Privacy policy
Your browser data stays under your direction.
This policy explains how Browser Control handles data when providing Codex chat, page attachment, and user-initiated browser actions.
Scope and single purpose
Browser Control is a Chrome side-panel extension whose single purpose is to let a user chat with Codex and request supervised actions on browser tabs and normal web pages. It uses a separately installed local companion to communicate with Codex CLI and Codex App Server. This policy covers the extension and that companion. The public product, privacy, and support pages do not contain extension telemetry or advertising trackers.
Data Browser Control handles
- Account information: the ChatGPT account email, account type, and plan state returned by Codex for display in the side panel. Reusable authentication credentials are managed by Codex, not stored in Chrome extension storage.
- Personal communications and user-generated content: prompts, model responses, local conversation titles and transcripts, and feedback needed to stop or retry a request.
- Website content: a page title, URL, origin, selected text, and bounded readable page text only when the user attaches a page; visible control descriptions and non-sensitive visible form values when the user requests page inspection or action.
- Web browsing activity: open-tab titles, URLs, tab and window identifiers, active state, and the origins on which the user grants browser-control access.
- User activity and form data: requested tab/page operations, their approval and result states, and non-sensitive values needed to fill, select, check, or review a form the user asked Browser Control to operate.
- Preferences and diagnostics: theme, selected model, permission mode, action budget, completion-sound choice, short-lived task state, companion version/status, and bounded error messages.
Browser Control does not intentionally collect passwords, payment-card data, authentication codes, private keys, CAPTCHAs, or purchase details. Its action policy refuses those fields and transactions. Content on a page chosen by the user can nevertheless contain personal or sensitive information, so users should review context before attaching a page or requesting an action.
How data is used
Data is used only to provide, secure, maintain, or support the user-facing features described above: authenticate through Codex, generate responses, attach chosen page context, carry out allowlisted browser actions, show activity, remember preferences and conversations, prevent duplicate actions, and diagnose failures.
Where data is stored
- Chrome local storage retains preferences and up to 30 conversation records, each bounded to its most recent messages and activity.
- Chrome session storage retains short-lived task, permission, approval, cancellation, and completion state across Manifest V3 service-worker suspension.
- The local companion gives Codex a dedicated home at
~/.codex-sidebar. Codex stores its Browser Control login/session material and persistent thread data there. - The companion runtime is installed separately from the Codex data directory so deleting product data does not silently uninstall or damage the companion.
Browser Control has no developer-operated telemetry, analytics, advertising, or conversation-storage server.
Data sent to others
To answer requests, prompts and any user-attached or tool-returned browser context are sent by the local companion to OpenAI's Codex service under the user's authenticated account. OpenAI processes that data according to the terms and privacy choices applicable to that account. Browser Control does not send browsing data to the publisher or to advertising companies.
Messages between the extension and the native companion stay on the same computer through Chrome Native Messaging. The public documentation site is hosted by GitHub Pages; GitHub may process ordinary web-server information when someone visits these pages under GitHub's own privacy terms. Visiting this site is separate from using the extension, which includes no remote site assets.
Permissions and user control
Browser Control requests only Chrome permissions used for its disclosed features. Optional HTTP and HTTPS host access is not granted at installation. The user can choose exact-site grants in Ask every time mode or explicitly enable optional all-sites access in Full access mode. Chrome site controls and Browser Control settings can revoke access.
A page attachment is created only after the user asks to attach the page and can be removed before sending. Browser actions start from a user's request, remain visible in activity, are bounded by an action limit, and can be stopped. Hard refusals apply in every permission mode.
Retention and deletion
Clear browser data and permissions removes Chrome-side transcripts, activity, settings, task state, and retained site grants. It does not delete the Codex login or persistent Codex threads on the Mac.
Delete all Browser Control data and sign out stops active work, clears the Chrome-side data and permissions, signs out the dedicated Browser Control Codex session, and deletes the dedicated ~/.codex-sidebar data directory. It leaves the installed companion runtime in place. The support page also explains manual removal and companion uninstall.
Security
The extension uses packaged code, strict message schemas, fixed allowlisted browser tools, exact native-host origins, short-lived opaque element references, permission checks, action limits, cancellation, and hard refusals. It does not execute model-provided JavaScript, selectors, coordinates, or remotely hosted code. Data sent from Codex to its service uses the secure transport provided by Codex; reusable credentials are not exposed to extension storage.
Chrome Web Store Limited Use
Browser Control's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser Control does not sell user data, use it for personalized or interest-based advertising, use it for creditworthiness or lending, or transfer it for unrelated purposes. Human access is not permitted except with the user's specific consent for support, when necessary for security, to comply with law, or for aggregated and anonymized internal operations allowed by policy.
Changes and contact
This policy will be updated before Browser Control materially changes the data it handles or its purposes. The effective date above will change with each revision. Questions or deletion concerns can be sent to cu.16bcs2797@gmail.com.