HGI Data Bridge Privacy Policy
This page explains what data HGI Data Bridge uses and why, in simple terms.
What this extension does
HGI Data Bridge helps move data between supported HGI pages and HGI services so users can sync their work faster.
Permissions and usage
The extension requests these Chrome permissions (see the packaged manifest for the exact list):
- tabs — Find the signed-in HGI portal tab and message its content script for authenticated API access; open tabs when you use in-extension controls (for example opening the portal or dashboard pages).
- identity — Google Sign-In via
chrome.identityfor profile-linked features. - storage — Persist settings and local state in your browser.
Site access: A content script runs only on HGI Back Office and HGI API pages declared in the manifest so the bridge can use your existing portal session. Separately, host permissions allow the service worker and extension pages to call specific HTTPS APIs you rely on (HGI API, hosted reports/activity endpoints, subscription billing, Firebase Auth/Firestore for optional signed-in notes, plan-enrollment data, and Google Analytics for optional usage analytics). The extension does not use activeTab or capture arbitrary visible tabs in this release. It does not request blanket access to all websites.
OAuth scopes (via Google sign-in) may include profile email, Firebase-related API access, Google Sheets, and Drive app data as declared for optional features; tokens are used only to provide those features.
What data we use
- Basic account info needed for sign-in, such as email/profile information from your sign-in provider.
- Data shown on supported HGI pages that is needed for sync features.
- Local extension settings saved in your browser.
- Optional usage analytics (when enabled via remote configuration): aggregated events such as which extension page was opened, which high-level feature was used (for example navigation or sync), and non-identifying error categories. We do not send agent codes, policy numbers, email addresses, or raw API payloads in analytics events.
Why we use this data
- To run core extension features.
- To verify your account for protected actions.
- To keep your extension settings and state working.
- To understand which features are used and to fix reliability issues (optional analytics only).
What we do not do
- We do not sell your personal data.
- We do not use your data for unrelated advertising.
Where data goes
Data is sent only as needed to support HGI sync functionality and authenticated service requests. When analytics is enabled, limited event data is sent to Google Analytics (GA4) using Google’s Measurement Protocol; configuration is controlled remotely and can be turned off without updating the extension.
How long data is kept
Browser-stored extension settings remain until you clear them or remove the extension. Service-side retention follows normal operational needs.
Security
We use reasonable safeguards and expect secure HTTPS connections for network requests.
Your choices
- You can remove this extension at any time.
- You can clear extension data from browser settings.
- You can stop account-linked behavior by signing out.
United States and Canada
This extension and its billing/privacy site are available to users in the United States and Canada. If you are in Canada, you can email us to ask what personal information we have, to correct it, or to withdraw consent where that applies.
Contact
Questions about privacy: privacy@akfinancialconsultants.com