Agent and Agent Browser Privacy Policy
In short. Agent is a hosted AI agent. The messages you write, the files you upload and the voice you record go to the Agent Harness deployment you sign in to, which stores your chats and sends your requests to AI model providers to produce answers. Agent Browser lets the agent also work in the browser tabs you place in its purple Agent tab group; what it reads there and the screenshots it takes go to the same deployment.
Tabs outside the Agent group are never read. If you buy a plan, Paystack processes your card and we keep the payment records. Your data is not sold, not used for advertising, and not used to decide creditworthiness or for lending.
1. Who is responsible
Your data is controlled by the operator of the Agent Harness deployment you sign in to. The default deployment, bot.sjalq.app, is operated by Palma Trading 14 CC, a close corporation registered in South Africa (registration number 2011/042440/23), 1305 Starkey Avenue, Waverley, Pretoria, 0186. It is the responsible party under the Protection of Personal Information Act (POPIA) for the personal information bot.sjalq.app processes, and its information officer is its member, Schalk Dormehl. Other deployments listed in the extension, or reached by their address, are run by their own operators, whose terms and policies also apply to the data you send them.
Contact for privacy questions and requests: schalk.dormehl@gmail.com, or telephone +27 82 564 2837.
2. Agent Browser's single purpose
Agent Browser has one purpose: to let you work with your AI agent beside the web page you are on, and to let that agent read and operate the tabs you place in the Agent tab group on your behalf. All data the extension handles is used only for that purpose.
3. What the extension does in your browser
Only in tabs that are in the Agent tab group, and only when your agent acts, the extension can:
- read the page's text, links, form fields and structure (password and file field values are never read into a snapshot);
- take a screenshot of the visible part of the page;
- click, type, paste, select, scroll, drag, press keys, open new tabs in the group and navigate them;
- run JavaScript the agent writes in the page, through the browser's debugger interface, so it can read or change that page.
The extension never reads or acts on tabs outside the Agent tab group, tabs in other windows, or the deployment's own chat pages. It does not record your browsing history, and it has no analytics or tracking code.
4. Data we collect and why
| Data | When | Why |
|---|---|---|
| Your email address and sign in record | When you sign in to a deployment | To identify your account. Sign in runs through Cloudflare Access (with the identity provider the operator configured, such as a Google or GitHub login or a one time code sent by email), which processes your email address and issues a sign in token. |
| Messages you write and the agent's replies | When you chat | To produce answers and keep your chat history. |
| Page content of tabs in the Agent group (text, structure, form field values other than passwords and files, page address and title) | When the agent observes or acts on a page | So the agent can understand and operate the page you asked it to work on. |
| Screenshots of tabs in the Agent group | When the agent takes one | So the agent can see the page. Screenshots are stored with the chat's media. |
| Results of JavaScript the agent runs in a page | When the agent runs it | So the agent can read or verify page state. |
| Voice notes and live voice calls | Only while you record a note or hold a call | Voice notes are stored with the chat and transcribed; live calls are streamed to a voice model to talk with you. |
| Files you upload and memory the agent keeps | When you upload, or when memory is switched on | To use them in your conversations (for example a personality file, observations and chat summaries). |
| Usage records | On each AI model call the deployment makes for you | The time, your account, the model and provider, the tokens used and the cost, and on a paid plan the charge to your credit. To show you your usage, charge your credit and keep the deployment's accounts. |
| Payment records (paid plans) | When you buy a plan or top up | Your email address, the amount in dollars and rand, the exchange rate, the payment reference, status and kind, and from Paystack your card's brand, last four digits and expiry date, plus a token that lets us charge the same card for renewals (stored encrypted). To take payments, renew your plan, make refunds and keep the records tax law requires. Your full card number goes only to Paystack. |
| Feedback you choose to send | Only when you submit feedback | Sent to the operator's issue board (Trello) with any screenshot or voice note you attach, so the operator can act on it. |
| Service logs | On each request | Time, account, path and status, to run, secure and troubleshoot the service. |
Stored only on your computer by the extension
- which deployment you chose;
- which chat belongs to which Agent tab group (cleared when the browser closes), and the progress of a running browser task (removed when the task ends);
- your agreement to this policy (its version and the time you agreed).
This is kept in the browser's extension storage and is removed when you uninstall the extension.
5. Who we share data with
To answer you, the deployment sends your messages and the relevant page content, screenshots, transcripts and files to the AI model providers it is configured to use. Depending on the model and features chosen, these are: OpenAI (including ChatGPT and live voice), Anthropic, Google (Gemini), xAI (Grok, including voice and transcription) and Fireworks AI. Some models run on the deployment's own server, and requests to them do not leave it. When the agent searches the web, its search queries go to the deployment's search provider (NOSIBLE). Each provider processes the data under its own terms for API customers.
Payments are processed by Paystack, which receives your email address and the payment amount from us and collects your card details itself, under its own privacy policy. Other service providers: Cloudflare (sign in and network transport) and the hosting provider of the deployment's server; bot.sjalq.app runs on its operator's own server in South Africa. Feedback you submit goes to Trello.
Most of these providers are outside South Africa, mainly in the United States and the European Union. Your data goes to them because the service cannot answer you or take your payment without it (POPIA section 72(1)(c)), and only to providers that process it under data protection terms.
We do not sell your data, we do not share it for advertising, and we do not transfer it to data brokers. We disclose data otherwise only if the law requires it, or to protect the security of the service and its users.
Limited Use. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data from your browser is used only to provide and improve Agent Browser's single purpose, is not used for personalised advertising, and is not read by people except with your permission, for security or abuse investigations, or to comply with the law.
6. Retention and deletion
- Chats, screenshots, voice notes, uploads and memory are kept on the deployment until you delete them. You can delete a chat or a voice note from the chat interface.
- Payment, credit and usage records are kept for at least five years after the transaction, because South African tax law requires it, even after your account is closed.
- When an account is closed, the operator disables it at once; its stored data is archived and then deleted on the operator's purge, apart from the records above.
- Data sent to AI model providers and to Paystack is kept by them under their own retention terms.
- Extension storage on your computer is removed when you uninstall the extension.
7. Security
All traffic between the extension, the deployment, the AI model providers and Paystack uses HTTPS. A deployment is reachable only after a verified Cloudflare Access sign in, and each account's data is kept in its own separate account on the server. Card details are entered on Paystack's payment page, never on ours; Paystack is PCI DSS certified, and the token for renewing your card is stored encrypted. The extension only accepts chat pages from the deployments it knows, and never lets the agent act on those pages.
8. Your rights and controls
- You may ask what personal information we hold about you and for a copy of it, ask us to correct or delete it, and object to how we use it. Contact us as in section 1; we answer within 30 days.
- If you are not satisfied with our answer, you may complain to the Information Regulator (inforegulator.org.za).
- Only tabs you put in the Agent group are reachable; remove a tab from the group to take it out of reach.
- The microphone is used only after you grant it and only while you record or call.
- You can sign out, delete chats, cancel a plan or uninstall the extension at any time.
9. Children
Agent and Agent Browser are not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect their data. You must be 18 or older to buy a plan. If you believe a child has provided data, contact us and we will delete it.
10. Changes to this policy
We will post changes on this page and update the effective date, and tell paying users by email before a change that affects them takes effect. If a change affects what data the extension collects or how it is shared, the extension will ask for your agreement again before it continues.