Is Gratly Safe? What the Extension Can and Cannot Do
Installing a browser extension means handing something a lot of access, so it is fair to ask what it does with it. This page answers that for Gratly without softening the awkward parts.
The short version
A small script from Gratly runs on the pages you visit and checks whether each one looks like a recipe, so the button can appear when it is useful. That check happens on your device. Nothing about a page is sent anywhere until you click to save it, and Gratly can only send data to one place: its own servers at gratly.app.
The warning Chrome shows you
When you install Gratly, Chrome says it can read and change all your data on all websites.
That is accurate, and every extension that puts a button on the right pages shows the same warning. It is worth understanding why, rather than either panicking or waving it away.
To know whether the page you are on is a recipe, something has to look at the page. Chrome has no permission level for "just check for a recipe marker". The options are all-sites access or nothing, so that is what gets requested.
What that script actually does is narrow: it looks for a recipe tag in the page's own structured data, or an ingredients list in the markup. If it finds one, the button appears. If it does not, nothing happens. It does not copy the page, store it, or send it anywhere.
When Gratly reads a page, precisely
There are two distinct moments, and conflating them is where most explanations go wrong.
On every page you visit: a lightweight check for recipe markers, run locally, to decide whether to show the button. Nothing leaves your device.
When you click save: the full recipe is extracted, and that recipe goes to your account so it syncs across your devices.
So the honest answer to "does it read pages on its own" is: it performs a small local check on its own, and it extracts and sends a recipe only when you ask it to.
Reading and sending are different things
This is the distinction that actually matters for your privacy, and it is the one worth holding onto.
An extension's ability to read a page and its ability to transmit what it read are governed separately. Gratly's network access is limited to gratly.app. It has no permission to reach any other server.
So even in the worst reading of the site-access warning, there is no route by which your browsing could be sent to an advertiser, a data broker, or anyone else, because the extension cannot open a connection to them. That is a structural limit, not a promise about intentions.
What each permission is for
- Access to the pages you visit. The recipe check described above, and reading the recipe itself once you click save.
- Storage. Your settings, such as unit preference, and a session token so you are not signed out on every page.
- Side panel. Where the clean recipe and cook mode appear, so you can cook alongside the original page.
- Scripting. Injecting the extraction routine and the cook-mode interface into the page you chose to save.
- Tabs. Knowing which tab you are saving from, and opening a saved recipe in the web app.
- Access to gratly.app. The only site Gratly can talk to. Used to sign you in and sync your recipes.
Where your recipes live
Saved recipes go to your Gratly account so you can open them on any device you sign in on.
You can delete a single recipe or your whole account whenever you want. The privacy policy has the full detail on what is stored.
What Gratly does not do
- It does not build a history of the sites you browse.
- It does not sell or share your recipe data.
- It does not send any page content anywhere before you click save.
- It cannot contact any server other than gratly.app.
How to check this for yourself
You do not have to take a vendor's word for it, and you should not. For any extension:
- Open
chrome://extensions, find it, and click Details. The site access and permissions are listed there. - Open DevTools on the Network tab and browse a few non-recipe pages. If an extension were exfiltrating browsing, it would need requests going somewhere, and you would see them.
- Read the privacy disclosures on its Chrome Web Store listing, which developers are required to complete.
Those three checks take a few minutes and work on any extension you are considering, not just this one. See also what to look for in a Chrome extension to save recipes.
FAQ
Does Gratly read every website I visit? It runs a small local check on pages you visit to see whether they contain a recipe, which is what makes the button appear at the right time. That check stays on your device. Full extraction happens only when you click save.
So does it send my browsing history anywhere? No, and it could not. Its network access is limited to gratly.app, so it has no route to any other server.
What data does Gratly actually collect? The recipes you choose to save, and your settings. Not your browsing history.
Why does it need access to all websites? Because recipes live on thousands of different sites, and Chrome offers no narrower permission for "check whether this page is a recipe".
Do I need an account? Yes, one free account, so your recipes sync across devices rather than living in a single browser profile. See saving recipes without creating another account.
Is Gratly free? Saving and cleaning recipes from any site is free, up to 20 active recipes, with cook mode. See what is free and what is Plus.
Can I remove it cleanly? Yes. Uninstalling removes the extension and its local data, and you can delete your account and its recipes separately from your settings.
Save recipes without giving up your privacy
Gratly asks for the access it needs to do one job and cannot reach anywhere beyond its own servers. Add Gratly to Chrome for free.