Privacy Policy

Your privacy and trust are important to us

Privacy Policy

Our Privacy Commitment (BYOK Model)

ChromePilot operates on a Bring Your Own Key (BYOK) model. Your AI interactions — screenshots, webpage content, commands, and your Gemini API key — are processed directly between your browser and Google Gemini, and are never sent to or stored on our servers. When you sign in to unlock advanced features, we do store limited account information to manage your license, as described below.

Basic features are free to use without signing in. Advanced features require a one-time $49 lifetime license and your own Gemini API key. Either way, your AI communication goes directly to the Gemini model without any intermediary data collection.

How Your Information Is Handled

Account Information & License

When you sign in with Google to unlock advanced features, we receive and store your email address, name, and profile picture, along with your license status and basic usage statistics (such as how many times you have opened the extension). This information is used solely to authenticate you and manage your lifetime license — we never sell it or share it for advertising. A signed authentication token is stored in your browser to keep you signed in. Payments are handled by our payment provider; we do not receive or store your card details.

Gemini API Key

You must provide your own Gemini API key from Google. This key is stored exclusively in your browser's local storage and is never sent to our servers. It is used only to authenticate your requests directly with Google Gemini.

Connectors

You can add connectors to various services (such as Gmail, GitHub, Google Sheets, Google Drive, and Google Docs) via OAuth authentication. These connections are established directly between your browser and the respective services. No data is sent to our servers - your communication with these services remains private and direct, with no third-party intermediary that could breach your data.

Webpage Content and Screenshots

To understand your commands, the extension captures a screenshot of the active webpage. This image is sent directly to Google Gemini's API to determine the appropriate action. This data is not seen or stored by us.

Text and Voice Commands

Your typed or spoken commands are sent to Google Gemini to be interpreted. Voice data is processed for transcription and is not stored by the extension.

Browser Automation and Super Power

When the extension reads a page

ChromePilot reads the page you are on only when a feature you invoked needs it — when you attach a tab with the "@" button, ask for a summary or extraction, fill a form, or start an automation. It does not monitor your browsing in the background, does not build a history of the sites you visit, and does not read pages you have not involved it in. The extension requests access to all sites because you may ask it to work on any site; that is a capability, not continuous collection.

Super Power (script execution)

The optional Super Power feature finishes repetitive work on the page you are viewing — such as building a table from a long list — by running one JavaScript routine instead of clicking through hundreds of elements one at a time. The routine is composed in your browser from your request and that page's structure. Nothing is downloaded from a server to run.

Why Chrome shows a debugging notice

Running that routine uses Chrome's debugger API, so Chrome displays its own banner ("ChromePilot started debugging this browser") while it runs. The extension attaches to the single active tab immediately before the routine starts and detaches the moment it finishes, so the banner appears only for that duration. It never attaches in the background or to tabs you are not working on.

What these routines are never allowed to do

Every routine is checked before it runs and is refused outright if it would write to browser storage, read cookies or password fields, send data anywhere (including to any address outside the page's own site), or navigate away. Your credentials and session data are therefore never readable by this feature. You can switch it off entirely in Settings under Browser Automation.

Protection against malicious pages

Text taken from a web page is treated as untrusted data, never as instructions. Websites sometimes hide commands in their content to try to manipulate an AI assistant. ChromePilot strips hidden characters, removes content that matches known manipulation patterns, and marks the remainder as page data so the assistant follows only your instructions — and tells you when a page has attempted this.

Data Security and Sharing

We do not sell your data or share it with third parties for advertising. The limited account information we store is used only to operate the service and manage your license. Your AI content (screenshots, commands) is processed by Google Gemini and is subject to their privacy policy and security practices, which you are responsible for reviewing.

Your Rights

You have full control over your data. You can clear your API key or sign out from the extension's settings at any time, and uninstall the extension to remove all locally stored data. To request deletion of the account information associated with your sign-in, contact us at the email below.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our extension. We will notify you by updating the "Last updated" date on this page.

Contact Us

If you have any questions about this Privacy Policy, please contact us at contact@chromepilot.org.