← All extension security reviews

Is Sider Safe? 2026 Chrome Extension Security Review

Independent Chrome extension security disclosure — permissions, data flow, and privacy-policy findings. Last scanned 2026-07-31.

Broader than typical

Requests broader permissions than typical for a AI sidebar assistant.

No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.

Scanned on 2026-07-31 · scanner extscan/0.2.0 · version 5.30.0

Is Sider safe to use?

Sider's Chrome extension requests broader permissions than typical for its ai sidebar category as of the 2026-07-31 scan. It requests access to all websites you visit. Privacy policy could not be fully assessed by our scanner. No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.

This is a disclosure based on a static scan of the Chrome extension and public policy documents — not a pass/fail safety certification. Full methodology:security methodology.

Quick security facts (2026 scan)

Chrome extensionSider: ChatGPT Sidebar
Permission profileBroader than typical
All-sites accessYes — can access every site you visit when enabled
Permissions beyond typicalcookies, userScripts, declarativeNetRequest, tabCapture
Privacy policy scoreNot fully assessed
Scan date / version2026-07-31 / 5.30.0

What permissions does Sider request?

The following permissions were declared in Chrome extension version 5.30.0 as of the 2026-07-31 scan. If you are asking is Sider for Chrome safe, this table is the primary evidence: it shows what the extension is allowed to do when installed.

Requests access to all websites you visit.

PermissionRiskWhat it can do
storagelowCan store data locally in the browser.
cookieshighCan read and modify cookies, which often include login sessions.
contextMenuslowCan add items to the right-click context menu.
scriptingmediumCan inject and run scripts on pages it has access to.
userScriptshighCan register and run arbitrary user scripts on pages.
activeTablowCan act on the current tab only when you click the extension.
unlimitedStoragelowCan store an unlimited amount of local data.
tabsmediumCan see the URLs, titles, and open/close state of your browser tabs.
sidePanellowCan display content in the browser side panel.
offscreenlowCan create a hidden document to use browser APIs that need a page.
alarmslowCan schedule code to run at set times.
declarativeNetRequestmediumCan block or modify network requests using declared rules.
tabCapturehighCan capture the visible content, audio, and video of a tab.
tabGroupslowCan organize your browser tabs into groups.

Permissions beyond the typical ai sidebar set

Compared with the permissions a typical ai sidebar extension needs, Sider also requests the following as of the 2026-07-31 scan. Extra permissions are not inherently a problem — each can support legitimate features. We list what each one can enable so you can weigh it for yourself.

  • cookies (high) — can support reading or setting site cookies, which can let it act inside web apps where you are already signed in.
  • userScripts (high) — can support registering and running its own scripts on pages, which supports user-defined automations.
  • declarativeNetRequest (medium) — can support blocking or rewriting network requests via declared rules, often used to reach an API or adjust headers.
  • tabCapture (high) — can support capturing a tab's audio or video, which can support screen-reading, recording, or meeting features.

As of the 2026-07-31 scan, Sider requests several permissions beyond the typical set for an AI sidebar assistant. The cookies permission can support reading or setting site cookies, which can let it act inside web apps where you are already signed in. The userScripts permission can support registering and running its own scripts on pages, supporting user-defined automations. The declarativeNetRequest permission can support blocking or rewriting network requests via declared rules, often used to reach an API or adjust headers. The tabCapture permission can support capturing a tab's audio or video, which can support screen-reading, recording, or meeting features.

Where can Sider data flow?

Domains below are extracted by static analysis and represent a lower bound — an extension may contact additional endpoints at runtime that this method does not capture.

  • amazon.comthird-party
  • amazonaws.comthird-party
  • anthropic.comthird-party
  • ar5iv.orgthird-party
  • awesomegpts.aithird-party
  • baidu.comthird-party
  • base-ui.comthird-party
  • bilibili.comthird-party
  • bing.comthird-party
  • brave.comthird-party
  • canny.iothird-party
  • cerebras.aithird-party
  • chatgpt.comthird-party
  • chevrotain.iothird-party
  • claude.aithird-party
  • claude.comthird-party
  • cloudflare.comthird-party
  • co.aothird-party
  • co.bwthird-party
  • co.ckthird-party
  • co.crthird-party
  • co.idthird-party
  • co.ilthird-party
  • co.kethird-party
  • co.lsthird-party
  • co.mathird-party
  • co.mzthird-party
  • co.ththird-party
  • co.tzthird-party
  • co.ugthird-party
  • co.uzthird-party
  • co.vethird-party
  • co.vithird-party
  • co.zmthird-party
  • co.zwthird-party
  • com.afthird-party
  • com.agthird-party
  • com.aithird-party
  • com.arthird-party
  • com.bdthird-party
  • com.bhthird-party
  • com.bnthird-party
  • com.bothird-party
  • com.bzthird-party
  • com.cothird-party
  • com.cuthird-party
  • com.cythird-party
  • com.dothird-party
  • com.ecthird-party
  • com.egthird-party
  • com.etthird-party
  • com.fjthird-party
  • com.ghthird-party
  • com.githird-party
  • com.gtthird-party
  • com.jmthird-party
  • com.khthird-party
  • com.kwthird-party
  • com.lbthird-party
  • com.lythird-party
  • com.mmthird-party
  • com.mtthird-party
  • com.mythird-party
  • com.nathird-party
  • com.ngthird-party
  • com.nithird-party
  • com.npthird-party
  • com.omthird-party
  • com.pathird-party
  • com.pethird-party
  • com.pgthird-party
  • com.phthird-party
  • com.pkthird-party
  • com.prthird-party
  • com.pythird-party
  • com.qathird-party
  • com.sathird-party
  • com.sbthird-party
  • com.slthird-party
  • com.svthird-party
  • com.tjthird-party
  • com.uythird-party
  • com.vcthird-party
  • com.vnthird-party
  • curl.sethird-party
  • dashif.orgthird-party
  • deepseek.comthird-party
  • discord.ggthird-party
  • duckduckgo.comthird-party
  • dummy.comthird-party
  • esm.shthird-party
  • example.comthird-party
  • expo.devthird-party
  • facebook.comthird-party
  • fb.methird-party
  • figma.comthird-party
  • fireworks.aithird-party
  • github.comthird-party
  • githubcopilot.comthird-party
  • google-analytics.comthird-party
  • google.adthird-party
  • google.aethird-party
  • google.althird-party
  • google.amthird-party
  • google.asthird-party
  • google.atthird-party
  • google.azthird-party
  • google.bathird-party
  • google.bethird-party
  • google.bfthird-party
  • google.bgthird-party
  • google.bithird-party
  • google.bjthird-party
  • google.bsthird-party
  • google.btthird-party
  • google.bythird-party
  • google.cathird-party
  • google.catthird-party
  • google.cdthird-party
  • google.cfthird-party
  • google.cgthird-party
  • google.chthird-party
  • google.cithird-party
  • google.clthird-party
  • google.cmthird-party
  • google.cnthird-party
  • google.co.inthird-party
  • google.co.jpthird-party
  • google.co.krthird-party
  • google.co.nzthird-party
  • google.co.ukthird-party
  • google.co.zathird-party
  • google.comthird-party
  • google.com.authird-party
  • google.com.brthird-party
  • google.com.hkthird-party
  • google.com.mxthird-party
  • google.com.sgthird-party
  • google.com.trthird-party
  • google.com.twthird-party
  • google.com.uathird-party
  • google.cvthird-party
  • google.czthird-party
  • google.dethird-party
  • google.djthird-party
  • google.dkthird-party
  • google.dmthird-party
  • google.dzthird-party
  • google.eethird-party
  • google.esthird-party
  • google.fithird-party
  • google.fmthird-party
  • google.frthird-party
  • google.gathird-party
  • google.gethird-party
  • google.ggthird-party
  • google.glthird-party
  • google.gmthird-party
  • google.grthird-party
  • google.gythird-party
  • google.hnthird-party
  • google.hrthird-party
  • google.htthird-party
  • google.huthird-party
  • google.iethird-party
  • google.imthird-party
  • google.iqthird-party
  • google.isthird-party
  • google.itthird-party
  • google.jethird-party
  • google.jothird-party
  • google.kgthird-party
  • google.kithird-party
  • google.kzthird-party
  • google.lathird-party
  • google.lithird-party
  • google.lkthird-party
  • google.ltthird-party
  • google.luthird-party
  • google.lvthird-party
  • google.mdthird-party
  • google.methird-party
  • google.mgthird-party
  • google.mkthird-party
  • google.mlthird-party
  • google.mnthird-party
  • google.msthird-party
  • google.muthird-party
  • google.mvthird-party
  • google.mwthird-party
  • google.nethird-party
  • google.nlthird-party
  • google.nothird-party
  • google.nrthird-party
  • google.nuthird-party
  • google.plthird-party
  • google.pnthird-party
  • google.psthird-party
  • google.ptthird-party
  • google.rothird-party
  • google.rsthird-party
  • google.ruthird-party
  • google.rwthird-party
  • google.scthird-party
  • google.sethird-party
  • google.shthird-party
  • google.sithird-party
  • google.skthird-party
  • google.smthird-party
  • google.snthird-party
  • google.sothird-party
  • google.srthird-party
  • google.stthird-party
  • google.tdthird-party
  • google.tgthird-party
  • google.tlthird-party
  • google.tmthird-party
  • google.tnthird-party
  • google.tothird-party
  • google.ttthird-party
  • google.vgthird-party
  • google.vuthird-party
  • google.wsthird-party
  • googleapis.comthird-party
  • gptshere.comthird-party
  • groq.comthird-party
  • huggingface.cothird-party
  • instagram.comthird-party
  • iso.orgthird-party
  • json-schema.orgthird-party
  • kagi.comthird-party
  • kimi.comthird-party
  • langium.orgthird-party
  • linkedin.comthird-party
  • microsoft.comthird-party
  • microsofttranslator.comthird-party
  • minimax.iothird-party
  • minimaxi.comthird-party
  • mistral.aithird-party
  • moonshot.aithird-party
  • moonshot.cnthird-party
  • naver.comthird-party
  • netflix.comthird-party
  • oaiusercontent.comthird-party
  • oauth.netthird-party
  • openai.comthird-party
  • opencode.aithird-party
  • openrouter.aithird-party
  • prosemirror.netthird-party
  • reactjs.orgthird-party
  • reddit.comthird-party
  • s3-fips.dualstackthird-party
  • s3.dualstackthird-party
  • searx.bethird-party
  • sider.aifirst-party
  • sidercontent.comthird-party
  • siderusercontent.comthird-party
  • stackexchange.comthird-party
  • threads.netthird-party
  • together.aithird-party
  • twitter.comthird-party
  • vercel.shthird-party
  • w3.orgthird-party
  • whatsapp.comthird-party
  • wikipedia.orgthird-party
  • wolframalpha.comthird-party
  • x.aithird-party
  • x.comthird-party
  • xiaomimimo.comthird-party
  • yahoo.co.jpthird-party
  • yahoo.comthird-party
  • ycombinator.comthird-party
  • youtu.bethird-party
  • youtube-nocookie.comthird-party
  • youtube.comthird-party
  • ytjs.devthird-party
  • z.aithird-party
  • zaobao.comthird-party
  • zaobao.com.sgthird-party
  • zeroclick.devthird-party

As of the 2026-07-31 scan, the extension references one first-party vendor-owned domain (sider.ai) and a large number of third-party external domains, including services such as amazonaws.com, anthropic.com, openai.com, google-analytics.com, and many others spanning search engines, social media platforms, and AI providers. This domain list is a static-analysis lower bound, meaning it may miss dynamically loaded endpoints not visible in the extension's code at scan time. What data, if any, flows to these domains depends on how the extension operates in practice, which this scan does not assess.

Privacy policy findings

No privacy policy was fetched or scored as of the 2026-07-31 scan.

Editor's analysis: is Sider safe?

Sider (by Sider AI / Vidline Inc.) has limited publicly available security documentation, and its privacy policy could not be reached during our automated scan. As of the 2026-07-31 scan, here is what the public record shows.

Security certifications: No ISO 27001, SOC 2, or equivalent third-party security certifications were found in public records as of the scan date. Sider's website does not publish a dedicated security or compliance page.

Privacy policy: Our automated scanner could not reach or assess Sider's privacy policy (scan status: partial:policy). This means we have no policy score, no criteria breakdown, and no red flags from the policy review. Without a reviewed privacy policy, we cannot report on what Sider states it collects, shares, retains, or whether user content trains AI models.

Data flows: Static analysis shows the extension communicates with sider.ai (first-party) and a very large number of third-party domains, including anthropic.com, openai.com, google-analytics.com, and amazonaws.com. This is expected for an AI sidebar that routes queries to multiple AI model providers (ChatGPT, Claude, Gemini, Grok). The extensive domain list reflects the multi-provider architecture.

Permissions: Sider requests cookies, userScripts, declarativeNetRequest, and tabCapture — all beyond the typical set for an AI sidebar. These can support running custom scripts on pages, interacting with signed-in web apps, modifying network requests, and capturing tab audio or video. Each can serve legitimate features, but together they represent a broad permission set.

For business use: Without published security certifications or a reviewed privacy policy, Sider's suitability for regulated industries cannot be assessed. There is no publicly available SOC 2 report, DPA, or enterprise security documentation.

Bottom line: The inability to assess Sider's privacy policy is itself a data gap. Combined with no known security certifications and a broad permission set, users should exercise caution with sensitive data. The multi-provider AI architecture means your queries may be routed to different AI models — understand what that implies for your data before use.

Is Sider safe to use? Sider routes queries across multiple model providers and requests broader-than-typical permissions (cookies, userScripts, declarativeNetRequest, tabCapture) plus all-sites access. We could not fully score the privacy policy during the automated scan, and no ISO/SOC 2 certifications were found publicly. That leaves a documentation gap: the product may be fine for casual use, but we cannot show the same control evidence we can for Grammarly or DeepL.

Is Sider for Chrome safe on a work laptop? If your company restricts extensions with tab capture or custom script injection, Sider will likely fail policy review. For personal research on non-sensitive pages, review the permission table on this page and decide against your own threat model.

FAQ: is Sider safe to use?

Is Sider safe?

No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.

Is Sider safe to use?

No security certifications found and privacy policy could not be assessed by our scanner. The extension routes queries to multiple AI providers (ChatGPT, Claude, Gemini) and requests broad permissions including custom script execution and tab capture.

Is Sider for Chrome safe?

The Sider Chrome extension was scanned on 2026-07-31 (version 5.30.0). Requests broader permissions than typical for a AI sidebar assistant. It can access all sites you visit when enabled. Privacy policy was not fully scored.

Is Sider secure for business use?

Security certifications: No ISO 27001, SOC 2, or equivalent third-party security certifications were found in public records as of the scan date. Sider's website does not publish a dedicated security or compliance page.

Does Sider use your data for AI training?

No clear statement was found in the privacy policy as of the 2026-07-31 scan.

What permissions does the Sider Chrome extension request?

Sider version 5.30.0 declares: storage, cookies, contextMenus, scripting, userScripts, activeTab, unlimitedStorage, tabs, sidePanel, offscreen, alarms, declarativeNetRequest, tabCapture, tabGroups as of the 2026-07-31 scan. Profile: Broader than typical.

Similar extensions

Monica

Peer AI sidebar — typical vs broader permission profile comparison.

Merlin

AI assistant with partial compliance claims — compare documentation gaps.

Grammarly

Certified baseline when your question is business security controls.

Compare other AI extensions we scanned

Still deciding? Read independent disclosures for other AI Chrome extensions — same methodology, same scan date window.