Quick security facts (2026 scan)
| Chrome extension | Merlin AI Assistant |
|---|---|
| Permission profile | Broader than typical |
| All-sites access | Yes — can access every site you visit when enabled |
| Permissions beyond typical | webRequest |
| Privacy policy score | 5/10 (3 red flags) |
| Scan date / version | 2026-07-31 / 8.0.17 |
What permissions does Merlin AI Assistant request?
The following permissions were declared in Chrome extension version 8.0.17 as of the 2026-07-31 scan. If you are asking is Merlin AI Assistant for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.
Requests access to all websites you visit.
| Permission | Risk | What it can do |
|---|---|---|
sidePanel | low | Can display content in the browser side panel. |
storage | low | Can store data locally in the browser. |
contextMenus | low | Can add items to the right-click context menu. |
tabs | medium | Can see the URLs, titles, and open/close state of your browser tabs. |
alarms | low | Can schedule code to run at set times. |
webNavigation | medium | Can observe how you navigate between pages. |
webRequest | high | Can observe network requests your browser makes. |
scripting | medium | Can inject and run scripts on pages it has access to. |
identity | medium | Can get an OAuth token tied to your signed-in account. |
Permissions beyond the typical ai sidebar set
Compared with the permissions a typical ai sidebar extension needs, Merlin AI Assistant also requests the following as of the 2026-07-31 scan. Extra permissions are not inherently a problem — each can support legitimate features. We list what each one can enable so you can weigh it for yourself.
webRequest(high) — can support observing or modifying the network requests your browser makes, which can support rewriting or routing API traffic.
As of the 2026-07-31 scan, the extension requests a broader permission profile than typical for its category. This includes the webRequest permission, which can support observing or modifying the network requests your browser makes. This capability is often used to support rewriting or routing API traffic.
Where can Merlin AI Assistant data flow?
Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.
bit.lythird-partychevrotain.iothird-partycloudfunctions.netthird-partyexample.comthird-partygetmerlin.infirst-partygithub.comthird-partygivefreely.comthird-partygoogle-analytics.comthird-partygoogle.comthird-partygoogleapis.comthird-partygstatic.comthird-partyibm.comthird-partyjsdelivr.netthird-partyjson-schema.orgthird-partylangium.orgthird-partylinkedin.comthird-partymozilla.orgthird-partyradix-ui.comthird-partyreact.devthird-partyshop.appthird-partytwitter.comthird-partyw3.orgthird-partywikipedia.orgthird-partyx.comthird-partyyoutube.comthird-partyytimg.comthird-party
As of the 2026-07-31 scan, data can flow to the first-party domain getmerlin.in, alongside several third-party domains such as google-analytics.com, linkedin.com, and x.com. This list is a static-analysis lower bound, meaning it may miss dynamically loaded endpoints, so data flow could be broader than what is statically visible.
Policy claims vs observed: the vendor publishes a privacy policy; the domains above reflect what static analysis observed as of the 2026-07-31 scan, which may differ from the policy's stated data handling.
Privacy policy findings
Policy score: 5/10 (as of the 2026-07-31 scan, reviewed against 11 fixed criteria — a measure of policy quality, not a safety verdict).
| Criterion | Score | Flag |
|---|---|---|
| collects only what the feature needs | 1/2 | — |
| sharing with third parties disclosed and limited | 2/2 | — |
| does not sell user data | 2/2 | — |
| retention period specified | 1/2 | — |
| user can request deletion | 0/2 | red flag |
| anonymization/pseudonymization practices stated | 1/2 | — |
| readable, specific, not boilerplate | 2/2 | — |
| GDPR/CCPA handling stated | 1/2 | red flag |
| notifies users of policy changes | 0/2 | — |
| children's data addressed | 0/2 | — |
| states whether user content trains AI models | 1/2 | red flag |
- No clear way to request deletion of your data
- GDPR/CCPA handling not stated
- May train AI models on user content
As of the 2026-07-31 scan, the privacy policy scores 5.0 out of 10 based on how well it addresses 11 fixed criteria. Disclosed red flags include no clear way to request data deletion, unstated GDPR/CCPA handling, and a statement that the service may train AI models on user content.
Editor's analysis: is Merlin AI Assistant safe?
Merlin (by getmerlin.in / 100x Engineers) is a smaller AI assistant with limited publicly verifiable security documentation. As of the 2026-07-31 scan, here is what the public record shows.
Security certifications: Merlin's privacy policy claims full compliance with SOC 2, GDPR, and ISO standards for users on paid plans (USD 5/month or more). However, these claims could not be independently verified through published certificates or audit reports as of the scan date. No ISO 27001 certificate or SOC 2 report was found on Merlin's website or through public registries.
Data handling: The privacy policy scored 5.0 out of 10 across our 11 fixed criteria. Three red flags were identified: no clear mechanism for users to request data deletion, GDPR/CCPA handling not clearly stated (only referenced for paid-tier users), and user content may be used to develop and improve AI models. The policy does address retention periods, stating extension activity data is kept only as long as reasonably necessary.
Infrastructure: Merlin's extension communicates with getmerlin.in (first-party) alongside google-analytics.com, linkedin.com, and x.com. The data flow suggests standard analytics and social sharing integrations.
For business use: The tiered compliance model — where security guarantees only apply to paid users — is unusual and creates a two-class system. Without independently verifiable certifications, Merlin's security claims cannot be relied upon for regulated industry use.
Bottom line: Merlin's security posture is in the lower tier among the extensions we scanned. The privacy policy's tiered compliance claim (paid users get SOC 2/GDPR/ISO, free users do not) is a red flag in itself. The policy score of 5.0/10 and three red flags — no deletion rights, unclear GDPR handling, and AI training — compound the concern. Users handling sensitive data should prefer extensions with independently verified certifications.
Is Merlin safe to use? Merlin claims SOC 2/GDPR/ISO benefits primarily for paid users — a tiered compliance story we treat as a caution signal because free-tier guarantees are weaker and claims were not independently verified at scan time. Privacy policy scored 5.0/10 with red flags for deletion clarity, GDPR/CCPA clarity, and AI training.
Is Merlin for Chrome safe for business? Not as a default for regulated work. Prefer extensions with independently published audit reports and clear, tier-agnostic data processing terms. Casual personal use is a user judgment call after reading the permission and policy sections above.
FAQ: is Merlin AI Assistant safe to use?
Is Merlin AI Assistant safe?
Claims SOC 2/GDPR/ISO compliance for paid users only — not independently verified. Privacy policy scored 5.0/10 with three red flags: no data deletion rights, unclear GDPR handling, and AI training on user content.
Is Merlin AI Assistant safe to use?
Claims SOC 2/GDPR/ISO compliance for paid users only — not independently verified. Privacy policy scored 5.0/10 with three red flags: no data deletion rights, unclear GDPR handling, and AI training on user content.
Is Merlin AI Assistant for Chrome safe?
The Merlin AI Assistant Chrome extension was scanned on 2026-07-31 (version 8.0.17). Requests broader permissions than typical for a AI sidebar assistant. It can access all sites you visit when enabled. Privacy policy quality score: 5/10 across 11 criteria.
Is Merlin AI Assistant secure for business use?
Security certifications: Merlin's privacy policy claims full compliance with SOC 2, GDPR, and ISO standards for users on paid plans (USD 5/month or more). However, these claims could not be independently verified through published certificates or audit reports as of the scan date. No ISO 27001 certificate or SOC 2 report was found on Merlin's website or through public registries.
Does Merlin AI Assistant use your data for AI training?
The privacy policy states: "Develop, test, and improve our AI models and Services"
What permissions does the Merlin AI Assistant Chrome extension request?
Merlin AI Assistant version 8.0.17 declares: sidePanel, storage, contextMenus, tabs, alarms, webNavigation, webRequest, scripting, identity as of the 2026-07-31 scan. Profile: Broader than typical.
Similar extensions
Monica
AI sidebar peer — compare privacy-policy scores and red flags.
Sider
Multi-model sidebar with broader permission set.
DeepL Translate
Example of ISO/SOC-backed extension disclosure for contrast.
Compare other AI extensions we scanned
Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.
Is Monica safe?
No ISO or SOC 2 certifications found. Privacy policy scored 4.1/10 with four red flags: no data deletion rights, no policy change notification, no children's data policy, and AI training on user content with no disclosed opt-out.
Typical for its category · scanned 2026-07-31
Is Sider safe?
No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.
Broader than typical · scanned 2026-07-31
Is DeepL Translate safe?
DeepL is ISO 27001 certified and GDPR-compliant. Free-tier translations may train AI models; paid plans do not. The browser extension requests broader permissions than typical for translation tools, but they serve legitimate translation functionality.
Broader than typical · scanned 2026-07-31
Is Grammarly safe?
Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.
Broader than typical · scanned 2026-07-31
Compare with every extension we have reviewed on theextension security index, or see how this disclosure is produced on our security methodology page. Looking for a tool by job-to-be-done? Try the AI Tool Finder.