- identify forms, fields, controls, and navigation elements;
- map Intake AI study information to the appropriate controls in the target application;
- generate and execute workflow plans;
- populate authorized study configuration information;
- verify completed actions through read-back;
- identify uncertainty or potential errors and request human review;
- allow users to pause, review, correct, approve, or resume workflows;
- support session recovery and reliability;
- maintain audit and diagnostic records;
- detect and investigate security incidents or abuse;
- troubleshoot errors and provide customer support;
- measure reliability and performance; and
- train, evaluate, test, and improve AI and machine-learning systems used to provide and improve the Extension’s disclosed functionality, as described in Section 8.
We do not use Extension data for targeted advertising, behavioral advertising, determining creditworthiness, or selling user profiles.
How Extension Data Is Processed
The Extension uses a combination of local browser processing and secure server-side processing.
Page Analysis in the Browser
A content script operating on supported pages identifies relevant visible and structural webpage elements and creates a reduced representation of the page needed for the workflow.
Where necessary, the Extension may also capture a screenshot of the visible supported tab.
Secure Transmission to Intake AI
Relevant structured page information, screenshots, workflow information, and session information may be transmitted to Intake AI servers over encrypted network connections.
AI-Assisted Interface Understanding
Intake AI may use artificial intelligence models to analyze page structure and screenshots and determine which browser elements correspond to the study operations requested by the user.
Information may be transmitted to an AI service provider as necessary to perform this processing.
Controlled Browser Actions
After a workflow plan is generated, instructions are returned to the Extension. The Extension may interact with the relevant page elements to perform authorized actions such as setting text, selecting an option, changing a supported control, navigating through the workflow, or reading a value for verification.
Verification and Human Review
The Extension can read resulting values to confirm whether an action was completed correctly.
Where Intake AI detects uncertainty, mapping ambiguity, or another condition requiring review, the workflow may pause and request user input rather than continuing automatically.
Chrome Extension Permissions
The Extension requests Chrome permissions only where they are required to provide its disclosed functionality.
Depending on the currently released version, these permissions may include:
activeTab- Allows the Extension to interact with the active supported browser tab when necessary to perform a user-requested workflow, including capturing the visible page where required.
tabs- Allows the Extension to identify and coordinate with the relevant supported browser tab and obtain limited tab information necessary for workflow operation.
scripting- Allows the Extension to run Intake AI scripts on supported clinical research pages so it can understand page structure, identify controls, perform authorized actions, and verify results.
storage- Allows the Extension to store limited configuration, preferences, identifiers, and session-related information needed for operation.
sidePanel- Allows Intake AI to display its workflow console and controls within Chrome’s side-panel interface.
Host Permissions
The Extension may request access to specific domains used by supported clinical research platforms, such as approved CRIO, RealTime, EClinPro, or other Intake AI-supported application domains.
Host permissions are used only to provide Extension functionality on those applications.
We do not request host access for the purpose of collecting general browsing activity.
Data Sharing and Third Parties
We do not sell Extension data.
We do not share Extension data with advertising networks, data brokers, or third parties for targeted advertising.
We may share Extension data with service providers strictly as necessary to operate, secure, maintain, and improve the Extension’s disclosed functionality.
At the time of this Policy, relevant service providers may include:
- Amazon Web Services (AWS) for cloud infrastructure and storage;
- MongoDB / MongoDB Atlas for database infrastructure;
- Clerk for authentication and identity services;
- OpenAI for artificial intelligence processing; and
- other infrastructure, security, monitoring, or AI service providers used to operate the Extension.
These providers may process only the information reasonably necessary to perform services for Intake AI, subject to our applicable contractual arrangements.
We may also transmit information to the clinical research system you are actively using when necessary to carry out actions you requested through the Extension.
We may disclose information where required by applicable law, legal process, or governmental authority, or where reasonably necessary to investigate security incidents, fraud, abuse, or threats to the rights or safety of Intake AI, our Customers, users, or others.
Information may also be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable legal requirements.
AI Training and Product Improvement
Intake AI develops and improves AI systems that help the Extension understand clinical research interfaces and perform the workflow described in this Policy.
Where permitted by applicable law and our agreements with the applicable Customer, we may use information generated or collected through the Extension to train, fine-tune, evaluate, test, validate, and improve AI and machine-learning systems used to provide and improve the Extension’s disclosed functionality.
This information may include structured page representations, screenshots, interface mappings, workflow plans, model outputs, confidence scores, execution results, user corrections, user feedback, and other interaction or performance data.
We may also create aggregated, de-identified, transformed, or derived datasets for evaluation, benchmarking, reliability improvement, and model development.
For information obtained through the Extension, model training and product improvement are limited to providing or improving the Extension’s disclosed purpose and associated user-facing functionality. We do not use Extension data to train systems for advertising, user profiling, credit decisions, data brokerage, or unrelated commercial purposes.
Where an applicable Customer agreement, Business Associate Agreement, Data Processing Agreement, or law prohibits use of particular information for model training, we do not use that information for those purposes.
Where Extension data constitutes PHI subject to HIPAA, our use of that information is governed by the applicable Business Associate Agreement and applicable law.
Human access to raw Extension user data is restricted. Personnel may access such information only where permitted by applicable law and policy, including where the user or Customer has authorized the access for support or review, where access is necessary for security or legal purposes, or where information has been appropriately aggregated or anonymized for permitted internal operations.
Data Storage and Retention
Some Extension information, such as preferences and limited session information, may be stored locally using Chrome storage.
Other information may be stored on Intake AI systems, including session state, workflow results, audit events, structured page information, screenshots, and other artifacts necessary for reliability, verification, security, support, product improvement, or auditability.
We retain information for as long as reasonably necessary to provide the Extension, satisfy Customer agreements, fulfill the purposes described in this Policy, comply with legal or regulatory requirements, maintain security and audit records, resolve disputes, and enforce our agreements.
Retention periods may differ depending on the Customer, type of information, applicable contractual requirements, and regulatory obligations.
Users may contact us to request deletion of eligible information as described below.
Deletion of source information may not necessarily remove statistical effects from an AI model that was previously trained using that information where such training and continued use are permitted by applicable law and contract.
Security
We use technical and organizational safeguards designed to protect information processed through the Extension. These safeguards include:
- encryption of information in transit;
- encryption of stored information;
- authenticated access to Intake AI systems;
- organization- and role-based access controls;
- restricted access to sensitive information;
- logging and monitoring;
- security and audit controls; and
- measures designed to detect unauthorized access or misuse.
The Extension communicates with Intake AI systems through authenticated and encrypted connections.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
Clinical Research Data and PHI
The Extension is designed for use by authorized clinical research personnel and may operate on applications containing regulated or sensitive information.
Customers and users are responsible for ensuring that they have authority to access the underlying system and to instruct Intake AI to process the information contained within it.
Where Intake AI processes PHI pursuant to a Business Associate Agreement, that BAA governs our processing of the PHI. If this Policy conflicts with an applicable BAA with respect to PHI, the BAA controls.
The Extension should not be used to access or process information that the user is not authorized to access.
Your Rights and Controls
You remain in control of whether you use the Extension.
You may stop or pause an active workflow using the controls provided by Intake AI. You may also uninstall or disable the Extension through Chrome, which prevents future Extension processing.
Depending on applicable law and our relationship with you, you may request access to, correction of, deletion of, or a copy of personal information maintained by Intake AI.
If Intake AI processes the relevant information on behalf of your employer, clinical research site, sponsor, or another Customer, you may need to submit your request to that organization. Intake AI will assist Customers with eligible privacy requests where required.
Uninstalling the Extension does not automatically delete information previously transmitted to Intake AI servers. Server-side information remains subject to our applicable retention and deletion policies.
To submit a privacy request, contact us using the information in Section 16.
Chrome Web Store User Data Policy and Limited Use
Intake AI is committed to complying with the Chrome Web Store User Data Policy and its Limited Use requirements.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Information obtained through Extension permissions is used only as necessary to provide or improve the Extension’s disclosed single purpose and associated user-facing functionality.
We do not use or transfer Extension user data for personalized or interest-based advertising, sell Extension user data to data brokers or information resellers, or use Extension user data to determine creditworthiness or for lending purposes.
We limit transfers of Extension user data to circumstances necessary to provide or improve the Extension’s disclosed functionality, comply with applicable law, protect against fraud, abuse, or security threats, or complete a permitted corporate transaction in accordance with applicable requirements.
Children’s Privacy
The Intake AI Chrome Extension is a business product designed for clinical research professionals and is not intended for use by children.
We do not knowingly allow children under 13 to create Extension accounts or use the Extension independently.
The underlying clinical research systems used by Customers may contain information regarding minors participating in clinical research. Where such information is processed, Intake AI processes it on behalf of the applicable Customer and subject to the Customer’s authorization, applicable agreements, and legal requirements.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Extension, our data practices, technology, or legal requirements.
When we make changes, we will update the “Last Updated” date above.
If we materially change the types of user data collected or how Extension user data is used, we will provide additional disclosure and obtain consent where required before applying the new data practice.
Contact Us
For questions, concerns, or requests regarding the Intake AI Chrome Extension or this Privacy Policy, please contact:
Intake AI
- hello@useintake.ai
- Website
- https://www.useintake.ai
Please include “Chrome Extension Privacy” in the subject line of privacy-related requests so that we can route them appropriately.