01What the extension asks for at install
| Permission | Why |
|---|---|
Side panel Chrome, Edge · sidePanel | Overset opens in the side panel so it can sit next to the spreadsheet you’re translating. Firefox uses its sidebar instead, which needs no permission. |
Storage All browsers · storage | Keeps your projects, settings and, if you add them, your keys and tokens on this device. |
Unlimited storage All browsers · unlimitedStorage | Game projects, uploaded fonts and translation memories regularly outgrow the browser’s default quota. Everything still stays on your device. |
Sign-in All browsers · identity | Lets you sign in to Google, only when you choose to write your translations to the Google Sheet you work in. Overset writes only the cells you changed in your own column, after checking each one hasn’t been changed by someone else. Without it, the browser can’t open Google’s sign-in window. |
Google Sheets docs.google.com/spreadsheets/* | Reads the sheet you have open, as CSV and with your own sign-in, when you choose to load or sync it. A content script on Sheets pages tells the panel which cell is selected and what you’re typing, so the checks follow you. |
Google’s download host *.googleusercontent.com/* | Google Sheets’ CSV export redirects to this domain, so loading a sheet needs it too. |
Anthropic API api.anthropic.com/* | Used only if you add your own API key and start a Claude action. The request goes straight from your browser to Anthropic. |
02What it asks for only when you use a connection
Nothing in this list is granted at install. Each entry is requested the first time you use that connection, and you can decline it; Overset then simply doesn’t reach that service. The choice is yours per service, and you can remove an allowed service from your browser’s extension settings at any time.
| Permission | Why |
|---|---|
Google Sheets API sheets.googleapis.com/* | Writes the cells you changed, and reads the developer’s cell notes. |
GitHub api.github.com/*, github.com/login/* | Lists your repositories, reads their language files, opens pull requests and issues for you, and signs you in with a one-time code. |
Crowdin api.crowdin.com/*, *.api.crowdin.com/* | Imports strings and pushes your translations in your Crowdin project, including its enterprise address. |
Weblate hosted.weblate.org/* | The same for Weblate’s hosted service. |
A self-hosted Weblate server https://*/*, for one address | Requested for the single address of your own Weblate server, the one you type in — never for other sites. |
DeepL api.deepl.com/*, api-free.deepl.com/* | Drafts translations with your own DeepL key. |
Discord discord.com/api/webhooks/*, discordapp.com/api/webhooks/* | Posts progress to a channel webhook you provide. |
03What it doesn’t ask for
- Access to any other website at install — the services above are requested one at a time, when you first use them
- Your browsing history, tabs, bookmarks or downloads
- Cookies, or your Google account identity beyond the sign-in you start yourself
- Remote code: nothing is loaded or evaluated from the network
04What your browser will say
Chrome and Edge ask at install. Their prompt words site access broadly — “read and change your data” on docs.google.com, googleusercontent.com and api.anthropic.com — because that is how browsers describe any site permission. Overset only reads from Google Sheets, and only talks to Anthropic when you start a Claude action. Later, each connection asks once, naming the service, the first time you use it.
Firefox asks for site access the first time you need it: when you first load a sheet, or first use Claude or a connection. If you said no, open about:addons, choose Overset, and allow it under Permissions.
05The web app
The web app asks for no permissions at all and has no connections. It works with files you open and sheets you paste, keeps projects in this site’s browser storage, and can’t read other tabs. See the Privacy Policy for the full picture.