Privacy

Privacy without hiding the product boundaries.

This policy explains the information BrowserPair processes to connect an authorized AI agent with a browser you control.

Information we process

When you create an account, BrowserPair processes your verified email address and identity-provider identifier. To operate the product, BrowserPair also processes browser pairing records, scoped agent-key metadata, task status and usage records.

Task goals, contracts, model-provider credentials and results stored by BrowserPair use encrypted storage appropriate to their role. BrowserPair does not export your full signed-in browser profile. During a task, minimum-necessary semantic observations may transit BrowserPair Cloud; accessibility data, bounded DOM representations or screenshots are transmitted only when the configured observation policy allows the task to request them.

Passwords, OTPs, payment fields, API secrets and auth tokens are redacted on-device by default. If you explicitly grant a protected category, BrowserPair may disclose only that category within the effective task, agent and domain scope. One-time permissions are bound to the exact pending action and are auditable and revocable.

How information is used

We use this information to authenticate you, connect browsers and agents you authorize, enforce permissions and usage limits, route and recover tasks, prevent abuse, investigate failures and maintain the service.

Advertising

We do not sell personal information or use browser content for advertising.

Service providers

Cloudflare provides hosting and storage. Auth0 provides authentication. GitHub or Google processes information when you choose those sign-in methods. If you configure a Brain or Reflex provider, BrowserPair sends that provider only the task context and observation mode needed for the active task, subject to your BrowserPair observation and sensitive-data settings. Provider API credentials stay encrypted in BrowserPair Cloud and are not sent to the browser extension.

Retention

Account and operational records are retained while your account is active and as reasonably needed for security, legal obligations and service continuity. Expired OAuth state, pairing sessions and connection tickets are periodically removed after they are no longer operationally useful. Expired or revoked web sessions are removed after a limited security grace period.

Your control

You can revoke agent keys and connected browsers from the product. To request access, correction or deletion of account information, email browserpair@gmail.com.

Security questions and reports may be sent to the same address.