Browser Control

Privacy policy

Your browser data stays under your direction.

This policy explains how Browser Control handles data when providing Codex chat, page attachment, and user-initiated browser actions.

Effective: August 22, 2026 · Publisher: Rishabh Bothra · Contact: cu.16bcs2797@gmail.com

Scope and single purpose

Browser Control is a Chrome side-panel extension whose single purpose is to let a user chat with Codex and request supervised actions on browser tabs and normal web pages. It uses a separately installed local companion to communicate with Codex CLI and Codex App Server. This policy covers the extension and that companion. The public product, privacy, and support pages do not contain extension telemetry or advertising trackers.

Data Browser Control handles

Browser Control does not intentionally collect passwords, payment-card data, authentication codes, private keys, CAPTCHAs, or purchase details. Its action policy refuses those fields and transactions. Content on a page chosen by the user can nevertheless contain personal or sensitive information, so users should review context before attaching a page or requesting an action.

How data is used

Data is used only to provide, secure, maintain, or support the user-facing features described above: authenticate through Codex, generate responses, attach chosen page context, carry out allowlisted browser actions, show activity, remember preferences and conversations, prevent duplicate actions, and diagnose failures.

Where data is stored

Browser Control has no developer-operated telemetry, analytics, advertising, or conversation-storage server.

Data sent to others

To answer requests, prompts and any user-attached or tool-returned browser context are sent by the local companion to OpenAI's Codex service under the user's authenticated account. OpenAI processes that data according to the terms and privacy choices applicable to that account. Browser Control does not send browsing data to the publisher or to advertising companies.

Messages between the extension and the native companion stay on the same computer through Chrome Native Messaging. The public documentation site is hosted by GitHub Pages; GitHub may process ordinary web-server information when someone visits these pages under GitHub's own privacy terms. Visiting this site is separate from using the extension, which includes no remote site assets.

Permissions and user control

Browser Control requests only Chrome permissions used for its disclosed features. Optional HTTP and HTTPS host access is not granted at installation. The user can choose exact-site grants in Ask every time mode or explicitly enable optional all-sites access in Full access mode. Chrome site controls and Browser Control settings can revoke access.

A page attachment is created only after the user asks to attach the page and can be removed before sending. Browser actions start from a user's request, remain visible in activity, are bounded by an action limit, and can be stopped. Hard refusals apply in every permission mode.

Retention and deletion

Clear browser data and permissions removes Chrome-side transcripts, activity, settings, task state, and retained site grants. It does not delete the Codex login or persistent Codex threads on the Mac.

Delete all Browser Control data and sign out stops active work, clears the Chrome-side data and permissions, signs out the dedicated Browser Control Codex session, and deletes the dedicated ~/.codex-sidebar data directory. It leaves the installed companion runtime in place. The support page also explains manual removal and companion uninstall.

Security

The extension uses packaged code, strict message schemas, fixed allowlisted browser tools, exact native-host origins, short-lived opaque element references, permission checks, action limits, cancellation, and hard refusals. It does not execute model-provided JavaScript, selectors, coordinates, or remotely hosted code. Data sent from Codex to its service uses the secure transport provided by Codex; reusable credentials are not exposed to extension storage.

Chrome Web Store Limited Use

Browser Control's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser Control does not sell user data, use it for personalized or interest-based advertising, use it for creditworthiness or lending, or transfer it for unrelated purposes. Human access is not permitted except with the user's specific consent for support, when necessary for security, to comply with law, or for aggregated and anonymized internal operations allowed by policy.

Changes and contact

This policy will be updated before Browser Control materially changes the data it handles or its purposes. The effective date above will change with each revision. Questions or deletion concerns can be sent to cu.16bcs2797@gmail.com.