Privacy Policy for Mendeley Referencer Extension
Last Updated: April 7, 2025
Introduction
Thank you for choosing the Mendeley Referencer Extension ("Extension"). This Privacy Policy explains how our Extension handles information when you use it to log into Mendeley and manage references. Our core principle is to respect your privacy and collect absolutely no personal data.
Information We Collect
We do not collect or store any personal data.
The Extension functions solely as a bridge between your browser and Mendeley's authentication system and APIs, allowing you to:
- Log into your Mendeley account via Mendeley's official authentication flow.
- Add references detected on web pages to your Mendeley library using Mendeley's official APIs.
The Extension does not track your browsing activity, the websites you visit, or the references you save beyond the immediate interaction required to save a reference when you trigger the action.
How Authentication Works
When you use our Extension to log in:
- The Extension redirects you or opens a window/tab to Mendeley's official authentication service (login page).
- You provide your username and password directly to Mendeley on their secure domain, not to our Extension.
- Mendeley's authentication system verifies your identity.
- Upon successful login, Mendeley provides the Extension with temporary authentication tokens (OAuth tokens or similar).
- The Extension uses these tokens solely to make authenticated requests to Mendeley's API on your behalf (e.g., to save a reference).
Data Storage
- Credentials: We do not store your Mendeley username, password, or any login credentials. These are handled directly by Mendeley.
- Authentication Tokens: To keep you logged in across browser sessions and avoid requiring you to log in every time, the Extension stores the authentication tokens provided by Mendeley in your browser's secure local storage (e.g., `chrome.storage.local` for Chrome/Edge, `browser.storage.local` for Firefox).
- These tokens are stored locally on your device only and are never transmitted to any servers operated by us. We do not operate any backend servers for the Extension's core functionality.
- Reference Data: We do not store any of your reference data, library contents, PDFs, or notes. This information resides solely within your Mendeley account and is accessed transiently via Mendeley's API only when needed to perform an action you initiate (like saving a reference).
Third-Party Services
Our Extension interacts directly with Mendeley's authentication and API services. Your interaction with Mendeley is governed by their own privacy policy and terms of service. We encourage you to review them:
Elsevier Terms and Conditions (Mendeley is an Elsevier product)
Changes To This Privacy Policy
We may update this Privacy Policy from time to time, particularly if the Extension's functionality changes in a way that impacts data handling (though our intention is to maintain the "no personal data collection" principle). We will notify users of any significant changes by updating the "Last Updated" date at the top of this Privacy Policy. We encourage you to review this policy periodically.
Contact Us
If you have any questions or concerns about this Privacy Policy or the Extension's practices, please contact us at:
Consent
By installing and using the Mendeley Referencer Extension, you acknowledge that you have read and understood this Privacy Policy and agree to its terms regarding the handling of authentication tokens as described herein.