Privacy Policy: SPIRITT Browser Bridge
Last updated: 2026-07-30
Applies to: SPIRITT Browser Bridge Chrome extension
What this policy covers
This policy describes what data the SPIRITT Browser Bridge Chrome extension collects, how it uses that data, and where it sends it.
Session data received by your SPIRITT workspace is used by your AI agent to perform tasks on your behalf. Separately, limited diagnostic events are used by SPIRITT to operate and support Browser Bridge. Data is never sold or used for advertising.
What data the extension collects
The extension collects data only when you explicitly click Share next to a domain in the popup. For each domain you select, the extension reads from your browser:
- Cookies set for that domain
- localStorage values for that domain
- sessionStorage values for that domain
- Your browser's User-Agent string
It also stores locally:
- The SPIRITT workspace URL you configure in the popup
- A random Browser Bridge installation identifier
- Up to 50 pending diagnostic events for no more than 24 hours when delivery is temporarily unavailable
- A local daily counter that limits diagnostics to 100 events per installation
To diagnose sign-in and connection problems, the extension records only:
- Browser Bridge version
- Browser family and major version, and operating-system family
- A random installation identifier and a random identifier for each sign-in attempt
- Event time and whether a sign-in was interactive
- Coarse outcome classifications such as sign-in started, succeeded, or failed; token refresh failed or recovered; or relay connected or disconnected
- For failures, bounded technical fields such as the phase, HTTP status, response media type, OAuth error code, relay close code, and retry count
- Limited connection metadata provided by the diagnostic service, which may include the source IP address and an approximate network-derived region
The extension does not collect:
- Your browsing history
- Bookmarks, passwords (Chrome's), downloads, autofill, or any other browser data
- Data from any domain you did not explicitly select
- Authentication tokens, authorization codes, cookies, response bodies, email addresses, workspace IDs, full URLs, or raw User-Agent strings in diagnostic events
- Names, email addresses, account identifiers, or other customer-profile fields in diagnostic events
How the extension uses the data
Session data is transmitted over HTTPS to the SPIRITT workspace URL you configured. Browser-control commands use the configured SPIRITT relay.
Diagnostic events are sent over HTTPS directly to SPIRITT's dedicated Chrome Extension project in PostHog US Cloud at us.i.posthog.com. The extension constructs each event from a fixed field allowlist and disables PostHog person-profile processing. PostHog may process standard connection metadata for reliability, security, and support diagnostics. Events are associated only with a random installation identifier and are not linked to a SPIRITT account profile. PostHog acts as SPIRITT's diagnostic data processor.
The extension does not:
- Sell data
- Use data for advertising
- Use data to determine creditworthiness or for lending decisions
- Include shared-site content or authentication material in diagnostic events
Where the data is stored
- Workspace URL setting: stored locally in
chrome.storage.local on your device. Never transmitted.
- Captured session data: transmitted to your SPIRITT workspace and stored there per the workspace's storage configuration. The extension keeps no copy after transmission.
- Diagnostic queue and daily counter: stored in
chrome.storage.local; the queue is limited to 50 events and deleted after successful delivery or 24 hours, and the counter limits diagnostics to 100 events per installation per UTC day.
- Diagnostic events: stored in SPIRITT's dedicated Chrome Extension project in PostHog according to SPIRITT's operational data-retention controls.
Your controls
In the extension popup, you can at any time:
- Revoke a single session: click the revoke button next to a domain.
- Revoke all sessions: click None, confirm.
- Change the workspace URL: click the gear icon and edit the field.
- Uninstall the extension: removes the workspace URL, random diagnostic identifier, and pending diagnostic queue from local storage immediately. Previously transmitted session data on the workspace side is unaffected by uninstall; revoke first if you want it deleted there too.
Contact
Reach the team through your SPIRITT workspace at https://workspaces.spiritt.ai.
Changes to this policy
If we change what the extension collects, transmits, or stores, we will update this document and bump the Last updated date. Material changes will also bump the extension version, so you'll see an update notice in Chrome.