
Extension Permissions
Last updated: June 20, 2026
Chrome shows a strong warning, “Read and change all your data on all websites,” when an extension like Kotoro needs to run on web pages. This page explains why that warning appears and what Kotoro actually does.
Why does Kotoro ask for broad permissions?
Kotoro is not limited to one website. It is a Chrome extension that places a cat on top of pages while you browse. To show the cat, let you drag it, open right-click chat, and run tutorials, Kotoro needs permission to add small UI elements to the page you are viewing.
Why does Chrome sound scary?
Chrome groups page-overlay features under a broad phrase: “read and change site data.” For Kotoro, the practical meaning is closer to: “Can Kotoro place and move the cat on this page?”
What Kotoro does not do
- We did not build features that collect passwords, card numbers, or government ID numbers.
- We did not build features that secretly save what you are typing.
- We did not build features that automatically send every page you visit to our server.
- Kotoro does not inject ads, manipulate shopping prices, or replace page content.
When is page content used?
Page information may be used only when it is needed for a feature, such as when you explicitly choose to include page context in chat. Showing, moving, or resizing the cat does not send the full page to our server.
What is the server permission for?
Access to the Kotoro API server (apiv2.kotoro.click) is used for login, chat, character data, and applying purchased characters. This is separate from permission to run on other websites.
What happens if I deny permission?
If you deny permission, Kotoro cannot provide its core feature of staying with you across web pages. You can allow or remove extension permissions later in Chrome settings.