The Anvil extension detects a PDF on the page you are viewing and lets you turn it into
a fillable form you can complete and sign, powered by your Anvil account. This policy explains what the extension accesses, what
it sends to Anvil, and what it stores on your device.
What the extension accesses, and why
The extension requests these Chrome permissions:
Tabs: reads the URLs of the tabs you have open to detect when a tab is displaying a PDF, so the
side panel can offer to fill and sign it.
Scripting + access to pages you visit: a small content script checks whether the current page
is a PDF. It reports only a yes/no signal; it does not read or transmit page content.
webRequest: to detect PDFs from a page's response headers.
Storage: to keep you signed in, and to remember which of your open tabs currently show a PDF (see "Stored on your device").
Side panel: to show the extension's interface.
Identity: to sign you in to Anvil through a standard OAuth consent flow.
Access to all sites and local files: so PDF detection and downloading work on any PDF you open,
including local files, before anything is sent to Anvil.
Data sent to Anvil
The extension sends data to Anvil (useanvil.com) when you use it:
The PDF you fill or sign. When you click Get Started, the extension downloads the PDF in your browser and
uploads its contents to Anvil, which uses AI to detect fields and generate a form you can fill and sign.
The values and signature you provide. Form fields you complete and any signature you add are saved to your Anvil account.
Authentication. You sign in to (or create) your Anvil account via OAuth. When you reopen the
side panel the extension restores your session automatically (unless you signed out), and it reads
which Anvil organization your account belongs to so your forms are filed to the right place. Anvil's
handling of your account data is governed by Anvil's own privacy policy.
Stored on your device
The extension stores the following locally via Chrome's extension storage:
Your Anvil session token, so you stay signed in between sessions.
A flag recording whether you explicitly signed out (so it does not silently sign you back in).
A temporary, per-tab note of whether each open tab shows a PDF, which Chrome clears when you close the browser.
This data is stored only on your device; your session token is sent to Anvil only to authenticate your
requests, and none of it is shared with any other party. Signing out clears your session token;
removing the extension clears everything the extension has stored.
How your data is protected
Data sent between the extension and Anvil is encrypted in transit using HTTPS/TLS. Once it reaches
your Anvil account, it is handled under the security practices described in
Anvil's privacy policy.
Accessing and deleting your data
On your device: sign out to clear your session token, or remove the extension to clear
everything it has stored (see "Stored on your device").
In your Anvil account: sign in to manage your data, or submit an access or deletion request
through our GDPR request form. Form data you create is retained in your Anvil account
until you delete it or close your account; on cancellation it is permanently deleted within 30
days. See Anvil's privacy policy for full details.
What the extension does not do
It does not send your browsing history to Anvil or any third party. The only page data it keeps is
a temporary, local note of which open tabs show a PDF (see "Stored on your device").
It does not read or send the contents of non-PDF pages.
It does not add analytics or third-party trackers of its own; the Anvil interface shown in the side
panel follows Anvil's privacy policy.
It does not sell your data.
Limited use
Anvil's use of data received through the extension adheres to the Chrome Web Store User Data
Policy, including its
Limited Use requirements. We use this data only to provide the extension's features — we do not sell
it, transfer it for advertising, or use it for any unrelated purpose.
Third parties
The extension sends your data only to Anvil. Anvil may use service providers to process your data on
its behalf — for example, to power the AI field detection described above — as described in
Anvil's privacy policy. The extension does not share your data with any other
party.
Changes
We may update this policy; material changes will be reflected by the effective date above.