适用范围
本政策仅适用于 Goclaw Browser Agent 扩展。扩展把当前 Google Chrome™ Profile 连接到用户选择并授权的私有 Goclaw Agent,只为用户主动要求的对话和浏览器任务处理数据。
可能处理的数据
- 用户提示词、Agent 回复与个人通信;
- 当前任务标签页的标题、URL、浏览活动、可见网页内容和无障碍结构;
- 用户要求填写或发送的文字、表单值、操作结果与用户要求的截图;
- 页面或截图中可见的联系、健康、金融、支付、身份验证或其他敏感信息;
- 随机安装、Chrome Profile、设备、绑定、会话与调用标识;
- 设备名、Chrome 版本、公钥、加密设备凭证、连接状态、设置和最小安全审计元数据。
chrome.history 历史记录 API、Cookie、下载、麦克风、摄像头或地理位置权限。 tabs 权限用于识别合规的当前/目标标签并读取其 URL/标题;Chrome 安装提示可能把这项能力概括为“读取您的浏览记录”,但扩展不会通过 chrome.history 查询过去的历史记录。扩展不提供读取 Cookie、授权头、浏览器已保存密码、Passkey 或支付凭证的接口。使用目的
数据仅用于连接用户授权的私有 Agent、理解聊天请求、定位页面控件、执行并展示用户要求的浏览器动作、恢复所选会话,以及防止重放、保持安全和诊断可靠性。
Goclaw 不出售扩展数据,不用于广告、信用或借贷决策、无关分析,也不使用扩展数据训练通用模型。
数据传输到哪里
完成任务所需的数据只发送到用户配置的 Goclaw Gateway。Gateway 可能把相关任务内容发送给用户或服务器管理员选择的模型提供商。自托管部署由用户或服务器所有者控制访问、模型、保留和删除;托管部署还适用对应服务与模型提供商的政策。
远程 Gateway 必须使用加密 wss://。明文 ws:// 仅允许同一电脑上的 localhost、127.0.0.1 或 [::1]。
本机保存与保留
- 设备凭证使用不可导出的本机 AES-GCM 密钥加密;
- 会话索引与当前会话缓存按安装、Profile、绑定、Agent 和 Session 精确加密隔离;
- 当前会话最多缓存 200 条可见用户/助手消息,不保存模型思考、工具参数、工具结果、原始页面内容或截图;
- 页面快照、元素引用和增量观察基线是临时数据,会在导航、切换目标、会话结束、停止、撤销或过期时清除;有界的 session RefStore 可能在正常 TTL 内短期保存已披露、经截断/脱敏的 AX 角色、名称和 locator 元数据,其中可能包含页面可见的会话或接收方标签;
- 对外通信审批所复制的实时编辑器完整正文、确认卡渲染的目标字符串、
actionDigest及由审批内容派生的 hash 只存在于当前 MV3 Worker 内存,不写入approval.v1或 metadata-only DraftGuard 恢复记录。Worker 重启会使旧审批和内存 Draft 证据失效;不含正文的安全栅栏只能阻止旧草稿误发或重复发送。继续发送必须重新查找元素,以一次新的原子输入并提交动作绑定已验证的接收方 Ref,再取得新的本机确认; - 服务器侧保留由所配置的 Gateway 运营者和模型提供商控制。
你的选择与删除
配对前,扩展会显著披露数据处理方式并要求肯定同意。新安装默认使用“执行前确认”。即使用户主动开启“直接执行”,客服、邮件、评论、帖子及其他对外消息仍会在发送前展示精确接收方/发布位置和完整正文,并要求逐次明确确认。
用户可以随时拒绝操作、停止所有控制、解绑 Agent、撤销设备、重置本机身份、撤销隐私同意、清除扩展数据或卸载。服务器侧数据的访问与删除请联系所配置的 Goclaw Gateway 管理员。
Chrome Web Store Limited Use
对 Chrome API 信息的使用遵守 Chrome Web Store User Data Policy(包括 Limited Use 要求)。Chrome API 数据仅在提供或改进扩展单一用户功能、保护安全、遵守法律或该政策明确允许的范围内使用和传输。
联系
隐私问题请发送到 hi@nextlevelbuilder.io。自托管用户还应联系其 Goclaw Gateway 管理员处理服务器侧访问、保留与删除。
Privacy Policy — English Summary
Last updated: August 18, 2026. This policy applies to the Goclaw Browser Agent extension for Google Chrome™. The extension connects the current browser profile to a private Goclaw agent selected and authorized by the user, solely to provide user-requested chat and browser-task functionality.
Data processed
The extension may process user prompts, agent responses, personal communications, task-tab titles and URLs, visible page content and accessibility information, user-supplied form or message text, action results, requested screenshots, and scoped installation, device, binding, session, and security metadata. A requested page or screenshot may contain sensitive visible content.
Use and transfer
Data is used only to authenticate the selected agent, complete the requested task, restore the selected conversation, and maintain security and reliability. Required task data is sent only to the user-configured Goclaw Gateway and may be sent by that Gateway to the model provider selected by the user or server operator. The developer does not sell extension data, use it for advertising or credit decisions, or train a general-purpose model with it.
Permissions and security
The extension does not request the chrome.history API, cookies, downloads, microphone, camera, or geolocation permissions. The tabs permission identifies eligible/current target tabs and reads their URL and title. Chrome may summarize that install-time capability as “Read your browsing history,” but the extension does not query past history through chrome.history. Remote Gateway connections require wss://; plaintext WebSocket is limited to loopback.
Storage and control
Device credentials and limited local conversation state are encrypted. Raw page snapshots, element references, screenshots, tool arguments, and tool results are not retained in the conversation cache. A separate bounded session RefStore may briefly retain previously disclosed, truncated/redacted accessibility roles, names, and locator metadata, including a visible conversation or recipient label, until expiry or invalidation.
For outbound approval, the copy of the exact live-editor body, the rendered confirmation destination, actionDigest, and any derived content hash exist only in the active MV3 worker's memory; they are not written to approval.v1 or the metadata-only DraftGuard recovery record. Restart invalidates the pending approval. A remaining content-free fence only blocks stale or uncertain dispatch, so continuation requires fresh element discovery, one new atomic fill/type-and-submit operation with a verified recipient reference, and a new confirmation. Customer-service messages, email, comments, posts, and other outbound communications always require that per-message confirmation, even in Direct execution mode.
The user can reject or stop actions, revoke consent, unbind or revoke the device, reset local identity, clear extension data, or uninstall at any time.
Limited Use and contact
Use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including Limited Use requirements. Contact hi@nextlevelbuilder.io for privacy questions.