diff --git a/.gitignore b/.gitignore index 9b0d3fa8b..4dc4fd145 100644 --- a/.gitignore +++ b/.gitignore @@ -55,6 +55,7 @@ Research/ # NEVER committed. The tiny committed test fixture (*.fixture.csv) is kept. showcase/server/data/dbip-city-lite.* !showcase/server/data/dbip-city-lite.fixture.csv +!showcase/server/data/dbip-city-lite.ipv6.fixture.csv .claude/worktrees/ BUG-REPORT-*.md dist/skill/ diff --git a/fly.toml b/fly.toml index 22ea25277..a22ce1410 100644 --- a/fly.toml +++ b/fly.toml @@ -10,10 +10,12 @@ primary_region = 'sjc' NODE_ENV = 'production' # Worldwide IP->region dataset (DB-IP IP-to-City Lite, generated by # showcase/server/scripts/refresh-dbip-dataset.mjs). Lives on the mounted - # /data volume (NOT baked into the image). Safe to set before the file exists: - # ip-geo.js degrades to 'unknown' until it is uploaded, then restart the - # machine so the lazy loader re-reads. See showcase/server/data/README.md. + # /data volume (NOT baked into the image). Safe to set before the files exist: + # ip-geo.js degrades to 'unknown' until they are uploaded, then restart the + # machine so the lazy loader re-reads. IPv4 + sibling IPv6. See + # showcase/server/data/README.md. DBIP_DATASET_PATH = '/data/dbip-city-lite.csv' + DBIP_IPV6_DATASET_PATH = '/data/dbip-city-lite.ipv6.csv' [http_service] internal_port = 3847 diff --git a/package.json b/package.json index 64015a9b7..b1b139c7c 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ "version:check": "node scripts/sync-product-version.mjs --check", "build": "node esbuild.config.js", "build:cfworker": "node_modules/.bin/esbuild node_modules/@cfworker/json-schema/dist/esm/index.js --bundle --format=iife --global-name=CfworkerJsonSchema --platform=browser --target=chrome120 --legal-comments=none --outfile=extension/lib/cfworker-json-schema.min.js", - "test": "node tests/test-overlay-state.js && node tests/cost-tracker-ordering.test.js && node tests/runtime-contracts.test.js && node tests/ai-integration-analytics.test.js && node tests/dashboard-runtime-state.test.js && node tests/task-router.test.js && node tests/agent-provider-forbidden-flags.test.js && node tests/phase60-full-tests-harness.test.js && node tests/phase64-full-tests-harness.test.js && node tests/phase65-full-tests-harness.test.js && node tests/delegation-routing.test.js && node tests/delegation-consent.test.js && npm --prefix mcp run build && node tests/delegation-event-store.test.js && node tests/delegation-controller.test.js && node tests/delegation-sidepanel-ui.test.js && node tests/delegation-phase-contract.test.js && node tests/mcp-native-host-packaging.test.js --section workflow-and-pack && node tests/mcp-native-host-protocol.test.js && node tests/mcp-native-host-daemon.test.js && node tests/mcp-native-host-registry-helper.test.js && node tests/mcp-native-host-install.test.js && node tests/native-host-background-wake.test.js && node tests/mcp-bridge-client-lifecycle.test.js && node tests/mcp-bridge-topology.test.js && node tests/mcp-reverse-channel-contract.test.js && node tests/mcp-bridge-auth.test.js && node tests/mcp-bridge-background-dispatch.test.js && node tests/agent-protocol-drift-diagnostics.test.js && node tests/mcp-tool-routing-contract.test.js && node tests/mcp-visual-session-contract.test.js && node tests/mcp-restricted-tab.test.js && node tests/mcp-recovery-messaging.test.js && node tests/mcp-in-flight-session-lookup.test.js && node tests/mcp-version-parity.test.js && node tests/mcp-agent-provider-contract.test.js && node tests/mcp-adapter-compatibility.test.js && node tests/mcp-agent-connection-test.test.js && node tests/mcp-claude-code-adapter.test.js && node tests/mcp-agent-drift-smoke.test.js && node tests/mcp-agent-stream-fixture.test.js && node tests/mcp-spawn-supervisor.test.js && node tests/mcp-agent-orphan-recovery.test.js && node tests/mcp-diagnostics-status.test.js && node tests/mcp-install-platforms.test.js && node tests/mcp-setup-guidance.test.js && node tests/mcp-client-identity.test.js && node tests/mcp-client-inventory.test.js && node tests/mcp-agent-providers-storage.test.js && node tests/onboarding-agent-provider-clicks.test.js && node tests/mcp-client-merged-view.test.js && node tests/mcp-client-identity-integration.test.js && node tests/providers-panel-logic.test.js && node tests/providers-panel-ui.test.js && node tests/turn-result.test.js && node tests/action-history.test.js && node tests/universal-provider-lmstudio.test.js && node tests/lmstudio-agent-request.test.js && node tests/lmstudio-startup-preflight.test.js && node tests/lmstudio-settings-persistence.test.js && node tests/onboarding-lmstudio.test.js && node tests/config-lmstudio.test.js && node tests/cost-tracker.test.js && node tests/install-identity.test.js && node tests/mcp-pricing.test.js && node tests/mcp-pricing-data-parity.test.js && node tests/mcp-metrics-recorder.test.js && node tests/mcp-dispatcher-client-label.test.js && node tests/mcp-session-recorder.test.js && node tests/automation-logger-mcp-retention.test.js && node tests/mcp-session-settings-ui.test.js && node tests/knowledge-graph-dedup.test.js && node tests/mcp-metrics-no-pii-leak.test.js && node tests/telemetry-collector.test.js && node tests/telemetry-collector-strips-internal-fields.test.js && node tests/telemetry-payload-allowlist.test.js && node tests/telemetry-registry-bootstrap.test.js && node tests/extension-record-dispatch-serializes.test.js && node tests/server-trust-proxy.test.js && node tests/server-telemetry-salt-rotation.test.js && node tests/server-telemetry-rate-limit.test.js && node tests/server-telemetry-body-cap.test.js && node tests/server-telemetry-parser-rate-limit.test.js && node tests/server-telemetry-batch-cap.test.js && node tests/server-telemetry-allowlist.test.js && node tests/server-telemetry-event-id-dedup.test.js && node tests/server-telemetry-timestamp-tolerance.test.js && node tests/server-telemetry-daily-budget.test.js && node tests/server-telemetry-ip-daily-budget.test.js && node tests/server-telemetry-sec-gpc.test.js && node tests/server-telemetry-optout-forget.test.js && node tests/telemetry-active-tracker-bounds.test.js && node tests/telemetry-uuid-budget-memory.test.js && node tests/server-telemetry-housekeeper.test.js && node tests/server-public-stats-headline.test.js && node tests/server-public-stats-series.test.js && node tests/server-public-stats-cache.test.js && node tests/server-public-stats-no-auth.test.js && node tests/server-github-cache.test.js && node tests/server-github-poller.test.js && node tests/fsb-telemetry-service.test.js && node tests/stats-view-state.test.js && node tests/showcase-build-smoke.test.js && node tests/showcase-route-fallback.test.js && node tests/stats-chart-overhaul.test.js && node scripts/verify-store-listing.mjs && node tests/verify-store-listing.test.js && node tests/cumulative-commits-aggregator.test.js && node tests/dashboard-stream-readiness-ping.test.js && node tests/dashboard-stream-pending-intent.test.js && node tests/dashboard-stream-recovery-parity.test.js && node tests/server-ws-backpressure.test.js && node tests/server-ws-phantomstream-relay-compat.test.js && node tests/showcase-privacy-page.test.js && node tests/server-no-ip-leak.test.js && node tests/server-ip-geo.test.js && node tests/server-ip-geo-merge.test.js && node tests/server-ip-geo-scale.test.js && node tests/server-region-aggregation.test.js && node tests/transcript-store.test.js && node tests/hook-pipeline.test.js && node tests/session-schema.test.js && node tests/state-emitter.test.js && node tests/secure-config-credential-vault.test.js && node tests/qr-pairing.test.js && node tests/ws-client-decompress.test.js && node tests/dashboard-task-direct-start.test.js && node tests/phantom-stream-protocol-envelope.test.js && node tests/phantom-stream-differential-parity.test.js && node tests/phantom-stream-remote-control-parity.test.js && node tests/phantom-stream-public-package.test.js && node tests/phantom-stream-exports.test.js && node tests/phantom-stream-content-bundle.test.js && node tests/phantom-stream-capture-adapter.test.js && node tests/phantom-stream-sidechannels.test.js && node tests/phantom-stream-security-masking.test.js && node tests/phantom-stream-dashboard-viewer-bundle.test.js && node tests/phantom-stream-static-viewer.test.js && node tests/phantom-stream-dashboard-parity.test.js && node tests/phantom-stream-dashboard-sidechannels.test.js && node tests/phantom-stream-media-sync.test.js && node tests/phantom-stream-media-wiring.test.js && node tests/dom-stream-perf.test.js && node tests/extension-content-script-files-completeness.test.js && node tests/dom-analysis-viewport-priority.test.js && node tests/redact-for-log.test.js && node tests/diagnostics-ring-buffer.test.js && node tests/agent-sunset-back-end.test.js && node tests/agent-sunset-control-panel.test.js && node tests/agent-sunset-showcase.test.js && node tests/sync-tab-runtime.test.js && node tests/remote-control-rebrand.test.js && node tests/server-accept-language.test.js && node tests/server-legacy-html-redirects.test.js && node tests/metrics-wireup.test.js && node tests/dashboard-metrics-render.test.js && node tests/stuck-action-repetition.test.js && node tests/goal-progress-tracker.test.js && node tests/model-discovery.test.js && node tests/model-discovery-ui.test.js && node tests/model-combobox-ui.test.js && node tests/settings-card-select-clipping.test.js && node tests/control-panel-scroll-containment.test.js && node tests/model-discovery-runtime.test.js && node tests/overlay-stability-cadence.test.js && node tests/overlay-content-audit.test.js && node tests/action-icon-behavior.test.js && node tests/meta-cognitive-tracker.test.js && node tests/agent-cap-recommendation.test.js && node tests/agent-cap-storage.test.js && node tests/agent-cap-ui.test.js && node tests/agent-registry.test.js && node tests/selected-tab-state.test.js && node tests/change-report-builder.test.js && node tests/change-report-size-cap.test.js && node tests/change-report-cross-origin.test.js && node tests/change-report-dispatcher.test.js && node tests/change-report-read-tools-excluded.test.js && node tests/change-report-toggle.test.js && node tests/change-report-settings-ui.test.js && node tests/agent-tab-resolver.test.js && node tests/read-tool-tab-resolution.test.js && node tests/open-tab-background-default.test.js && node tests/visual-session-agent-scoped.test.js && node tests/action-tool-agent-scoped.test.js && node tests/recovery-tools-bootstrap.test.js && node tests/legacy-agent-synthesis.test.js && node tests/visual-session-reentry.test.js && node tests/ownership-error-codes.test.js && node tests/multi-agent-regression.test.js && node tests/tool-definitions-parity.test.js && node tests/mcp-numeric-param-coercion.test.js && node tests/visual-session-schema-lock.test.js && node tests/mcp-visual-tick-lifecycle.test.js && node tests/agent-id-threading.test.js && node tests/skill-fsb-spec.test.js && node tests/agent-loop-empty-contents.test.js && node --test tests/google-sheets-session.test.js tests/google-sheets-content-actions.test.js tests/gsheets-handler.test.js tests/google-sheets-wiring.test.js tests/spreadsheet-record-redaction.test.js && node tests/lattice-public-package.test.js && node tests/lattice-smoke.test.js && node tests/lattice-tripwire-smoke.test.js && node tests/lattice-checkpoint-smoke.test.js && node tests/lattice-providers-smoke.test.js && node tests/lattice-survivability-smoke.test.js && node tests/lattice-provider-bridge-smoke.test.js && node tests/lattice-host-step-transition-smoke.test.js && node tests/lattice-session-replay.test.js && node tests/lattice-replay-background-contract.test.js && node tests/lattice-step-emitter-smoke.test.js && node tests/mcp-philosophy-parity-smoke.test.js && node tests/sidepanel-tab-aware-smoke.test.js && node tests/sidepanel-message-log-smoke.test.js && node tests/sidepanel-mcpvisualsession-listener.test.js && node tests/delegation-sidepanel-tab-follow.test.js && node tests/sidepanel-tab-scoping-fix-redo-smoke.test.js && node tests/sidepanel-progress-tick-setter-routing.test.js && node tests/sidepanel-background-tab-completion.test.js && node tests/sidepanel-multi-document-fanout.test.js && node tests/sidepanel-automation-runner.test.js && node tests/trigger-store.test.js && node tests/trigger-lifecycle.test.js && node tests/value-extractor.test.js && node tests/trigger-manager.test.js && node tests/trigger-cap.test.js && node tests/trigger-observe.test.js && node tests/trigger-observe-pulse.test.js && node tests/trigger-refresh-poll.test.js && node tests/trigger-tool-dispatcher.test.js && node tests/trigger-blocking-reporting.test.js && node tests/capability-recipe-schema.test.js && node tests/capability-interpreter.test.js && node tests/recipe-path-guard.test.js && node tests/capability-fetch.test.js && node tests/capability-search-eval.test.js && node tests/capability-mcp-surface.test.js && node tests/capability-router.test.js && node tests/capability-autopilot-parity.test.js && node tests/capability-head-handlers.test.js && node tests/consent-policy-store.test.js && node tests/consent-gate.test.js && node tests/consent-mutation-gate.test.js && node tests/consent-chokepoint.test.js && node tests/audit-log.test.js && node tests/audit-log-no-secret.test.js && node tests/recipe-signature.test.js && node tests/recipe-signature-interpreter-hook.test.js && node tests/service-denylist.test.js && node tests/classification-gate.test.js && node tests/provenance-scaffold.test.js && node tests/upload-file-route.test.js && node tests/upload-path-denylist.test.js && node tests/consent-audit-settings-ui.test.js && node tests/agent-loop-iterator-guard.test.js && node tests/network-capture.test.js && node tests/network-capture-consent.test.js && node tests/network-capture-redaction.test.js && node tests/recipe-synthesizer.test.js && node tests/learned-recipe-store.test.js && node tests/learned-search-add.test.js && node tests/learned-t2-outranking.test.js && node tests/learned-promote-after-replay.test.js && node tests/discovery-seeds-load.test.js && node tests/seed-resolve-t2.test.js && node tests/recipe-learn-pending-affordance.test.js && node tests/learned-local-provenance-exempt.test.js && node tests/provider-parity.test.js && node tests/recipe-schema-lock.test.js && node tests/capability-rot-detector.test.js && node tests/relearn-coalescing.test.js && node tests/rot-recurrence-classify.test.js && node tests/app-degraded-surfacing.test.js && node tests/relearn-router-wiring.test.js && node tests/import-extraction.test.js && node tests/import-forbidden-prescan.test.js && node tests/import-classify-gate-call.test.js && node tests/catalog-crosscheck.test.js && node tests/no-dead-entry.test.js && node tests/catalog-inline-shape.test.js && node tests/head-handler-cap.test.js && node tests/head-handler-upgrade.test.js && node tests/confluence-t1-handler.test.js && node tests/verify-origin-classification.test.js && node tests/guarded-write-failclosed.test.js && node tests/breadth-search-return.test.js && node tests/breadth-batch-gate.test.js && node tests/backing-status-annotation.test.js && node tests/t1-port-contract.test.js && node tests/t1-port-contract-gate.test.js && node tests/dom-only-default.test.js && node tests/sensitive-write-import-gate.test.js && node tests/coverage-report.test.js && node tests/payment-op-guard.test.js && node tests/vendor-augment-preserved.test.js && node tests/no-duplicate-stem.test.js && node tests/full-corpus-screen.test.js && node tests/full-corpus-scale.test.js && node tests/keyboard-attach-robustness.test.js && node --import tsx tests/no-orphan-descriptor.test.js", + "test": "node tests/test-overlay-state.js && node tests/cost-tracker-ordering.test.js && node tests/runtime-contracts.test.js && node tests/ai-integration-analytics.test.js && node tests/dashboard-runtime-state.test.js && node tests/task-router.test.js && node tests/agent-provider-forbidden-flags.test.js && node tests/phase60-full-tests-harness.test.js && node tests/phase64-full-tests-harness.test.js && node tests/phase65-full-tests-harness.test.js && node tests/delegation-routing.test.js && node tests/delegation-consent.test.js && npm --prefix mcp run build && node tests/delegation-event-store.test.js && node tests/delegation-controller.test.js && node tests/delegation-sidepanel-ui.test.js && node tests/delegation-phase-contract.test.js && node tests/mcp-native-host-packaging.test.js --section workflow-and-pack && node tests/mcp-native-host-protocol.test.js && node tests/mcp-native-host-daemon.test.js && node tests/mcp-native-host-registry-helper.test.js && node tests/mcp-native-host-install.test.js && node tests/native-host-background-wake.test.js && node tests/mcp-bridge-client-lifecycle.test.js && node tests/mcp-bridge-topology.test.js && node tests/mcp-reverse-channel-contract.test.js && node tests/mcp-bridge-auth.test.js && node tests/mcp-bridge-background-dispatch.test.js && node tests/agent-protocol-drift-diagnostics.test.js && node tests/mcp-tool-routing-contract.test.js && node tests/mcp-visual-session-contract.test.js && node tests/mcp-restricted-tab.test.js && node tests/mcp-recovery-messaging.test.js && node tests/mcp-in-flight-session-lookup.test.js && node tests/mcp-version-parity.test.js && node tests/mcp-agent-provider-contract.test.js && node tests/mcp-adapter-compatibility.test.js && node tests/mcp-agent-connection-test.test.js && node tests/mcp-claude-code-adapter.test.js && node tests/mcp-agent-drift-smoke.test.js && node tests/mcp-agent-stream-fixture.test.js && node tests/mcp-spawn-supervisor.test.js && node tests/mcp-agent-orphan-recovery.test.js && node tests/mcp-diagnostics-status.test.js && node tests/mcp-install-platforms.test.js && node tests/mcp-setup-guidance.test.js && node tests/mcp-client-identity.test.js && node tests/mcp-client-inventory.test.js && node tests/mcp-agent-providers-storage.test.js && node tests/onboarding-agent-provider-clicks.test.js && node tests/mcp-client-merged-view.test.js && node tests/mcp-client-identity-integration.test.js && node tests/providers-panel-logic.test.js && node tests/providers-panel-ui.test.js && node tests/turn-result.test.js && node tests/action-history.test.js && node tests/universal-provider-lmstudio.test.js && node tests/lmstudio-agent-request.test.js && node tests/lmstudio-startup-preflight.test.js && node tests/lmstudio-settings-persistence.test.js && node tests/onboarding-lmstudio.test.js && node tests/config-lmstudio.test.js && node tests/cost-tracker.test.js && node tests/install-identity.test.js && node tests/mcp-pricing.test.js && node tests/mcp-pricing-data-parity.test.js && node tests/mcp-metrics-recorder.test.js && node tests/mcp-dispatcher-client-label.test.js && node tests/mcp-session-recorder.test.js && node tests/automation-logger-mcp-retention.test.js && node tests/mcp-session-settings-ui.test.js && node tests/knowledge-graph-dedup.test.js && node tests/mcp-metrics-no-pii-leak.test.js && node tests/telemetry-collector.test.js && node tests/telemetry-collector-strips-internal-fields.test.js && node tests/telemetry-payload-allowlist.test.js && node tests/telemetry-registry-bootstrap.test.js && node tests/extension-record-dispatch-serializes.test.js && node tests/server-trust-proxy.test.js && node tests/server-telemetry-salt-rotation.test.js && node tests/server-telemetry-rate-limit.test.js && node tests/server-telemetry-body-cap.test.js && node tests/server-telemetry-parser-rate-limit.test.js && node tests/server-telemetry-batch-cap.test.js && node tests/server-telemetry-allowlist.test.js && node tests/server-telemetry-event-id-dedup.test.js && node tests/server-telemetry-timestamp-tolerance.test.js && node tests/server-telemetry-daily-budget.test.js && node tests/server-telemetry-ip-daily-budget.test.js && node tests/server-telemetry-sec-gpc.test.js && node tests/server-telemetry-optout-forget.test.js && node tests/telemetry-active-tracker-bounds.test.js && node tests/telemetry-uuid-budget-memory.test.js && node tests/server-telemetry-housekeeper.test.js && node tests/server-public-stats-headline.test.js && node tests/server-public-stats-series.test.js && node tests/server-public-stats-cache.test.js && node tests/server-public-stats-no-auth.test.js && node tests/server-github-cache.test.js && node tests/server-github-poller.test.js && node tests/fsb-telemetry-service.test.js && node tests/stats-view-state.test.js && node tests/showcase-build-smoke.test.js && node tests/showcase-route-fallback.test.js && node tests/stats-chart-overhaul.test.js && node scripts/verify-store-listing.mjs && node tests/verify-store-listing.test.js && node tests/cumulative-commits-aggregator.test.js && node tests/dashboard-stream-readiness-ping.test.js && node tests/dashboard-stream-pending-intent.test.js && node tests/dashboard-stream-recovery-parity.test.js && node tests/server-ws-backpressure.test.js && node tests/server-ws-phantomstream-relay-compat.test.js && node tests/showcase-privacy-page.test.js && node tests/server-no-ip-leak.test.js && node tests/server-ip-geo.test.js && node tests/server-client-ip-geo.test.js && node tests/server-ip-geo-merge.test.js && node tests/server-ip-geo-scale.test.js && node tests/server-region-aggregation.test.js && node tests/transcript-store.test.js && node tests/hook-pipeline.test.js && node tests/session-schema.test.js && node tests/state-emitter.test.js && node tests/secure-config-credential-vault.test.js && node tests/qr-pairing.test.js && node tests/ws-client-decompress.test.js && node tests/dashboard-task-direct-start.test.js && node tests/phantom-stream-protocol-envelope.test.js && node tests/phantom-stream-differential-parity.test.js && node tests/phantom-stream-remote-control-parity.test.js && node tests/phantom-stream-public-package.test.js && node tests/phantom-stream-exports.test.js && node tests/phantom-stream-content-bundle.test.js && node tests/phantom-stream-capture-adapter.test.js && node tests/phantom-stream-sidechannels.test.js && node tests/phantom-stream-security-masking.test.js && node tests/phantom-stream-dashboard-viewer-bundle.test.js && node tests/phantom-stream-static-viewer.test.js && node tests/phantom-stream-dashboard-parity.test.js && node tests/phantom-stream-dashboard-sidechannels.test.js && node tests/phantom-stream-media-sync.test.js && node tests/phantom-stream-media-wiring.test.js && node tests/dom-stream-perf.test.js && node tests/extension-content-script-files-completeness.test.js && node tests/dom-analysis-viewport-priority.test.js && node tests/redact-for-log.test.js && node tests/diagnostics-ring-buffer.test.js && node tests/agent-sunset-back-end.test.js && node tests/agent-sunset-control-panel.test.js && node tests/agent-sunset-showcase.test.js && node tests/sync-tab-runtime.test.js && node tests/remote-control-rebrand.test.js && node tests/server-accept-language.test.js && node tests/server-legacy-html-redirects.test.js && node tests/metrics-wireup.test.js && node tests/dashboard-metrics-render.test.js && node tests/stuck-action-repetition.test.js && node tests/goal-progress-tracker.test.js && node tests/model-discovery.test.js && node tests/model-discovery-ui.test.js && node tests/model-combobox-ui.test.js && node tests/settings-card-select-clipping.test.js && node tests/control-panel-scroll-containment.test.js && node tests/model-discovery-runtime.test.js && node tests/overlay-stability-cadence.test.js && node tests/overlay-content-audit.test.js && node tests/action-icon-behavior.test.js && node tests/meta-cognitive-tracker.test.js && node tests/agent-cap-recommendation.test.js && node tests/agent-cap-storage.test.js && node tests/agent-cap-ui.test.js && node tests/agent-registry.test.js && node tests/selected-tab-state.test.js && node tests/change-report-builder.test.js && node tests/change-report-size-cap.test.js && node tests/change-report-cross-origin.test.js && node tests/change-report-dispatcher.test.js && node tests/change-report-read-tools-excluded.test.js && node tests/change-report-toggle.test.js && node tests/change-report-settings-ui.test.js && node tests/agent-tab-resolver.test.js && node tests/read-tool-tab-resolution.test.js && node tests/open-tab-background-default.test.js && node tests/visual-session-agent-scoped.test.js && node tests/action-tool-agent-scoped.test.js && node tests/recovery-tools-bootstrap.test.js && node tests/legacy-agent-synthesis.test.js && node tests/visual-session-reentry.test.js && node tests/ownership-error-codes.test.js && node tests/multi-agent-regression.test.js && node tests/tool-definitions-parity.test.js && node tests/mcp-numeric-param-coercion.test.js && node tests/visual-session-schema-lock.test.js && node tests/mcp-visual-tick-lifecycle.test.js && node tests/agent-id-threading.test.js && node tests/skill-fsb-spec.test.js && node tests/agent-loop-empty-contents.test.js && node --test tests/google-sheets-session.test.js tests/google-sheets-content-actions.test.js tests/gsheets-handler.test.js tests/google-sheets-wiring.test.js tests/spreadsheet-record-redaction.test.js && node tests/lattice-public-package.test.js && node tests/lattice-smoke.test.js && node tests/lattice-tripwire-smoke.test.js && node tests/lattice-checkpoint-smoke.test.js && node tests/lattice-providers-smoke.test.js && node tests/lattice-survivability-smoke.test.js && node tests/lattice-provider-bridge-smoke.test.js && node tests/lattice-host-step-transition-smoke.test.js && node tests/lattice-session-replay.test.js && node tests/lattice-replay-background-contract.test.js && node tests/lattice-step-emitter-smoke.test.js && node tests/mcp-philosophy-parity-smoke.test.js && node tests/sidepanel-tab-aware-smoke.test.js && node tests/sidepanel-message-log-smoke.test.js && node tests/sidepanel-mcpvisualsession-listener.test.js && node tests/delegation-sidepanel-tab-follow.test.js && node tests/sidepanel-tab-scoping-fix-redo-smoke.test.js && node tests/sidepanel-progress-tick-setter-routing.test.js && node tests/sidepanel-background-tab-completion.test.js && node tests/sidepanel-multi-document-fanout.test.js && node tests/sidepanel-automation-runner.test.js && node tests/trigger-store.test.js && node tests/trigger-lifecycle.test.js && node tests/value-extractor.test.js && node tests/trigger-manager.test.js && node tests/trigger-cap.test.js && node tests/trigger-observe.test.js && node tests/trigger-observe-pulse.test.js && node tests/trigger-refresh-poll.test.js && node tests/trigger-tool-dispatcher.test.js && node tests/trigger-blocking-reporting.test.js && node tests/capability-recipe-schema.test.js && node tests/capability-interpreter.test.js && node tests/recipe-path-guard.test.js && node tests/capability-fetch.test.js && node tests/capability-search-eval.test.js && node tests/capability-mcp-surface.test.js && node tests/capability-router.test.js && node tests/capability-autopilot-parity.test.js && node tests/capability-head-handlers.test.js && node tests/consent-policy-store.test.js && node tests/consent-gate.test.js && node tests/consent-mutation-gate.test.js && node tests/consent-chokepoint.test.js && node tests/audit-log.test.js && node tests/audit-log-no-secret.test.js && node tests/recipe-signature.test.js && node tests/recipe-signature-interpreter-hook.test.js && node tests/service-denylist.test.js && node tests/classification-gate.test.js && node tests/provenance-scaffold.test.js && node tests/upload-file-route.test.js && node tests/upload-path-denylist.test.js && node tests/consent-audit-settings-ui.test.js && node tests/agent-loop-iterator-guard.test.js && node tests/network-capture.test.js && node tests/network-capture-consent.test.js && node tests/network-capture-redaction.test.js && node tests/recipe-synthesizer.test.js && node tests/learned-recipe-store.test.js && node tests/learned-search-add.test.js && node tests/learned-t2-outranking.test.js && node tests/learned-promote-after-replay.test.js && node tests/discovery-seeds-load.test.js && node tests/seed-resolve-t2.test.js && node tests/recipe-learn-pending-affordance.test.js && node tests/learned-local-provenance-exempt.test.js && node tests/provider-parity.test.js && node tests/recipe-schema-lock.test.js && node tests/capability-rot-detector.test.js && node tests/relearn-coalescing.test.js && node tests/rot-recurrence-classify.test.js && node tests/app-degraded-surfacing.test.js && node tests/relearn-router-wiring.test.js && node tests/import-extraction.test.js && node tests/import-forbidden-prescan.test.js && node tests/import-classify-gate-call.test.js && node tests/catalog-crosscheck.test.js && node tests/no-dead-entry.test.js && node tests/catalog-inline-shape.test.js && node tests/head-handler-cap.test.js && node tests/head-handler-upgrade.test.js && node tests/confluence-t1-handler.test.js && node tests/verify-origin-classification.test.js && node tests/guarded-write-failclosed.test.js && node tests/breadth-search-return.test.js && node tests/breadth-batch-gate.test.js && node tests/backing-status-annotation.test.js && node tests/t1-port-contract.test.js && node tests/t1-port-contract-gate.test.js && node tests/dom-only-default.test.js && node tests/sensitive-write-import-gate.test.js && node tests/coverage-report.test.js && node tests/payment-op-guard.test.js && node tests/vendor-augment-preserved.test.js && node tests/no-duplicate-stem.test.js && node tests/full-corpus-screen.test.js && node tests/full-corpus-scale.test.js && node tests/keyboard-attach-robustness.test.js && node --import tsx tests/no-orphan-descriptor.test.js", "test:openai-request": "node tests/openai-agent-request.test.js", "test:grok-build": "npm --prefix mcp run build && node tests/mcp-grok-build-adapter.test.js", "test:lattice": "node tests/lattice-public-package.test.js && node tests/lattice-smoke.test.js && node tests/lattice-tripwire-smoke.test.js && node tests/lattice-checkpoint-smoke.test.js && node tests/lattice-providers-smoke.test.js && node tests/lattice-survivability-smoke.test.js && node tests/lattice-provider-bridge-smoke.test.js && node tests/lattice-host-step-transition-smoke.test.js && node tests/lattice-session-replay.test.js && node --test tests/lattice-replay-playback.test.js && node tests/lattice-replay-background-contract.test.js && node tests/lattice-step-emitter-smoke.test.js", diff --git a/showcase/angular/src/app/core/stats/fsb-telemetry.types.ts b/showcase/angular/src/app/core/stats/fsb-telemetry.types.ts index a90681f95..defdc73d1 100644 --- a/showcase/angular/src/app/core/stats/fsb-telemetry.types.ts +++ b/showcase/angular/src/app/core/stats/fsb-telemetry.types.ts @@ -63,6 +63,12 @@ export interface FSBTelemetryHeadline { popular_agents: Array<{ label: string; uniq: number }>; /** Latest day's coarse region aggregate with a k>=5 floor. */ popular_regions: Array<{ label: string; uniq: number }>; + /** + * Last-known coarse region per install across the retained 365-day rollups, + * k>=5 floored. Anonymous (country / US-state labels only). Powers the globe + * so location survives the 7-day raw-event wipe. + */ + users_by_region_365d?: Array<{ label: string; uniq: number }>; /** Compatibility alias for avg_agents_per_reporting_user. */ avg_agents_per_user: number; /** active_agents_now / active_agents_reporting_users_now. */ diff --git a/showcase/angular/src/app/layout/language-picker/language-picker.component.scss b/showcase/angular/src/app/layout/language-picker/language-picker.component.scss index b17fcd1f7..fe4712d0f 100644 --- a/showcase/angular/src/app/layout/language-picker/language-picker.component.scss +++ b/showcase/angular/src/app/layout/language-picker/language-picker.component.scss @@ -67,9 +67,12 @@ appearance: none; -webkit-appearance: none; -moz-appearance: none; - background: transparent; + /* Blink ignores a fully transparent select background and keeps UA Field + * (white unless color-scheme is dark). --bg-card is opaque and matches the footer. */ + background-color: var(--bg-card); border: 0; color: inherit; + color-scheme: inherit; font: inherit; padding: 0.25rem 1.25rem 0.25rem 0.5rem; cursor: pointer; diff --git a/showcase/angular/src/app/pages/privacy/privacy-history-archive.component.html b/showcase/angular/src/app/pages/privacy/privacy-history-archive.component.html index 14addaf89..5b2cbe5ed 100644 --- a/showcase/angular/src/app/pages/privacy/privacy-history-archive.component.html +++ b/showcase/angular/src/app/pages/privacy/privacy-history-archive.component.html @@ -1,3 +1,242 @@ +
+ + August 2026 + v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + +
+

Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.

+ +

TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.

+ +

Data Collection

+

FSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.

+ + +

Site API capabilities

+

FSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.

+

Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.

+ +

Chrome permissions FSB requests

+

To run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.

+ +

Microphone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.

+ +

Data Storage

+

All settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.

+ + +

External Services

+

FSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.

+ + +

Local Agent Service and Native Messaging

+

FSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.

+ + +

Delegated CLI Agents

+

FSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.

+ + +

Reading and Filling Google Sheets

+

FSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.

+ + +

Remote Dashboard and PhantomStream Live Preview

+

When you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.

+ + +

No Third-Party Tracking

+

FSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.

+ +

API Keys

+

Your API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.

+ + +

Auto-Passwords

+

FSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.

+ + +

Payment Methods

+

FSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.

+ + +

Speech-to-Text

+

FSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.

+ + +

Prompt Injection Prevention

+

Web pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.

+ + +

Background Agents and Server Sync

+

Deprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.

+

If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.

+ + +

Memory System

+

FSB's memory system stores navigation patterns and site intelligence to improve automation over time.

+ + +

Session Replay and Screenshots

+

When an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.

+ + +

Anonymous Usage Telemetry

+

FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.

+ +

What we collect

+ + +

What we do NOT collect

+ + +

Region (state-level) metric

+ + +

Retention

+

Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.

+ +

How to opt out

+

Open the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.

+ +

How to erase your data

+

To request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:

+
curl -X POST -H "Content-Type: application/json" \
+-d '{{ '{' }}"install_uuid":"<your-uuid>"{{ '}' }}' \
+https://full-selfbrowsing.com/api/telemetry/forget
+ +

Limited Use affirmation

+

FSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.

+ +

Aggregated public metrics

+

We publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.

+ +

Consent and Audit Controls

+

FSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.

+ + +

Open Source

+

FSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.

+ +

Changes to This Policy

+

If this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.

+ +

Contact

+

If you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues.

+
+
+
May – July 2026 diff --git a/showcase/angular/src/app/pages/privacy/privacy-page.component.html b/showcase/angular/src/app/pages/privacy/privacy-page.component.html index a1cf9d13a..1532561e7 100644 --- a/showcase/angular/src/app/pages/privacy/privacy-page.component.html +++ b/showcase/angular/src/app/pages/privacy/privacy-page.component.html @@ -3,7 +3,7 @@

Privacy Policy

-

Last updated: August 2026

+

Last updated: September 2026

@@ -194,7 +194,7 @@

Session Replay and Screenshots<

Anonymous Usage Telemetry

-

FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.

+

FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.

What we collect

    @@ -210,20 +210,20 @@

    What we do NOT collect

  • Page URLs, hostnames, or browsing history.
  • Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.
  • Page DOM, screenshots, page content, site API payloads, or AI responses.
  • -
  • Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.
  • +
  • Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged.
  • Names, usernames, account handles, or any free-form identity fields.
  • Email addresses, phone numbers, or contact information.

Region (state-level) metric

    -
  • The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IP IP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.
  • -
  • Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.
  • -
  • There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).
  • +
  • The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IP IP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept.
  • +
  • Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs.
  • +
  • The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com).

Retention

-

Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.

+

Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.

How to opt out

Open the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.

diff --git a/showcase/angular/src/app/pages/stats/stats-page.component.html b/showcase/angular/src/app/pages/stats/stats-page.component.html index aa292f364..8a2d82970 100644 --- a/showcase/angular/src/app/pages/stats/stats-page.component.html +++ b/showcase/angular/src/app/pages/stats/stats-page.component.html @@ -101,7 +101,7 @@

Stats @if (hasPlottableRegions) { - Regional distribution from today's hourly aggregate. + Where installs were last seen, by coarse region, over the past 365 days. } @else { Not enough anonymous activity yet to break down by region — check back soon. } diff --git a/showcase/angular/src/app/pages/stats/stats-page.component.ts b/showcase/angular/src/app/pages/stats/stats-page.component.ts index 256cebafd..7288f0024 100644 --- a/showcase/angular/src/app/pages/stats/stats-page.component.ts +++ b/showcase/angular/src/app/pages/stats/stats-page.component.ts @@ -298,14 +298,14 @@ export class StatsPageComponent implements OnInit, OnDestroy { } get accessibleGlobeData(): readonly AccessibleDatum[] { - return (this.latestFsbHeadline?.popular_regions ?? []).map((item) => ({ + return this.globeRegionList.map((item) => ({ label: this.displayLabel(item.label), value: this.fmtNum(item.uniq), })); } get globeAriaLabel(): string { - return $localize`:@@stats.globe.aria:Globe showing today's hourly FSB regional distribution`; + return $localize`:@@stats.globe.aria:Globe showing where FSB installs were last seen over the past 365 days, by coarse region`; } get tabMetrics(): readonly TabMetric[] { @@ -415,8 +415,13 @@ export class StatsPageComponent implements OnInit, OnDestroy { // an explicit "still gathering data" message when this is false rather // than silently showing a globe with no nodes. get hasPlottableRegions(): boolean { - const regions = this.latestFsbHeadline?.popular_regions ?? []; - return regions.some((r) => regionCentroid(r.label) !== null); + return this.globeRegionList.some((r) => regionCentroid(r.label) !== null); + } + + private get globeRegionList(): readonly { label: string; uniq: number }[] { + const persistent = this.latestFsbHeadline?.users_by_region_365d; + if (persistent && persistent.length > 0) return persistent; + return this.latestFsbHeadline?.popular_regions ?? []; } get fanItemsLeft(): readonly FanItem[] { @@ -793,7 +798,7 @@ export class StatsPageComponent implements OnInit, OnDestroy { if (this.selectedView === 'fsb-active-now') { const key = JSON.stringify({ - regions: this.latestFsbHeadline?.popular_regions ?? [], + regions: this.globeRegionList, reducedMotion: this.prefersReducedMotion, theme: typeof document === 'undefined' ? '' @@ -888,7 +893,7 @@ export class StatsPageComponent implements OnInit, OnDestroy { // moderate jitter radius since we only have a single centroid per label, // not a real distribution. private buildGlobeRegions(): GlobeRegion[] { - const list = this.latestFsbHeadline?.popular_regions ?? []; + const list = this.globeRegionList; const regions: GlobeRegion[] = []; for (const { label, uniq } of list) { const centroid = regionCentroid(label); diff --git a/showcase/angular/src/locale/messages.de.xlf b/showcase/angular/src/locale/messages.de.xlf index 62aec8a40..871f61093 100644 --- a/showcase/angular/src/locale/messages.de.xlf +++ b/showcase/angular/src/locale/messages.de.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + August 2026v0.9.91 — Lokaler Agent-Dienst und Native Messaging, Delegierte CLI-Agenten, Google Sheets, Sitzungswiedergabe und Screenshots (vollständiger archivierter Text) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + Archivierte Fassung der Datenschutzrichtlinie vom August 2026, vor der Aktualisierung im September 2026.Kurzfassung: FSB läuft in deinem Browser, und es werden keine Browserdaten von FSB-Servern erfasst. KI-Aufrufe gehen direkt von deinem Browser an den von dir gewählten Anbieter. API-Schlüssel und Zugangsdaten werden lokal verschlüsselt, und Speicherdaten bleiben auf deinem Gerät. Wenn du den optionalen lokalen Agent-Dienst installierst, kann FSB auch von einem MCP-Client gesteuert werden, der auf deinem eigenen Rechner über eine Loopback-Verbindung läuft, sowie von bereits installierten Coding-Agent-CLIs. Die einzigen Daten, die deinen Rechner jemals für FSB verlassen, sind die abwählbare anonyme Nutzungstelemetrie, die die öffentliche Seite /stats speist. Wenn du Remote Dashboard koppelst, können vorübergehende Live-Vorschaubilder während der Sitzung über das Relay laufen, werden aber nicht gespeichert. Alles ist quelloffen und überprüfbar.DatenerfassungFSB wird vollständig in Ihrem Browser ausgeführt. Wenn Sie eine Automatisierungsaufgabe starten, kann die Erweiterung das DOM (Document Object Model) des aktiven Tabs untersuchen und beim Aufruf einer Fähigkeit gleichursprüngliche Website-API-Anfragen aus Ihrer Browsersitzung stellen.Es wird kein Browser-Verlauf über die aktuelle Sitzung hinaus erfasst oder gespeichertDOM-Daten und Ergebnisse von Website-API werden lokal analysiert und nach jedem Automatisierungsschritt verworfen, sofern Sie sie nicht ausdrücklich im Gedächtnis speichernEs werden keine persönlichen Informationen aus den von Ihnen besuchten Seiten gesammeltFähigkeiten für Website-APIFSB-Fähigkeitsschicht kann aus dem Seitenkontext die eigene First-Party-API einer Website über Ihre bereits authentifizierte Browsersitzung aufrufen. Diese Anfragen werden lokal in Chrome ausgeführt. Der Browser kann für die Zielwebsite First-Party-Cookies oder eine Website-Authentifizierung anhängen; FSB gibt jedoch weder Cookies, Token, CSRF-Werte noch Anfrage- oder Antworttexte zurück und speichert, protokolliert oder sendet sie auch nicht an FSB-Server.Fähigkeitsaufrufe unterliegen den Einwilligungssteuerungen von FSB und werden ausschließlich im geschwärzten lokalen Prüfprotokoll aufgezeichnet: Ursprung, Fähigkeitskennung, Methode, Nebenwirkungsklasse, Einwilligungsentscheidung und Ergebnis. Das Prüfprotokoll speichert niemals Aufrufargumente, Anfrage- oder Antworttexte, Cookies, Token, CSRF-Werte oder Nutzdaten von Website-Antworten.Chrome-Berechtigungen, die FSB anfordertUm Web-Automatisierung auszuführen, deklariert FSB die folgenden Berechtigungen in seinem Chrome-Manifest. Jede wird nur für den dokumentierten Zweck verwendet; auf ihrer Grundlage wird nichts vom Gerät übertragen.DOM und Tabs, activeTab, scripting, tabs, windows, sidePanel, sowie die Hostberechtigung <all_urls>: den aktiven Tab lesen und beschreiben, das Automatisierungs-Inhaltsskript einfügen, Tabs auflisten und wechseln sowie die Seitenleiste darstellenErweiterte Automatisierung, debugger: das Chrome DevTools Protocol für koordinatenbasierte Klicks, Zieh- und Gedrückthalten-Aktionen anbinden, die die reguläre DOM API nicht ausführen kann. webNavigation: Start- und Endereignisse der Navigation beobachten, damit die Automatisierung auf den richtigen Moment wartetLokaler Speicher, storage, unlimitedStorage: Ihre Einstellungen, Anmeldedaten, Zahlungsmethoden und das Gedächtnis in chrome.storage.local auf Ihrem Gerät speichern. Unbegrenzter Speicher hebt das standardmäßige Kontingent von 10 MB auf, damit Gedächtnis und Sitzungsprotokolle wachsen können, ohne an eine Grenze zu stoßenUX-Hilfen, clipboardWrite: Ergebnisse der Automatisierung in die Zwischenablage schreiben. alarms: Hintergrundwartung planen. offscreen: den Spracherkennungsrekorder in einem ausgeblendeten Dokument ausführen, da Service Worker Audio nicht direkt erfassen könnenLokaler Dienst, nativeMessaging: startet den optionalen lokalen Agent-Dienst, der unter Lokaler Agent-Dienst und Native Messaging weiter unten beschrieben wird. Nichts über die von dir besuchten Seiten läuft über diesen Kanal. system.memory: liest ausschließlich den Wert des insgesamt installierten RAM, damit FSB eine sinnvolle Obergrenze für gleichzeitig laufende Agenten vorschlagen kann. Der verfügbare Speicher und die Aufschlüsselung pro Prozessor werden nie gelesen, und der Wert verlässt die Erweiterung nieDer Mikrofonzugriff für Speech-to-Text ist nicht im Manifest deklariert. Chrome zeigt beim ersten Klick auf die Mikrofon-Schaltfläche seine eigene Berechtigungsanfrage an.DatenspeicherungAlle Einstellungen und Daten werden lokal im Erweiterungsspeicher von Chrome abgelegt, wobei sensible Werte im Ruhezustand verschlüsselt sind, wie in den folgenden Abschnitten beschrieben.Die Konfiguration wird in chrome.storage.local gespeichertAPI-Schlüssel, Zugangsdaten und Zahlungsmethoden werden vor der Speicherung verschlüsselt; Einzelheiten stehen jeweils im eigenen Abschnitt weiter untenSitzungsprotokolle werden lokal gespeichert und können jederzeit gelöscht werdenAnalytikdaten (Aufgabenanzahl, Erfolgsraten) bleiben auf Ihrem GerätExterne DiensteFSB kommuniziert nur dann mit externen KI-Anbietern, wenn Sie einen gehosteten Anbieter konfigurieren und nutzen. Wenn Sie LM Studio verwenden, bleiben KI-Anfragen über dessen lokalen OpenAI-kompatiblen Server auf Ihrem Rechner. Die Wahl des Anbieters und die gesendeten Daten liegen in Ihrer Hand.Gehostete API-Aufrufe gehen ausschließlich an den von Ihnen gewählten Anbieter (xAI, OpenAI, Anthropic, Google oder OpenRouter)LM Studio nutzt einen lokalen OpenAI-kompatiblen Server auf Ihrem Gerät und benötigt keinen API-KeyGesendete Daten umfassen: Aufgabenbeschreibung, DOM-Strukturzusammenfassung und AktionskontextWenn du Remote Dashboard koppelst oder die alte Background-Agents-Synchronisierung nutzt, verarbeitet ein optionaler Relay-Server die WebSocket-Nachrichten dieser Sitzung. Live-Vorschaubilder können vorübergehend über das Relay laufen, aber nichts davon wird jemals auf einem FSB-Server gespeichert: Seiteninhalte, DOM-Daten, Browserverlauf, Screenshots, KI-Prompts, KI-Antworten, Cookies, Tokens oder Site-API-Nutzdaten. Dies ist ausschließlich Opt-in, und der Rest dieser Richtlinie verweist auf diese Liste, statt sie zu wiederholenJeder Anbieter hat eigene Datenschutzbestimmungen, die regeln, wie er API-Anfragen behandeltLokaler Agent-Dienst und Native MessagingFSB kann von einem MCP-Client gesteuert werden, der auf deinem eigenen Rechner läuft. Dafür ist ein kleiner lokaler Agent-Dienst nötig, den du selbst installierst, und die Berechtigung nativeMessaging besteht ausschließlich dazu, dass die Erweiterung ihn starten kann. Chrome kann kein lokales Programm direkt starten, daher ist dies der einzige unterstützte Mechanismus.Der Messaging-Host io.github.fullselfbrowsing.fsb_native_host wird nur durch eine ausdrückliche Aktion von dir registriert, indem du fsb-mcp-server install --native-host ausführst. Die Erweiterung kann ihn nicht installieren, und seine Registrierung nennt genau einen zulässigen ErweiterungsursprungDer Austausch folgt einem geschlossenen Schema. FSB sendet eine Versionsnummer, eine Aktion entweder wake oder bootstrap sowie eine lokal erzeugte Korrelationskennung; zurück kommt dieselbe Kennung mit einem Ergebnis und einem Grund aus einer festen Liste. Jedes zusätzliche Feld wird rundweg abgelehnt, und Nachrichten sind auf 4 KB begrenzt. Weder URL noch Tab, Seiteninhalt oder DOM-Daten kommen in diesem Schema überhaupt vorEin erfolgreicher Start liefert einen Kopplungscode zurück. Dabei handelt es sich um ein Loopback-Authentifizierungsgeheimnis, das auf deinem Gerät erzeugt, mit Zugriff nur für den Eigentümer gespeichert und bei jedem Start des Dienstes neu erzeugt wird. Es enthält keinerlei Informationen über dich oder dein SurfverhaltenDer Dienst lauscht ausschließlich auf deinem Rechner. Die Erweiterungsbrücke weigert sich, an eine Adresse zu binden, die nicht Loopback ist, und der MCP-Endpunkt bindet standardmäßig und immer dann, wenn 127.0.0.1 ihn startet, an FSBIn seinem eigenen Verzeichnis führt der Dienst ausschließlich Betriebsaufzeichnungen: ein Diagnoseprotokoll der Ergebnisse delegierter Läufe, beschränkt auf eine feste Feldliste, sowie ein Prozessüberwachungsjournal. Aufgabentexte, Umgebungswerte, Binärpfade und Fehlertexte gelangen in keines von beiden, und Einträge mit zugangsdatenartigen Werten werden verworfen statt geschriebenIst der Host nicht installiert, startet die Funktion schlicht nicht. Es wird nichts übertragen, und der Rest der Erweiterung funktioniert normal weiterDelegierte CLI-AgentenFSB kann eine Aufgabe an ein Coding-Agent-Kommandozeilenwerkzeug übergeben, das du bereits installiert hast, derzeit Claude Code oder Grok Build. FSB startet dieses Programm auf deinem eigenen Rechner; deine Aufgabe wird niemals über FSB-Server geleitet.Dein Aufgabentext erreicht das Werkzeug ausschließlich über dessen Standardeingabe. FSB prüft das vor jedem Lauf: Taucht die Aufgabe in der Kommandozeile, im Arbeitsverzeichnis, in der Umgebung oder in irgendeinem Dateipfad auf, wird der Lauf abgebrochen statt gestartet. Aufgaben sind auf 64 KB begrenztWährend der Lauf aktiv ist, ruft das Werkzeug über die Loopback-Verbindung zurück in FSB, um deinen Browser zu steuern. Alles, was es auf diesem Weg liest — Seitentext, DOM-Snapshots, Tabellenwerte, Screenshots —, wird an dieses Werkzeug zurückgegeben und gelangt damit zu dessen Anbieter: Anthropic bei Claude Code, xAI bei Grok BuildDer Lauf nutzt das Konto, das in diesem Werkzeug bereits angemeldet ist. FSB hält, liest oder überträgt deine Zugangsdaten für Anthropic oder xAI nicht, und jegliche Nutzung oder Kosten richten sich nach dem Tarif des jeweiligen AnbietersGrok Build läuft in einem Profilverzeichnis, das FSB von deinem eigenen getrennt hält. Die dort abgelegten Anmeldedaten schreibt das Grok-Werkzeug während seines eigenen Anmeldevorgangs selbstDie von FSB mitgelieferten Agent-Anweisungen legen fest, dass Passwörter, CVV-Werte, Zahlungskartendaten und gespeicherte Zugangsdaten niemals in Prompts, Erzählungen, Protokolle oder Werkzeugargumente gelangen dürfenLesen und Befüllen von Google SheetsFSB kann einen Bereich in Google Sheets lesen und befüllen, indem es die Tabellenoberfläche in deiner bereits authentifizierten Browsersitzung bedient.Beim Lesen eines Bereichs werden diese Zellwerte an das von dir gewählte Modell gesendet, genau wie jeder andere Seiteninhalt, den FSB in deinem Auftrag liest. Es wird nur der von dir angeforderte Bereich gelesen; einen Export der gesamten Tabelle gibt es nichtTabelleninhalte werden entfernt, bevor irgendetwas in den lokalen Sitzungsverlauf von FSB geschrieben wird. Erhalten bleiben nur Umfangszahlen — wie viele Zeilen, Spalten und Werte beteiligt waren. Die Tabellenadresse, der Blattname, Zellbezüge und jeder einzelne Zellwert werden verworfenLässt sich diese Filterung aus irgendeinem Grund nicht auf einen Datensatz anwenden, wird der Datensatz verworfen statt gespeichertRemote Dashboard und PhantomStream-Live-VorschauWenn Sie Remote Dashboard koppeln, kann FSB mithilfe von PhantomStream eine Live-Vorschau des aktiven Browser-Tabs anzeigen. Die Vorschau streamt strukturierte DOM-Daten statt Pixeln: einen anfänglichen Snapshot, MutationObserver-Diffs, Scrollposition, Automatisierungsüberlagerungen, Dialogstatus, Medienwiedergabestatus und Fernsteuerungsnachrichten über WebSocket.Das Relay leitet diese Live-Vorschaubilder nur an die gekoppelte Dashboard-Sitzung weiter, und nichts aus dem Vorschaustream wird auf FSB-Servern gespeichert — siehe die Liste unter Externe Dienste weiter obenFSB aktiviert die Eingabemaskierung von PhantomStream (maskInputs: true); dadurch werden Passwörter und Werte von Formularelementen maskiert, bevor sie die erfasste Seite verlassenDie Ansicht der Übersicht rendert gespiegelte Inhalte in einer skriptlosen Sandbox und bereinigt gespiegeltes DOM sowie CSS vor der AnzeigeBilder, Video und Audio werden im aktuellen Übersichtsmodus per Verweis gespiegelt. Mediendaten durchlaufen das Relay nicht; die Ansicht kann erlaubte öffentliche HTTPS-URLs für Assets oder Medien direkt abrufen. Private, interne, nicht HTTPS-basierte oder anderweitig gesperrte Ursprünge werden dagegen durch Platzhalter ersetzt; dafür sorgt die im Fehlerfall sperrende Abrufrichtlinie von PhantomStreamKein Tracking durch DritteFSB enthält keinerlei Drittanbieter-Analytik, Anzeigen-Tracker oder seitenübergreifendes Fingerprinting. Es gibt keine Cookies und keine Drittanbieter-Skripte über die von Ihnen ausdrücklich konfigurierten AI-Anbieter-APIs hinaus. Die einzige First-Party-Datenmenge, die FSB übermittelt, ist die unten beschriebene Opt-out-Anonymous-Usage-Telemetry, die ausschließlich zur Bereitstellung des öffentlichen /stats-Dashboards dient.API-SchlüsselIhre API-Keys werden vor der Speicherung lokal mit AES-GCM verschlüsselt. Sie werden nirgendwohin übertragen außer an den von Ihnen konfigurierten KI-Anbieter, und nur als Authentifizierungs-Header in API-Anfragen.Keys sind im Chrome-Speicher im Ruhezustand verschlüsseltDie Entschlüsselung erfolgt nur im Arbeitsspeicher beim API-AufrufKeys werden niemals protokolliert, exportiert oder geteiltAuto-PasswörterFSB enthält einen optionalen Zugangsdaten-Manager, der Anmeldedaten verschlüsselt auf Ihrem Gerät speichert. Passwörter werden niemals an KI-Modelle weitergegeben. Sie werden direkt vom Content Script in die Seiten eingefügt und umgehen die KI vollständig.Zugangsdaten werden mit AES-GCM mit 256-Bit-Schlüsseln und PBKDF2-Schlüsselableitung im Ruhezustand verschlüsseltWenn die KI eine Seite analysiert, werden Werte von Passwortfeldern durch [hidden] ersetzt. Das echte Passwort taucht in keinem KI-Prompt aufDas Inhaltsskript füllt Werte automatisch aus, indem es sie direkt in das DOM einfügt; die KI ist nicht am Anmeldedatenfluss beteiligtDie Listenansicht der Zugangsdaten zeigt nur Benutzernamen und Domains. Passwörter werden nur einzeln und bei Bedarf für das Auto-Ausfüllen entschlüsseltZugangsdaten werden pro Domain mit Eltern-Domain-Fallback gespeichert (z. B. accounts.google.com erbt von google.com)ZahlungsmethodenFSB enthält einen optionalen Zahlungsmethoden-Tresor, der Kartendaten auf Ihrem Gerät für das Auto-Ausfüllen beim Checkout speichert. Karten werden mit derselben Verschlüsselung und KI-Isolierung wie Zugangsdaten behandelt, und die vollständige Kartennummer wird niemals an ein KI-Modell gesendet.Kartendaten (Nummer, Gültigkeit, Karteninhaber und PLZ) werden mit demselben aus dem Tresor abgeleiteten Schlüssel, der auch für Zugangsdaten verwendet wird, mit AES-GCM ruhend verschlüsseltWenn die KI eine Checkout-Seite analysiert, werden alle erkannten Kartennummern-Feldwerte vor dem Bau des Prompts durch [hidden] ersetzt. Kartennummern, CVV und Gültigkeit werden niemals in einen KI-Prompt aufgenommenDas Auto-Ausfüllen erfolgt, indem das Content-Script direkt in die DOM-Felder der Seite schreibt und die KI dabei vollständig umgangen wirdDie Listenansicht zeigt nur einen Kartenspitznamen und die letzten 4 Ziffern. Vollständige Nummern werden ausschließlich im Speicher und nur zum Zeitpunkt des Ausfüllens entschlüsseltEin MCP-Client kann ein Zahlungs-Auto-Ausfüllen über use_payment_method anfordern, dem Benutzer wird jedoch eine Bestätigungsaufforderung in der Erweiterung angezeigt, bevor Kartendaten in die Seite geschrieben werdenCVV wird niemals dauerhaft gespeichert, es sei denn, Sie aktivieren dies pro Karte; selbst dann wird er zusammen mit dem restlichen Datensatz verschlüsseltSpracherkennungFSB enthält eine optionale Mikrofoneingabe für das Prompt-Feld. Der Standardanbieter läuft vollständig in Ihrem Browser; in den Einstellungen können Sie optional einen OpenAI Whisper-Fallback aktivieren, wenn Sie höhere Genauigkeit wünschen.Standardanbieter: die native SpeechRecognition API. Audio wird von Chrome verarbeitet und verlässt Ihr Gerät niemals über FSBOptionaler Whisper-Anbieter: Wenn sttProvider auf whisper gesetzt ist und ein OpenAI-Key konfiguriert ist, werden aufgezeichnete Audioabschnitte direkt von Ihrem Browser an den Transkriptions-Endpunkt von OpenAI hochgeladen. FSB sieht oder speichert das Audio niemalsDas Mikrofon ist nur aktiv, während Sie die Mikrofon-Schaltfläche gedrückt halten oder umgeschaltet haben. Chrome fragt beim ersten Mal nach Berechtigung; FSB fordert im Erweiterungsmanifest keinen Mikrofonzugriff anTranskripte werden ausschließlich in das Prompt-Textfeld eingefügt und niemals außerhalb der aktiven KI-Anfrage, die Sie selbst abschicken, protokolliert, gespeichert oder übertragenSie können die Sprachfunktion vollständig deaktivieren, indem Sie die Mikrofon-Schaltfläche unberührt lassen oder den optionalen Whisper-Anbieter im Chrome-Erweiterungsspeicher löschenSchutz vor Prompt InjectionWebseiten können versteckten Text enthalten, der KI-Agenten kapern soll. FSB setzt mehrschichtige Schutzmaßnahmen ein, damit die KI ausschließlich Ihren Anweisungen folgt und keine in Seiteninhalten eingebetteten Anweisungen befolgt.Alle Seiteninhalte werden in [PAGE_CONTENT]-Begrenzungsmarker eingebettet, und die KI wird angewiesen, niemals Anweisungen innerhalb dieser Marker zu befolgenEine Sanitisierungs-Engine entfernt bekannte Injection-Muster (z. B. "Ignoriere vorherige Anweisungen", gefälschte Systemprompts, Override-Versuche) aus allen Seiteninhalten, bevor sie die KI erreichenVon der KI generierte Aktionen werden vor der Ausführung validiert. Gefährliche URLs (javascript:, data:) und Skript-Injection-Versuche werden blockiertNur eine strenge, feste Positivliste bekannter Werkzeuge kann ausgeführt werden. Die KI kann keine beliebigen Aktionen erfinden oder aufrufen.Die Inhaltsgröße ist begrenzt (500 Zeichen pro Wert, 15 K Gesamtprompt-Limit), um Payload-Übertragungen zu erschwerenUnsichtbare Unicode-Steuerzeichen, die Webseiten einbetten, werden vor der Verarbeitung entferntHintergrund-Agenten und Server-SynchronisationVeraltet seit v0.9.45rc1. FSB integrierte Background Agents wurden durch OpenClaw und Claude Routines ersetzt; die Fernsteuerung erfolgt jetzt über den Tab Sync. Die folgenden Angaben bleiben für Benutzer erhalten, die noch v0.9.44 oder älter verwenden. In aktuellen Builds wird der Relay-Server nur kontaktiert, wenn Sie eine Sync-Sitzung koppeln.Wenn Sie die veraltete Serversynchronisierung für Background Agents aktivieren oder Remote Dashboard koppeln, vermittelt ein Relay-Server die Kommunikation zwischen Ihrer Erweiterung und der Übersicht.Der Server speichert: Agentendefinitionen (Name, Zeitplan, Ziel-URL), Laufmetriken (Token-Anzahl, Kosten, Dauer, Erfolg/Fehler-Status) und Sitzungs-Pairing-TokensÜber diese Lauf-Metadaten hinaus speichert der Server nichts, was aus den von dir besuchten Seiten stammt — siehe die Liste unter Externe Dienste weiter obenDie Authentifizierung verwendet (lokal erzeugte) Hash-Keys und Sitzungs-Tokens, die nach 24 Stunden ablaufenEinmal-Pairing-Tokens laufen nach 60 Sekunden ab und können nicht wiederverwendet werdenDie Server-Synchronisation ist standardmäßig deaktiviert. Sie müssen sie in den Optionen ausdrücklich aktivierenSpeichersystemDas Speichersystem von FSB sichert Navigationsmuster und Site-Intelligenz, um die Automatisierung mit der Zeit zu verbessern.Alle Speicherdaten (semantisch, episodisch, prozedural) werden lokal in chrome.storage.local abgelegtKeine Speicherdaten werden an einen externen Server übertragenDer Speicher kann jederzeit im Optionen-Dashboard angesehen und gelöscht werdenSite-Maps und Navigationsmuster sind domainspezifisch und voneinander isoliertSitzungswiedergabe und ScreenshotsWenn ein MCP-Client FSB steuert, zeichnet die Erweiterung auf, was der Agent getan hat, damit du den Lauf später ansehen oder wiedergeben kannst. Diese Aufzeichnungen bleiben auf deinem Gerät.Noch laufende Durchläufe liegen im Sitzungsspeicher von Chrome, damit sie das Verdrängen des Service Workers überstehen; abgeschlossene Durchläufe werden über chrome.storage.local in denselben Verlaufsspeicher geschrieben, den auch deine eigenen Automatisierungsläufe nutzenAufzeichnungen werden vor dem Speichern bereinigt. Werte unter zugangsdatenartigen Schlüsseln, Text, der in Felder eingegeben wurde, die nach Passwort, Einmalcode oder Karte aussehen, sowie signierte oder tokenhaltige URL-Parameter werden allesamt ersetzt. Gewöhnliche Adressen und Selektoren bleiben erhalten, weil die Wiedergabe ohne sie nicht funktioniertAufgezeichnete Durchläufe werden standardmäßig 30 Tage aufbewahrt, einstellbar zwischen 1 und 365 Tagen, und ältere werden von einem täglichen Job entfernt. Die Aufzeichnung lässt sich in den erweiterten Einstellungen vollständig abschaltenScreenshot-Bilder werden nie in diesen Verlauf geschrieben. Erhalten bleiben nur Aufnahme-Metadaten wie Abmessungen und BytegrößeVon einem MCP-Client angeforderte Screenshots speichert der lokale Dienst als Dateien auf deiner eigenen Festplatte mit Zugriff nur für den Eigentümer und löscht sie automatisch nach sieben Tagen. Das Bild wird außerdem an den anfragenden Client zurückgegeben und gelangt damit zu dessen ModellAnonyme NutzungstelemetrieFSB v0.9.69 hat eine opt-out-fähige Pipeline für anonyme Nutzungstelemetrie eingeführt, damit das Projekt aggregierte Adoptionszahlen veröffentlichen kann (siehe /stats), ohne jemals auf die von dir besuchten Seiten zuzugreifen. Das einzige Standortsignal ist eine grobe Land-/Bundesland-Kennung, die der Server beim Eingang aus deiner Anfrage-IP ableitet (niemals aus Seiteninhalten) und nur aggregiert speichert – siehe Region (auf Bundeslandebene) weiter unten. Telemetrie ist standardmäßig aktiv, kann aber mit einem einzigen Schalter deaktiviert werden, und die Daten pro Installation können auf Anfrage gelöscht werden.Was wir erfassenEine zufällige UUID pro Installation, gespeichert in chrome.storage.local unter dem Schlüssel fsbInstallUuid. Die UUID wird lokal generiert und niemals mit deiner Identität verknüpft.Der Name des verwendeten MCP-Clients (z. B. Claude Code, Cursor, Codex), aus einer festen Allowlist gezogen.Der Modellname, der in einer Sitzung verwendet wird (z. B. grok-4-fast, claude-opus-4), aus einer festen Allowlist gezogen.Aggregierte Eingabe-/Ausgabe-Token-Zählungen pro Sitzung.Die Anzahl aktiver FSB-Agenten auf deiner Installation (ein ganzzahliger Wert).Was wir NICHT erfassenSeiten-URLs, Hostnamen oder Browserverlauf.Prompts, Anweisungen, Aufgabenbeschreibungen oder beliebigen natürlichsprachlichen Text, den du an deinen Modellanbieter sendest.Seiten-DOM, Bildschirmaufnahmen, Seiteninhalte, Nutzdaten von Website-API oder AI-Antworten.Klartext-IP-Adressen. Der Server verwendet die Anfrage-IP vorübergehend und inline für genau zwei Zwecke – einen Hash mit täglich rotierendem Salt zur Ratenbegrenzung und die Ableitung einer groben Land-/Bundesland-Kennung (siehe unten) – und verwirft sie danach sofort. Die Klartext-IP wird niemals gespeichert oder protokolliert.Namen, Benutzernamen, Konto-Handles oder beliebige Freitext-Identitätsfelder.E-Mail-Adressen, Telefonnummern oder Kontaktinformationen.Region (auf Bundeslandebene)Der Server leitet beim Eingang eine grobe Land- und US-Bundesland-Kennung (Subdivision) aus deiner Anfrage-IP ab, mithilfe eines selbst gehosteten DB-IP-IP-to-City-Lite-Datensatzes und unserer eigenen Suche – kein Live-Geolokalisierungsdienst eines Dritten und niemals MaxMind. Die Klartext-IP wird inline verarbeitet und verworfen; nur die abgeleitete Kennung wird behalten.Die Region wird nur im Tagesaggregat gespeichert, hinter einer k≥5-Anonymitätsschwelle: Jedes Bundesland mit weniger als 5 eindeutigen Installationen an einem Tag fällt in einen einzigen „Other“-Sammeleintrag (vollständig unterdrückt, wenn selbst diese Summe unter 5 liegt). Keine einzelne Bundesland-Kennung steht jemals für weniger als 5 Installationen.Es gibt kein Standortprofil pro Installation. Die grobe Kennung existiert nur im kurzlebigen Rohereignis (durch die 7-Tage-Aufbewahrung gelöscht) und im k≥5-gefilterten Tages-Rollup; wir erstellen oder behalten niemals eine dauerhafte Zuordnung von deiner Installation zu einem Ort. Geolokalisierungsdaten von DB-IP (https://db-ip.com).AufbewahrungRohereignisse werden 7 Tage lang aufbewahrt. Tägliche Aggregate (eine Zeile pro Installation pro Tag) werden 365 Tage lang aufbewahrt. Globale Aggregate (eine Zeile pro Tag, ohne Pro-Installation-Dimension) werden unbegrenzt aufbewahrt, damit historische Diagramme auf /stats stabil bleiben.Wie du dich abmeldestÖffne das FSB-Bedienfeld, scrolle zu „Erweiterte Einstellungen" und deaktiviere den Schalter Anonyme Nutzungsdaten senden. Die Änderung wird sofort wirksam; es werden keine weiteren Ereignisse von deiner Installation gesendet.Wie du deine Daten löschtUm die Löschung aller mit Ihrer Installation verknüpften Telemetriezeilen anzufordern (GDPR Artikel 17), suchen Sie Ihre fsbInstallUuid in Chrome DevTools → Anwendung → Speicher → Erweiterungsspeicher und senden Sie anschließend eine einzelne HTTP-Anfrage:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited-Use-ErklärungDie anonyme Nutzungstelemetrie von FSB wird ausschließlich verwendet, um aggregierte Nutzungsstatistiken zu berechnen, die öffentlich auf full-selfbrowsing.com/stats angezeigt werden. Die Daten werden niemals verkauft, niemals an Dritte weitergegeben, niemals für Werbung verwendet und niemals zum Training von Modellen für maschinelles Lernen verwendet. Diese Verpflichtung erfüllt die Chrome Web Store-Anforderung des Limited Use.Aggregierte öffentliche MetrikenWir veröffentlichen aggregierte Metriken aus dieser Telemetrie-Pipeline auf /stats. Es werden nur Zählungen und Summen angezeigt; niemals wird eine Zeile pro Installation offengelegt.Steuerung von Einwilligung und PrüfungFSB verfolgt bei der Automatisierung ein Opt-out-Modell: Ursprünge, die nicht auf der Sperrliste stehen, übernehmen eine vom Benutzer konfigurierbare globale Voreinstellung, die derzeit als Auto ausgeliefert wird. Explizite ursprungsspezifische Richtlinien können einen Ursprung auf Off, Ask oder Auto setzen. Das Prüfprotokoll wird lokal und zeitlich begrenzt aufbewahrt; im Kontrollzentrum stehen Funktionen zum Exportieren und Löschen bereit.Die Dienstsperrliste bleibt eine harte Blockade. Gesperrte Ursprünge können unabhängig von der globalen Voreinstellung oder einer gespeicherten ursprungsspezifischen Richtlinie nicht aktiviert werden.Auf sensiblen Ursprüngen können unter Auto Lesevorgänge ausgeführt werden; Schreibvorgänge setzen vor der Ausführung jedoch erneut die ursprungsspezifische Zustimmung zu Änderungen durch. Nicht sensible Ursprünge können deaktiviert oder im Bereich Einwilligung & Prüfung des Kontrollzentrums auf Ask gesetzt werden.Jeder Capability-Aufruf wird in einem redigierten, ausschließlich anhängenden lokalen Audit-Protokoll erfasst. Es werden niemals Argumente, Tokens, Cookies oder Antwortinhalte gespeichert.QuelloffenFSB ist unter der MIT-Lizenz vollständig quelloffen. Sie können jede Codezeile prüfen, um diese Datenschutzaussagen zu verifizieren. Der Quellcode ist auf GitHub verfügbar.Änderungen dieser RichtlinieWird diese Richtlinie aktualisiert, spiegelt sich das im Datum "Zuletzt aktualisiert" oben auf dieser Seite wider. Wesentliche Änderungen werden zusätzlich in den Release-Notes des Projekts auf GitHub vermerkt.KontaktWenn Sie Fragen zu dieser Datenschutzrichtlinie oder zum Umgang von FSB mit Daten haben, öffnen Sie bitte ein Ticket unter GitHub Issues. + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) Mai – Juli 2026v0.9.90 — Site-API-Fähigkeiten, Remote Dashboard und PhantomStream, Zahlungsmethoden, Sprache-zu-Text, Regionsmetrik (vollständiger archivierter Text) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - Zuletzt aktualisiert: August 2026 + Last updated: September 2026 + Zuletzt aktualisiert: September 2026 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69 hat eine opt-out-fähige Pipeline für anonyme Nutzungstelemetrie eingeführt, damit das Projekt aggregierte Adoptionszahlen veröffentlichen kann (siehe /stats), ohne jemals auf die von dir besuchten Seiten zuzugreifen. Das einzige Standortsignal ist eine grobe Land-/Bundesland-Kennung, die der Server beim Eingang aus deiner Anfrage-IP ableitet (niemals aus Seiteninhalten) und nur aggregiert speichert – siehe Region (auf Bundeslandebene) weiter unten. Telemetrie ist standardmäßig aktiv, kann aber mit einem einzigen Schalter deaktiviert werden, und die Daten pro Installation können auf Anfrage gelöscht werden. + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 hat eine opt-out-fähige Pipeline für anonyme Nutzungstelemetrie eingeführt, damit das Projekt aggregierte Adoptionszahlen veröffentlichen kann (siehe /stats), ohne jemals auf die von dir besuchten Seiten zuzugreifen. Das einzige Standortsignal ist eine grobe Land-/Bundesland-Kennung, die der Server beim Eingang aus deiner Anfrage-IP ableitet (niemals aus Seiteninhalten) und nur aggregiert veröffentlicht – siehe Region (auf Bundeslandebene) weiter unten. Telemetrie ist standardmäßig aktiv, kann aber mit einem einzigen Schalter deaktiviert werden, und die Daten pro Installation können auf Anfrage gelöscht werden. src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - Klartext-IP-Adressen. Der Server verwendet die Anfrage-IP vorübergehend und inline für genau zwei Zwecke – einen Hash mit täglich rotierendem Salt zur Ratenbegrenzung und die Ableitung einer groben Land-/Bundesland-Kennung (siehe unten) – und verwirft sie danach sofort. Die Klartext-IP wird niemals gespeichert oder protokolliert. + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + Klartext-IP-Adressen. Der Server verwendet die Anfrage-IP vorübergehend und inline für genau drei Zwecke – einen Hash mit täglich rotierendem Salt zur Ratenbegrenzung, die Ableitung einer groben Land-/Bundesland-Kennung (siehe unten) und die Feststellung, ob es sich um eine IPv4- oder IPv6-Adresse handelt – und verwirft sie danach sofort. Die Klartext-IP wird niemals gespeichert oder protokolliert. src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - Der Server leitet beim Eingang eine grobe Land- und US-Bundesland-Kennung (Subdivision) aus deiner Anfrage-IP ab, mithilfe eines selbst gehosteten DB-IP-IP-to-City-Lite-Datensatzes und unserer eigenen Suche – kein Live-Geolokalisierungsdienst eines Dritten und niemals MaxMind. Die Klartext-IP wird inline verarbeitet und verworfen; nur die abgeleitete Kennung wird behalten. + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + Der Server leitet beim Eingang eine grobe Land- und US-Bundesland-Kennung (Subdivision) aus deiner Anfrage-IP ab, mithilfe eines selbst gehosteten DB-IP-IP-to-City-Lite-Datensatzes und unserer eigenen Suche – kein Live-Geolokalisierungsdienst eines Dritten und niemals MaxMind. Die Klartext-IP wird inline verarbeitet und verworfen; nur die abgeleitete Kennung und die Adressfamilie (IPv4 oder IPv6) werden behalten. src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - Die Region wird nur im Tagesaggregat gespeichert, hinter einer k≥5-Anonymitätsschwelle: Jedes Bundesland mit weniger als 5 eindeutigen Installationen an einem Tag fällt in einen einzigen „Other“-Sammeleintrag (vollständig unterdrückt, wenn selbst diese Summe unter 5 liegt). Keine einzelne Bundesland-Kennung steht jemals für weniger als 5 Installationen. + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + Die Region wird nur aggregiert veröffentlicht, hinter einer k≥5-Anonymitätsschwelle: Jedes Bundesland mit weniger als 5 eindeutigen Installationen fällt in einen einzigen „Other“-Sammeleintrag (vollständig unterdrückt, wenn selbst diese Summe unter 5 liegt). Keine veröffentlichte Bundesland-Kennung steht jemals für weniger als 5 Installationen. src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - Es gibt kein Standortprofil pro Installation. Die grobe Kennung existiert nur im kurzlebigen Rohereignis (durch die 7-Tage-Aufbewahrung gelöscht) und im k≥5-gefilterten Tages-Rollup; wir erstellen oder behalten niemals eine dauerhafte Zuordnung von deiner Installation zu einem Ort. Geolokalisierungsdaten von DB-IP (https://db-ip.com). + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + Die grobe Kennung wird im Rohereignis (durch die 7-Tage-Aufbewahrung gelöscht) und im Tages-Rollup deiner Installation gespeichert, das 365 Tage lang aufbewahrt wird, damit /stats jede Installation einmal anhand ihrer jüngsten Region zählen kann. Sie ist niemals eine IP-Adresse, eine Stadt oder eine Koordinate; sie wird zusammen mit den übrigen Daten deiner Installation gelöscht, wenn du die Löschung beantragst; und sie wird nur hinter der oben beschriebenen k≥5-Schwelle veröffentlicht. Geolokalisierungsdaten von DB-IP (https://db-ip.com). src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - Rohereignisse werden 7 Tage lang aufbewahrt. Tägliche Aggregate (eine Zeile pro Installation pro Tag) werden 365 Tage lang aufbewahrt. Globale Aggregate (eine Zeile pro Tag, ohne Pro-Installation-Dimension) werden unbegrenzt aufbewahrt, damit historische Diagramme auf /stats stabil bleiben. + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + Rohereignisse werden 7 Tage lang aufbewahrt. Tägliche Aggregate (eine Zeile pro Installation pro Tag, einschließlich der groben Regionskennung) werden 365 Tage lang aufbewahrt. Globale Aggregate (eine Zeile pro Tag, ohne Pro-Installation-Dimension) werden unbegrenzt aufbewahrt, damit historische Diagramme auf /stats stabil bleiben. src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - Regionale Verteilung aus dem heutigen Stundenaggregat. + Where installs were last seen, by coarse region, over the past 365 days. + Wo Installationen zuletzt gesehen wurden, nach grober Region, über die letzten 365 Tage. src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - Globus mit der heutigen stündlichen regionalen FSB-Verteilung + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + Globus, der zeigt, wo FSB-Installationen in den letzten 365 Tagen zuletzt gesehen wurden, nach grober Region src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/locale/messages.es.xlf b/showcase/angular/src/locale/messages.es.xlf index e5d8f9806..157516445 100644 --- a/showcase/angular/src/locale/messages.es.xlf +++ b/showcase/angular/src/locale/messages.es.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + Agosto de 2026v0.9.91 — Servicio de agente local y mensajería nativa, Agentes CLI delegados, Google Sheets, Reproducción de sesiones y capturas de pantalla (texto archivado completo) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + Copia archivada de la política de privacidad tal como estaba en agosto de 2026, antes de la actualización de septiembre de 2026.Resumen: FSB se ejecuta dentro de tu navegador y los servidores de FSB no recopilan datos de navegación. Las llamadas de IA van directamente desde tu navegador al proveedor que elijas. Las claves de API y las credenciales se cifran localmente, y los datos de memoria permanecen en tu dispositivo. Si instalas el servicio de agente local opcional, FSB también puede ser controlado por un cliente MCP que se ejecute en tu propia máquina mediante una conexión de bucle invertido, y por las CLIs de agentes de programación que ya tengas instaladas. Los únicos datos que salen de tu máquina hacia FSB son la telemetría de uso anónima con opción de exclusión que alimenta la página pública /stats. Si vinculas Remote Dashboard, los fotogramas transitorios de vista previa en vivo pueden pasar por el relé durante la sesión, pero no se almacenan. Todo es de código abierto y auditable.Recopilación de datosFSB funciona íntegramente dentro de tu navegador. Cuando inicias una tarea de automatización, la extensión puede inspeccionar el DOM (modelo de objetos del documento) de la pestaña activa y, cuando invocas una capacidad, realizar solicitudes a la API del sitio y del mismo origen desde la sesión de tu navegador.No se recopila ni almacena historial de navegación más allá de la sesión actualLos datos del DOM y los resultados de la API del sitio se analizan localmente y se descartan después de cada paso de automatización, salvo que los guardes expresamente en la memoria.No se extrae información personal de las páginas que visitasCapacidades de la API del sitioLa capa de capacidades de FSB puede llamar a la API propia de un sitio desde el contexto de la página mediante tu sesión de navegador ya autenticada. Estas solicitudes se ejecutan localmente en Chrome; el navegador puede adjuntar cookies propias o la autenticación del sitio de destino, pero FSB no devuelve, almacena, registra ni envía cookies, tokens, valores CSRF, cuerpos de solicitudes o cuerpos de respuestas a los servidores de FSB.Las invocaciones de capacidades siguen los controles de consentimiento de FSB y solo se registran en el registro de auditoría local censurado: origen, slug de capacidad, método, clase de efecto secundario, decisión de consentimiento y resultado. El registro de auditoría nunca almacena argumentos de invocación, cuerpos de solicitudes o respuestas, cookies, tokens, valores CSRF ni cargas de respuestas del sitio.Permisos de Chrome que solicita FSBPara ejecutar la automatización web, FSB declara los siguientes permisos en su manifiesto de Chrome. Cada uno se utiliza únicamente para el propósito documentado; nada se envía fuera del dispositivo basándose en ninguno de ellos.DOM y pestañas, activeTab, scripting, tabs, windows, sidePanel y el permiso de host <all_urls>: leer y escribir en la pestaña activa, inyectar el script de contenido de automatización, enumerar y cambiar de pestaña y renderizar el panel lateral.Automatización avanzada, debugger: conectar Chrome DevTools Protocol para realizar clics por coordenadas y acciones de arrastre y pulsación prolongada de teclas que la DOM normal del API no puede ejecutar. webNavigation: observar los eventos de inicio y finalización de la navegación para que la automatización espere el momento adecuado.Almacenamiento local, storage, unlimitedStorage: guardar tu configuración, credenciales, métodos de pago y memoria en chrome.storage.local en tu dispositivo. El almacenamiento ilimitado elimina la cuota predeterminada de 10 MB para que la memoria y los registros de sesión puedan crecer sin alcanzar un límite.Ayudas de UX, clipboardWrite: escribir en el portapapeles los resultados de la automatización. alarms: programar tareas de mantenimiento en segundo plano. offscreen: alojar el grabador de voz a texto en un documento oculto porque los service workers no pueden capturar audio directamente.Servicio local, nativeMessaging: inicia el servicio de agente local opcional descrito en Servicio de agente local y mensajería nativa más abajo. Nada sobre las páginas que visitas pasa por ese canal. system.memory: lee únicamente la cifra de RAM total instalada, para que FSB pueda sugerir un límite razonable de agentes simultáneos. La memoria disponible y el desglose por procesador nunca se leen, y la cifra nunca sale de la extensiónEl acceso al micrófono para voz a texto no está declarado en el manifiesto. Chrome muestra su propia solicitud de permiso la primera vez que utilizas el botón del micrófono.Almacenamiento de datosToda la configuración y los datos se almacenan localmente en el almacenamiento de extensiones de Chrome, con los valores sensibles cifrados en reposo tal como se describe en las secciones siguientes.La configuración se almacena en chrome.storage.localLas claves de API, las credenciales y los métodos de pago se cifran antes de almacenarse; cada uno se detalla en su propia sección más abajoLos registros de sesión se almacenan localmente y se pueden borrar en cualquier momentoLos datos de analítica (conteos de tareas, tasas de éxito) permanecen en tu dispositivoServicios externosFSB se comunica con proveedores de IA externos solo cuando configuras y usas un proveedor alojado. Si usas LM Studio, las solicitudes de IA permanecen en tu máquina a través de su servidor local compatible con OpenAI. La elección de proveedor y qué datos se envían está bajo tu control.Las llamadas a APIs alojadas se hacen solo al proveedor que selecciones (xAI, OpenAI, Anthropic, Google u OpenRouter)LM Studio usa un servidor local compatible con OpenAI en tu dispositivo y no requiere clave de APILos datos enviados incluyen: descripción de la tarea, resumen de la estructura del DOM y contexto de la acción.Si vinculas Remote Dashboard o usas la sincronización heredada de Background Agents, un servidor de relé opcional gestiona los mensajes WebSocket de esa sesión. Los fotogramas de vista previa en vivo pueden pasar transitoriamente por el relé, pero nada de lo siguiente se conserva jamás en un servidor de FSB: contenido de la página, datos DOM, historial de navegación, capturas de pantalla, prompts de IA, respuestas de IA, cookies, tokens o cargas útiles de la API del sitio. Es solo opcional, y el resto de esta política remite a esta lista en lugar de repetirlaCada proveedor tiene su propia política de privacidad que rige cómo maneja las solicitudes de APIServicio de agente local y mensajería nativaFSB puede ser controlado por un cliente MCP que se ejecute en tu propia máquina. Eso requiere un pequeño servicio de agente local que instalas tú mismo, y el permiso nativeMessaging existe únicamente para que la extensión pueda iniciarlo. Chrome no puede lanzar un programa local directamente, así que este es el único mecanismo admitido.El host de mensajería io.github.fullselfbrowsing.fsb_native_host solo se registra mediante una acción explícita tuya, ejecutando fsb-mcp-server install --native-host. La extensión no puede instalarlo, y su registro nombra un único origen de extensión permitidoEl intercambio sigue un esquema cerrado. FSB envía un número de versión, una acción que es o bien wake o bien bootstrap, y un identificador de correlación generado localmente; recibe de vuelta ese identificador con un resultado y un motivo tomados de una lista fija. Cualquier campo adicional se rechaza de plano y los mensajes están limitados a 4 KB. En este esquema no existe ninguna URL, pestaña, contenido de página ni dato DOMUn inicio correcto devuelve un código de emparejamiento. Es un secreto de autenticación de bucle invertido generado en tu dispositivo y almacenado con permisos exclusivos del propietario, que se renueva cada vez que arranca el servicio. No contiene información alguna sobre ti ni sobre tu navegaciónEl servicio escucha únicamente en tu máquina. El puente de la extensión se niega a enlazar a cualquier dirección que no sea de bucle invertido, y el punto final MCP enlaza a 127.0.0.1 de forma predeterminada y siempre que lo inicie FSBEn su propio directorio, el servicio solo conserva registros operativos: un registro de diagnóstico de los resultados de las ejecuciones delegadas, limitado a una lista fija de campos, y un diario de supervisión de procesos. El texto de la tarea, los valores de entorno, las rutas de binarios y los textos de error nunca llegan a ninguno de los dos, y las entradas con valores que parecen credenciales se descartan en lugar de escribirseSi el host no está instalado, la función simplemente no se inicia. No se transmite nada y el resto de la extensión sigue funcionando con normalidadAgentes CLI delegadosFSB puede entregar una tarea a una herramienta de línea de comandos de agente de programación que ya tengas instalada, actualmente Claude Code o Grok Build. FSB inicia ese programa en tu propia máquina; tu tarea nunca pasa por servidores de FSB.El texto de tu tarea llega a la herramienta por su entrada estándar y por ninguna otra vía. FSB lo comprueba antes de cada ejecución: si la tarea aparece en la línea de comandos, el directorio de trabajo, el entorno o cualquier ruta de archivo, la ejecución se aborta en lugar de iniciarse. Las tareas están limitadas a 64 KBMientras la ejecución está en curso, la herramienta vuelve a llamar a FSB por la conexión de bucle invertido para controlar tu navegador. Todo lo que lea de ese modo (texto de la página, instantáneas del DOM, valores de hojas de cálculo, capturas de pantalla) se devuelve a esa herramienta y, por tanto, llega a su proveedor: Anthropic para Claude Code, xAI para Grok BuildLa ejecución usa la cuenta con la que ya has iniciado sesión en esa herramienta. FSB no guarda, lee ni transmite tu credencial de Anthropic ni de xAI, y cualquier uso o cargo se rige por el plan de ese proveedorGrok Build se ejecuta dentro de un directorio de perfil que FSB mantiene separado del tuyo. La credencial de inicio de sesión guardada allí la escribe la propia herramienta Grok durante su propio flujo de accesoLas instrucciones de agente que suministra FSB establecen que las contraseñas, los valores CVV, los datos de tarjetas de pago y las credenciales guardadas nunca deben entrar en prompts, narraciones, registros ni argumentos de herramientasLectura y relleno de Google SheetsFSB puede leer y rellenar un rango en Google Sheets manejando la interfaz de la hoja de cálculo en tu propia sesión de navegador ya autenticada.Al leer un rango, esos valores de celda se envían al modelo que hayas seleccionado, igual que cualquier otro contenido de página que FSB lea en tu nombre. Solo se lee el rango que has pedido; no existe una exportación de la hoja completaEl contenido de la hoja de cálculo se elimina antes de escribir nada en el historial de sesión local de FSB. Solo sobreviven los recuentos de forma: cuántas filas, columnas y valores intervinieron. La dirección de la hoja, el nombre de la pestaña, las referencias de celda y todos los valores se descartanSi ese filtrado no puede aplicarse a un registro por cualquier motivo, el registro se descarta en lugar de almacenarseVista previa en directo del Remote Dashboard y PhantomStreamCuando emparejas el Remote Dashboard, FSB puede mostrar una vista previa en directo de la pestaña activa del navegador mediante PhantomStream. La vista previa transmite datos estructurados del DOM en lugar de píxeles: una instantánea inicial, cambios de MutationObserver, posición de desplazamiento, superposiciones de automatización, estado de los cuadros de diálogo, estado de reproducción multimedia y mensajes de control remoto mediante WebSocket.El relé reenvía esos fotogramas de vista previa en vivo solo a la sesión del panel vinculada, y nada del flujo de vista previa se conserva en los servidores de FSB: consulta la lista en Servicios externos más arribaFSB activa el enmascaramiento de entradas de PhantomStream (maskInputs: true), por lo que las contraseñas y los valores de los controles de formulario se enmascaran antes de salir de la página capturada.El visor del panel renderiza el contenido replicado en un entorno aislado sin scripts y sanea el DOM y el CSS replicados antes de mostrarlos.En el modo actual del panel, las imágenes, el vídeo y el audio se replican por referencia. Los bytes multimedia no atraviesan el relé; el visor puede obtener directamente las URL públicas permitidas de recursos o contenido multimedia HTTPS, mientras que los orígenes privados, internos, no HTTPS o bloqueados por cualquier otro motivo se sustituyen por marcadores de posición conforme a la política de obtención con bloqueo ante fallos de PhantomStream.Sin rastreo de tercerosFSB no incluye ninguna analítica de terceros, rastreadores publicitarios ni fingerprinting entre sitios. No hay cookies ni scripts de terceros más allá de las AI de proveedores de APIs que configuras explícitamente. El único dato de primera parte que FSB envía es la Telemetría de Uso Anónima opt-out descrita más adelante, utilizada únicamente para alimentar el panel público /stats.Claves de APITus claves de API se cifran localmente usando AES-GCM antes de almacenarse. Nunca se transmiten a ningún lugar excepto al proveedor de IA que configuraste, y solo como encabezados de autenticación en las solicitudes de API.Las claves están cifradas en reposo en el almacenamiento de ChromeEl descifrado solo ocurre en memoria al hacer llamadas a la APILas claves nunca se registran, exportan ni compartenContraseñas automáticasFSB incluye un gestor de credenciales opcional que almacena las credenciales de inicio de sesión cifradas en tu dispositivo. Las contraseñas nunca se exponen a los modelos de IA. Se completan directamente en las páginas mediante el content script, evitando por completo a la IA.Las credenciales se cifran en reposo usando AES-GCM con claves de 256 bits y derivación de claves PBKDF2Cuando la IA analiza una página, los valores de los campos de contraseña se reemplazan con [hidden]. La contraseña real nunca se incluye en ningún prompt de IAEl autocompletado lo realiza el script de contenido, que inyecta los valores directamente en el DOM, sin intervención de la IA en el flujo de credenciales.La vista de lista de credenciales solo muestra usuarios y dominios. Las contraseñas se descifran individualmente y solo cuando se necesitan para el autorrellenadoLas credenciales se almacenan por dominio con respaldo al dominio padre (por ejemplo, accounts.google.com hereda de google.com)Métodos de pagoFSB incluye una bóveda opcional de métodos de pago que almacena los datos de la tarjeta en tu dispositivo para autocompletar el pago. Las tarjetas se tratan con el mismo cifrado y aislamiento de IA que las credenciales de inicio de sesión, y el número completo de la tarjeta nunca se envía a ningún modelo de IA.Los datos de la tarjeta (número, caducidad, titular y código postal) se cifran en reposo con AES-GCM usando la misma clave derivada de la bóveda que se utiliza para las credencialesCuando la IA analiza una página de pago, los valores detectados en los campos del número de tarjeta se sustituyen por [hidden] antes de construir el prompt. Los números de tarjeta, el CVV y la caducidad nunca se incluyen en ningún prompt de IAEl autocompletado se realiza mediante el script de contenido escribiendo directamente en los campos DOM de la página, evitando por completo a la IALa vista de lista solo muestra un alias de tarjeta y los últimos 4 dígitos. Los números completos solo se descifran en memoria y únicamente en el momento del autocompletadoUn cliente MCP puede solicitar un autocompletado de pago mediante use_payment_method, pero al usuario se le muestra una confirmación dentro de la extensión antes de escribir cualquier dato de la tarjeta en la páginaEl CVV nunca se persiste salvo que actives esa opción por cada tarjeta; e incluso así se cifra junto con el resto del registroVoz a textoFSB incluye una entrada de micrófono opcional para el cuadro del prompt. El proveedor por defecto se ejecuta completamente en tu navegador; en los ajustes puedes habilitar opcionalmente un fallback de OpenAI Whisper si quieres mayor precisión.Proveedor predeterminado: la SpeechRecognition API nativa del navegador. Chrome procesa el audio, que nunca sale de tu dispositivo a través de FSB.Proveedor Whisper opcional: cuando sttProvider está configurado como whisper y se ha configurado una clave de OpenAI, los fragmentos de audio grabados se suben directamente desde tu navegador al endpoint de transcripción de OpenAI. FSB nunca ve ni almacena el audioEl micrófono solo está activo mientras mantienes pulsado o has alternado el botón del micrófono. Chrome solicita el permiso la primera vez que lo utilizas; FSB no solicita el acceso al micrófono en el manifiesto de la extensiónLas transcripciones se insertan únicamente en el área de texto del prompt y nunca se registran, persisten ni transmiten fuera de la solicitud activa de IA que decides enviarPara deshabilitar la voz por completo, deja sin tocar el botón del micrófono, o borra el proveedor opcional de Whisper en el almacenamiento de la extensión de ChromePrevención de inyección de promptsLas páginas web pueden contener texto oculto diseñado para secuestrar agentes de IA. FSB implementa defensas en múltiples capas para asegurar que la IA solo siga tus instrucciones, nunca instrucciones incrustadas en el contenido de la página.Todo el contenido de la página se envuelve en marcadores de límite [PAGE_CONTENT], y se instruye a la IA a nunca seguir instrucciones encontradas dentro de estos marcadoresUn motor de saneamiento elimina patrones de inyección conocidos (por ejemplo, "ignora las instrucciones previas", prompts de sistema falsos, intentos de anulación) de todo el contenido de la página antes de que llegue a la IALas acciones generadas por la IA se validan antes de ejecutarse. URLs peligrosas (javascript:, data:) e intentos de inyección de scripts se bloqueanSolo se puede ejecutar una lista fija y estricta de herramientas conocidas. La IA no puede inventar ni llamar a acciones arbitrarias.El tamaño del contenido está limitado (500 caracteres por valor, tope total de prompt de 15K) para restringir la entrega de carga útilLos caracteres de control Unicode invisibles que incrustan los sitios web se eliminan antes del procesamientoAgentes en segundo plano y sincronización con servidorObsoleto desde v0.9.45rc1. Los Background Agents integrados de FSB han sido sustituidos por OpenClaw y Claude Routines, mientras que el control remoto ahora se gestiona desde la pestaña Sync. La información siguiente se conserva para quienes aún utilizan v0.9.44 o una versión anterior; en las versiones actuales solo se contacta con el servidor de relé cuando emparejas una sesión Sync.Si activas la sincronización heredada de Background Agents con el servidor o emparejas el Remote Dashboard, un servidor de relé facilita la comunicación entre la extensión y el panel.El servidor almacena: definiciones de agentes (nombre, programación, URL objetivo), métricas de ejecución (conteo de tokens, costo, duración, estado de éxito/fallo) y tokens de emparejamiento de sesiónMás allá de esos metadatos de ejecución, el servidor no conserva nada derivado de las páginas que visitas: consulta la lista en Servicios externos más arribaLa autenticación usa claves hash (generadas localmente) y tokens de sesión que expiran después de 24 horasLos tokens de emparejamiento de un solo uso expiran después de 60 segundos y no pueden reutilizarseLa sincronización con servidor está deshabilitada por defecto. Debes habilitarla explícitamente en OpcionesSistema de memoriaEl sistema de memoria de FSB almacena patrones de navegación e inteligencia de sitios para mejorar la automatización con el tiempo.Todos los datos de memoria (semántica, episódica, procedimental) se almacenan localmente en chrome.storage.localNingún dato de memoria se envía a ningún servidor externoLa memoria se puede ver y borrar en cualquier momento desde el panel de opcionesLos mapas de sitios y patrones de navegación son específicos del dominio y están aislados entre síReproducción de sesiones y capturas de pantallaCuando un cliente MCP controla FSB, la extensión registra lo que hizo el agente para que puedas revisar o reproducir la ejecución más tarde. Esos registros permanecen en tu dispositivo.Las ejecuciones aún en curso se guardan en el almacenamiento de sesión de Chrome para que sobrevivan al desalojo del service worker; las ejecuciones terminadas se escriben en chrome.storage.local, el mismo almacén de historial que usan tus propias automatizacionesLos registros se depuran antes de almacenarse. Se sustituyen los valores bajo claves que parecen credenciales, el texto escrito en campos que parecen de contraseña, código de un solo uso o tarjeta, y los parámetros de URL firmados o portadores de tokens. Las direcciones y los selectores corrientes se conservan, porque sin ellos la reproducción no funcionaLas ejecuciones registradas se conservan 30 días de forma predeterminada, ajustable entre 1 y 365 días, y las más antiguas las elimina un trabajo diario. El registro puede desactivarse por completo en los ajustes avanzadosLas imágenes de las capturas de pantalla nunca se escriben en ese historial. Solo se conservan metadatos de la captura, como las dimensiones y el tamaño en bytesLas capturas de pantalla que solicita un cliente MCP las guarda el servicio local como archivos en tu propio disco con permisos exclusivos del propietario y las elimina automáticamente a los siete días. La imagen también se devuelve al cliente solicitante y, por tanto, a su modeloTelemetría anónima de usoFSB v0.9.69 introdujo una canalización de telemetría de uso anónima con opción de exclusión para que el proyecto pueda publicar cifras de adopción agregadas (consulta /stats) sin tocar nunca las páginas que navegas. La única señal de ubicación es una etiqueta aproximada de país/estado que el servidor deriva de la IP de tu solicitud en el momento de la ingesta (nunca del contenido de la página), conservada solo de forma agregada: consulta Métrica de región (a nivel de estado) más abajo. La telemetría está activada de forma predeterminada, pero puede desactivarse con un solo interruptor, y los datos por instalación pueden borrarse a petición.Lo que recopilamosUn UUID aleatorio por instalación, almacenado en chrome.storage.local bajo la clave fsbInstallUuid. El UUID se genera localmente y nunca se vincula a tu identidad.El nombre del cliente MCP usado (p. ej. Claude Code, Cursor, Codex), extraído de una lista de permitidos fija.El nombre del modelo utilizado en una sesión (p. ej. grok-4-fast, claude-opus-4), extraído de una lista de permitidos fija.Recuentos agregados de tokens de entrada/salida por sesión.El número de agentes FSB activos en tu instalación (un recuento entero).Lo que NO recopilamosURLs de páginas, nombres de host o historial de navegación.Prompts, instrucciones, descripciones de tareas o cualquier texto en lenguaje natural que envíes a tu proveedor de modelos.El DOM y el contenido de la página, capturas de pantalla, cargas de la API del sitio o respuestas de AI.Direcciones IP en texto plano. El servidor usa la IP de la solicitud de forma transitoria y en línea para exactamente dos fines —un hash con sal rotada a diario para la limitación de tasa y la derivación de una etiqueta aproximada de país/estado (ver más abajo)— y luego la descarta de inmediato. La IP en texto plano nunca se almacena ni se registra.Nombres, nombres de usuario, identificadores de cuenta o cualquier campo de identidad de forma libre.Direcciones de correo electrónico, números de teléfono o información de contacto.Métrica de región (a nivel de estado)El servidor deriva una etiqueta aproximada de país y estado de EE. UU. (subdivisión) a partir de la IP de tu solicitud en el momento de la ingesta, usando un conjunto de datos DB-IP IP-to-City Lite autoalojado y nuestra propia búsqueda: no un servicio de geolocalización de terceros en vivo, y nunca MaxMind. La IP en texto plano se procesa en línea y se descarta; solo se conserva la etiqueta derivada.La región se almacena solo en el agregado diario, tras un umbral de anonimato k≥5: cualquier estado con menos de 5 instalaciones distintas en un día se agrupa en un único cubo «Other» (suprimido por completo cuando incluso ese recuento combinado es inferior a 5). Ninguna etiqueta de estado individual representa jamás menos de 5 instalaciones.No hay perfil de ubicación por instalación. La etiqueta aproximada solo existe en el evento bruto de corta duración (eliminado por la retención de 7 días) y en el resumen diario filtrado con k≥5; nunca creamos ni conservamos una asignación duradera de tu instalación a un lugar. Datos de geolocalización por DB-IP (https://db-ip.com).RetenciónLos eventos en bruto se retienen durante 7 días. Los agregados diarios (una fila por instalación por día) se retienen durante 365 días. Los agregados globales (una fila por día, sin dimensión por instalación) se retienen indefinidamente para que los gráficos históricos en /stats se mantengan estables.Cómo darse de bajaAbre el Panel de control de FSB, desplázate a Ajustes avanzados y desactiva el interruptor Enviar datos de uso anónimos. El cambio tiene efecto inmediato; no se enviarán más eventos desde tu instalación.Cómo borrar tus datosPara solicitar la eliminación de todas las filas de telemetría asociadas a tu instalación (artículo 17 del GDPR), busca tu fsbInstallUuid en Chrome DevTools → Aplicación → Almacenamiento → Almacenamiento de extensiones y envía una única solicitud HTTP:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetAfirmación de Uso LimitadoLa telemetría anónima de uso de FSB se usa únicamente para calcular estadísticas de uso agregadas mostradas públicamente en full-selfbrowsing.com/stats. Los datos nunca se venden, nunca se comparten con terceros, nunca se usan para publicidad y nunca se usan para entrenar modelos de aprendizaje automático. Este compromiso satisface el requisito de Chrome Web Store de Limited Use.Métricas públicas agregadasPublicamos métricas agregadas derivadas de este pipeline de telemetría en /stats. Solo se muestran conteos y totales; nunca se expone ninguna fila por instalación.Controles de consentimiento y auditoríaLa postura de automatización de FSB permite la exclusión: los orígenes que no están en la lista de denegación heredan un valor global predeterminado configurable por el usuario, que actualmente se entrega como Auto, mientras que las políticas explícitas por origen pueden configurarlo como Off, Ask o Auto. La retención del registro de auditoría es local y limitada, con controles para exportarlo y borrarlo disponibles en el Panel de control.La lista de denegación de servicios sigue siendo un bloqueo estricto. Los orígenes denegados no se pueden habilitar, independientemente del valor global predeterminado o de cualquier política por origen almacenada.Los orígenes sensibles pueden realizar lecturas con Auto, pero las escrituras vuelven a exigir la autorización por origen para mutaciones antes de ejecutarse. Los orígenes no sensibles pueden excluirse o cambiarse a Ask desde la sección Consentimiento y auditoría del Panel de control.Cada llamada a una capacidad se registra en un registro de auditoría local redactado y de solo anexión. Nunca se almacenan argumentos, tokens, cookies ni cuerpos de respuesta.Código abiertoFSB es totalmente de código abierto bajo la licencia MIT. Puedes auditar cada línea de código para verificar estas afirmaciones sobre privacidad. El código fuente está disponible en GitHub.Cambios en esta políticaSi se actualiza esta política, los cambios se reflejarán por la fecha de "Última actualización" en la parte superior de esta página. Los cambios significativos también se anotarán en las notas de versión del proyecto en GitHub.ContactoSi tienes preguntas sobre esta política de privacidad o el tratamiento de datos de FSB, abre una incidencia en GitHub Issues. + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) Mayo – julio de 2026v0.9.90 — Capacidades de la API del sitio, Remote Dashboard y PhantomStream, Métodos de pago, Voz a texto, Métrica de región (texto archivado completo) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - Última actualización: agosto de 2026 + Last updated: September 2026 + Última actualización: septiembre de 2026 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69 introdujo una canalización de telemetría de uso anónima con opción de exclusión para que el proyecto pueda publicar cifras de adopción agregadas (consulta /stats) sin tocar nunca las páginas que navegas. La única señal de ubicación es una etiqueta aproximada de país/estado que el servidor deriva de la IP de tu solicitud en el momento de la ingesta (nunca del contenido de la página), conservada solo de forma agregada: consulta Métrica de región (a nivel de estado) más abajo. La telemetría está activada de forma predeterminada, pero puede desactivarse con un solo interruptor, y los datos por instalación pueden borrarse a petición. + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 introdujo una canalización de telemetría de uso anónima con opción de exclusión para que el proyecto pueda publicar cifras de adopción agregadas (consulta /stats) sin tocar nunca las páginas que navegas. La única señal de ubicación es una etiqueta aproximada de país/estado que el servidor deriva de la IP de tu solicitud en el momento de la ingesta (nunca del contenido de la página), publicada solo de forma agregada: consulta Métrica de región (a nivel de estado) más abajo. La telemetría está activada de forma predeterminada, pero puede desactivarse con un solo interruptor, y los datos por instalación pueden borrarse a petición. src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - Direcciones IP en texto plano. El servidor usa la IP de la solicitud de forma transitoria y en línea para exactamente dos fines —un hash con sal rotada a diario para la limitación de tasa y la derivación de una etiqueta aproximada de país/estado (ver más abajo)— y luego la descarta de inmediato. La IP en texto plano nunca se almacena ni se registra. + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + Direcciones IP en texto plano. El servidor usa la IP de la solicitud de forma transitoria y en línea para exactamente tres fines —un hash con sal rotada a diario para la limitación de tasa, la derivación de una etiqueta aproximada de país/estado (ver más abajo) y la anotación de si la dirección es IPv4 o IPv6— y luego la descarta de inmediato. La IP en texto plano nunca se almacena ni se registra. src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - El servidor deriva una etiqueta aproximada de país y estado de EE. UU. (subdivisión) a partir de la IP de tu solicitud en el momento de la ingesta, usando un conjunto de datos DB-IP IP-to-City Lite autoalojado y nuestra propia búsqueda: no un servicio de geolocalización de terceros en vivo, y nunca MaxMind. La IP en texto plano se procesa en línea y se descarta; solo se conserva la etiqueta derivada. + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + El servidor deriva una etiqueta aproximada de país y estado de EE. UU. (subdivisión) a partir de la IP de tu solicitud en el momento de la ingesta, usando un conjunto de datos DB-IP IP-to-City Lite autoalojado y nuestra propia búsqueda: no un servicio de geolocalización de terceros en vivo, y nunca MaxMind. La IP en texto plano se procesa en línea y se descarta; solo se conservan la etiqueta derivada y la familia de direcciones (IPv4 o IPv6). src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - La región se almacena solo en el agregado diario, tras un umbral de anonimato k≥5: cualquier estado con menos de 5 instalaciones distintas en un día se agrupa en un único cubo «Other» (suprimido por completo cuando incluso ese recuento combinado es inferior a 5). Ninguna etiqueta de estado individual representa jamás menos de 5 instalaciones. + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + La región se publica solo de forma agregada, tras un umbral de anonimato k≥5: cualquier estado con menos de 5 instalaciones distintas se agrupa en un único cubo «Other» (suprimido por completo cuando incluso ese recuento combinado es inferior a 5). Ninguna etiqueta de estado publicada representa jamás menos de 5 instalaciones. src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - No hay perfil de ubicación por instalación. La etiqueta aproximada solo existe en el evento bruto de corta duración (eliminado por la retención de 7 días) y en el resumen diario filtrado con k≥5; nunca creamos ni conservamos una asignación duradera de tu instalación a un lugar. Datos de geolocalización por DB-IP (https://db-ip.com). + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + La etiqueta aproximada se almacena en el evento bruto (eliminado por la retención de 7 días) y en el resumen diario de tu instalación, que se conserva durante 365 días para que /stats pueda contar cada instalación una sola vez según su región más reciente. Nunca es una dirección IP, una ciudad ni unas coordenadas; se elimina junto con el resto de los datos de tu instalación cuando solicitas el borrado; y solo se publica tras el umbral k≥5 descrito arriba. Datos de geolocalización por DB-IP (https://db-ip.com). src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - Los eventos en bruto se retienen durante 7 días. Los agregados diarios (una fila por instalación por día) se retienen durante 365 días. Los agregados globales (una fila por día, sin dimensión por instalación) se retienen indefinidamente para que los gráficos históricos en /stats se mantengan estables. + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + Los eventos en bruto se retienen durante 7 días. Los agregados diarios (una fila por instalación por día, incluida la etiqueta aproximada de región) se retienen durante 365 días. Los agregados globales (una fila por día, sin dimensión por instalación) se retienen indefinidamente para que los gráficos históricos en /stats se mantengan estables. src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - Distribución regional del agregado horario de hoy. + Where installs were last seen, by coarse region, over the past 365 days. + Dónde se vieron por última vez las instalaciones, por región aproximada, en los últimos 365 días. src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - Globo que muestra la distribución regional horaria de FSB de hoy + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + Globo que muestra dónde se vieron por última vez las instalaciones de FSB en los últimos 365 días, por región aproximada src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/locale/messages.ja.xlf b/showcase/angular/src/locale/messages.ja.xlf index 2729a41a4..05f3eeb2f 100644 --- a/showcase/angular/src/locale/messages.ja.xlf +++ b/showcase/angular/src/locale/messages.ja.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + 2026 年 8 月v0.9.91 — ローカルエージェントサービスとネイティブメッセージング、委任された CLI エージェント、Google Sheets、セッションリプレイとスクリーンショット(アーカイブ全文) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + 2026年9月の更新前、2026年8月時点のプライバシーポリシーのアーカイブです。要約: FSB はブラウザ内で動作し、FSB のサーバーが閲覧データを収集することはありません。AI 呼び出しはブラウザから選択したプロバイダーへ直接送信されます。API キーと認証情報はローカルで暗号化され、メモリーデータは端末内に留まります。任意のローカルエージェントサービスをインストールすると、FSB は自分のマシン上でループバック接続を介して動作する MCP クライアントや、すでにインストール済みのコーディングエージェント CLIs からも操作できます。FSB のためにマシンから送信される唯一のデータは、公開ページ /stats を支えるオプトアウト可能な匿名利用テレメトリだけです。Remote Dashboard をペアリングすると、一時的なライブプレビューのフレームがセッション中にリレーを経由することがありますが、保存されることはありません。すべてオープンソースで検証可能です。データ収集FSB はブラウザ内だけで動作します。自動化タスクを開始すると、拡張機能はアクティブなタブの DOM(Document Object Model)を調べる場合があります。また、ケイパビリティを呼び出すと、ブラウザセッションから同一オリジンのサイト API リクエストを実行する場合があります。現在のセッションを超えて閲覧履歴を収集・保存しませんDOM データとサイト API の結果はローカルで解析され、明示的にメモリへ保存しない限り、各自動化ステップ後に破棄されます訪問先ページから個人情報を抽出しませんサイト API 機能FSB のケイパビリティ層は、認証済みのブラウザセッションを使って、ページコンテキストからサイト自身のファーストパーティ API を呼び出せます。リクエストは Chrome 内でローカル実行され、対象サイトのファーストパーティ Cookie やサイト認証情報がブラウザによって付与される場合があります。ただし FSB は Cookie、トークン、CSRF 値、リクエスト本文、レスポンス本文を返却、保存、記録したり、FSB のサーバーへ送信したりしません。ケイパビリティ呼び出しは FSB の同意制御に従い、オリジン、ケイパビリティスラッグ、メソッド、副作用区分、同意判断、結果だけが秘匿化済みのローカル監査ログに記録されます。監査ログに呼び出し引数、リクエスト本文、レスポンス本文、Cookie、トークン、CSRF 値、サイトのレスポンス内容が保存されることはありません。Chrome がリクエストする FSB パーミッションウェブ自動化を実行するため、FSB は Chrome マニフェストで以下のパーミッションを宣言します。それぞれは記載された目的のためにのみ使用され、いずれを根拠としてもデータが端末外に送信されることはありません。DOM とタブ、activeTab、scripting、tabs、windows、sidePanel、ホスト権限 <all_urls>:アクティブなタブの読み書き、自動化コンテンツスクリプトの挿入、タブの一覧表示と切り替え、サイドパネルの描画高度な自動化、debugger:Chrome DevTools Protocol を接続し、通常の DOM API では実行できない座標指定クリック、ドラッグ、キー長押し操作を可能にします。webNavigation:ナビゲーションの開始・完了イベントを監視し、自動化が適切なタイミングまで待機ローカルストレージ、storage、unlimitedStorage:設定、認証情報、支払い方法、メモリをデバイス上の chrome.storage.local に保存。無制限ストレージにより既定の 10 MB 上限が解除され、メモリやセッションログを容量不足なしで増やせますUX ヘルパー、clipboardWrite:自動化結果をクリップボードへ書き込み。alarms:バックグラウンドの定期処理をスケジュール。offscreen:Service Worker は音声を直接取得できないため、非表示ドキュメントで音声テキスト変換レコーダーを実行ローカルサービス, nativeMessaging: 下記の ローカルエージェントサービスとネイティブメッセージング で説明する任意のローカルエージェントサービスを起動します。閲覧したページに関する情報がこのチャネルを通ることはありません。system.memory: 搭載されている総 RAM 容量のみを読み取り、FSB が同時に実行するエージェント数の妥当な上限を提案できるようにします。空きメモリーやプロセッサーごとの内訳が読み取られることはなく、この値が拡張機能の外に出ることもありません音声認識用のマイクアクセスはマニフェストで宣言されていません。マイクボタンを初めて使用したときに Chrome 自身が許可プロンプトを表示します。データ保存すべての設定とデータは Chrome の拡張機能ストレージにローカル保存され、機微な値は以下の各セクションで説明するとおり保存時に暗号化されます。設定は chrome.storage.local に保存されますAPI キー、認証情報、支払い方法は保存前に暗号化されます。詳細はそれぞれ下記の該当セクションに記載していますセッションログはローカル保存され、いつでも削除できます分析データ (タスク数、成功率) は端末上に残ります外部サービスFSB はホスト型プロバイダーを設定して利用する場合にのみ、外部 AI プロバイダーと通信します。LM Studio を使う場合、AI リクエストはローカルの OpenAI 互換サーバーを介して端末内にとどまります。プロバイダーの選択と送信するデータはユーザーの管理下にあります。ホスト API への呼び出しは、選択したプロバイダー (xAI、OpenAI、Anthropic、Google、または OpenRouter) にのみ送信されますLM Studio は端末上のローカル OpenAI 互換サーバーを使用し、API キーは不要です送信データ:タスクの説明、DOM 構造の要約、操作コンテキストRemote Dashboard をペアリングした場合、または従来の Background Agents 同期を使用する場合、オプションのリレーサーバーがそのセッションの WebSocket メッセージを処理します。ライブプレビューのフレームが一時的にリレーを経由することはありますが、以下のいずれも FSB のサーバーに保存されることはありません: ページ内容、DOM データ、閲覧履歴、スクリーンショット、AI プロンプト、AI 応答、Cookie、トークン、サイトの API ペイロード。これはオプトインのみで、本ポリシーの他の箇所はこの一覧を繰り返さずに参照します各プロバイダーは、API リクエストの取り扱いを定める独自のプライバシーポリシーを有しますローカルエージェントサービスとネイティブメッセージングFSB は自分のマシン上で動作する MCP クライアントから操作できます。そのためには自分でインストールする小さなローカルエージェントサービスが必要で、nativeMessaging 権限は拡張機能がそれを起動するためだけに存在します。Chrome はローカルプログラムを直接起動できないため、これが唯一のサポートされた仕組みです。メッセージングホスト io.github.fullselfbrowsing.fsb_native_host は、あなたが fsb-mcp-server install --native-host を実行するという明示的な操作によってのみ登録されます。拡張機能がインストールすることはできず、その登録には許可された拡張機能のオリジンが 1 つだけ記載されますこのやり取りは閉じたスキーマです。FSB はバージョン番号、wake または bootstrap のいずれかのアクション、およびローカルで生成した相関 ID を送信し、その ID と、固定リストから選ばれた結果と理由を受け取ります。追加のフィールドは即座に拒否され、メッセージは 4 KB に制限されます。このスキーマには URL、タブ、ページ内容、DOM データのいずれも存在しません起動に成功するとペアリングコードが返されます。これは端末上で生成され、所有者のみがアクセスできる権限で保存され、サービスが起動するたびに更新されるループバック認証シークレットです。あなた自身や閲覧内容に関する情報は一切含みませんこのサービスは自分のマシン上でのみ待ち受けます。拡張機能ブリッジはループバック以外のアドレスへのバインドを拒否し、MCP エンドポイントは既定で、また 127.0.0.1 が起動する場合は常に FSB にバインドしますこのサービスは自身のディレクトリに運用記録のみを保持します: 固定のフィールド一覧に限定された委任実行結果の診断ログと、プロセス監視ジャーナルです。タスクテキスト、環境変数の値、バイナリのパス、エラーテキストがどちらにも記録されることはなく、認証情報らしき値を含むエントリは書き込まれずに破棄されますホストがインストールされていない場合、この機能は単に起動しません。何も送信されず、拡張機能の他の部分はこれまでどおり動作します委任された CLI エージェントFSB は、すでにインストール済みのコーディングエージェントのコマンドラインツール(現在は Claude Code または Grok Build)にタスクを引き渡せます。FSB はそのプログラムを自分のマシン上で起動します。タスクが FSB のサーバーを経由することはありません。タスクのテキストは標準入力経由でのみツールに渡され、それ以外の経路はありません。FSB は実行のたびにこれを検証し、タスクがコマンドライン、作業ディレクトリ、環境変数、いずれかのファイルパスに現れた場合は、実行を開始せずに中止します。タスクの上限は 64 KB です実行中、ツールはループバック接続を介して FSB を呼び出し、ブラウザを操作します。その過程で読み取ったもの、すなわちページテキスト、DOM スナップショット、スプレッドシートの値、スクリーンショットはそのツールに返され、したがってその提供元に渡ります。対応は Anthropic が Claude Code、xAI が Grok Build実行にはそのツールで既にサインイン済みのアカウントが使われます。FSB があなたの Anthropic や xAI の認証情報を保持・読み取り・送信することはなく、利用量や料金はその提供元のプランに従いますGrok Build は、FSB があなた自身のものとは分離して管理するプロファイルディレクトリ内で実行されます。そこに保存されるサインイン認証情報は、Grok ツール自身がそのサインインフローの中で書き込みますFSB が提供するエージェント指示は、パスワード、CVV の値、支払いカード情報、保存済み認証情報がプロンプト、説明文、ログ、ツール引数に決して入ってはならないと定めていますGoogle Sheets の読み取りと入力FSB は、既に認証済みのブラウザセッション内でスプレッドシートの画面を操作することにより、Google Sheets の範囲を読み取ったり入力したりできます。範囲を読み取ると、それらのセルの値は、FSB があなたの代わりに読み取る他のページ内容とまったく同様に、選択したモデルへ送信されます。読み取られるのは指定した範囲のみで、スプレッドシート全体がエクスポートされることはありませんスプレッドシートの内容は、FSB のローカルセッション履歴に何かが書き込まれる前に取り除かれます。残るのは規模を示す件数(行数、列数、値の数)だけです。スプレッドシートのアドレス、シート名、セル参照、すべてのセルの値は破棄されます何らかの理由でこのフィルタリングをレコードに適用できない場合、そのレコードは保存されずに破棄されますRemote Dashboard と PhantomStream のライブプレビューRemote Dashboard とペアリングすると、FSB は PhantomStream を使ってアクティブなブラウザタブをライブプレビューできます。プレビューではピクセルではなく構造化された DOM データをストリーミングします。初期スナップショット、MutationObserver 差分、スクロール位置、自動化オーバーレイ、ダイアログ状態、メディア再生状態、WebSocket 経由のリモート操作メッセージが含まれます。リレーはこれらのライブプレビューのフレームをペアリング済みのダッシュボードセッションにのみ転送し、プレビューストリームの内容が FSB のサーバーに保存されることはありません。上記の 外部サービスの一覧 を参照してくださいFSB は PhantomStream の入力マスキング(maskInputs: true)を有効にするため、パスワードとフォームコントロールの値はキャプチャしたページを離れる前にマスクされますダッシュボードのビューアーはスクリプトを実行できないサンドボックス内でミラー内容を描画し、表示前にミラーされた DOM と CSS をサニタイズします現在のダッシュボードモードでは、画像、動画、音声を参照としてミラーします。メディアのバイト列はリレーを通過しません。ビューアーは許可された公開 HTTPS アセットまたはメディア URL を直接取得できますが、プライベート、内部、非 HTTPS、その他ブロック対象のオリジンは、PhantomStream のフェイルクローズ取得ポリシーによってプレースホルダーに置き換えられますサードパーティトラッキングなしFSB はサードパーティのアナリティクス、広告トラッカー、クロスサイトフィンガープリンティングを一切含みません。Cookie もなく、明示的に設定した AI プロバイダーの APIs 以外のサードパーティスクリプトもありません。FSB が送信するファーストパーティデータは、以下に説明するオプトアウト式の匿名利用テレメトリのみであり、これは公開 /stats ダッシュボードの提供のみに使用されます。API キーAPI キーは保存前にローカルで AES-GCM で暗号化されます。設定した AI プロバイダー以外には送信されず、送信時も API リクエストの認証ヘッダーとしてのみ使われます。キーは Chrome ストレージ上で暗号化された状態で保管されます復号は API 呼び出し時にメモリ内でのみ行われますキーは記録、エクスポート、共有のいずれもされません自動パスワード入力FSB はログイン情報を端末上で暗号化保存するオプションの認証情報マネージャーを含みます。パスワードは AI モデルに渡されることはなく、AI を介さずに Content Script が直接ページに入力します。認証情報は 256 ビット鍵と AES-GCM 鍵導出による PBKDF2 で保存時に暗号化されますAI がページを解析する際、パスワードフィールドの値は [hidden] に置き換えられます。実際のパスワードが AI プロンプトに含まれることはありません自動入力はコンテンツスクリプトが値を直接 DOM へ挿入して行い、認証情報の処理に AI は一切関与しません認証情報の一覧表示にはユーザー名とドメインのみが表示されます。パスワードは自動入力に必要なときにのみ個別に復号されます認証情報はドメイン単位で保存され、親ドメインへのフォールバックを行います (例: accounts.google.com は google.com を継承)決済方法FSB には、決済時の自動入力用にカード情報をお使いの端末に保存するオプションの決済方法ボールトが含まれています。カードはログイン認証情報と同じ暗号化と AI 隔離で扱われ、完全なカード番号は決してどの AI モデルにも送信されません。カード情報(番号、有効期限、カード名義人、郵便番号)は、認証情報と同じボールト由来のキーを使用して AES-GCM で保管時に暗号化されますAI が決済ページを解析する際、検出されたカード番号フィールドの値はプロンプトの組み立て前に [hidden] に置き換えられます。カード番号、CVV、有効期限はいかなる AI プロンプトにも含まれません自動入力はコンテンツスクリプトがページの DOM フィールドに直接書き込むことで行われ、AI を完全に経由しませんリスト表示ではカードのニックネームと下4桁のみが表示されます。完全な番号は入力の瞬間のみ、メモリー内でのみ復号されますMCP クライアントは use_payment_method 経由で決済の自動入力をリクエストできますが、カード情報がページに書き込まれる前に、拡張機能内で確認プロンプトがユーザーに表示されますカードごとに明示的にオプトインしない限り、CVV は決して保存されません。保存される場合でも、他のレコードと一緒に暗号化されます音声認識(Speech-to-Text)FSB にはプロンプト入力欄のオプションのマイク入力が含まれています。既定のプロバイダーはブラウザ内で完全に動作します。より高い精度が必要な場合は、設定でオプションの OpenAI Whisper フォールバックを有効にできます。既定のプロバイダー:ブラウザ標準の SpeechRecognition API。音声は Chrome で処理され、FSB を通じて端末外へ送信されることはありませんオプションの Whisper プロバイダー: sttProvider が whisper に設定されており、OpenAI キーが設定されている場合、録音された音声チャンクはお使いのブラウザから直接 OpenAI の文字起こしエンドポイントにアップロードされます。FSB がその音声を見たり保存したりすることはありませんマイクはマイクボタンを押し続けている、または切り替えている間だけ作動します。初回使用時に Chrome が許可を求めます。FSB は拡張機能マニフェストでマイクアクセスをリクエストしません文字起こしはプロンプトのテキストエリアにのみ挿入され、お客様が送信する有効な AI リクエスト以外に記録、保存、または送信されることは決してありませんマイクボタンを触らないか、Chrome の拡張機能ストレージからオプションの Whisper プロバイダーをクリアすることで、音声機能を完全に無効化できますプロンプトインジェクション対策Web ページには AI エージェントを乗っ取るための隠しテキストが含まれることがあります。FSB は多層防御を実装し、AI が指示するのは常にユーザーの指示のみで、ページコンテンツに埋め込まれた指示には従わないようにします。すべてのページコンテンツは [PAGE_CONTENT] 境界マーカーで囲まれ、AI はその内側にある指示には絶対に従わないよう指示されますサニタイズエンジンが既知のインジェクションパターン(例:「以前の指示を無視」、偽のシステムプロンプト、上書き試行)を、AI に渡る前にページ内容から取り除きますAI が生成したアクションは実行前に検証されます。危険な URL (javascript:、data:) やスクリプト挿入の試みはブロックされます実行できるのは、厳格に固定された許可リスト内の既知ツールだけです。AI が任意の操作を作成したり呼び出したりすることはできませんコンテンツサイズには上限があり (値あたり 500 文字、プロンプト全体 15K)、ペイロードの送り込みを制限しますWeb サイトが埋め込む不可視の Unicode 制御文字は処理前に取り除かれますバックグラウンドエージェントとサーバー同期v0.9.45rc1 で非推奨。 FSB の組み込みバックグラウンドエージェントは OpenClaw と Claude Routines に置き換えられ、リモート操作は現在 Sync タブが担っています。以下の開示は v0.9.44 以前を使用するユーザー向けに残しています。現在のビルドでリレーサーバーへ接続するのは、Sync セッションをペアリングした場合だけです。従来のバックグラウンドエージェントのサーバー同期をオプトインで使用するか、Remote Dashboard とペアリングすると、リレーサーバーが拡張機能とダッシュボード間の通信を仲介します。サーバーが保存するのは、エージェント定義 (名前、スケジュール、対象 URL)、実行メトリクス (トークン数、コスト、所要時間、成功/失敗ステータス)、セッションペアリングトークンですその実行メタデータ以外に、閲覧したページに由来するものをサーバーが保存することはありません。上記の 外部サービスの一覧 を参照してください認証にはローカル生成のハッシュ鍵と、24 時間で失効するセッショントークンを使用しますワンタイムペアリングトークンは 60 秒で失効し、再利用できませんサーバー同期はデフォルトで無効です。オプションから明示的に有効化する必要がありますメモリーシステムFSB のメモリーシステムは、自動化を時とともに改善するためにナビゲーションパターンとサイトインテリジェンスを蓄積します。すべてのメモリーデータ (意味、エピソード、手続き) は chrome.storage.local にローカル保存されますメモリーデータが外部サーバーに送信されることはありませんメモリーはオプションダッシュボードからいつでも参照・削除できますサイトマップとナビゲーションパターンはドメイン単位で、互いに分離されますセッションリプレイとスクリーンショットMCP クライアントが FSB を操作すると、拡張機能はエージェントの動作を記録し、後から実行内容を確認したり再生したりできるようにします。これらの記録は端末内に留まります。進行中の実行は Chrome のセッションストレージに保持され、Service Worker が破棄されても失われません。完了した実行は chrome.storage.local を通じて、自分の自動化実行と同じ履歴ストアに書き込まれます記録は保存前に秘匿処理されます。認証情報らしきキーの下にある値、パスワード・ワンタイムコード・カード入力とみられるフィールドに入力されたテキスト、署名付きやトークンを含む URL パラメーターはすべて置き換えられます。通常のアドレスやセレクターは、それがないとリプレイが成立しないため保持されます記録された実行は既定で 30 日間保持され、1 日から 365 日の範囲で調整でき、古いものは日次ジョブによって削除されます。記録は詳細設定で完全に無効化できますスクリーンショットの画像がこの履歴に書き込まれることはありません。保持されるのは寸法やバイトサイズといったキャプチャのメタデータだけですMCP クライアントが要求したスクリーンショットは、ローカルサービスが所有者のみアクセスできる権限で自分のディスク上にファイルとして保存し、7 日後に自動削除します。画像は要求元のクライアントにも返されるため、そのクライアントのモデルにも渡ります匿名利用テレメトリーFSB v0.9.69 では、プロジェクトが集計された導入数を公開できるよう、オプトアウト可能な匿名利用テレメトリパイプラインを導入しました(/stats を参照)。閲覧中のページに触れることは一切ありません。唯一の位置情報シグナルは、サーバーが取り込み時にリクエストの IP から導出する大まかな国/州ラベルであり(ページ内容からではありません)、集計形式でのみ保持されます。詳しくは下記の 地域(州レベル)指標 を参照してください。テレメトリは既定で有効ですが、1 つのトグルで無効化でき、インストールごとのデータはリクエストにより消去できます。収集する情報インストールごとにランダムな UUID を生成し、chrome.storage.local のキー fsbInstallUuid に保存します。UUID はローカルで生成され、あなたの身元には決して紐付けられません。使用された MCP クライアントの名前 (例: Claude Code、Cursor、Codex)。固定の許可リストから取得します。セッションで使用されたモデル名 (例: grok-4-fast、claude-opus-4)。固定の許可リストから取得します。セッションごとの入出力トークン数の集計値。お使いのインストールでアクティブな FSB エージェントの数 (整数値)。収集しない情報ページの URLs、ホスト名、または閲覧履歴。プロンプト、指示、タスクの説明、またはモデルプロバイダーに送信する自然言語テキスト。ページの DOM、スクリーンショット、ページ内容、サイト API ペイロード、AI レスポンス。平文の IP アドレス。サーバーはリクエストの IP を、ちょうど 2 つの目的(レート制限のための日次ローテーションソルトによるハッシュと、大まかな国/州ラベルの導出(下記参照))のために一時的かつインラインで使用し、その後直ちに破棄します。平文の IP が保存またはログ記録されることは決してありません。氏名、ユーザー名、アカウントハンドル、または自由記述のあらゆる身元フィールド。メールアドレス、電話番号、または連絡先情報。地域(州レベル)指標サーバーは取り込み時に、自己ホストの IP DB-IP-to-City Lite データセットと独自のルックアップを用いて、リクエストの IP から大まかな国および米国の州(サブディビジョン)ラベルを導出します。これはライブのサードパーティ地理位置情報サービスではなく、MaxMind でもありません。平文の IP はインラインで処理されて破棄され、導出されたラベルのみが保持されます。地域は日次集計の中にのみ、k≥5 の匿名性しきい値の背後で保存されます。ある日に固有インストール数が 5 未満の州はすべて単一の「Other」バケットにまとめられます(その合計数自体が 5 未満の場合は完全に抑制されます)。個々の州ラベルが 5 未満のインストールを表すことは決してありません。インストールごとの位置プロファイルは存在しません。大まかなラベルは、短命な生イベント(7 日間の保持期間で削除)と k≥5 でフィルタされた日次ロールアップの中にのみ存在します。インストールから場所への永続的な対応付けを作成または保持することは一切ありません。地理位置情報データは DB-IP(https://db-ip.com)によります。保持期間生イベントは 7 日間保持されます。日次ロールアップ (インストールごと、日ごとに 1 行) は 365 日間保持されます。グローバル集計 (日ごとに 1 行、インストール次元なし) は /stats の履歴チャートが安定するよう無期限に保持されます。オプトアウトの方法「FSB コントロールパネル」を開き、「詳細設定」までスクロールして、匿名利用データを送信 をオフにしてください。変更は直ちに反映され、それ以降このインストール環境からイベントは送信されません。データを消去する方法インストールに関連するすべてのテレメトリ行の消去を依頼するには(GDPR 第 17 条)、fsbInstallUuid を Chrome DevTools → アプリケーション → ストレージ → 拡張機能ストレージ で確認し、次の HTTP リクエストを 1 回送信します:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use への準拠表明FSB の匿名利用テレメトリーは、full-selfbrowsing.com/stats で公開される集計利用統計の算出にのみ使用されます。データは決して販売されず、第三者と共有されず、広告のために使用されず、機械学習モデルの学習にも使用されません。この方針は Chrome Web Store の Limited Use 要件を満たします。集計された公開メトリクスこのテレメトリーパイプラインから導出された集計メトリクスを /stats で公開しています。表示されるのは件数と合計のみで、インストールごとの行は決して公開されません。同意と監査の制御FSB の自動化方針はオプトアウト式です。拒否リスト外のオリジンは、現在「自動」で提供されるユーザー設定可能な全体既定値を継承し、オリジンごとの明示的なポリシーでは「オフ」「確認」「自動」を設定できます。監査ログはローカルに期限付きで保持され、コントロールパネルからエクスポートと消去を行えます。サービス拒否リストは引き続き強制ブロックです。拒否対象のオリジンは、全体既定値や保存済みのオリジン別ポリシーに関係なく有効化できません。機密性の高いオリジンでは「自動」で読み取りを実行できますが、書き込み前にはオリジン別の変更許可を再確認します。機密性の低いオリジンはオプトアウトするか、コントロールパネルの「同意と監査」セクションで「確認」に変更できます。すべてのケイパビリティ呼び出しは、墨消しされた追記専用のローカル監査ログに記録されます。引数、トークン、Cookie、レスポンスボディが保存されることは決してありません。オープンソースFSB は MIT ライセンスの下で完全にオープンソースです。プライバシーに関する主張はコードを 1 行ずつ監査して確認できます。ソースコードは GitHub で公開されています。本ポリシーの変更本ポリシーが更新された場合、ページ上部の「最終更新」日に反映されます。重大な変更は、プロジェクトの GitHub リリースノートにも記載されます。お問い合わせこのプライバシーポリシーや FSB のデータ取り扱いについて質問がある場合は、GitHub Issues で課題を作成してください。 + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) 2026 年 5 月 – 7 月v0.9.90 — サイト API 機能、Remote Dashboard と PhantomStream、支払い方法、音声入力、地域指標(アーカイブ全文) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - 最終更新: 2026 年 8 月 + Last updated: September 2026 + 最終更新: 2026 年 9 月 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69 では、プロジェクトが集計された導入数を公開できるよう、オプトアウト可能な匿名利用テレメトリパイプラインを導入しました(/stats を参照)。閲覧中のページに触れることは一切ありません。唯一の位置情報シグナルは、サーバーが取り込み時にリクエストの IP から導出する大まかな国/州ラベルであり(ページ内容からではありません)、集計形式でのみ保持されます。詳しくは下記の 地域(州レベル)指標 を参照してください。テレメトリは既定で有効ですが、1 つのトグルで無効化でき、インストールごとのデータはリクエストにより消去できます。 + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 では、プロジェクトが集計された導入数を公開できるよう、オプトアウト可能な匿名利用テレメトリパイプラインを導入しました(/stats を参照)。閲覧中のページに触れることは一切ありません。唯一の位置情報シグナルは、サーバーが取り込み時にリクエストの IP から導出する大まかな国/州ラベルであり(ページ内容からではありません)、集計形式でのみ公開されます。詳しくは下記の 地域(州レベル)指標 を参照してください。テレメトリは既定で有効ですが、1 つのトグルで無効化でき、インストールごとのデータはリクエストにより消去できます。 src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - 平文の IP アドレス。サーバーはリクエストの IP を、ちょうど 2 つの目的(レート制限のための日次ローテーションソルトによるハッシュと、大まかな国/州ラベルの導出(下記参照))のために一時的かつインラインで使用し、その後直ちに破棄します。平文の IP が保存またはログ記録されることは決してありません。 + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + 平文の IP アドレス。サーバーはリクエストの IP を、ちょうど 3 つの目的(レート制限のための日次ローテーションソルトによるハッシュ、大まかな国/州ラベルの導出(下記参照)、およびアドレスが IPv4 と IPv6 のどちらであるかの記録)のために一時的かつインラインで使用し、その後直ちに破棄します。平文の IP が保存またはログ記録されることは決してありません。 src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - サーバーは取り込み時に、自己ホストの IP DB-IP-to-City Lite データセットと独自のルックアップを用いて、リクエストの IP から大まかな国および米国の州(サブディビジョン)ラベルを導出します。これはライブのサードパーティ地理位置情報サービスではなく、MaxMind でもありません。平文の IP はインラインで処理されて破棄され、導出されたラベルのみが保持されます。 + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + サーバーは取り込み時に、自己ホストの IP DB-IP-to-City Lite データセットと独自のルックアップを用いて、リクエストの IP から大まかな国および米国の州(サブディビジョン)ラベルを導出します。これはライブのサードパーティ地理位置情報サービスではなく、MaxMind でもありません。平文の IP はインラインで処理されて破棄され、導出されたラベルとアドレスファミリー(IPv4 または IPv6)のみが保持されます。 src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - 地域は日次集計の中にのみ、k≥5 の匿名性しきい値の背後で保存されます。ある日に固有インストール数が 5 未満の州はすべて単一の「Other」バケットにまとめられます(その合計数自体が 5 未満の場合は完全に抑制されます)。個々の州ラベルが 5 未満のインストールを表すことは決してありません。 + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + 地域は集計形式でのみ、k≥5 の匿名性しきい値の背後で公開されます。固有インストール数が 5 未満の州はすべて単一の「Other」バケットにまとめられます(その合計数自体が 5 未満の場合は完全に抑制されます)。公開される州ラベルが 5 未満のインストールを表すことは決してありません。 src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - インストールごとの位置プロファイルは存在しません。大まかなラベルは、短命な生イベント(7 日間の保持期間で削除)と k≥5 でフィルタされた日次ロールアップの中にのみ存在します。インストールから場所への永続的な対応付けを作成または保持することは一切ありません。地理位置情報データは DB-IP(https://db-ip.com)によります。 + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + 大まかなラベルは、生イベント(7 日間の保持期間で削除)と、インストールの日次ロールアップに保存されます。日次ロールアップは、/stats が各インストールを最新の地域で 1 回だけ数えられるよう 365 日間保持されます。このラベルが IP アドレス、都市、座標であることはありません。消去をリクエストすると、インストールごとの他のデータとともに削除され、上記の k≥5 しきい値の背後でのみ公開されます。地理位置情報データは DB-IP(https://db-ip.com)によります。 src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - 生イベントは 7 日間保持されます。日次ロールアップ (インストールごと、日ごとに 1 行) は 365 日間保持されます。グローバル集計 (日ごとに 1 行、インストール次元なし) は /stats の履歴チャートが安定するよう無期限に保持されます。 + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + 生イベントは 7 日間保持されます。日次ロールアップ (インストールごと、日ごとに 1 行。大まかな地域ラベルを含む) は 365 日間保持されます。グローバル集計 (日ごとに 1 行、インストール次元なし) は /stats の履歴チャートが安定するよう無期限に保持されます。 src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - 本日の時間別集計による地域分布です。 + Where installs were last seen, by coarse region, over the past 365 days. + 過去 365 日間にインストールが最後に確認された場所を、大まかな地域別に示します。 src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - 本日の時間別FSB地域分布を示す地球儀 + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + 過去 365 日間に FSB のインストールが最後に確認された場所を大まかな地域別に示す地球儀 src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/locale/messages.ko.xlf b/showcase/angular/src/locale/messages.ko.xlf index 85dacbb51..b19d09b62 100644 --- a/showcase/angular/src/locale/messages.ko.xlf +++ b/showcase/angular/src/locale/messages.ko.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + 2026년 8월v0.9.91 — 로컬 에이전트 서비스와 네이티브 메시징, 위임된 CLI 에이전트, Google Sheets, 세션 리플레이와 스크린샷 (아카이브 전문) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + 2026년 9월 업데이트 이전인 2026년 8월 시점의 개인정보처리방침 아카이브 사본입니다.요약: FSB는 브라우저 안에서 실행되며, FSB 서버는 어떠한 브라우징 데이터도 수집하지 않습니다. AI 호출은 브라우저에서 선택한 제공업체로 직접 전송됩니다. API 키와 자격 증명은 로컬에서 암호화되고 메모리 데이터는 기기에 남습니다. 선택 사항인 로컬 에이전트 서비스를 설치하면 FSB는 사용자의 컴퓨터에서 루프백 연결로 실행되는 MCP 클라이언트, 그리고 이미 설치해 둔 코딩 에이전트 CLIs로도 제어할 수 있습니다. FSB를 위해 컴퓨터를 떠나는 유일한 데이터는 공개 페이지 /stats를 뒷받침하는, 수신 거부 가능한 익명 사용 통계뿐입니다. Remote Dashboard를 페어링하면 세션 중 일시적인 실시간 미리 보기 프레임이 릴레이를 거칠 수 있으나 저장되지는 않습니다. 모든 것이 오픈 소스이며 감사할 수 있습니다.데이터 수집FSB는 전적으로 브라우저 안에서 동작합니다. 자동화 작업을 시작하면 확장 프로그램이 활성 탭의 DOM(문서 객체 모델)을 검사할 수 있으며, 기능을 호출할 때는 브라우저 세션에서 동일 출처 사이트 API 요청을 보낼 수 있습니다.현재 세션을 넘어서는 브라우징 기록은 수집하거나 저장하지 않습니다DOM 데이터와 사이트 API 결과는 로컬에서 분석되며, 메모리에 명시적으로 저장하지 않는 한 각 자동화 단계 후 폐기됩니다방문한 페이지에서 개인 정보를 수집하지 않습니다사이트 API 기능FSB의 기능 계층은 이미 인증된 브라우저 세션을 사용하여 페이지 컨텍스트에서 사이트 자체의 1자 API를 호출할 수 있습니다. 이러한 요청은 Chrome에서 로컬로 실행됩니다. 대상 사이트에 대해 브라우저가 1자 쿠키나 사이트 인증을 첨부할 수 있으나, FSB는 쿠키, 토큰, CSRF 값, 요청 본문, 응답 본문을 FSB 서버로 반환하거나 저장하거나 기록하거나 전송하지 않습니다.기능 호출은 FSB의 동의 제어를 따르며, 편집된 로컬 감사 로그에만 기록됩니다. 기록 항목은 출처, 기능 슬러그, 메서드, 부수 효과 등급, 동의 결정, 결과입니다. 감사 로그는 호출 인수, 요청 본문, 응답 본문, 쿠키, 토큰, CSRF 값, 사이트 응답 페이로드를 결코 저장하지 않습니다.Chrome 권한 요청 항목: FSB웹 자동화를 실행하기 위해 FSB는 다음 권한을 Chrome 매니페스트에 선언합니다. 각 권한은 문서화된 목적으로만 사용되며, 어떤 권한을 근거로도 기기 밖으로 데이터를 보내지 않습니다.DOM 및 탭, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: 활성 탭을 읽고 쓰며, 자동화 콘텐츠 스크립트를 삽입하고, 탭을 나열·전환하며, 사이드 패널을 렌더링합니다고급 자동화, debugger: 일반 Chrome DevTools Protocol 을 연결하여 좌표 기반 클릭, 드래그, 키 홀드 동작을 수행합니다. 이는 일반 DOM API로는 불가능합니다. webNavigation: 탐색 시작/종료 이벤트를 관찰하여 자동화가 적절한 시점을 기다리게 합니다로컬 저장소, storage, unlimitedStorage: 설정, 자격 증명, 결제 수단, 메모리를 기기의 chrome.storage.local에 저장합니다. 무제한 저장소는 기본 10 MB 할당량을 해제하여 메모리와 세션 로그가 한계에 부딪히지 않고 늘어날 수 있게 합니다UX 보조 기능, clipboardWrite: 자동화의 클립보드 복사 결과를 씁니다. alarms: 백그라운드 정리 작업을 예약합니다. offscreen: 서비스 워커가 오디오를 직접 캡처할 수 없으므로 음성 입력 레코더를 숨겨진 문서에서 실행합니다로컬 서비스, nativeMessaging: 아래 로컬 에이전트 서비스와 네이티브 메시징에서 설명하는 선택적 로컬 에이전트 서비스를 시작합니다. 방문한 페이지에 관한 정보는 이 채널을 통과하지 않습니다. system.memory: 설치된 총 RAM 용량만 읽어 FSB가 동시에 실행할 에이전트 수의 적절한 상한을 제안할 수 있게 합니다. 여유 메모리나 프로세서별 내역은 결코 읽지 않으며, 이 값이 확장 프로그램 밖으로 나가지도 않습니다음성 입력을 위한 마이크 접근 권한은 매니페스트에 선언되어 있지 않습니다. Chrome가 마이크 버튼을 처음 사용할 때 자체 권한 요청을 표시합니다.데이터 저장모든 설정과 데이터는 Chrome의 확장 프로그램 저장소에 로컬로 저장되며, 민감한 값은 아래 각 섹션에서 설명하는 대로 저장 시 암호화됩니다.구성은 다음 위치에 저장됩니다: chrome.storage.localAPI 키, 자격 증명, 결제 수단은 저장 전에 암호화되며, 각각의 세부 사항은 아래 해당 섹션에 있습니다세션 로그는 로컬에 저장되며 언제든지 삭제할 수 있습니다분석 데이터(작업 수, 성공률)는 기기에 남습니다외부 서비스FSB는 호스팅형 제공업체를 구성하고 사용할 때만 외부 AI 제공업체와 통신합니다. LM Studio를 사용하면 AI 요청은 로컬 OpenAI 호환 서버를 통해 기기 안에 머무릅니다. 제공업체 선택과 전송되는 데이터는 사용자가 통제합니다.호스팅형 API 호출은 선택한 제공업체(xAI, OpenAI, Anthropic, Google, OpenRouter)로만 이루어집니다LM Studio는 기기의 로컬 OpenAI 호환 서버를 사용하며 API 키가 필요하지 않습니다전송되는 데이터: 작업 설명, DOM 구조 요약, 동작 컨텍스트Remote Dashboard를 페어링하거나 기존 백그라운드 에이전트 동기화를 사용하면 선택적 릴레이 서버가 해당 세션의 WebSocket 메시지를 처리합니다. 실시간 미리 보기 프레임이 릴레이를 일시적으로 거칠 수 있으나, 다음 중 어느 것도 FSB 서버에 저장되지 않습니다: 페이지 콘텐츠, DOM 데이터, 브라우징 기록, 스크린샷, AI 프롬프트, AI 응답, 쿠키, 토큰, 사이트 API 페이로드. 이 기능은 수신 동의 방식이며, 본 방침의 나머지 부분은 이 목록을 반복하지 않고 참조합니다각 제공업체는 API 요청 처리 방식을 규율하는 자체 개인정보처리방침을 가지고 있습니다로컬 에이전트 서비스와 네이티브 메시징FSB는 사용자의 컴퓨터에서 실행되는 MCP 클라이언트로 제어할 수 있습니다. 이를 위해서는 사용자가 직접 설치하는 작은 로컬 에이전트 서비스가 필요하며, nativeMessaging 권한은 오직 확장 프로그램이 이를 시작할 수 있도록 하기 위해 존재합니다. Chrome는 로컬 프로그램을 직접 실행할 수 없으므로 이것이 유일하게 지원되는 방식입니다.메시징 호스트 io.github.fullselfbrowsing.fsb_native_host는 사용자가 fsb-mcp-server install --native-host를 실행하는 명시적 조치를 통해서만 등록됩니다. 확장 프로그램은 이를 설치할 수 없으며, 등록 항목에는 허용된 확장 프로그램 출처가 하나만 지정됩니다이 교환은 닫힌 스키마입니다. FSB는 버전 번호, wake 또는 bootstrap 중 하나의 동작, 그리고 로컬에서 생성한 상관 식별자를 전송하고, 그 식별자와 함께 고정된 목록에서 선택된 결과 및 사유를 돌려받습니다. 추가 필드는 즉시 거부되며 메시지는 4 KB로 제한됩니다. 이 스키마에는 URL, 탭, 페이지 콘텐츠, DOM 데이터가 전혀 존재하지 않습니다시작에 성공하면 페어링 코드가 반환됩니다. 이는 기기에서 생성되어 소유자만 접근할 수 있는 권한으로 저장되며 서비스가 시작될 때마다 교체되는 루프백 인증 비밀입니다. 사용자나 브라우징에 관한 정보는 담고 있지 않습니다이 서비스는 사용자의 컴퓨터에서만 수신 대기합니다. 확장 프로그램 브리지는 루프백이 아닌 주소로의 바인딩을 거부하며, MCP 엔드포인트는 기본적으로, 그리고 127.0.0.1가 시작하는 경우에는 항상 FSB에 바인딩합니다이 서비스는 자체 디렉터리에 운영 기록만 보관합니다. 고정된 필드 목록으로 제한된 위임 실행 결과 진단 로그와 프로세스 감독 저널입니다. 작업 텍스트, 환경 변수 값, 바이너리 경로, 오류 텍스트는 둘 중 어느 곳에도 기록되지 않으며, 자격 증명 형태의 값을 담은 항목은 기록되지 않고 폐기됩니다호스트가 설치되어 있지 않으면 이 기능은 단순히 시작되지 않습니다. 아무것도 전송되지 않으며 확장 프로그램의 나머지 기능은 정상적으로 동작합니다위임된 CLI 에이전트FSB는 이미 설치해 둔 코딩 에이전트 명령줄 도구(현재 Claude Code 또는 Grok Build)에 작업을 넘길 수 있습니다. FSB는 해당 프로그램을 사용자의 컴퓨터에서 실행합니다. 작업 내용이 FSB 서버를 거쳐 전달되는 일은 없습니다.작업 텍스트는 도구의 표준 입력으로만 전달되며 다른 어떤 경로로도 전달되지 않습니다. FSB는 실행할 때마다 이를 확인합니다. 작업 내용이 명령줄, 작업 디렉터리, 환경 변수, 파일 경로 중 어디에라도 나타나면 실행을 시작하지 않고 중단합니다. 작업 크기는 64 KB로 제한됩니다실행 중에 이 도구는 루프백 연결을 통해 FSB를 다시 호출하여 브라우저를 제어합니다. 그 과정에서 읽은 것, 즉 페이지 텍스트, DOM 스냅숏, 스프레드시트 값, 스크린샷은 해당 도구로 반환되며 따라서 그 공급업체에 전달됩니다. 대응은 Anthropic가 Claude Code, xAI가 Grok Build실행에는 해당 도구에 이미 로그인된 계정이 사용됩니다. FSB는 사용자의 Anthropic 또는 xAI 자격 증명을 보관하거나 읽거나 전송하지 않으며, 사용량과 요금은 해당 공급업체의 요금제를 따릅니다Grok Build는 FSB가 사용자 소유와 분리해 관리하는 프로필 디렉터리 안에서 실행됩니다. 그곳에 저장되는 로그인 자격 증명은 Grok 도구가 자체 로그인 절차 중에 직접 기록합니다FSB가 제공하는 에이전트 지침은 비밀번호, CVV 값, 결제 카드 정보, 저장된 자격 증명이 프롬프트, 설명, 로그, 도구 인수에 절대 들어가서는 안 된다고 명시합니다Google Sheets 읽기와 입력FSB는 이미 인증된 브라우저 세션에서 스프레드시트 화면을 조작하여 Google Sheets의 범위를 읽고 입력할 수 있습니다.범위를 읽으면 해당 셀 값이, FSB가 사용자를 대신해 읽는 다른 페이지 콘텐츠와 똑같이 선택한 모델로 전송됩니다. 요청한 범위만 읽으며 스프레드시트 전체를 내보내지 않습니다스프레드시트 내용은 FSB의 로컬 세션 기록에 무언가가 기록되기 전에 제거됩니다. 남는 것은 규모를 나타내는 개수(행, 열, 값의 수)뿐입니다. 스프레드시트 주소, 시트 이름, 셀 참조, 모든 셀 값은 폐기됩니다어떤 이유로든 이 필터링을 레코드에 적용할 수 없으면 해당 레코드는 저장되지 않고 폐기됩니다Remote Dashboard 및 PhantomStream 실시간 미리 보기Remote Dashboard를 페어링하면 FSB는 PhantomStream을 사용하여 활성 브라우저 탭의 실시간 미리 보기를 표시할 수 있습니다. 미리 보기는 픽셀 대신 구조화된 DOM 데이터를 전송합니다. 최초 스냅숏, MutationObserver 차이, 스크롤 위치, 자동화 오버레이, 대화 상자 상태, 미디어 재생 상태, 원격 제어 메시지가 WebSocket을 통해 전달됩니다.릴레이는 이러한 실시간 미리 보기 프레임을 페어링된 대시보드 세션에만 전달하며, 미리 보기 스트림의 어떤 내용도 FSB 서버에 저장되지 않습니다. 위의 외부 서비스 목록을 참조하십시오FSB는 PhantomStream 입력 마스킹(maskInputs: true)을 활성화하므로 비밀번호와 폼 컨트롤 값은 캡처된 페이지를 떠나기 전에 가려집니다대시보드 뷰어는 미러링된 콘텐츠를 스크립트가 없는 샌드박스에서 렌더링하며, 표시 전에 미러링된 DOM과 CSS를 정화합니다현재 대시보드 모드에서 이미지, 동영상, 오디오는 참조로 미러링됩니다. 미디어 바이트는 릴레이를 거치지 않으며, 뷰어가 허용된 공개 HTTPS 자산이나 미디어 URL을 직접 가져올 수 있습니다. 반면 비공개, 내부, 비 HTTPS, 그 밖에 차단된 출처는 PhantomStream의 실패 시 차단 정책에 따라 자리 표시자로 대체됩니다제3자 추적 없음FSB는 어떠한 제3자 분석 도구, 광고 추적기, 교차 사이트 핑거프린팅도 포함하지 않습니다. 쿠키가 없으며, 사용자가 직접 구성한 AI 제공업체 APIs 외에는 제3자 스크립트도 없습니다. FSB가 본사로 보내는 유일한 1자 데이터는 아래에 설명한 수신 거부 가능한 익명 사용 통계이며, 오직 공개 /stats 대시보드를 뒷받침하는 데에만 사용됩니다.API 키사용자의 API 키는 저장 전에 AES-GCM을 사용해 로컬에서 암호화됩니다. 사용자가 구성한 AI 제공업체 외에는 어디에도 전송되지 않으며, 전송 시에도 API 요청의 인증 헤더로만 사용됩니다.키는 Chrome 저장소에 암호화된 상태로 보관됩니다복호화는 API 호출을 수행할 때 메모리 안에서만 이루어집니다키는 기록되거나 내보내지거나 공유되지 않습니다자동 비밀번호FSB는 로그인 자격 증명을 기기에 암호화해 저장하는 선택적 자격 증명 관리자를 포함합니다. 비밀번호는 AI 모델에 절대 노출되지 않습니다. 콘텐츠 스크립트가 AI를 완전히 우회하여 페이지에 직접 입력합니다.자격 증명은 256비트 키와 AES-GCM 키 파생을 사용하는 PBKDF2으로 저장 시 암호화됩니다AI가 페이지를 분석할 때 비밀번호 필드의 값은 [hidden]으로 대체됩니다. 실제 비밀번호는 어떤 AI 프롬프트에도 포함되지 않습니다자동 입력은 콘텐츠 스크립트가 값을 DOM에 직접 써넣는 방식으로 이루어지며, 자격 증명 흐름에 AI는 전혀 관여하지 않습니다자격 증명 목록 화면에는 사용자 이름과 도메인만 표시됩니다. 비밀번호는 자동 입력에 필요할 때만 개별적으로 복호화됩니다자격 증명은 도메인별로 저장되며 상위 도메인으로 대체됩니다(예: accounts.google.com는 google.com에서 상속)결제 수단FSB는 결제 화면 자동 입력을 위해 카드 정보를 기기에 저장하는 선택적 결제 수단 볼트를 포함합니다. 카드는 로그인 자격 증명과 동일한 암호화 및 AI 격리로 취급되며, 전체 카드 번호는 어떤 AI 모델에도 전송되지 않습니다.카드 정보(번호, 유효기간, 소유자, 우편번호)는 자격 증명과 동일한 볼트 파생 키를 사용하는 AES-GCM으로 저장 시 암호화됩니다AI가 결제 페이지를 분석할 때, 감지된 카드 번호 필드의 값은 프롬프트가 구성되기 전에 [hidden]으로 대체됩니다. 카드 번호, CVV, 유효기간은 어떤 AI 프롬프트에도 포함되지 않습니다자동 입력은 콘텐츠 스크립트가 페이지의 DOM 필드에 직접 써넣는 방식으로 이루어지며 AI를 완전히 우회합니다목록 화면에는 카드 별칭과 마지막 네 자리만 표시됩니다. 전체 번호는 입력하는 순간에만 메모리에서 복호화됩니다MCP 클라이언트는 use_payment_method를 통해 결제 입력을 요청할 수 있으나, 카드 정보가 페이지에 기록되기 전에 확장 프로그램 내 확인 창이 사용자에게 표시됩니다CVV는 카드별로 사용자가 동의하지 않는 한 저장되지 않으며, 동의한 경우에도 나머지 기록과 함께 암호화됩니다음성 입력FSB는 프롬프트 입력란에 선택적 마이크 입력을 제공합니다. 기본 제공자는 전적으로 브라우저 안에서 동작하며, 더 높은 정확도를 원하면 설정에서 선택적 OpenAI Whisper 대체 수단을 활성화할 수 있습니다.기본 제공자: 브라우저의 네이티브 SpeechRecognition API. 오디오는 Chrome가 처리하며 FSB를 통해 기기를 떠나지 않습니다선택적 Whisper 제공자: sttProvider가 whisper로 설정되고 OpenAI 키가 구성되어 있으면, 녹음된 오디오 조각이 브라우저에서 OpenAI의 전사 엔드포인트로 직접 업로드됩니다. FSB는 그 오디오를 보거나 저장하지 않습니다마이크는 마이크 버튼을 누르고 있거나 켜 둔 동안에만 활성화됩니다. Chrome가 처음 사용할 때 권한을 요청하며, FSB는 확장 프로그램 매니페스트에서 마이크 접근 권한을 요청하지 않습니다전사 결과는 프롬프트 입력란에만 삽입되며, 사용자가 보내기로 선택한 활성 AI 요청 밖으로 기록되거나 저장되거나 전송되지 않습니다마이크 버튼을 사용하지 않거나, Chrome 확장 프로그램 저장소에서 선택적 Whisper 제공자를 지우면 음성 기능을 완전히 비활성화할 수 있습니다프롬프트 인젝션 방지웹 페이지에는 AI 에이전트를 탈취하도록 설계된 숨은 텍스트가 포함될 수 있습니다. FSB는 AI가 오직 사용자의 지시만 따르고 페이지 콘텐츠에 삽입된 지시는 따르지 않도록 다층 방어를 구현합니다.모든 페이지 콘텐츠는 [PAGE_CONTENT] 경계 표시로 감싸이며, AI는 이 표시 안에서 발견된 지시를 절대 따르지 않도록 지시받습니다정화 엔진이 알려진 인젝션 패턴(예: "이전 지시를 무시하라", 가짜 시스템 프롬프트, 재정의 시도)을 AI에 도달하기 전에 모든 페이지 콘텐츠에서 제거합니다AI가 생성한 동작은 실행 전에 검증됩니다. 위험한 URL(javascript:, data:)과 스크립트 인젝션 시도는 차단됩니다알려진 도구의 엄격한 고정 허용 목록만 실행할 수 있습니다. AI는 임의의 동작을 만들어 내거나 호출할 수 없습니다콘텐츠 크기는 값당 500자, 프롬프트 전체 15K로 제한되어 페이로드 전달을 억제합니다웹사이트가 삽입하는 보이지 않는 유니코드 제어 문자는 처리 전에 제거됩니다백그라운드 에이전트와 서버 동기화지원 중단 버전: v0.9.45rc1. FSB의 내장 백그라운드 에이전트는 OpenClaw 및 Claude Routines로 대체되었으며, 원격 제어는 이제 Sync 탭에서 처리합니다. 아래 고지는 아직 v0.9.44 이하를 사용하는 분들을 위해 유지합니다. 현재 빌드에서는 Sync 세션을 페어링할 때만 릴레이 서버에 접속합니다.기존 백그라운드 에이전트 서버 동기화를 사용하기로 선택하거나 Remote Dashboard를 페어링하면, 릴레이 서버가 확장 프로그램과 대시보드 사이의 통신을 중계합니다.서버에 저장되는 항목: 에이전트 정의(이름, 일정, 대상 URL), 실행 지표(토큰 수, 비용, 소요 시간, 성공/실패 상태), 세션 페어링 토큰그 실행 메타데이터 외에, 방문한 페이지에서 파생된 것은 서버에 저장되지 않습니다. 위의 외부 서비스 목록을 참조하십시오인증에는 로컬에서 생성된 해시 키와 24시간 후 만료되는 세션 토큰을 사용합니다일회용 페어링 토큰은 60초 후 만료되며 재사용할 수 없습니다서버 동기화는 기본적으로 비활성화되어 있습니다. 옵션에서 명시적으로 활성화해야 합니다메모리 시스템FSB의 메모리 시스템은 시간이 지날수록 자동화를 개선하기 위해 탐색 패턴과 사이트 인텔리전스를 저장합니다.모든 메모리 데이터(의미, 일화, 절차)는 다음 위치에 로컬로 저장됩니다: chrome.storage.local어떤 메모리 데이터도 외부 서버로 전송되지 않습니다메모리는 옵션 대시보드에서 언제든지 확인하고 삭제할 수 있습니다사이트 맵과 탐색 패턴은 도메인별로 구분되어 서로 격리됩니다세션 리플레이와 스크린샷MCP 클라이언트가 FSB를 제어하면, 확장 프로그램은 나중에 실행 내용을 검토하거나 재생할 수 있도록 에이전트의 동작을 기록합니다. 이 기록은 기기에 남습니다.진행 중인 실행은 Chrome의 세션 저장소에 보관되어 서비스 워커가 종료되어도 유지됩니다. 완료된 실행은 사용자 본인의 자동화 실행과 동일한 기록 저장소를 통해 chrome.storage.local에 기록됩니다기록은 저장 전에 편집됩니다. 자격 증명 형태의 키 아래에 있는 값, 비밀번호·일회용 코드·카드 입력으로 보이는 필드에 입력된 텍스트, 서명되었거나 토큰을 포함한 URL 매개변수는 모두 대체됩니다. 일반적인 주소와 선택자는 그것이 없으면 리플레이가 동작하지 않으므로 보존됩니다기록된 실행은 기본적으로 30일간 보관되며 1일에서 365일 사이로 조정할 수 있고, 오래된 것은 매일 실행되는 작업이 정리합니다. 고급 설정에서 기록 기능을 완전히 끌 수 있습니다스크린샷 이미지는 그 기록에 저장되지 않습니다. 크기와 바이트 수 같은 캡처 메타데이터만 유지됩니다MCP 클라이언트가 요청한 스크린샷은 로컬 서비스가 소유자만 접근할 수 있는 권한으로 사용자 디스크에 파일로 저장하며 7일 후 자동으로 삭제합니다. 이 이미지는 요청한 클라이언트에도 반환되므로 해당 클라이언트의 모델에도 전달됩니다익명 사용 통계FSB v0.9.69에서는 프로젝트가 집계된 도입 수치를 공개할 수 있도록 수신 거부 가능한 익명 사용 통계 파이프라인을 도입했습니다(/stats 참조). 이 과정에서 사용자가 탐색하는 페이지에는 전혀 접근하지 않습니다. 유일한 위치 신호는 서버가 수집 시점에 요청 IP에서 도출하는 대략적인 국가/주 라벨이며(페이지 콘텐츠에서 도출하지 않습니다) 집계 형태로만 보관됩니다. 아래 지역(주 단위) 지표를 참조하십시오. 통계는 기본적으로 켜져 있으나 토글 하나로 끌 수 있으며, 설치별 데이터는 요청 시 삭제할 수 있습니다.수집하는 항목설치마다 무작위로 생성되는 UUID. chrome.storage.local에 키 fsbInstallUuid로 저장됩니다. 이 UUID는 로컬에서 생성되며 사용자의 신원과 결코 연결되지 않습니다.사용한 MCP 클라이언트의 이름(예: Claude Code, Cursor, Codex). 고정된 허용 목록에서 가져옵니다.세션에 사용한 모델 이름(예: grok-4-fast, claude-opus-4). 고정된 허용 목록에서 가져옵니다.세션당 입력/출력 토큰 수의 합계입니다.설치된 환경에서 활성화된 FSB 에이전트의 수(정수)입니다.수집하지 않는 항목페이지 URLs, 호스트 이름, 브라우징 기록.프롬프트, 지시, 작업 설명 등 모델 제공업체로 보내는 모든 자연어 텍스트.페이지 DOM, 스크린샷, 페이지 콘텐츠, 사이트 API 페이로드, AI 응답.평문 IP 주소. 서버는 요청 IP를 일시적으로, 그리고 인라인으로 정확히 두 가지 용도에만 사용합니다. 속도 제한을 위한 매일 교체되는 솔트 해시와, 대략적인 국가/주 라벨 도출(아래 참조)입니다. 그 후 즉시 폐기합니다. 평문 IP는 저장하거나 기록하지 않습니다.이름, 사용자명, 계정 핸들 등 자유 형식의 신원 필드.이메일 주소, 전화번호, 연락처 정보.지역(주 단위) 지표서버는 수집 시점에 요청 IP로부터 대략적인 국가 및 미국 주(하위 행정구역) 라벨을 도출합니다. 이때 자체 호스팅하는 DB-IP IP-to-City Lite 데이터셋과 자체 조회를 사용하며, 실시간 제3자 위치 서비스는 사용하지 않고 MaxMind도 결코 사용하지 않습니다. 평문 IP는 인라인으로 소비된 뒤 폐기되며, 도출된 라벨만 보관됩니다.지역은 k≥5 익명성 하한을 적용한 일별 집계에만 한정하여 저장됩니다. 특정 일자에 고유 설치 수가 5 미만인 주는 모두 하나의 "기타" 묶음으로 합쳐지며(합쳐진 수마저 5 미만이면 완전히 억제됩니다), 개별 주 라벨이 설치 5건 미만을 나타내는 일은 결코 없습니다.설치별 위치 프로필은 존재하지 않습니다. 대략적인 라벨은 수명이 짧은 원시 이벤트(7일 보관 기간이 지나면 삭제)와 k≥5 하한이 적용된 일별 집계에만 존재하며, 설치와 장소를 잇는 지속적인 매핑을 만들거나 보관하지 않습니다. 위치 데이터 제공: DB-IP (https://db-ip.com).보관 기간원시 이벤트는 7일간 보관합니다. 일별 집계(설치당 하루 한 행)는 365일간 보관합니다. 전역 집계(하루 한 행, 설치별 구분 없음)는 /stats의 과거 차트가 안정적으로 유지되도록 무기한 보관합니다.수신 거부 방법FSB 제어판을 열고 고급 설정으로 스크롤한 뒤 Send anonymous usage data를 끄십시오. 변경 사항은 즉시 적용되며, 이후로는 해당 설치에서 어떤 이벤트도 전송되지 않습니다.데이터 삭제 방법설치와 연결된 모든 통계 행의 삭제를 요청하려면(GDPR 제17조), fsbInstallUuid에서 Chrome DevTools → 애플리케이션 → 저장소 → 확장 프로그램 저장소 경로로 HTTP 요청을 한 번 보내십시오:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forget제한적 사용 확약FSB의 익명 사용 통계는 오직 full-selfbrowsing.com/stats에 공개적으로 표시되는 집계 사용 통계를 계산하는 데에만 사용됩니다. 이 데이터는 판매되거나, 제3자와 공유되거나, 광고에 사용되거나, 어떤 머신러닝 모델의 학습에 사용되지 않습니다. 이 약속은 Chrome Web Store의 Limited Use 요건을 충족합니다.공개 집계 지표이 통계 파이프라인에서 도출한 집계 지표를 /stats에 공개합니다. 개수와 합계만 표시하며, 설치별 행은 결코 공개하지 않습니다.동의 및 감사 제어FSB의 자동화 태세는 수신 거부 방식입니다. 차단 목록에 없는 출처는 사용자가 구성할 수 있는 전역 기본값을 상속하며 현재 기본값은 자동입니다. 출처별 명시 정책으로 특정 출처를 끄기, 확인, 자동 중 하나로 설정할 수 있습니다. 감사 로그 보관은 로컬에서 제한적으로 이루어지며, 제어판에서 내보내기와 삭제를 할 수 있습니다.서비스 차단 목록은 여전히 강제 차단입니다. 차단된 출처는 전역 기본값이나 저장된 출처별 정책과 관계없이 활성화할 수 없습니다.민감한 출처는 자동 상태에서 읽기를 수행할 수 있으나, 쓰기는 실행 전에 출처별 변경 동의를 다시 확인합니다. 민감하지 않은 출처는 제어판의 동의 및 감사 섹션에서 수신 거부하거나 확인 모드로 변경할 수 있습니다.모든 기능 호출은 편집된 추가 전용 로컬 감사 로그에 기록됩니다. 인수, 토큰, 쿠키, 응답 본문은 결코 저장되지 않습니다.오픈 소스FSB는 MIT 라이선스로 완전히 공개된 오픈 소스입니다. 모든 코드를 직접 검토하여 이러한 개인정보 보호 주장을 확인할 수 있습니다. 소스 코드는 GitHub에서 확인할 수 있습니다.본 방침의 변경본 방침이 업데이트되면 이 페이지 상단의 "최종 업데이트" 날짜에 변경 사항이 반영됩니다. 중요한 변경 사항은 프로젝트의 GitHub 릴리스 노트에도 기재됩니다.문의본 개인정보처리방침이나 FSB의 데이터 처리에 대해 궁금한 점이 있으면 GitHub Issues에 이슈를 등록해 주십시오. + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) 2026년 5월 – 7월v0.9.90 — 사이트 API 기능, Remote Dashboard 및 PhantomStream, 결제 수단, 음성 입력, 지역 지표 (아카이브 전문) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - 최종 업데이트: 2026년 8월 + Last updated: September 2026 + 최종 업데이트: 2026년 9월 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69에서는 프로젝트가 집계된 도입 수치를 공개할 수 있도록 수신 거부 가능한 익명 사용 통계 파이프라인을 도입했습니다(/stats 참조). 이 과정에서 사용자가 탐색하는 페이지에는 전혀 접근하지 않습니다. 유일한 위치 신호는 서버가 수집 시점에 요청 IP에서 도출하는 대략적인 국가/주 라벨이며(페이지 콘텐츠에서 도출하지 않습니다) 집계 형태로만 보관됩니다. 아래 지역(주 단위) 지표를 참조하십시오. 통계는 기본적으로 켜져 있으나 토글 하나로 끌 수 있으며, 설치별 데이터는 요청 시 삭제할 수 있습니다. + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69에서는 프로젝트가 집계된 도입 수치를 공개할 수 있도록 수신 거부 가능한 익명 사용 통계 파이프라인을 도입했습니다(/stats 참조). 이 과정에서 사용자가 탐색하는 페이지에는 전혀 접근하지 않습니다. 유일한 위치 신호는 서버가 수집 시점에 요청 IP에서 도출하는 대략적인 국가/주 라벨이며(페이지 콘텐츠에서 도출하지 않습니다) 집계 형태로만 공개됩니다. 아래 지역(주 단위) 지표를 참조하십시오. 통계는 기본적으로 켜져 있으나 토글 하나로 끌 수 있으며, 설치별 데이터는 요청 시 삭제할 수 있습니다. src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - 평문 IP 주소. 서버는 요청 IP를 일시적으로, 그리고 인라인으로 정확히 두 가지 용도에만 사용합니다. 속도 제한을 위한 매일 교체되는 솔트 해시와, 대략적인 국가/주 라벨 도출(아래 참조)입니다. 그 후 즉시 폐기합니다. 평문 IP는 저장하거나 기록하지 않습니다. + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + 평문 IP 주소. 서버는 요청 IP를 일시적으로, 그리고 인라인으로 정확히 세 가지 용도에만 사용합니다. 속도 제한을 위한 매일 교체되는 솔트 해시, 대략적인 국가/주 라벨 도출(아래 참조), 그리고 주소가 IPv4인지 IPv6인지 기록하는 것입니다. 그 후 즉시 폐기합니다. 평문 IP는 저장하거나 기록하지 않습니다. src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - 서버는 수집 시점에 요청 IP로부터 대략적인 국가 및 미국 주(하위 행정구역) 라벨을 도출합니다. 이때 자체 호스팅하는 DB-IP IP-to-City Lite 데이터셋과 자체 조회를 사용하며, 실시간 제3자 위치 서비스는 사용하지 않고 MaxMind도 결코 사용하지 않습니다. 평문 IP는 인라인으로 소비된 뒤 폐기되며, 도출된 라벨만 보관됩니다. + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + 서버는 수집 시점에 요청 IP로부터 대략적인 국가 및 미국 주(하위 행정구역) 라벨을 도출합니다. 이때 자체 호스팅하는 DB-IP IP-to-City Lite 데이터셋과 자체 조회를 사용하며, 실시간 제3자 위치 서비스는 사용하지 않고 MaxMind도 결코 사용하지 않습니다. 평문 IP는 인라인으로 소비된 뒤 폐기되며, 도출된 라벨과 주소 체계(IPv4 또는 IPv6)만 보관됩니다. src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - 지역은 k≥5 익명성 하한을 적용한 일별 집계에만 한정하여 저장됩니다. 특정 일자에 고유 설치 수가 5 미만인 주는 모두 하나의 "기타" 묶음으로 합쳐지며(합쳐진 수마저 5 미만이면 완전히 억제됩니다), 개별 주 라벨이 설치 5건 미만을 나타내는 일은 결코 없습니다. + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + 지역은 k≥5 익명성 하한을 적용한 집계 형태로만 한정하여 공개됩니다. 고유 설치 수가 5 미만인 주는 모두 하나의 "기타" 묶음으로 합쳐지며(합쳐진 수마저 5 미만이면 완전히 억제됩니다), 공개되는 주 라벨이 설치 5건 미만을 나타내는 일은 결코 없습니다. src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - 설치별 위치 프로필은 존재하지 않습니다. 대략적인 라벨은 수명이 짧은 원시 이벤트(7일 보관 기간이 지나면 삭제)와 k≥5 하한이 적용된 일별 집계에만 존재하며, 설치와 장소를 잇는 지속적인 매핑을 만들거나 보관하지 않습니다. 위치 데이터 제공: DB-IP (https://db-ip.com). + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + 대략적인 라벨은 원시 이벤트(7일 보관 기간이 지나면 삭제)와 설치의 일별 집계에 저장되며, 일별 집계는 /stats가 각 설치를 가장 최근 지역 기준으로 한 번만 셀 수 있도록 365일간 보관됩니다. 이 라벨은 IP 주소, 도시, 좌표가 아닙니다. 삭제를 요청하면 설치별 나머지 데이터와 함께 삭제되며, 위의 k≥5 하한 뒤에서만 공개됩니다. 위치 데이터 제공: DB-IP (https://db-ip.com). src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - 원시 이벤트는 7일간 보관합니다. 일별 집계(설치당 하루 한 행)는 365일간 보관합니다. 전역 집계(하루 한 행, 설치별 구분 없음)는 /stats의 과거 차트가 안정적으로 유지되도록 무기한 보관합니다. + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + 원시 이벤트는 7일간 보관합니다. 일별 집계(설치당 하루 한 행, 대략적인 지역 라벨 포함)는 365일간 보관합니다. 전역 집계(하루 한 행, 설치별 구분 없음)는 /stats의 과거 차트가 안정적으로 유지되도록 무기한 보관합니다. src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - 오늘의 시간별 집계에 따른 지역 분포입니다. + Where installs were last seen, by coarse region, over the past 365 days. + 지난 365일 동안 설치가 마지막으로 확인된 위치를 대략적인 지역별로 보여 줍니다. src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - 오늘의 시간별 FSB 지역 분포를 보여 주는 지구본 + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + 지난 365일 동안 FSB 설치가 마지막으로 확인된 위치를 대략적인 지역별로 보여 주는 지구본 src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/locale/messages.xlf b/showcase/angular/src/locale/messages.xlf index 440816baf..1218e9a7b 100644 --- a/showcase/angular/src/locale/messages.xlf +++ b/showcase/angular/src/locale/messages.xlf @@ -8357,11 +8357,27 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) src/app/pages/privacy/privacy-history-archive.component.html - 3,6 + 242,245 @@ -8370,14 +8386,14 @@ https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. src/app/pages/privacy/privacy-history-archive.component.html - 7,198 + 246,437 March 2026v9.0.2 — Background Agents, Memory System, Server Sync, Anonymous Usage Telemetry, Legal Posture (full archived text) src/app/pages/privacy/privacy-history-archive.component.html - 202,205 + 441,444 @@ -8386,21 +8402,21 @@ https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Legal Posture and Consent ModelFSB's automation posture, audit-log retention, and per-origin consent model were presented as explicit product controls. FSB does nothing on an origin until you explicitly allow it, automated read access never implies write access, and a conservative service denylist blocks automation on sensitive categories (financial and government services) outright.Per-origin consent is default-off. Auto and write (mutating) access are separate, explicit opt-ins managed from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.A service denylist renders sensitive origins non-enableable, enforced at the capability gate and not merely in the interface.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. src/app/pages/privacy/privacy-history-archive.component.html - 206,345 + 445,584 February 2026v0.9 — Initial privacy policy (full archived text) src/app/pages/privacy/privacy-history-archive.component.html - 349,352 + 588,591 Archived copy of the initial privacy policy as it stood in February 2026. This snapshot is reproduced from the original static showcase page, with the page chrome removed and the policy content preserved.Data CollectionFSB operates entirely within your browser. The extension only accesses the DOM (Document Object Model) of the currently active tab when you initiate an automation task.No browsing history is collected or stored beyond the current sessionDOM data is analyzed locally and discarded after each automation stepNo personal information is harvested from pages you visitData StorageAll settings and data are stored locally in Chrome's extension storage. FSB uses AES-GCM encryption for sensitive data like API keys.Configuration is stored in chrome.storage.localAPI keys are encrypted before storage using AES-GCMSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use them. The choice of provider and what data is sent is under your control.API calls are made only to the provider you select (xAI, OpenAI, Anthropic, or Google)Sent data includes: task description, DOM structure summary, and action contextNo data is sent to FSB servers -- there are noneEach provider has their own privacy policy governing how they handle API requestsNo TrackingFSB does not include any analytics, telemetry, or tracking services. There are no cookies, no fingerprinting, and no third-party scripts beyond the AI provider APIs you explicitly configure.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-Passwords BetaFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models -- they are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden] -- the actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains -- passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Prompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution -- dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict allowlist of 30+ known tools can be executed -- the AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingOpen SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.View the source code on GitHubSummaryFSB processes data locally, encrypts sensitive information, never exposes passwords to AI models, defends against prompt injection attacks, communicates only with AI providers you choose, includes no tracking, and is fully auditable as open source software. src/app/pages/privacy/privacy-history-archive.component.html - 353,420 + 592,659 @@ -8418,7 +8434,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 + Last updated: September 2026 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -9230,7 +9246,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. src/app/pages/privacy/privacy-page.component.html 197,199 @@ -9307,7 +9323,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. src/app/pages/privacy/privacy-page.component.html 213,214 @@ -9335,21 +9351,21 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). src/app/pages/privacy/privacy-page.component.html 222,223 @@ -9363,7 +9379,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. src/app/pages/privacy/privacy-page.component.html 226,228 @@ -15893,7 +15909,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. + Where installs were last seen, by coarse region, over the past 365 days. src/app/pages/stats/stats-page.component.html 104,106 @@ -16061,7 +16077,7 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution + Globe showing where FSB installs were last seen over the past 365 days, by coarse region src/app/pages/stats/stats-page.component.ts 308 @@ -16155,56 +16171,56 @@ https://full-selfbrowsing.com/api/telemetry/forget src/app/pages/stats/stats-page.component.ts - 478 + 483 Live aggregate adoption, usage, and repository signals for FSB. src/app/pages/stats/stats-page.component.ts - 486 + 491 Cumulative stars src/app/pages/stats/stats-page.component.ts - 973 + 978 Cumulative commits src/app/pages/stats/stats-page.component.ts - 994 + 999 Tokens (last 30 days) src/app/pages/stats/stats-page.component.ts - 1022 + 1027 Popular MCP clients src/app/pages/stats/stats-page.component.ts - 1045 + 1050 Could not load chart library. src/app/pages/stats/stats-page.component.ts - 1099 + 1104 Could not render the selected chart. src/app/pages/stats/stats-page.component.ts - 1100 + 1105 diff --git a/showcase/angular/src/locale/messages.zh-CN.xlf b/showcase/angular/src/locale/messages.zh-CN.xlf index 29eaa97f1..179111dc8 100644 --- a/showcase/angular/src/locale/messages.zh-CN.xlf +++ b/showcase/angular/src/locale/messages.zh-CN.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + 2026 年 8 月v0.9.91 — 本地代理服务与原生消息传递、委派的 CLI 代理、Google Sheets、会话回放与屏幕截图(完整存档文本) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + 这是 2026 年 8 月隐私政策的存档副本,内容为 2026 年 9 月更新前的版本。摘要: FSB 在你的浏览器内运行,FSB 服务器不会收集任何浏览数据。AI 调用直接从你的浏览器发送到你选择的提供商。API 密钥和凭据在本地加密,记忆数据保留在你的设备上。如果你安装了可选的本地代理服务,FSB 还可以由运行在你自己机器上、通过回环连接通信的 MCP 客户端驱动,以及由你已安装的编码代理 CLIs 驱动。为 FSB 而离开你机器的唯一数据,是支撑公开页面 /stats 的可选择退出的匿名使用情况遥测。Remote Dashboard 配对后,短暂的实时预览帧可能在会话期间经过中继,但不会被存储。一切均为开源且可审计。数据收集FSB完全在浏览器内运行 。 当您启动自动化任务时, 扩展可检查活动标签DOM(文件对象模型),并在援引能力时,建立同源网站API浏览器会话中的请求。不收集或保存当前会话之外的任何浏览历史DOM数据和网址API本地分析结果,并在每个自动化步骤后丢弃,除非您明确保存在内存中不从你访问的页面采集任何个人信息站点API能力FSB 的能力层可在页面上下文中使用您已通过身份验证的浏览器会话,调用网站自身的第一方 API。这些请求会在 Chrome 中本地运行;浏览器可能会附加该目标网站的第一方 Cookie 或网站身份验证信息,但 FSB 不会将 Cookie、令牌、CSRF 值、请求正文或响应正文返回、存储、记录或发送到 FSB 服务器。能力调用会遵循 FSB 的同意控制,且仅记录在经过脱敏的本地审计日志中:来源、能力标识、方法、副作用类别、同意决定与结果。审计日志绝不会存储调用参数、请求正文、响应正文、Cookie、令牌、CSRF 值或网站响应载荷。Chrome 权限中 FSB 请求的项目为了执行网页自动化,FSB 在其 Chrome 清单中声明以下权限。每项仅用于其记录的用途;不会以任何一项为依据将数据发送至设备外。DOM 和标签页、activeTab、scripting、tabs、windows、sidePanel,以及主机权限 <all_urls>:读取和写入当前标签页,注入自动化内容脚本,列出并切换标签页,以及呈现侧边栏高级自动化,debugger:挂接 Chrome DevTools Protocol,以执行常规 DOM API 无法完成的基于坐标的点击、拖动和长按按键操作。webNavigation:监测导航开始和结束事件,使自动化在正确时机继续本地存储 ,storage,unlimitedStorage:将您的设置,证书,支付方法,以及内存存储在设备上的 chrome.storage.local. 无限制存储可以解除默认的 10 MB 配额, 这样内存和会话日志可以在不撞墙的情况下增长UX帮助者,clipboardWrite:通过自动化将复制到剪贴板的结果写入. alarms:安排背景内务。 offscreen:在隐藏文档中托管语音对文本记录器,因为服务人员无法直接捕捉音频本地服务, nativeMessaging:启动下方 本地代理服务与原生消息传递 中描述的可选本地代理服务。你访问的页面信息不会经过该通道。system.memory:仅读取已安装的 RAM 总量,以便 FSB 建议合理的并发代理数量上限。可用内存和各处理器的明细从不读取,该数值也从不离开扩展程序语音转文字所需的麦克风访问权限未在清单中声明。当你首次使用麦克风按钮时,Chrome 会自行弹出权限请求。数据存储所有设置和数据都本地存储在 Chrome 的扩展程序存储中,敏感值按下文各节所述在静态时加密。配置保存在 chrome.storage.local 中API 密钥、凭据和支付方式在存储前均已加密,各自的细节见下文对应章节会话日志保存在本地,可随时清除分析数据(任务计数、成功率)保留在你的设备上外部服务FSB 仅在你配置并使用托管提供商时,才与外部 AI 提供商通信。如果你使用 LM Studio,AI 请求会通过其本地 OpenAI 兼容服务器留在本机。提供商选择与发送的数据完全由你掌控。托管 API 调用只会发往你选择的提供商(xAI、OpenAI、Anthropic、Google 或 OpenRouter)LM Studio 在你的设备上使用本地 OpenAI 兼容服务器,且无需 API Key发送的数据包括:任务说明,DOM结构摘要和行动背景如果你配对 Remote Dashboard 或使用旧版 Background Agents 同步,可选的中继服务器会处理该会话的 WebSocket 消息。实时预览帧可能短暂经过中继,但以下内容绝不会保存在 FSB 服务器上:页面内容、DOM 数据、浏览历史、屏幕截图、AI 提示、AI 响应、Cookie、令牌或站点 API 负载。此功能仅为选择加入,本政策其余部分引用此列表而不再重复每个提供商都有自己的隐私政策,规定其如何处理 API 请求本地代理服务与原生消息传递FSB 可由运行在你自己机器上的 MCP 客户端驱动。这需要一个由你自行安装的小型本地代理服务,而 nativeMessaging 权限的存在仅仅是为了让扩展程序能够启动它。Chrome 无法直接启动本地程序,因此这是唯一受支持的机制。消息主机 io.github.fullselfbrowsing.fsb_native_host 仅通过你的明确操作注册,即运行 fsb-mcp-server install --native-host。扩展程序无法安装它,且其注册仅列出一个被允许的扩展程序来源该交换采用封闭模式。FSB 发送一个版本号、一个为 wake 或 bootstrap 的操作,以及一个本地生成的关联标识符;返回的是该标识符,附带取自固定列表的结果和原因。任何额外字段都会被直接拒绝,消息上限为 4 KB。该模式中不存在任何 URL、标签页、页面内容或 DOM 数据成功启动后会返回一个配对码。它是在你的设备上生成、以仅限所有者的权限保存、并在每次服务启动时轮换的回环认证密钥。其中不包含任何关于你或你浏览行为的信息该服务仅在你的机器上监听。扩展程序桥接拒绝绑定任何非回环地址,而 MCP 端点在默认情况下以及每当由 127.0.0.1 启动时都绑定 FSB该服务在自己的目录中仅保留运行记录:一份限定于固定字段列表的委派运行结果诊断日志,以及一份进程监督日志。任务文本、环境变量值、二进制路径和错误文本都不会进入其中任何一个,含有疑似凭据值的条目会被丢弃而非写入如果未安装该主机,此功能就不会启动。不会传输任何内容,扩展程序的其余部分照常运行委派的 CLI 代理FSB 可以把任务交给你已安装的编码代理命令行工具,目前为 Claude Code 或 Grok Build。FSB 会在你自己的机器上启动该程序;你的任务绝不会经由 FSB 服务器转发。你的任务文本仅通过工具的标准输入传递,别无他途。FSB 在每次运行前都会检查这一点:若任务出现在命令行、工作目录、环境变量或任何文件路径中,该次运行会被中止而非启动。任务上限为 64 KB运行期间,该工具会通过回环连接回调 FSB 以驱动你的浏览器。它由此读取的一切内容——页面文本、DOM 快照、电子表格数值、屏幕截图——都会返回给该工具,因而也就到达其供应商:Anthropic 对应 Claude Code,xAI 对应 Grok Build该次运行使用你已在该工具中登录的账户。FSB 不会保存、读取或传输你的 Anthropic 或 xAI 凭据,任何用量或费用均遵循该供应商自身的方案Grok Build 在 FSB 与你自己的目录分开保管的配置文件目录中运行。存放在那里的登录凭据由 Grok 工具在其自身的登录流程中写入由 FSB 提供的代理指令规定,密码、CVV 值、支付卡数据和已保存的凭据绝不得进入提示、叙述、日志或工具参数读取与填写 Google SheetsFSB 可以在你已通过身份验证的浏览器会话中操作电子表格界面,从而读取和填写 Google Sheets 中的某个区域。读取某个区域时,这些单元格数值会发送给你所选择的模型,与 FSB 代表你读取的任何其他页面内容完全一样。只会读取你请求的区域;不存在整表导出在向 FSB 的本地会话历史写入任何内容之前,电子表格内容都会被剥离。仅保留规模计数——涉及多少行、多少列、多少个数值。电子表格地址、工作表名称、单元格引用以及每一个单元格数值都会被丢弃如果由于任何原因无法对某条记录应用该过滤,则该记录会被丢弃而非存储Remote Dashboard和PhantomStream现场预览配对 Remote Dashboard 时,FSB 可使用 PhantomStream 显示当前浏览器标签页的实时预览。预览流传输结构化 DOM 数据而非像素,包括初始快照、MutationObserver 差异、滚动位置、自动化叠加层、对话框状态、媒体播放状态,以及通过 WebSocket 传输的远程控制消息。中继仅将这些实时预览帧转发给已配对的仪表板会话,预览流中的任何内容都不会保存在 FSB 服务器上——参见上文 外部服务中的列表FSB 会启用 PhantomStream 输入内容遮蔽(maskInputs: true),因此密码和表单控件的值会在离开被捕获页面前被遮蔽仪表盘查看器将镜像内容装在一个无脚本的沙盒中并对镜像进行消毒DOM和CSS显示前在目前的仪表板模式下,图像,视频,和音频通过参考镜像. 媒体字节不通过中继器; 查看器可能获取允许的公开HTTPS资产或媒体 URL 直接,而私人、内部、非HTTPS,或以其他方式被封存的源头替换为占位符PhantomStream失败的获取策略无第三方跟踪FSB 不包含任何第三方分析、广告跟踪器或跨站点指纹识别。除你显式配置的 AI 提供商 APIs 之外,没有 Cookie,也没有第三方脚本。FSB 向自身发送的唯一第一方数据是下面描述的可选退出的匿名使用遥测,仅用于驱动公开的 /stats 仪表板。API Key你的 API Key 会在保存前通过 AES-GCM 在本地加密。除了你配置的 AI 提供商之外,绝不会发送到任何地方,且只在 API 请求的身份验证头中使用。Key 在 Chrome 存储中以加密形式静态保存仅在 API 调用时在内存中解密Key 绝不会被记录、导出或共享自动密码FSB 提供可选的凭据管理器,将登录凭据加密保存到你的设备。密码不会暴露给 AI 模型,而是由内容脚本直接填入页面,完全绕过 AI。凭据静态存储时使用 AES-GCM 和 256 位密钥,并通过 PBKDF2 派生密钥进行加密AI 分析页面时,密码字段的值会被替换为 [hidden]。真实密码绝不会出现在任何 AI 提示中自动填充由内容脚本直接插入到DOM 中,没有AI参与证书流凭据列表视图仅显示用户名和域名。密码只在自动填充需要时单独解密凭据按域名存储,并具备父域回退(例如 accounts.google.com 会继承 google.com)付款方式FSB 包含一个可选的付款方式保险库,将卡片信息保存在你的设备上以便结账时自动填写。卡片采用与登录凭据相同的加密与 AI 隔离机制,完整的卡号绝不会发送给任何 AI 模型。卡片信息(卡号、有效期、持卡人和邮编)使用与凭据相同的保险库派生密钥,通过 AES-GCM 在静态时加密当 AI 分析结账页面时,检测到的卡号字段值会在构建提示词之前被替换为 [hidden]。卡号、CVV 和有效期绝不会包含在任何 AI 提示词中自动填写由内容脚本直接写入页面的 DOM 字段完成,完全绕过 AI列表视图仅显示卡片别名与后 4 位数字。完整卡号仅在填写的那一刻在内存中解密MCP 客户端可以通过 use_payment_method 请求执行付款自动填写,但在任何卡片数据写入页面之前,会在扩展内向用户显示确认提示除非你为某张卡片明确启用,否则 CVV 永远不会被持久保存;即使启用,它也会与记录的其余部分一起加密语音转文字FSB 在提示词输入框中包含一个可选的麦克风输入。默认提供商完全在你的浏览器中运行;如果你需要更高的准确性,可在设置中启用可选的 OpenAI Whisper 后备方案。默认提供者: 浏览器的本地SpeechRecognition API。音频由Chrome永远不要离开你的设备FSB可选的 Whisper 提供商:当 sttProvider 设置为 whisper 且配置了 OpenAI 密钥时,录制的音频片段会从你的浏览器直接上传到 OpenAI 的转录接口。FSB 从不查看或存储该音频麦克风仅在你按住或已切换开启麦克风按钮的期间处于活动状态。首次使用时 Chrome 会请求权限;FSB 不会在扩展清单中请求麦克风访问权限转录结果只插入到提示词文本框中,绝不会在你选择发送的活跃 AI 请求之外被记录、保存或传输通过不触碰麦克风按钮,或在 Chrome 扩展存储中清除可选的 Whisper 提供商,即可完全禁用语音功能防止提示词注入网页可能包含旨在劫持 AI 智能体的隐藏文本。FSB 通过多层防御确保 AI 只遵循你的指令,绝不执行嵌入在页面内容中的指令。所有页面内容都被包裹在 [PAGE_CONTENT] 边界标记内,并指示 AI 永远不要执行其中的指令在内容到达 AI 之前,清洗引擎会剥离已知的注入模式(例如“忽略以上指令”、伪造的系统提示、覆盖请求)AI 生成的动作会在执行前进行验证。危险 URL(javascript:、data:)和脚本注入尝试将被阻止只能执行严格且固定的已知工具白名单中的操作。AI 无法自行构造或调用任意操作内容大小有上限(单值 500 字符,提示总上限 15K),限制有效载荷投递网站嵌入的不可见 Unicode 控制字符会在处理前被剥离后台智能体与服务器同步已在 v0.9.45rc1 中弃用。 FSB 内置后台代理已由 OpenClaw 和 Claude Routines 取代,远程控制现在由“同步”标签页处理。下列说明保留给仍使用 v0.9.44 或更早版本的用户;在当前版本中,只有在配对“同步”会话时才会连接至中继服务器。如果您选择使用遗留的背景代理服务器同步或对齐Remote Dashboard,中继服务器将促进您的扩展和仪表板之间的通信。服务器会保存:智能体定义(名称、计划、目标 URL)、运行指标(Token 数、成本、时长、成功/失败状态)、会话配对令牌除那些运行元数据之外,服务器不会保存任何源自你所访问页面的内容——参见上文 外部服务中的列表身份验证使用本地生成的哈希 Key,以及 24 小时后失效的会话令牌一次性配对令牌在 60 秒后失效,无法重复使用服务器同步默认关闭,需要你在“选项”中显式启用记忆系统FSB 的记忆系统会沉淀导航模式和站点情报,让自动化随时间持续优化。所有记忆数据(语义、情景、过程)都保存在 chrome.storage.local 中记忆数据不会发送到任何外部服务器你可在选项控制台中随时查看并清除记忆站点地图和导航模式按域名隔离,互不影响会话回放与屏幕截图当 MCP 客户端驱动 FSB 时,扩展程序会记录代理的操作,以便你之后查看或回放该次运行。这些记录保留在你的设备上。仍在进行中的运行保存在 Chrome 的会话存储中,以便在 service worker 被回收后依然留存;已完成的运行则通过 chrome.storage.local 写入与你自己的自动化运行相同的历史存储记录在存储前会先经过脱敏。疑似凭据键下的数值、输入到形似密码、一次性验证码或银行卡字段中的文本,以及带签名或携带令牌的 URL 参数,都会被替换。普通地址和选择器会保留,因为没有它们回放就无法进行已记录的运行默认保留 30 天,可在 1 至 365 天之间调整,较旧的记录由每日任务清理。可在高级设置中完全关闭记录功能屏幕截图图像绝不会写入该历史记录。仅保留尺寸、字节大小等捕获元数据由 MCP 客户端请求的屏幕截图,会由本地服务以仅限所有者的权限保存为你自己磁盘上的文件,并在七天后自动删除。该图像同时也会回传给发起请求的客户端,因而也会到达该客户端的模型匿名使用遥测FSB v0.9.69 引入了一个可选择退出的匿名使用情况遥测管道,以便项目可以发布汇总的采用数据(参见 /stats),且绝不触及你浏览的页面。唯一的位置信号是服务器在接收时从你的请求 IP 派生出的粗略国家/州标签(绝不来自页面内容),且仅以汇总形式保留——参见下方的 地区(州级)指标。遥测默认开启,但可通过单个开关禁用,并且可应请求删除每次安装的数据。我们收集的内容每次安装随机生成的 UUID,存储在 chrome.storage.local 的键 fsbInstallUuid 下。UUID 在本地生成,永不与你的身份关联。所使用的 MCP 客户端名称(例如 Claude Code、Cursor、Codex),取自固定的允许列表。会话中使用的模型名称(例如 grok-4-fast、claude-opus-4),取自固定的允许列表。每个会话的输入/输出 token 数量聚合值。你的安装上活跃的 FSB 代理数量(一个整数值)。我们不收集的内容页面 URLs、主机名或浏览历史。提示、指令、任务描述或你发送给模型提供商的任何自然语言文本。页面DOM,截图,页面内容,站点API有效载荷,或AI响应.明文 IP 地址。服务器仅出于两个目的临时且内联地使用请求 IP——用于限流的每日轮换加盐哈希,以及派生粗略的国家/州标签(见下文)——随后立即将其丢弃。明文 IP 绝不会被存储或记录。姓名、用户名、账号 handle 或任何自由文本身份字段。电子邮件地址、电话号码或联系信息。地区(州级)指标服务器在接收请求时,根据请求的 IP,使用自托管的 DB-IP IP-to-City Lite 数据集和自有查找逻辑,推导出粗略的国家及美国州(行政区)标签——这并非实时第三方地理定位服务,也绝不会使用 MaxMind。明文 IP 会被即时处理并丢弃;仅保留推导出的标签。地区仅存储在每日汇总中,且位于 k≥5 的匿名阈值之后:某一天内不同安装数少于 5 的任何州都会合并到单个“Other”桶中(当该合并计数本身低于 5 时则完全抑制)。任何单个州标签都绝不会代表少于 5 次安装。不存在按安装的位置画像。粗略标签仅存在于短暂的原始事件(由 7 天保留策略删除)和经 k≥5 过滤的每日汇总中;我们绝不构建或保留从你的安装到某个地点的持久映射。地理定位数据来自 DB-IP(https://db-ip.com)。保留期原始事件保留 7 天。每日汇总(每安装每天一行)保留 365 天。全局聚合(每天一行,不按安装维度)无限期保留,以便 /stats 上的历史图表保持稳定。如何选择退出打开 FSB 控制面板,滚动到"高级设置",将 发送匿名使用数据 开关关闭。更改立即生效;之后不会再从你的安装发送事件。如何擦除你的数据如要请求删除与您的安装相关的所有遥测数据行(GDPR 第 17 条),请查找您的 fsbInstallUuid:前往 Chrome DevTools → 应用程序 → 存储 → 扩展程序存储,然后发送一次 HTTP 请求:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use 合规声明FSB 的匿名使用遥测仅用于计算在 full-selfbrowsing.com/stats 公开展示的聚合使用统计。数据从不出售、从不与第三方共享、从不用于广告,且从不用于训练任何机器学习模型。此承诺满足 Chrome Web Store 的 Limited Use 要求。聚合的公开指标我们在 /stats 发布来自此遥测管道的聚合指标。仅展示计数和总数;每安装的行从不暴露。同意和审计控制FSB 的自动化策略采用选择退出模式:未列入拒绝列表的来源会继承用户可配置的全局默认设置,当前默认出厂设置为 Auto;明确的按来源策略则可将来源设置为 Off、Ask 或 Auto。审计日志仅在本地保留且有期限,控制面板也提供导出与清除功能。服务拒绝列表仍是硬性限制。无论全局默认值或已存储的按来源策略为何,被拒绝的来源都无法启用。敏感源可以运行在 Auto 下读取,但在执行前写着重新强制每个源的变异选择。 非敏感来源可选择退出或移至控制小组的同意和审计科。每次能力调用都会记录在经过脱敏的、仅可追加的本地审计日志中。绝不会存储任何参数、令牌、Cookie 或响应正文。开源FSB在MIT下完全开源 执照 你可以对每条代码进行审核 以核实这些隐私诉求 源代码可见于GitHub.本政策的变更若本政策更新,变更将体现在页面顶部的“最后更新”日期。重要变更也会在项目的 GitHub 发布说明中注明。联系方式如果您对此项隐私政策或FSB的数据处理有疑问,请在GitHub Issues上打开一个问题。 + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) 2026 年 5 月 – 7 月v0.9.90 — 站点 API 能力、Remote Dashboard 与 PhantomStream、支付方式、语音转文字、地区指标(完整存档文本) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - 最后更新:2026 年 8 月 + Last updated: September 2026 + 最后更新:2026 年 9 月 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69 引入了一个可选择退出的匿名使用情况遥测管道,以便项目可以发布汇总的采用数据(参见 /stats),且绝不触及你浏览的页面。唯一的位置信号是服务器在接收时从你的请求 IP 派生出的粗略国家/州标签(绝不来自页面内容),且仅以汇总形式保留——参见下方的 地区(州级)指标。遥测默认开启,但可通过单个开关禁用,并且可应请求删除每次安装的数据。 + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 引入了一个可选择退出的匿名使用情况遥测管道,以便项目可以发布汇总的采用数据(参见 /stats),且绝不触及你浏览的页面。唯一的位置信号是服务器在接收时从你的请求 IP 派生出的粗略国家/州标签(绝不来自页面内容),且仅以汇总形式公开——参见下方的 地区(州级)指标。遥测默认开启,但可通过单个开关禁用,并且可应请求删除每次安装的数据。 src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - 明文 IP 地址。服务器仅出于两个目的临时且内联地使用请求 IP——用于限流的每日轮换加盐哈希,以及派生粗略的国家/州标签(见下文)——随后立即将其丢弃。明文 IP 绝不会被存储或记录。 + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + 明文 IP 地址。服务器仅出于三个目的临时且内联地使用请求 IP——用于限流的每日轮换加盐哈希、派生粗略的国家/州标签(见下文),以及记录该地址是 IPv4 还是 IPv6——随后立即将其丢弃。明文 IP 绝不会被存储或记录。 src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - 服务器在接收请求时,根据请求的 IP,使用自托管的 DB-IP IP-to-City Lite 数据集和自有查找逻辑,推导出粗略的国家及美国州(行政区)标签——这并非实时第三方地理定位服务,也绝不会使用 MaxMind。明文 IP 会被即时处理并丢弃;仅保留推导出的标签。 + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + 服务器在接收请求时,根据请求的 IP,使用自托管的 DB-IP IP-to-City Lite 数据集和自有查找逻辑,推导出粗略的国家及美国州(行政区)标签——这并非实时第三方地理定位服务,也绝不会使用 MaxMind。明文 IP 会被即时处理并丢弃;仅保留推导出的标签和地址族(IPv4 或 IPv6)。 src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - 地区仅存储在每日汇总中,且位于 k≥5 的匿名阈值之后:某一天内不同安装数少于 5 的任何州都会合并到单个“Other”桶中(当该合并计数本身低于 5 时则完全抑制)。任何单个州标签都绝不会代表少于 5 次安装。 + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + 地区仅以汇总形式公开,且位于 k≥5 的匿名阈值之后:不同安装数少于 5 的任何州都会合并到单个“Other”桶中(当该合并计数本身低于 5 时则完全抑制)。任何公开的州标签都绝不会代表少于 5 次安装。 src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - 不存在按安装的位置画像。粗略标签仅存在于短暂的原始事件(由 7 天保留策略删除)和经 k≥5 过滤的每日汇总中;我们绝不构建或保留从你的安装到某个地点的持久映射。地理定位数据来自 DB-IP(https://db-ip.com)。 + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + 粗略标签存储在原始事件(由 7 天保留策略删除)以及你的安装的每日汇总中;每日汇总保留 365 天,以便 /stats 按每次安装最近的地区只计数一次。该标签绝不是 IP 地址、城市或坐标;当你请求删除时,它会与你安装的其余数据一并删除;并且它只会在上述 k≥5 阈值之后公开。地理定位数据来自 DB-IP(https://db-ip.com)。 src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - 原始事件保留 7 天。每日汇总(每安装每天一行)保留 365 天。全局聚合(每天一行,不按安装维度)无限期保留,以便 /stats 上的历史图表保持稳定。 + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + 原始事件保留 7 天。每日汇总(每安装每天一行,包括粗略的地区标签)保留 365 天。全局聚合(每天一行,不按安装维度)无限期保留,以便 /stats 上的历史图表保持稳定。 src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - 来自今日每小时汇总的地区分布。 + Where installs were last seen, by coarse region, over the past 365 days. + 过去 365 天内各安装最后出现的位置,按粗略地区显示。 src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - 显示今日每小时 FSB 地区分布的地球仪 + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + 显示过去 365 天内 FSB 安装最后出现位置(按粗略地区)的地球仪 src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/locale/messages.zh-TW.xlf b/showcase/angular/src/locale/messages.zh-TW.xlf index 5262e19bd..582b118ab 100644 --- a/showcase/angular/src/locale/messages.zh-TW.xlf +++ b/showcase/angular/src/locale/messages.zh-TW.xlf @@ -9542,6 +9542,26 @@ 307 + + August 2026v0.9.91 — Local Agent Service and Native Messaging, Delegated CLI Agents, Google Sheets, Session Replay and Screenshots (full archived text) + 2026 年 8 月v0.9.91 — 本機代理服務與原生訊息傳遞、委派的 CLI 代理、Google Sheets、工作階段重播與螢幕截圖(完整封存文本) + + src/app/pages/privacy/privacy-history-archive.component.html + 3,6 + + + + Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.Data CollectionFSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.No browsing history is collected or stored beyond the current sessionDOM data and site API results are analyzed locally and discarded after each automation step unless you explicitly save them in memoryNo personal information is harvested from pages you visitSite API capabilitiesFSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.Chrome permissions FSB requestsTo run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.DOM and tabs, activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side panelAdvanced automation, debugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentLocal storage, storage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallUX helpers, clipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlyLocal service, nativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.Data StorageAll settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.Configuration is stored in chrome.storage.localAPI keys, credentials, and payment methods are encrypted before storage, each detailed in its own section belowSession logs are stored locally and can be cleared at any timeAnalytics data (task counts, success rates) stays on your deviceExternal ServicesFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.Hosted API calls are made only to the provider you select (xAI, OpenAI, Anthropic, Google, or OpenRouter)LM Studio uses a local OpenAI-compatible server on your device and does not require an API keySent data includes: task description, DOM structure summary, and action contextIf you pair Remote Dashboard or use legacy Background Agents sync, an optional relay server handles WebSocket messages for that session. Live-preview frames may pass through the relay transiently, but none of the following is ever persisted on an FSB server: page content, DOM data, browsing history, screenshots, AI prompts, AI responses, cookies, tokens, or site API payloads. This is opt-in only, and the rest of this policy refers back to this list rather than restating itEach provider has their own privacy policy governing how they handle API requestsLocal Agent Service and Native MessagingFSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.The messaging host io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originThe exchange is a closed schema. FSB sends a version number, an action of either wake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schemaA successful start returns a pairing code. This is a loopback authentication secret generated on your device and stored with owner-only permissions, rotated every time the service starts. It carries no information about you or your browsingThe service listens on your machine only. The extension bridge refuses to bind any address that is not loopback, and the MCP endpoint binds 127.0.0.1 by default and whenever FSB starts itUnder its own directory the service keeps only operational records: a diagnostics log of delegated-run outcomes restricted to a fixed field list, and a process-supervision journal. Task text, environment values, binary paths, and error text never reach either of them, and entries carrying credential-shaped values are discarded rather than writtenIf the host is not installed, the feature simply does not start. Nothing is transmitted, and the rest of the extension continues to work normallyDelegated CLI AgentsFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.Your task text reaches the tool over its standard input and nowhere else. FSB checks this before every run: if the task appears in the command line, the working directory, the environment, or any file path, the run is aborted rather than started. Tasks are capped at 64 KBWhile the run is in progress the tool calls back into FSB over the loopback connection to drive your browser. Whatever it reads that way — page text, DOM snapshots, spreadsheet values, screenshots — is returned to that tool, and therefore reaches its vendor: Anthropic for Claude Code, xAI for Grok BuildThe run uses the account already signed in to that tool. FSB does not hold, read, or transmit your Anthropic or xAI credential, and any usage or charges follow that vendor's own planGrok Build runs inside a profile directory FSB keeps separate from your own. The sign-in credential stored there is written by the Grok tool itself during its own sign-in flowThe agent instructions FSB supplies state that passwords, CVV values, payment-card data, and saved credentials must never enter prompts, narration, logs, or tool argumentsReading and Filling Google SheetsFSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.Reading a range returns those cell values to the model you selected, exactly like any other page content FSB reads on your behalf. Only the range you asked for is read; there is no whole-spreadsheet exportSpreadsheet content is stripped out before anything is written to FSB's local session history. Only shape counts survive — how many rows, columns, and values were involved. The spreadsheet address, sheet name, cell references, and every cell value are discardedIf that filtering cannot be applied to a record for any reason, the record is dropped rather than storedRemote Dashboard and PhantomStream Live PreviewWhen you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.The relay forwards those live-preview frames only to the paired dashboard session, and nothing from the preview stream is persisted on FSB servers — see the list under External Services aboveFSB enables PhantomStream input masking (maskInputs: true), so passwords and form-control values are masked before they leave the captured pageThe dashboard viewer renders mirrored content in a scriptless sandbox and sanitizes mirrored DOM and CSS before displayImages, video, and audio are mirrored by reference in current dashboard mode. Media bytes do not cross the relay; the viewer may fetch allowed public HTTPS asset or media URLs directly, while private, internal, non-HTTPS, or otherwise blocked origins are replaced with placeholders by PhantomStream's fail-closed fetch policyNo Third-Party TrackingFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.API KeysYour API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.Keys are encrypted at rest in Chrome storageDecryption only happens in-memory when making API callsKeys are never logged, exported, or sharedAuto-PasswordsFSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.Credentials are encrypted at rest using AES-GCM with 256-bit keys and PBKDF2 key derivationWhen the AI analyzes a page, password field values are replaced with [hidden]. The actual password is never included in any AI promptAuto-fill is performed by the content script injecting values directly into the DOM, with no AI involvement in the credential flowThe credential list view only shows usernames and domains. Passwords are decrypted individually and only when needed for auto-fillCredentials are stored per-domain with parent domain fallback (e.g., accounts.google.com inherits from google.com)Payment MethodsFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.Card details (number, expiry, cardholder, and zip) are encrypted at rest using AES-GCM with the same vault-derived key used for credentialsWhen the AI analyzes a checkout page, any detected card-number field values are replaced with [hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptAuto-fill happens via the content script writing directly into the page's DOM fields, bypassing the AI entirelyThe list view shows only a card nickname and last-4 digits. Full numbers are decrypted in memory only at the moment of fillAn MCP client can request a payment fill via use_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageCVV is never persisted unless you opt in per-card, and even then it is encrypted alongside the rest of the recordSpeech-to-TextFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.Default provider: the browser's native SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBOptional Whisper provider: when sttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioThe microphone is only active while you are holding or have toggled the mic button. Chrome prompts for permission the first time you use it; FSB does not request microphone access in the extension manifestTranscripts are inserted into the prompt textarea only and are never logged, persisted, or transmitted outside the active AI request you choose to sendDisable speech entirely by leaving the mic button untouched, or by clearing the optional Whisper provider in Chrome extension storagePrompt Injection PreventionWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.All page content is wrapped in [PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersA sanitization engine strips known injection patterns (e.g., "ignore previous instructions", fake system prompts, override attempts) from all page content before it reaches the AIAI-generated actions are validated before execution. Dangerous URLs (javascript:, data:) and script injection attempts are blockedOnly a strict, fixed allowlist of known tools can be executed. The AI cannot invent or call arbitrary actionsContent size is capped (500 chars per value, 15K total prompt cap) to limit payload deliveryInvisible Unicode control characters that websites embed are stripped before processingBackground Agents and Server SyncDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.The server stores: agent definitions (name, schedule, target URL), run metrics (token count, cost, duration, success/fail status), and session pairing tokensBeyond that run metadata the server persists nothing derived from the pages you visit — see the list under External Services aboveAuthentication uses hash keys (generated locally) and session tokens that expire after 24 hoursOne-time pairing tokens expire after 60 seconds and cannot be reusedServer sync is disabled by default. You must explicitly enable it in OptionsMemory SystemFSB's memory system stores navigation patterns and site intelligence to improve automation over time.All memory data (semantic, episodic, procedural) is stored locally in chrome.storage.localNo memory data is sent to any external serverMemory can be viewed and cleared at any time from the Options dashboardSite maps and navigation patterns are domain-specific and isolated from each otherSession Replay and ScreenshotsWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.Runs still in progress are held in Chrome's session storage so they survive the service worker being evicted; finished runs are written to chrome.storage.local through the same history store your own automation runs useRecords are redacted before they are stored. Values under credential-shaped keys, text typed into fields that look like password, one-time-code, or card inputs, and signed or token-bearing URL parameters are all replaced. Ordinary addresses and selectors are preserved, because replay does not work without themRecorded runs are kept for 30 days by default, adjustable between 1 and 365 days, and older ones are pruned by a daily job. Recording can be switched off entirely in Advanced SettingsScreenshot images are never written into that history. Only capture metadata such as dimensions and byte size is retainedScreenshots an MCP client requests are saved by the local service as files on your own disk with owner-only permissions and deleted automatically after seven days. The image is also handed back to the requesting client, and therefore to that client's modelAnonymous Usage TelemetryFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.What we collectA random per-install UUID stored in chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.The name of the MCP client used (e.g. Claude Code, Cursor, Codex), drawn from a fixed allowlist.The model name used for a session (e.g. grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Aggregate input/output token counts per session.The number of active FSB agents on your install (an integer count).What we do NOT collectPage URLs, hostnames, or browsing history.Prompts, instructions, task descriptions, or any natural-language text you send to your model provider.Page DOM, screenshots, page content, site API payloads, or AI responses.Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged.Names, usernames, account handles, or any free-form identity fields.Email addresses, phone numbers, or contact information.Region (state-level) metricThe server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept.Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs.There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com).RetentionRaw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.How to opt outOpen the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.How to erase your dataTo request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use affirmationFSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.Aggregated public metricsWe publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.Consent and Audit ControlsFSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.The service denylist is still a hard block. Denied origins are non-enableable regardless of the global default or any stored per-origin policy.Sensitive origins can run reads under Auto, but writes re-enforce the per-origin mutating opt-in before execution. Non-sensitive origins can be opted out or moved to Ask from the Control Panel's Consent & Audit section.Every capability call is recorded in a redacted, append-only local audit log. No arguments, tokens, cookies, or response bodies are ever stored.Open SourceFSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.Changes to This PolicyIf this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.ContactIf you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues. + 此為 2026 年 8 月隱私權政策的封存副本,內容為 2026 年 9 月更新前的版本。摘要: FSB 在你的瀏覽器內執行,FSB 伺服器不會收集任何瀏覽資料。AI 呼叫直接從你的瀏覽器傳送到你選擇的供應商。API 金鑰與憑證在本機加密,記憶資料保留在你的裝置上。如果你安裝了選用的本機代理服務,FSB 也可以由執行在你自己機器上、透過回送連線通訊的 MCP 用戶端驅動,以及由你已安裝的程式設計代理 CLIs 驅動。為 FSB 而離開你機器的唯一資料,是支撐公開頁面 /stats 的可選擇退出匿名使用情況遙測。Remote Dashboard 配對後,短暫的即時預覽影格可能在工作階段期間經過中繼,但不會被儲存。一切均為開源且可稽核。資料收集FSB 完全在你的瀏覽器內運作。當你啟動自動化工作時,擴充功能可能會檢查作用中分頁的 DOM(文件物件模型);當你呼叫某項功能時,也可能從瀏覽器工作階段向同源網站發出 API 請求。不收集或儲存當前工作階段之外的任何瀏覽歷史DOM 資料和網站 API 結果會在本機分析,並於每個自動化步驟後丟棄,除非你明確將其儲存到記憶中不從你訪問的頁面採集任何個人資訊網站 API 功能FSB 的功能層可在頁面情境中使用你已驗證的瀏覽器工作階段,呼叫網站自身的第一方 API。這些請求會在 Chrome 本機執行;瀏覽器可能會附加該目標網站的第一方 Cookie 或網站驗證資訊,但 FSB 不會將 Cookie、權杖、CSRF 值、請求本文或回應本文傳回、儲存、記錄或傳送到 FSB 伺服器。功能呼叫會遵循 FSB 的同意控制,且僅記錄在經過遮蔽的本機稽核日誌中:來源、功能代稱、方法、副作用類別、同意決定與結果。稽核日誌絕不會儲存呼叫引數、請求本文、回應本文、Cookie、權杖、CSRF 值或網站回應內容。Chrome 權限(FSB 要求)為了執行網頁自動化,FSB 在其 Chrome 資訊清單中宣告以下權限。每項僅用於其記錄的用途;不會以任何一項為依據將資料傳送至裝置外。DOM 與分頁、activeTab、scripting、tabs、windows、sidePanel 和主機權限 <all_urls>:讀寫作用中分頁、插入自動化內容指令碼、列出並切換分頁,以及顯示側邊面板進階自動化,debugger:附加 Chrome DevTools Protocol,以執行一般 DOM API 無法完成的座標點擊、拖曳與按住按鍵操作。webNavigation:監看導覽開始/完成事件,讓自動化在正確時機繼續本機儲存空間,storage、unlimitedStorage:將你的設定、認證資料、付款方式與記憶儲存在裝置上的 chrome.storage.local。無限制儲存空間會解除預設的 10 MB 配額,讓記憶和工作階段日誌可持續增長,不會觸及上限UX 輔助功能,clipboardWrite:寫入自動化的複製到剪貼簿結果。alarms:排程背景維護工作。offscreen:在隱藏文件中承載語音轉文字錄音器,因為 Service Worker 無法直接擷取音訊本機服務, nativeMessaging:啟動下方 本機代理服務與原生訊息傳遞 中描述的選用本機代理服務。你造訪的頁面資訊不會經過該通道。system.memory:僅讀取已安裝的 RAM 總量,以便 FSB 建議合理的並行代理數量上限。可用記憶體與各處理器的明細從不讀取,該數值也從不離開擴充功能語音轉文字所需的麥克風存取權限未在資訊清單中宣告。當你首次使用麥克風按鈕時,Chrome 會自行顯示權限提示。資料儲存所有設定與資料都本機儲存在 Chrome 的擴充功能儲存空間中,敏感值依下文各節所述在靜態時加密。設定儲存在 chrome.storage.local 中API 金鑰、憑證與付款方式在儲存前均已加密,各自的細節見下文對應章節工作階段日誌儲存在本機,可隨時清除分析資料(任務計數、成功率)保留在你的裝置上外部服務FSB 僅在你設定並使用託管供應商時,才與外部 AI 供應商通訊。如果你使用 LM Studio,AI 請求會透過其本機 OpenAI 相容伺服器留在本機。供應商選擇與傳送的資料完全由你掌控。託管 API 呼叫只會發往你選擇的供應商(xAI、OpenAI、Anthropic、Google 或 OpenRouter)LM Studio 在你的裝置上使用本機 OpenAI 相容伺服器,且無需 API 金鑰傳送的資料包括:工作描述、DOM 結構摘要和動作情境如果你配對 Remote Dashboard 或使用舊版 Background Agents 同步,選用的中繼伺服器會處理該工作階段的 WebSocket 訊息。即時預覽影格可能短暫經過中繼,但以下內容絕不會保存在 FSB 伺服器上:頁面內容、DOM 資料、瀏覽記錄、螢幕截圖、AI 提示、AI 回應、Cookie、權杖或網站 API 酬載。此功能僅為選擇加入,本政策其餘部分引用此清單而不再重複每個供應商都有自己的隱私政策,規定其如何處理 API 請求本機代理服務與原生訊息傳遞FSB 可由執行在你自己機器上的 MCP 用戶端驅動。這需要一個由你自行安裝的小型本機代理服務,而 nativeMessaging 權限的存在僅僅是為了讓擴充功能能夠啟動它。Chrome 無法直接啟動本機程式,因此這是唯一受支援的機制。訊息主機 io.github.fullselfbrowsing.fsb_native_host 僅透過你的明確操作註冊,即執行 fsb-mcp-server install --native-host。擴充功能無法安裝它,且其註冊僅列出一個被允許的擴充功能來源該交換採用封閉結構。FSB 傳送一個版本號、一個為 wake 或 bootstrap 的動作,以及一個本機產生的關聯識別碼;回傳的是該識別碼,附帶取自固定清單的結果與原因。任何額外欄位都會被直接拒絕,訊息上限為 4 KB。該結構中不存在任何 URL、分頁、頁面內容或 DOM 資料成功啟動後會回傳一個配對碼。它是在你的裝置上產生、以僅限擁有者的權限保存、並在每次服務啟動時輪替的回送驗證密鑰。其中不包含任何關於你或你瀏覽行為的資訊該服務僅在你的機器上接聽。擴充功能橋接拒絕繫結任何非回送位址,而 MCP 端點在預設情況下以及每當由 127.0.0.1 啟動時都繫結 FSB該服務在自己的目錄中僅保留運行記錄:一份限定於固定欄位清單的委派執行結果診斷日誌,以及一份程序監督日誌。任務文字、環境變數值、二進位路徑與錯誤文字都不會進入其中任何一個,含有疑似憑證值的項目會被丟棄而非寫入如果未安裝該主機,此功能就不會啟動。不會傳輸任何內容,擴充功能的其餘部分照常運行委派的 CLI 代理FSB 可以把任務交給你已安裝的程式設計代理命令列工具,目前為 Claude Code 或 Grok Build。FSB 會在你自己的機器上啟動該程式;你的任務絕不會經由 FSB 伺服器轉發。你的任務文字僅透過工具的標準輸入傳遞,別無他途。FSB 在每次執行前都會檢查這一點:若任務出現在命令列、工作目錄、環境變數或任何檔案路徑中,該次執行會被中止而非啟動。任務上限為 64 KB執行期間,該工具會透過回送連線回呼 FSB 以驅動你的瀏覽器。它由此讀取的一切內容——頁面文字、DOM 快照、試算表數值、螢幕截圖——都會回傳給該工具,因而也就到達其供應商:Anthropic 對應 Claude Code,xAI 對應 Grok Build該次執行使用你已在該工具中登入的帳戶。FSB 不會保存、讀取或傳輸你的 Anthropic 或 xAI 憑證,任何用量或費用均遵循該供應商自身的方案Grok Build 在 FSB 與你自己的目錄分開保管的設定檔目錄中執行。存放在那裡的登入憑證由 Grok 工具在其自身的登入流程中寫入由 FSB 提供的代理指令規定,密碼、CVV 值、付款卡資料與已儲存的憑證絕不得進入提示、敘述、日誌或工具參數讀取與填寫 Google SheetsFSB 可以在你已通過身分驗證的瀏覽器工作階段中操作試算表介面,從而讀取與填寫 Google Sheets 中的某個範圍。讀取某個範圍時,這些儲存格數值會傳送給你所選擇的模型,與 FSB 代表你讀取的任何其他頁面內容完全一樣。只會讀取你請求的範圍;不存在整表匯出在向 FSB 的本機工作階段記錄寫入任何內容之前,試算表內容都會被剝離。僅保留規模計數——涉及多少列、多少欄、多少個數值。試算表位址、工作表名稱、儲存格參照以及每一個儲存格數值都會被丟棄如果由於任何原因無法對某筆記錄套用該過濾,則該筆記錄會被丟棄而非儲存Remote Dashboard 與 PhantomStream 即時預覽配對 Remote Dashboard 時,FSB 可透過 PhantomStream 顯示作用中瀏覽器分頁的即時預覽。預覽串流傳送結構化的 DOM 資料而非像素,包括初始快照、MutationObserver 差異、捲動位置、自動化覆疊、對話方塊狀態、媒體播放狀態,以及透過 WebSocket 傳送的遠端控制訊息。中繼僅將這些即時預覽影格轉發給已配對的儀表板工作階段,預覽串流中的任何內容都不會保存在 FSB 伺服器上——參見上文 外部服務中的清單FSB 會啟用 PhantomStream 輸入遮蔽(maskInputs: true),因此密碼和表單控制項的值會在離開擷取頁面前遮蔽儀表板檢視器會在無指令碼的沙箱中呈現鏡像內容,並在顯示前清理鏡像的 DOM 和 CSS目前的儀表板模式會以參照方式鏡像圖片、影片和音訊。媒體位元組不會經過中繼站;檢視器可直接擷取允許的公開 HTTPS 資產或媒體 URL,而私人、內部、非 HTTPS 或其他遭封鎖的來源,則會由 PhantomStream 的失敗即封鎖擷取原則替換為預留位置無第三方追蹤FSB 不包含任何第三方分析、廣告追蹤器或跨站指紋識別。除你明確設定的 AI 供應商 APIs 之外,沒有 Cookie,也沒有第三方指令碼。FSB 向自身傳送的唯一第一方資料是下方描述的可選退出的匿名使用遙測,僅用於驅動公開的 /stats 儀表板。API 金鑰你的 API 金鑰 會在儲存前透過 AES-GCM 在本機加密。除了你設定的 AI 供應商之外,絕不會傳送到任何地方,且只在 API 請求的身份驗證頭中使用。Key 在 Chrome 儲存中以加密形式靜態儲存僅在 API 呼叫時在記憶體中解密Key 絕不會被記錄、匯出或共享自動密碼FSB 提供可選的認證資料管理器,將登入認證資料加密儲存到你的裝置。密碼不會暴露給 AI 模型,而是由內容指令碼直接填入頁面,完全繞過 AI。認證資料靜態儲存時會使用 AES-GCM、256 位元金鑰與 PBKDF2 金鑰衍生方式加密AI 分析頁面時,密碼欄位的值會被替換為 [hidden]。真實密碼絕不會出現在任何 AI 提示中自動填入由內容指令碼直接將值插入 DOM 完成,認證資料流程完全不會涉及 AI認證資料清單檢視僅顯示使用者名稱和網域。密碼只在自動填充需要時單獨解密認證資料按網域儲存,並具備父域回退(例如 accounts.google.com 會繼承 google.com)付款方式FSB 包含一個可選的付款方式保險庫,將卡片資訊保存在你的裝置上以便結帳時自動填入。卡片採用與登入憑證相同的加密與 AI 隔離機制,完整的卡號絕不會傳送給任何 AI 模型。卡片資訊(卡號、有效期限、持卡人與郵遞區號)使用與憑證相同的保險庫衍生金鑰,透過 AES-GCM 在靜態時加密當 AI 分析結帳頁面時,偵測到的卡號欄位值會在建立提示之前被替換為 [hidden]。卡號、CVV 和有效期限絕不會被納入任何 AI 提示之中自動填入由內容指令碼直接寫入頁面的 DOM 欄位完成,完全繞過 AI清單檢視僅顯示卡片暱稱與後 4 碼。完整卡號僅在填入的當下在記憶體中解密MCP 用戶端可透過 use_payment_method 請求執行付款自動填入,但在任何卡片資料寫入頁面之前,會在擴充套件內向使用者顯示確認提示除非你為某張卡片明確啟用,否則 CVV 永遠不會被持久保存;即使啟用,也會與紀錄的其餘部分一同加密語音轉文字FSB 在提示輸入框中包含一個可選的麥克風輸入。預設提供者完全在你的瀏覽器中執行;若你需要更高的準確性,可於設定中啟用可選的 OpenAI Whisper 後備方案。預設供應商:瀏覽器原生的 SpeechRecognition API。音訊由 Chrome 處理,不會透過 FSB 離開你的裝置可選的 Whisper 提供者:當 sttProvider 設定為 whisper 且已設定 OpenAI 金鑰時,錄製的音訊片段會從你的瀏覽器直接上傳到 OpenAI 的轉錄端點。FSB 從不檢視或保存該音訊麥克風僅在你按住或已切換開啟麥克風按鈕期間處於作用狀態。首次使用時 Chrome 會要求權限;FSB 不會在擴充套件資訊清單中要求麥克風存取權限轉錄結果僅插入到提示文字框中,絕不會在你選擇傳送的作用中 AI 請求之外被記錄、保存或傳輸透過不觸碰麥克風按鈕,或在 Chrome 擴充套件儲存中清除可選的 Whisper 提供者,即可完全停用語音功能防止提示詞注入網頁可能包含旨在劫持 AI 代理程式的隱藏文字。FSB 透過多層防禦確保 AI 只遵循你的指令,絕不執行嵌入在頁面內容中的指令。所有頁面內容都被包裹在 [PAGE_CONTENT] 邊界標記內,並指示 AI 永遠不要執行其中的指令在內容到達 AI 之前,清洗引擎會剝離已知的注入模式(例如“忽略以上指令”、偽造的系統提示、覆蓋請求)AI 產生的動作會在執行前進行驗證。危險 URL(javascript:、data:)和指令碼注入嘗試將被阻止只能執行固定且嚴格的已知工具允許清單。AI 無法自行發明或呼叫任意動作內容大小有上限(單值 500 字元,提示總上限 15K),限制承載資料投遞網站嵌入的不可見 Unicode 控制字元會在處理前被剝離背景代理程式與伺服器同步已於 v0.9.45rc1 淘汰。 FSB 內建的背景代理程式已由 OpenClaw 和 Claude Routines 取代,遠端控制現由「同步」分頁處理。下列說明保留給仍使用 v0.9.44 或更早版本的使用者;在目前版本中,只有在配對同步工作階段時才會連線至中繼伺服器。如果你選擇加入舊版背景代理程式伺服器同步,或配對 Remote Dashboard,中繼伺服器會協助擴充功能與儀表板通訊。伺服器會儲存:代理程式定義(名稱、計劃、目標 URL)、執行指標(權杖 數、成本、時長、成功/失敗狀態)、工作階段配對權杖除那些執行中繼資料之外,伺服器不會保存任何源自你所造訪頁面的內容——參見上文 外部服務中的清單身份驗證使用本機產生的雜湊金鑰,以及 24 小時後失效的工作階段權杖一次性配對權杖在 60 秒後失效,無法重複使用伺服器同步預設關閉,需要你在“選項”中明確啟用記憶系統FSB 的記憶系統會沉澱導覽模式和網站情報,讓自動化隨時間持續最佳化。所有記憶資料(語義、情景、過程)都儲存在 chrome.storage.local 中記憶資料不會傳送到任何外部伺服器你可在選項控制台中隨時檢視並清除記憶網站地圖和導覽模式按網域隔離,互不影響工作階段重播與螢幕截圖當 MCP 用戶端驅動 FSB 時,擴充功能會記錄代理的操作,以便你之後查看或重播該次執行。這些記錄保留在你的裝置上。仍在進行中的執行保存在 Chrome 的工作階段儲存空間中,以便在 service worker 被回收後依然留存;已完成的執行則透過 chrome.storage.local 寫入與你自己的自動化執行相同的記錄儲存空間記錄在儲存前會先經過去識別化。疑似憑證鍵下的數值、輸入到形似密碼、一次性驗證碼或金融卡欄位中的文字,以及帶簽章或攜帶權杖的 URL 參數,都會被取代。一般位址與選擇器會保留,因為沒有它們重播就無法進行已記錄的執行預設保留 30 天,可在 1 至 365 天之間調整,較舊的記錄由每日工作清理。可在進階設定中完全關閉記錄功能螢幕截圖影像絕不會寫入該記錄。僅保留尺寸、位元組大小等擷取中繼資料由 MCP 用戶端請求的螢幕截圖,會由本機服務以僅限擁有者的權限保存為你自己磁碟上的檔案,並在七天後自動刪除。該影像同時也會回傳給發起請求的用戶端,因而也會到達該用戶端的模型匿名使用遙測FSB v0.9.69 引入了一個可選擇退出的匿名使用情況遙測管道,讓專案可以發布彙總的採用資料(參見 /stats),且絕不觸及你瀏覽的頁面。唯一的位置訊號是伺服器在接收時從你的請求 IP 衍生出的粗略國家/州標籤(絕不來自頁面內容),且僅以彙總形式保留——參見下方的 地區(州級)指標。遙測預設開啟,但可透過單一開關停用,並且可應請求刪除每次安裝的資料。我們收集的內容每次安裝隨機產生的 UUID,儲存於 chrome.storage.local 的鍵 fsbInstallUuid 之下。UUID 於本機產生,永遠不會與你的身分關聯。所使用的 MCP 用戶端名稱(例如 Claude Code、Cursor、Codex),取自固定的允許清單。工作階段中使用的模型名稱(例如 grok-4-fast、claude-opus-4),取自固定的允許清單。每個工作階段的彙總輸入/輸出權杖數量。你的安裝上活躍的 FSB 代理數量(一個整數值)。我們不收集的內容頁面 URLs、主機名稱或瀏覽歷史紀錄。提示、指令、工作描述,或你傳送給模型供應商的任何自然語言文字。頁面 DOM、螢幕擷取畫面、頁面內容、網站 API 承載資料或 AI 回應。明文 IP 位址。伺服器僅出於兩個目的暫時且內聯地使用請求 IP——用於限流的每日輪換加鹽雜湊,以及衍生粗略的國家/州標籤(見下文)——隨後立即將其丟棄。明文 IP 絕不會被儲存或記錄。姓名、使用者名稱、帳號代號,或任何自由文字身分欄位。電子郵件地址、電話號碼,或聯絡資訊。地區(州級)指標伺服器在接收時,會從請求的 IP 位址衍生粗略的國家與美國州(行政區)標籤,使用自行託管的 DB-IP IP-to-City Lite 資料集及自有查詢機制;並非即時第三方地理定位服務,也絕不使用 MaxMind。明文 IP 會在處理時直接使用後立即丟棄,只保留衍生標籤。地區僅儲存在每日彙總中,且位於 k≥5 的匿名閾值之後:某一天內不同安裝數少於 5 的任何州都會合併到單一「Other」桶中(當該合併計數本身低於 5 時則完全抑制)。任何單一州標籤都絕不會代表少於 5 次安裝。不存在按安裝的位置剖析。粗略標籤僅存在於短暫的原始事件(由 7 天保留策略刪除)和經 k≥5 過濾的每日彙總中;我們絕不建立或保留從你的安裝到某個地點的持久對應。地理定位資料來自 DB-IP(https://db-ip.com)。保留期原始事件保留 7 天。每日彙總(每安裝每天一列)保留 365 天。全域聚合(每天一列,無按安裝維度)無限期保留,以便 /stats 上的歷史圖表保持穩定。如何選擇退出開啟 FSB 控制面板,捲動至「進階設定」,將 傳送匿名使用資料 開關關閉。變更立即生效;之後不會再從你的安裝傳送事件。如何抹除你的資料如要請求刪除與你的安裝相關的所有遙測資料列(GDPR 第 17 條),請查詢你的 fsbInstallUuid:前往 Chrome DevTools → 應用程式 → 儲存空間 → 擴充功能儲存空間,然後傳送一次 HTTP 請求:curl -X POST -H "Content-Type: application/json" \ +-d '"install_uuid":"<your-uuid>"' \ +https://full-selfbrowsing.com/api/telemetry/forgetLimited Use 合規聲明FSB 的匿名使用遙測僅用於計算在 full-selfbrowsing.com/stats 公開展示的聚合使用統計。資料從不出售、從不與第三方共享、從不用於廣告,且從不用於訓練任何機器學習模型。此承諾滿足 Chrome Web Store 的 Limited Use 要求。聚合的公開指標我們在 /stats 發布來自此遙測管線的聚合指標。僅展示計數和總數;每安裝的列從不公開。同意與稽核控制FSB 的自動化立場採選擇退出制:不在拒絕清單中的來源會繼承使用者可設定的全域預設值,目前出廠值為 Auto;明確的個別來源原則則可將來源設為 Off、Ask 或 Auto。稽核日誌會在本機保留且有期限,控制面板也提供匯出與清除功能。服務拒絕清單仍是強制封鎖。無論全域預設值或已儲存的個別來源原則為何,遭拒絕的來源都無法啟用。敏感來源可在 Auto 模式下執行讀取,但寫入前會再次強制檢查個別來源的變更操作加入設定。非敏感來源可在控制面板的「同意與稽核」區段選擇退出,或改為 Ask。每次能力呼叫都會記錄於經過遮蔽、僅可附加的本機稽核日誌中。絕不會儲存任何引數、權杖、Cookie 或回應內容。開源FSB 完全採用 MIT 授權條款開放原始碼。你可以稽核每一行程式碼,驗證這些隱私權聲明。原始碼可在 GitHub 取得。本政策的變更若本政策更新,變更將體現在頁面頂部的“最後更新”日期。重要變更也會在專案的 GitHub 釋出說明中註明。聯絡方式如果你對本隱私權政策或 FSB 的資料處理方式有任何疑問,請在 GitHub Issues 提出問題。 + + src/app/pages/privacy/privacy-history-archive.component.html + 7,238 + + May – July 2026v0.9.90 — Site API capabilities, Remote Dashboard and PhantomStream, Payment Methods, Speech-to-Text, Region metric (full archived text) 2026 年 5 月 – 7 月v0.9.90 — 網站 API 能力、Remote Dashboard 與 PhantomStream、付款方式、語音轉文字、地區指標(完整封存文本) @@ -9615,8 +9635,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Last updated: August 2026 - 最後更新:2026 年 8 月 + Last updated: September 2026 + 最後更新:2026 年 9 月 src/app/pages/privacy/privacy-page.component.html 6,9 @@ -10543,8 +10563,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. - FSB v0.9.69 引入了一個可選擇退出的匿名使用情況遙測管道,讓專案可以發布彙總的採用資料(參見 /stats),且絕不觸及你瀏覽的頁面。唯一的位置訊號是伺服器在接收時從你的請求 IP 衍生出的粗略國家/州標籤(絕不來自頁面內容),且僅以彙總形式保留——參見下方的 地區(州級)指標。遙測預設開啟,但可透過單一開關停用,並且可應請求刪除每次安裝的資料。 + FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request. + FSB v0.9.69 引入了一個可選擇退出的匿名使用情況遙測管道,讓專案可以發布彙總的採用資料(參見 /stats),且絕不觸及你瀏覽的頁面。唯一的位置訊號是伺服器在接收時從你的請求 IP 衍生出的粗略國家/州標籤(絕不來自頁面內容),且僅以彙總形式公開——參見下方的 地區(州級)指標。遙測預設開啟,但可透過單一開關停用,並且可應請求刪除每次安裝的資料。 src/app/pages/privacy/privacy-page.component.html 197,199 @@ -10631,8 +10651,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Plaintext IP addresses. The server uses the request IP transiently and inline for exactly two purposes — a daily-rotating-salt hash for rate limiting, and deriving a coarse country/state label (see below) — then discards it immediately. The plaintext IP is never stored or logged. - 明文 IP 位址。伺服器僅出於兩個目的暫時且內聯地使用請求 IP——用於限流的每日輪換加鹽雜湊,以及衍生粗略的國家/州標籤(見下文)——隨後立即將其丟棄。明文 IP 絕不會被儲存或記錄。 + Plaintext IP addresses. The server uses the request IP transiently and inline for exactly three purposes — a daily-rotating-salt hash for rate limiting, deriving a coarse country/state label (see below), and noting whether the address is IPv4 or IPv6 — then discards it immediately. The plaintext IP is never stored or logged. + 明文 IP 位址。伺服器僅出於三個目的暫時且內聯地使用請求 IP——用於限流的每日輪換加鹽雜湊、衍生粗略的國家/州標籤(見下文),以及記錄該位址是 IPv4 還是 IPv6——隨後立即將其丟棄。明文 IP 絕不會被儲存或記錄。 src/app/pages/privacy/privacy-page.component.html 213,214 @@ -10663,24 +10683,24 @@ https://full-selfbrowsing.com/api/telemetry/forget - The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label is kept. - 伺服器在接收時,會從請求的 IP 位址衍生粗略的國家與美國州(行政區)標籤,使用自行託管的 DB-IP IP-to-City Lite 資料集及自有查詢機制;並非即時第三方地理定位服務,也絕不使用 MaxMind。明文 IP 會在處理時直接使用後立即丟棄,只保留衍生標籤。 + The server derives a coarse country and US-state (subdivision) label from your request IP at ingest, using a self-hosted DB-IPIP-to-City Lite dataset and our own lookup — not a live third-party geolocation service, and never MaxMind. The plaintext IP is consumed inline and discarded; only the derived label and the address family (IPv4 or IPv6) are kept. + 伺服器在接收時,會從請求的 IP 位址衍生粗略的國家與美國州(行政區)標籤,使用自行託管的 DB-IP IP-to-City Lite 資料集及自有查詢機制;並非即時第三方地理定位服務,也絕不使用 MaxMind。明文 IP 會在處理時直接使用後立即丟棄,只保留衍生標籤與位址類型(IPv4 或 IPv6)。 src/app/pages/privacy/privacy-page.component.html 220,221 - Region is stored only in the daily aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs on a given day collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No individual state label ever represents fewer than 5 installs. - 地區僅儲存在每日彙總中,且位於 k≥5 的匿名閾值之後:某一天內不同安裝數少於 5 的任何州都會合併到單一「Other」桶中(當該合併計數本身低於 5 時則完全抑制)。任何單一州標籤都絕不會代表少於 5 次安裝。 + Region is published only in aggregate, behind a k≥5 anonymity floor: any state with fewer than 5 distinct installs collapses into a single “Other” bucket (suppressed entirely when even that combined count is below 5). No published state label ever represents fewer than 5 installs. + 地區僅以彙總形式公開,且位於 k≥5 的匿名閾值之後:不同安裝數少於 5 的任何州都會合併到單一「Other」桶中(當該合併計數本身低於 5 時則完全抑制)。任何公開的州標籤都絕不會代表少於 5 次安裝。 src/app/pages/privacy/privacy-page.component.html 221 - There is no per-install location profile. The coarse label lives only on the short-lived raw event (dropped by the 7-day retention) and in the k≥5-floored daily rollup; we never build or retain a durable mapping from your install to a place. Geolocation data is by DB-IP (https://db-ip.com). - 不存在按安裝的位置剖析。粗略標籤僅存在於短暫的原始事件(由 7 天保留策略刪除)和經 k≥5 過濾的每日彙總中;我們絕不建立或保留從你的安裝到某個地點的持久對應。地理定位資料來自 DB-IP(https://db-ip.com)。 + The coarse label is stored on the raw event (dropped by the 7-day retention) and on your install's daily rollup, which is kept for 365 days so /stats can count each install once by its most recent region. It is never an IP address, city, or coordinates; it is deleted with the rest of your per-install data when you request erasure; and it is only published behind the k≥5 floor above. Geolocation data is by DB-IP (https://db-ip.com). + 粗略標籤儲存在原始事件(由 7 天保留策略刪除)以及你的安裝的每日彙總中;每日彙總保留 365 天,讓 /stats 依每次安裝最近的地區只計算一次。該標籤絕不是 IP 位址、城市或座標;當你請求刪除時,它會與你安裝的其餘資料一併刪除;而且只會在上述 k≥5 閾值之後公開。地理定位資料來自 DB-IP(https://db-ip.com)。 src/app/pages/privacy/privacy-page.component.html 222,223 @@ -10695,8 +10715,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. - 原始事件保留 7 天。每日彙總(每安裝每天一列)保留 365 天。全域聚合(每天一列,無按安裝維度)無限期保留,以便 /stats 上的歷史圖表保持穩定。 + Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable. + 原始事件保留 7 天。每日彙總(每安裝每天一列,包括粗略的地區標籤)保留 365 天。全域聚合(每天一列,無按安裝維度)無限期保留,以便 /stats 上的歷史圖表保持穩定。 src/app/pages/privacy/privacy-page.component.html 226,228 @@ -18159,8 +18179,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Regional distribution from today's hourly aggregate. - 來自今日每小時彙總的地區分布。 + Where installs were last seen, by coarse region, over the past 365 days. + 過去 365 天內各安裝最後出現的位置,依粗略地區顯示。 src/app/pages/stats/stats-page.component.html 104,106 @@ -18371,8 +18391,8 @@ https://full-selfbrowsing.com/api/telemetry/forget - Globe showing today's hourly FSB regional distribution - 顯示今日每小時 FSB 地區分布的地球儀 + Globe showing where FSB installs were last seen over the past 365 days, by coarse region + 顯示過去 365 天內 FSB 安裝最後出現位置(依粗略地區)的地球儀 src/app/pages/stats/stats-page.component.ts 308 diff --git a/showcase/angular/src/styles.scss b/showcase/angular/src/styles.scss index c1ecb4f33..fcd7cf72f 100644 --- a/showcase/angular/src/styles.scss +++ b/showcase/angular/src/styles.scss @@ -1,8 +1,11 @@ @import url('https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.6.0/css/all.min.css'); @import url('https://unpkg.com/@phosphor-icons/web@2.1.1/src/regular/style.css'); -/* Shared showcase foundation: tokens, reset, typography, and utilities only. */ +/* Shared showcase foundation: tokens, reset, typography, and utilities only. + * color-scheme is required so native form controls (the footer