Corroba

Corroba browser extension

Privacy policy

Last updated: July 6, 2026

The Corroba “Check a Source” extension is built the same way as corroba.com: no accounts, no ads, and no tracking. This policy explains exactly what it does and does not do with your data.

The short version

What the extension sends, and when

When you click “Check this source,” the text in the box (a DOI, link, or citation) is sent to Corroba's server (corroba.com/api/source) so it can be looked up against public scholarly databases (Crossref, OpenAlex, PubMed, DOAJ, and the DOI system). The result — whether the source is peer-reviewed, a preprint, retracted, indexed, and so on — is shown back to you. That request is only ever made when you click the button.

The current tab's address

When you open the popup, the extension reads the URL of the tab you're on and pre-fills it into the box, so checking the page you're reading takes one click. That URL stays on your device and is not sent anywhere unless you then choose to check it. This is what the activeTab permission is for.

Permissions, explained

Data retention

Corroba caches source lookups briefly to keep the service fast, since bibliographic data rarely changes. These caches are keyed by the source identifier (e.g., a DOI), not by you — there is no account, cookie, or identifier tying a lookup to a person.

Changes

If the extension's data practices ever change, we'll update this page and its date. The current, always-free web tools at corroba.com follow the same principles.

Contact

Questions? Email support@corroba.com.