Quick security facts (2026 scan)
| Chrome extension | Monica: ChatGPT AI Assistant |
|---|---|
| Permission profile | Typical for its category |
| All-sites access | Yes — can access every site you visit when enabled |
| Permissions beyond typical | None listed |
| Privacy policy score | 4.1/10 (4 red flags) |
| Scan date / version | 2026-07-31 / 9.0.21 |
What permissions does Monica request?
The following permissions were declared in Chrome extension version 9.0.21 as of the 2026-07-31 scan. If you are asking is Monica for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.
Requests access to all websites you visit.
| Permission | Risk | What it can do |
|---|---|---|
storage | low | Can store data locally in the browser. |
scripting | medium | Can inject and run scripts on pages it has access to. |
sidePanel | low | Can display content in the browser side panel. |
contextMenus | low | Can add items to the right-click context menu. |
tabs | medium | Can see the URLs, titles, and open/close state of your browser tabs. |
tabGroups | low | Can organize your browser tabs into groups. |
activeTab | low | Can act on the current tab only when you click the extension. |
As of the 2026-07-31 scan, the extension requests permissions typical for an AI sidebar assistant, including all-sites access, which is not broader than usual for its category. It requests no permissions beyond this standard set. These typical permissions can support features that read and interact with web page content to provide AI assistance.
Where can Monica data flow?
Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.
12306.cnthird-partyadjust.comthird-partyairbnb.comthird-partyamazon.comthird-partyappsumo.comthird-partyartstation.comthird-partyarxiv.orgthird-partybaidu.comthird-partybbc.comthird-partybilibili.comthird-partybing.comthird-partybit.lythird-partybohemiancoding.comthird-partybooking.comthird-partybutterfly-effect.devthird-partycamelcamelcamel.comthird-partychatgpt.comthird-partycnn.comthird-partycoinmarketcap.comthird-partycrates.iothird-partyctrip.comthird-partydamai.cnthird-partydiscord.comthird-partydiscord.ggthird-partydoordash.comthird-partyduckduckgo.comthird-partyebay.comthird-partyeclipse.orgthird-partyengelschall.comthird-partyetsy.comthird-partyeventbrite.comthird-partyexample.comthird-partyexpedia.comthird-partyexplainpaper.comthird-partyfacebook.comthird-partyfandango.comthird-partyfb.methird-partyfeross.orgthird-partyfiverr.comthird-partygithub.comthird-partygithub.iothird-partygo.devthird-partygoogle.comthird-partygoogleapis.comthird-partygoogleusercontent.comthird-partyhakim.sethird-partyhertzen.comthird-partyibm.comthird-partyimdb.comthird-partyinstagram.comthird-partyjd.comthird-partyjetbrains.comthird-partyjquery.orgthird-partyjsdelivr.netthird-partykonvajs.orgthird-partylinkedin.comthird-partylive.comthird-partylobste.rsthird-partylodash.comthird-partylookintobitcoin.comthird-partymaoyan.comthird-partymarketwatch.comthird-partymeituan.comthird-partymescius.comthird-partymicrosoft.comthird-partymicrosofttranslator.comthird-partymonica-cdn.imthird-partymonica.coolthird-partymonica.imfirst-partymonica.sothird-partymonicausercontent.comthird-partymozilla.orgthird-partymths.bethird-partymusicbrainz.orgthird-partynature.comthird-partynytimes.comthird-partyoclc.orgthird-partyoffice.comthird-partyopenai.comthird-partyopenjsf.orgthird-partyopensource.orgthird-partyopenxmlformats.orgthird-partypinterest.comthird-partyplantuml.comthird-partyplaywright.devthird-partypoeditor.comthird-partyproducthunt.comthird-partyprosemirror.netthird-partypurl.orgthird-partyrarbg.tothird-partyreactjs.orgthird-partyreddit.comthird-partyreuters.comthird-partyrevealjs.comthird-partyscholar.googlethird-partysmzdm.comthird-partysteamcommunity.comthird-partystuartk.comthird-partysvgjs.devthird-partyt.methird-partytaobao.comthird-partythreads.netthird-partyticketmaster.comthird-partytiktok.comthird-partytldrlegal.comthird-partytradingview.comthird-partytripadvisor.comthird-partytwitch.tvthird-partytwitter.comthird-partyubereats.comthird-partyunderscorejs.orgthird-partyunpkg.comthird-partyvercel.appthird-partyvisualstudio.comthird-partyw3.orgthird-partywa.methird-partywalmart.comthird-partywebofscience.comthird-partyweibo.comthird-partywhatsapp.comthird-partywhatwg.orgthird-partywikipedia.orgthird-partyx.comthird-partyxiaohongshu.comthird-partyyahoo.comthird-partyyelp.comthird-partyyou.comthird-partyyoutube.comthird-partyzfrontier.comthird-partyzhihu.comthird-party
As of the 2026-07-31 scan, the extension communicates with the first-party domain monica.im. It also connects to a large number of third-party domains, including amazon.com, google.com, and openai.com. Please note that this external-domain list is a static-analysis lower bound and may miss dynamically loaded endpoints.
Policy claims vs observed: the vendor publishes a privacy policy; the domains above reflect what static analysis observed as of the 2026-07-31 scan, which may differ from the policy's stated data handling.
Privacy policy findings
Policy score: 4.1/10 (as of the 2026-07-31 scan, reviewed against 11 fixed criteria — a measure of policy quality, not a safety verdict).
| Criterion | Score | Flag |
|---|---|---|
| collects only what the feature needs | 2/2 | — |
| sharing with third parties disclosed and limited | 1/2 | — |
| does not sell user data | 2/2 | — |
| retention period specified | 1/2 | — |
| user can request deletion | 0/2 | red flag |
| anonymization/pseudonymization practices stated | 0/2 | — |
| readable, specific, not boilerplate | 1/2 | — |
| GDPR/CCPA handling stated | 2/2 | — |
| notifies users of policy changes | 0/2 | red flag |
| children's data addressed | 0/2 | red flag |
| states whether user content trains AI models | 0/2 | red flag |
- No clear way to request deletion of your data
- Does not commit to notifying users of policy changes
- Children's data handling not addressed
- May train AI models on user content
As of the 2026-07-31 scan, the privacy policy scores 4.1 out of 10 based on how well it addresses 11 fixed criteria. The disclosed facts indicate there is no clear way to request data deletion and it does not commit to notifying users of policy changes. Additionally, children's data handling is not addressed, and the policy states it may train AI models on user content.
Editor's analysis: is Monica safe?
Monica (by Butterfly Effect Pte. Ltd., Singapore) has limited publicly available security documentation. As of the 2026-07-31 scan, here is what the public record shows.
Security certifications: No ISO 27001, SOC 2, or equivalent third-party security certifications were found in public records as of the scan date. Monica's website states it complies with relevant privacy regulations, but does not publish independent audit reports or a dedicated security/compliance page.
Data handling: Monica's privacy policy scored 4.1 out of 10 across our 11 fixed criteria — the lowest among the extensions we scanned. The policy does not provide a clear mechanism for users to request data deletion, does not commit to notifying users of policy changes, and does not address children's data handling. The policy also states that user content may be used to train AI models, with no disclosed opt-out mechanism.
Third-party data flows: Static analysis shows the extension communicates with openai.com, amazon.com, and numerous other third-party domains. This is expected for an AI assistant that routes queries to multiple AI model providers, but the full list of data recipients is not clearly documented in the privacy policy.
For business use: Without published security certifications or a dedicated compliance program, Monica is not suitable for regulated industries or sensitive business use. There is no publicly available SOC 2 report, DPA, or enterprise security documentation.
Bottom line: Monica's security transparency is below the standard set by competitors like Grammarly or DeepL. The low privacy policy score (4.1/10) and multiple red flags — no deletion rights, no change notification, no children's data policy, and undisclosed AI training — are the most significant concerns. If you use Monica, avoid processing sensitive or personal data.
Is Monica safe to use? Monica's permission profile is typical for an AI sidebar (including all-sites access), but public security documentation is thin: no ISO/SOC 2 found at scan time, and the privacy policy scored 4.1/10 with four red flags (deletion rights, policy-change notice, children's data, AI training without clear opt-out). That combination is why we flag it for sensitive or business data — not because the extension is "proven malicious," but because you cannot verify enterprise-grade controls from the public record.
Is Monica for Chrome safe for casual browsing help? For low-stakes prompts (rewriting a tweet, summarizing a public article), many users accept the trade-off. Do not use it as a vault for passwords, health data, legal drafts, or employer confidential material until certifications and a stronger policy appear.
FAQ: is Monica safe to use?
Is Monica safe?
No ISO or SOC 2 certifications found. Privacy policy scored 4.1/10 with four red flags: no data deletion rights, no policy change notification, no children's data policy, and AI training on user content with no disclosed opt-out.
Is Monica safe to use?
No ISO or SOC 2 certifications found. Privacy policy scored 4.1/10 with four red flags: no data deletion rights, no policy change notification, no children's data policy, and AI training on user content with no disclosed opt-out.
Is Monica for Chrome safe?
The Monica Chrome extension was scanned on 2026-07-31 (version 9.0.21). Requests the permissions typical for a AI sidebar assistant. It can access all sites you visit when enabled. Privacy policy quality score: 4.1/10 across 11 criteria.
Is Monica secure for business use?
Security certifications: No ISO 27001, SOC 2, or equivalent third-party security certifications were found in public records as of the scan date. Monica's website states it complies with relevant privacy regulations, but does not publish independent audit reports or a dedicated security/compliance page.
Does Monica use your data for AI training?
The privacy policy states: ""
What permissions does the Monica Chrome extension request?
Monica version 9.0.21 declares: storage, scripting, sidePanel, contextMenus, tabs, tabGroups, activeTab as of the 2026-07-31 scan. Profile: Typical for its category.
Similar extensions
Sider
Another AI sidebar with multi-provider routing — compare permission breadth and policy coverage.
Merlin
AI assistant sidebar with tiered compliance claims — side-by-side disclosure.
Grammarly
Benchmark for certified AI writing extensions when evaluating “is it safe enough for work?”
Compare other AI extensions we scanned
Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.
Is Merlin AI Assistant safe?
Claims SOC 2/GDPR/ISO compliance for paid users only — not independently verified. Privacy policy scored 5.0/10 with three red flags: no data deletion rights, unclear GDPR handling, and AI training on user content.
Broader than typical · scanned 2026-07-31
Is Sider safe?
No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.
Broader than typical · scanned 2026-07-31
Is DeepL Translate safe?
DeepL is ISO 27001 certified and GDPR-compliant. Free-tier translations may train AI models; paid plans do not. The browser extension requests broader permissions than typical for translation tools, but they serve legitimate translation functionality.
Broader than typical · scanned 2026-07-31
Is Grammarly safe?
Grammarly holds SOC 2 Type 2, ISO 27001, ISO 42001, and HIPAA compliance — one of the broadest security portfolios among AI writing tools. Users can opt out of AI training on their content. The extension requests broader permissions than typical, supporting desktop app integration and signed-in web app access.
Broader than typical · scanned 2026-07-31
Compare with every extension we have reviewed on theextension security index, or see how this disclosure is produced on our security methodology page. Looking for a tool by job-to-be-done? Try the AI Tool Finder.