What the extension does
The extension connects an authenticated Apify Console session to an ActorConsole workspace. After a workspace is connected, you can also ask the extension to create or reuse a dedicated member API key for that workspace. You can enter an API key manually in ActorConsole instead.
Data accessed
Pairing requires you to sign in to ActorConsole in a browser tab. The extension stores a scoped ActorConsole device credential in trusted Chrome extension storage, along with the paired account ID, username, name, email, and profile image URL. It checks that pairing before each Apify workspace connection. Disconnecting in the sidebar revokes the credential. The pairing expires after 90 days unless revoked sooner.
While paired, the extension requests that account's workspace names and Apify connection status from ActorConsole. You may select a workspace or create a new one from the sidebar. A new workspace is owned by the paired ActorConsole account and receives Apify credentials only after the connection completes.
On Apify Console pages, the extension observes only the request and response forconsole-backend.apify.com/public/authentication/resume. It reads the returned user ID and short-lived UI token, and the request's viewed account ID when present. It uses the token once to request the signed-in person's profile from api.apify.com and accessible organizations fromconsole-backend.apify.com, then discards the token. If the authenticated profile lookup fails, it tries Apify's public profile endpoint.
After you request a diagnostic check or start a connection and approve Chrome's permission request, the extension checks console.apify.com and console-backend.apify.com for a cookie named ApifyRT. The first domain is checked only to provide a useful diagnostic. Only a live cookie available to the Console Backend domain is sent.
The detected user ID, username, account name, picture URL, selected account ID, and available organization IDs, names, usernames, and picture URLs are kept in Chrome session storage for up to 30 minutes. Non-secret profile and organization display details are also kept in trusted local extension storage so the account list can be shown after Chrome restarts. They are cleared when you disconnect the ActorConsole pairing. The extension keeps the last cookie check's availability flags, outcome, and time for that detected Apify user in session storage. The sidebar asks for a recheck after ten minutes. Cookie values and UI tokens are never stored in Chrome storage.
The extension also handles a short-lived handoff ID, random challenge, workspace name, and expiration time supplied by ActorConsole. This handoff metadata is kept in Chrome session storage until the connection completes or expires, so the sidebar can recover if Chrome restarts the extension service worker.
Use, transmission, and retention
The selected ApifyRT value is relayed once through the authenticated ActorConsole page over HTTPS. The extension does not write it to Chrome storage, localStorage, the clipboard, URLs, analytics, or logs. ActorConsole validates the session, reduces it to the required cookie, encrypts it, and stores it only for the selected workspace.
If you choose to create an ActorConsole API key, the extension uses the current Apify Console session to find an existing dedicated key for that workspace or create a new member key in the selected personal account or organization. The key is sent directly over HTTPS to the paired ActorConsole account, which verifies that it belongs to the workspace's selected Apify account and stores it encrypted with that workspace's credentials. The extension does not retain the key in Chrome storage, URLs, the clipboard, analytics, or logs. Removing the workspace connection deletes ActorConsole's saved key, but does not revoke the key in Apify Console; you can manage or revoke it there.
Data not accessed
The extension does not inspect browsing history, arbitrary website content, other network responses outside the Apify authentication and user-initiated API key flow, complete cookie exports, unrelated cookies, cURL data, payment information, or advertising identifiers. It does not use the debugger or webRequest APIs and contains no third-party tracking or remotely hosted code.
Sharing and sale
Authentication data is used only to provide the workspace connection requested by the user. It is not sold, used for advertising, shared with data brokers, or used to determine creditworthiness.
User control
Cookie access is requested at runtime and can be denied or revoked in Chrome. You can use ActorConsole's manual cookie or cURL instructions instead. The extension removes its optional cookie permission after each check or connection attempt. Disconnecting Apify from the workspace removes its saved credentials from ActorConsole. A dedicated API key remains in Apify until you revoke it there.
Contact
Questions about the extension or this disclosure can be sent through the ActorConsole contact page. The general ActorConsole privacy policy also applies to account and workspace data.