Pomegranate — Capture & Review privacy policy.
Last updated August 18, 2026 · alpha build, invited testers only
What this extension does
The Pomegranate browser extension lets a signed-in Pomegranate user save selected web content — text, images, or whole pages — into their team's Pomegranate workspace, and ask questions or request a review of the current page against that workspace's content.
What data the extension accesses
- Page content you act on. Only text, images, or page content you explicitly select and choose to capture, ask about, or review. The extension never transmits page content automatically or in the background — every capture is triggered by you (the right-click menu, a button in the side panel, or a small "Add to Pomegranate" button that appears next to your selection, or floats on the page for whole-page capture). That in-page button does check, locally and on every page you visit, whether you currently have text selected — purely to decide whether to show itself. That check never leaves your device; nothing is sent to Pomegranate until you click Save.
- Your Pomegranate connection token. A credential provisioned for you by your Pomegranate workspace admin, used to authenticate requests to Pomegranate's API. Stored only on your device (
chrome.storage.local), never transmitted anywhere except toapp.pomegranate.expertas an authentication header, and never synced across devices via your Google account.
Why this extension can read any site you visit
Chrome will show you a warning at install that this extension can "read and change all your data on the sites you visit." That's broader than most extensions ask for, and we want to be direct about why: it's what lets you select text on any page and see a small "Add to Pomegranate" button appear right there, and it's what keeps that working reliably even if you switch tabs before clicking a button in the side panel. Without it, capture would either require re-approving access one site at a time, or would silently fail after switching tabs — both worse than the broader, one-time grant. What that access does not do: it doesn't mean we see, log, or transmit what you browse. The section above still holds exactly as written — reading a page to check for a selection is local-only, and nothing reaches Pomegranate until you explicitly act.
Where data goes
Everything the extension sends leaves your browser for exactly one destination: https://app.pomegranate.expert — Pomegranate's own API, over HTTPS. There are no third-party analytics, ad networks, or trackers in this extension. We do not sell or share the content you capture with anyone outside your own Pomegranate workspace.
Data retention and deletion
Content you capture is stored in your team's Pomegranate workspace under the same retention and deletion rules as any other content added to Pomegranate — via the web app, Slack, or any other client — visible to whoever you set the capture's audience to (Team / Private / Only me), and removable through the Pomegranate web app. Disconnecting the extension (Settings → Disconnect) deletes the locally stored token immediately; it does not delete anything already saved to your workspace.
Permissions, plainly
- Read pages you visit — to grab your selection or the page's text when you trigger a capture/ask/review, and to power the small in-page button that appears when you select text (so you don't have to open a menu first). Reading a page to check for a selection, or to show that button, never sends anything anywhere — only a capture/ask/review you explicitly confirm is transmitted, and only to app.pomegranate.expert.
- Show a right-click menu and a side panel — the extension's UI.
- Store your token locally — so you don't have to re-enter it.
- Show a notification — to confirm a capture succeeded or failed.
No permission is used for anything beyond what's described above.
Contact
Questions about this extension or your data: hello@pomegranate.expert.