MyChart Takeout (the bookmarklet and the browser extension) exports your own health record from an Epic MyChart patient portal you are signed in to. This policy covers both.
The tool has no server, no account, no analytics and no telemetry. Its author never receives your health data, your portal credentials, your browsing activity, or anything else.
When you start an export, the tool reads your record from your portal using the session you are already signed in with, inside your own browser tab. It assembles a ZIP file in that tab's memory and offers it to you as a download. The only network requests it makes go to the portal you are on. Closing the tab discards everything that wasn't downloaded. A small run log (request paths and outcomes — no record contents) is kept in the tab's session storage so a failed run can be diagnosed; it is cleared when the tab closes.
The extension does nothing until you click its toolbar button. activeTab gives it access
to the one tab you clicked it on, at that moment; scripting lets it start the exporter in
that tab. It requests no access to any site in advance, runs nothing in the background, and loads no
remote code — everything it runs ships inside the extension.
If something fails you can click Debug to produce a text report. It is shown to you first and is sent nowhere; sharing it is your choice. It is designed to leave out record contents, but it names your health system, so share it privately.
The downloaded ZIP contains sensitive health information. Once it is on your computer, keeping it safe is up to you.
Questions or concerns: https://github.com/jmandel/mychart-takeout/issues. The full source code is public at https://github.com/jmandel/mychart-takeout.