Actilot — AI Browser Agent

Privacy

Effective date: 6 October 2026. This policy describes version 0.1.0 in this repository.

Actilot does not operate an intermediary task-processing backend. Actilot does not receive or store your browsing/task data on Actilot servers. Relevant task context is transmitted directly from your browser to the AI provider you configure.

Data stored in your browser

Settings, provider configuration, prompts, drafts, user attachments, generated files, normalized objectives, plans, clarification questions and answers, automatic clarification decisions, task progress, action records, approvals, page observations, task-tab metadata, token usage and provider-reported cost are stored in your browser profile. There is no Actilot account, cloud synchronization, automatic telemetry, advertising, tracking SDK or external error-reporting service. The NDNCI footer link includes fixed UTM attribution and the extension language when clicked; it includes no prompt, attachment or task identifier. The destination website may collect ordinary visit analytics under its own policy. History remains until you delete it or remove the browser profile. Uninstall storage removal follows your browser's behavior.

API keys are kept in extension-origin IndexedDB by default. Session mode keeps keys only in browser-session storage. Optional passphrase mode encrypts persisted secrets with a passphrase-derived key and unlocks the key for the current session. Keys are sent only to the provider endpoint you configure, as needed to authenticate. They are never sent to automated websites or content scripts. No provider secret is returned in task history or panel snapshots. Persistent local storage is convenience, not a guarantee against malware or other users of your machine.

Data transmitted to your provider

When you submit a task, your chosen provider receives the prompt and relevant context needed for the selected AI model to operate. That context may contain the current page URL/title, compact visible text, semantic control metadata, explicit user preferences, recent action results and limited evidence snapshots. Bounded text/image previews of explicit attachments, text chunks requested with readAttachment, and generated-file contents are also included in that task’s provider context. Originals up to 50 MiB are stored locally in a separate extension-origin IndexedDB database and can be downloaded; they are not automatically copied wholesale into model messages. Pages can include personal, financial, health, location or communications information. Review the website you authorize and the provider you select before automating sensitive work. Input field values are excluded from observations; protected password, payment-card and one-time-code fields cannot be read or filled through the defined tools. This is not a general personal-data anonymizer.

Screenshots are disabled by default and captured only when the agent chooses the screenshot tool after you enable vision or choose Autonomous mode. After three failures, the extension suggests visual assistance or offers to enable it; Autonomous mode permits supported visual assistance for that task without changing the global vision setting. Only an already-active, owned task tab can be captured, and capture is refused when protected fields are detected. Images can still contain other personal information visible on the page. They are stored locally as task records and transmitted directly to the selected vision-capable model. Both the primary model and any fallback receiving an image must have verified image input support in the provider catalogue; unknown or text-only models do not receive images. Native Chrome capture requires an activeTab user grant (activate the task tab and invoke the extension toolbar action). Captures are discarded if the active page or protected-field state changes during capture.

Provider model metadata may be requested during setup or when you click Load models. OpenRouter key validation contacts OpenRouter directly. Your provider's privacy policy, logging, retention, pricing and training settings govern what that provider does with the data. Configure a compatible loopback local model if you want model processing on your machine. Actilot does not guarantee that any particular local-model application never makes its own network requests.

Optional microphone dictation uses the browser’s native speech recognition service, which may transmit audio to its own online service. It starts only when you click the microphone and stops on manual editing, submission or closing the panel. Final transcripts enter the draft and are sent to the configured AI provider only if you submit the task. Browser support and service availability vary.

Websites and permissions

Normal browsing and agent actions communicate with the websites you authorize. Your existing authenticated browser profile supplies website sessions; Actilot does not read browser-stored passwords, cookies, Authorization headers or session tokens. Site access is requested per origin. Revoking access pauses running tasks. Site navigation and redirects may load resources from other origins just as normal browsing does; this policy cannot control a website's own tracking or third-party resources.

Consequential controls require an action-specific confirmation in guarded Auto mode. Autonomous mode executes actions without confirmation, renews retry windows within configured total task limits, and inspects interrupted actions without automatic replay. The heuristic risk classifier is conservative but cannot establish what an arbitrary or malicious website actually does behind a button. Ask-before-acting is the default. Do not use automated actions as a substitute for reviewing transactions.

The tabs permission makes tab URLs available to the extension so it can identify redirected destinations. The agent only receives metadata for task-owned tabs; unrelated tabs are not enumerated for model context. Website content still requires a host grant. Native notifications show a short task title when approval/intervention is needed, subject to browser/OS notification settings.

Your controls

You can answer clarification questions, configure Autonomous clarification timers, copy task details, change autonomy from task details while a task is running, pause, stop, manually complete and resume tasks, cancel tasks, deny confirmations, inspect controlled tabs, revoke website permissions, delete individual tasks, clear task history, or clear all local data and credentials in Settings. Deleting local data does not delete copies already sent to an AI provider or change external actions already performed on websites. Closing the browser suspends local execution. No data is sold by Actilot.

Distribution

The optional Next.js website is static and contains no Actilot analytics code. A deployment operator or hosting service may keep ordinary HTTP access logs under its own policy. The website can be hosted on Cloudflare Pages; its hosting infrastructure may process request metadata such as IP addresses and requested URLs to serve and secure the website. Visiting the website does not send extension task history or provider credentials to the site. Publisher and privacy contact details are displayed on the public privacy and support pages. Store distribution remains subject to browser store review, signing and accurate disclosure forms.

Limited use

Actilot uses user data only to provide its disclosed, user-directed browser automation features. Relevant task context is transferred directly to the AI provider selected by the user as needed to perform the requested task; normal website interactions contact the authorized websites. Actilot does not sell user data, use or transfer it for advertising or unrelated purposes, or use or transfer it to determine creditworthiness or for lending. The publisher does not receive task contents through an Actilot task-processing server or provide staff with access to local task history. Actilot's use and transfer of user data follows the Chrome Web Store User Data Policy, including its Limited Use requirements.

Publisher and privacy contact

Ahliman HUSEYNOV · contact@ahlimanhuseynov.com

Support uses your message to reply. Email services govern delivery and retention. Do not send credentials or sensitive task content.

Support and data controls