Archived copy of the privacy policy as it stood in August 2026, before the September 2026 update.
+ +TLDR: FSB runs inside your browser, and no browsing data is collected by FSB servers. AI calls go directly from your browser to the provider you choose. API keys and credentials are encrypted locally, and memory data stays on your device. If you install the optional local agent service, FSB can also be driven by an MCP client running on your own machine over a loopback connection, and by coding-agent CLIs you have already installed. The only data that ever leaves your machine for FSB is opt-out anonymous usage telemetry that powers the public /stats page. If you pair Remote Dashboard, transient live-preview frames can pass through the relay during the session, but they are not stored. Everything is open source and auditable.
+ +FSB operates entirely within your browser. When you initiate an automation task, the extension may inspect the active tab's DOM (Document Object Model) and, when you invoke a capability, make same-origin site API requests from your browser session.
+FSB's capability layer can call a site's own first-party API from the page context, using your already-authenticated browser session. These requests run locally in Chrome; first-party cookies or site auth may be attached by the browser for that target site, but FSB does not return, store, log, or send cookies, tokens, CSRF values, request bodies, or response bodies to FSB servers.
+Capability invocations follow FSB's consent controls and are recorded only in the redacted local audit log: origin, capability slug, method, side-effect class, consent decision, and outcome. The audit log never stores invocation arguments, request bodies, response bodies, cookies, tokens, CSRF values, or site response payloads.
+ +To run web automation, FSB declares the following permissions in its Chrome manifest. Each is used only for the documented purpose; nothing is sent off-device on the strength of any of them.
+activeTab, scripting, tabs, windows, sidePanel, and host permission <all_urls>: read and write the active tab, inject the automation content script, list and switch tabs, and render the side paneldebugger: attach the Chrome DevTools Protocol for coordinate-based clicks, drag, and key-hold actions that the regular DOM API cannot perform. webNavigation: observe navigation start/finish events so automation waits for the right momentstorage, unlimitedStorage: store your settings, credentials, payment methods, and memory in chrome.storage.local on your device. Unlimited storage lifts the default 10 MB quota so memory and session logs can grow without hitting a wallclipboardWrite: write copy-to-clipboard results from automation. alarms: schedule background housekeeping. offscreen: host the speech-to-text recorder in a hidden document because service workers cannot capture audio directlynativeMessaging: start the optional local agent service described under Local Agent Service and Native Messaging below. Nothing about the pages you visit crosses that channel. system.memory: read the total installed RAM figure only, so FSB can suggest a sensible limit on how many agents run at once. The available-memory and per-processor breakdowns are never read, and the figure never leaves the extensionMicrophone access for speech-to-text is not declared in the manifest. Chrome shows its own permission prompt the first time you use the mic button.
+ +All settings and data are stored locally in Chrome's extension storage, with sensitive values encrypted at rest as described in the sections below.
+chrome.storage.localFSB communicates with external AI providers only when you configure and use a hosted provider. If you use LM Studio, AI requests stay on your machine through its local OpenAI-compatible server. The choice of provider and what data is sent is under your control.
+FSB can be driven by an MCP client running on your own machine. That requires a small local agent service which you install yourself, and the nativeMessaging permission exists solely so the extension can start it. Chrome cannot launch a local program directly, so this is the only supported mechanism.
io.github.fullselfbrowsing.fsb_native_host is registered only by an explicit action you take, by running fsb-mcp-server install --native-host. The extension cannot install it, and its registration names one permitted extension originwake or bootstrap, and a locally generated correlation identifier; it receives that identifier back with an outcome and a reason drawn from a fixed list. Any additional field is rejected outright and messages are capped at 4 KB. No URL, tab, page content, or DOM data exists anywhere in this schema127.0.0.1 by default and whenever FSB starts itFSB can hand a task to a coding-agent command-line tool you have already installed, currently Claude Code or Grok Build. FSB starts that program on your own machine; your task is never proxied through FSB servers.
+FSB can read and fill a range in Google Sheets by driving the spreadsheet interface in your own already-authenticated browser session.
+When you pair Remote Dashboard, FSB can show a live preview of the active browser tab using PhantomStream. The preview streams structured DOM data instead of pixels: an initial snapshot, MutationObserver diffs, scroll position, automation overlays, dialog state, media playback state, and remote-control messages over WebSocket.
+maskInputs: true), so passwords and form-control values are masked before they leave the captured pageFSB does not include any third-party analytics, ad trackers, or cross-site fingerprinting. There are no cookies and no third-party scripts beyond the AI provider APIs you explicitly configure. The one piece of first-party data FSB sends home is the opt-out Anonymous Usage Telemetry described below, used solely to power the public /stats dashboard.
+ +Your API keys are encrypted locally using AES-GCM before being stored. They are never transmitted anywhere except to the AI provider you configured, and only as authentication headers in API requests.
+FSB includes an optional credential manager that stores login credentials encrypted on your device. Passwords are never exposed to AI models. They are filled directly into pages by the content script, bypassing the AI entirely.
+[hidden]. The actual password is never included in any AI promptFSB includes an optional payment-method vault that stores card details on your device for checkout auto-fill. Cards are treated with the same encryption and AI isolation as login credentials, and the full card number is never sent to any AI model.
+[hidden] before the prompt is built. Card numbers, CVV, and expiry are never included in any AI promptuse_payment_method, but the user is shown an in-extension confirmation prompt before any card data is written into the pageFSB includes an optional microphone input for the prompt box. The default provider runs entirely in your browser; an optional OpenAI Whisper fallback can be enabled in settings if you want higher accuracy.
+SpeechRecognition API. Audio is processed by Chrome and never leaves your device through FSBsttProvider is set to whisper and an OpenAI key is configured, recorded audio chunks are uploaded directly from your browser to OpenAI's transcription endpoint. FSB never sees or stores the audioWeb pages can contain hidden text designed to hijack AI agents. FSB implements multi-layered defenses to ensure the AI only follows your instructions, never instructions embedded in page content.
+[PAGE_CONTENT] boundary markers, and the AI is instructed to never follow instructions found within these markersjavascript:, data:) and script injection attempts are blockedDeprecated in v0.9.45rc1. FSB's built-in Background Agents have been superseded by OpenClaw and Claude Routines, with remote control now handled by the Sync tab. The disclosures below are retained for users still running v0.9.44 or earlier; on current builds the relay server is only contacted when you pair a Sync session.
+If you opt into legacy Background Agents server sync or pair Remote Dashboard, a relay server facilitates communication between your extension and the dashboard.
+FSB's memory system stores navigation patterns and site intelligence to improve automation over time.
+chrome.storage.localWhen an MCP client drives FSB, the extension records what the agent did so you can review or replay the run afterwards. These records stay on your device.
+chrome.storage.local through the same history store your own automation runs useFSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.
+ +chrome.storage.local under the key fsbInstallUuid. The UUID is generated locally and never tied to your identity.grok-4-fast, claude-opus-4), drawn from a fixed allowlist.Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.
+ +Open the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.
+ +To request erasure of all telemetry rows associated with your install (GDPR Article 17), look up your fsbInstallUuid in Chrome DevTools → Application → Storage → Extension storage, then send a single HTTP request:
curl -X POST -H "Content-Type: application/json" \
+-d '{{ '{' }}"install_uuid":"<your-uuid>"{{ '}' }}' \
+https://full-selfbrowsing.com/api/telemetry/forget
+
+ FSB's anonymous usage telemetry is used only to compute aggregate usage statistics displayed publicly at full-selfbrowsing.com/stats. The data is never sold, never shared with third parties, never used for advertising, and never used to train any machine-learning models. This commitment satisfies the Chrome Web Store's Limited Use requirement.
+ +We publish aggregated metrics derived from this telemetry pipeline at /stats. Only counts and totals are shown; no per-install row is ever exposed.
+ +FSB's automation posture is opt-out: non-denylisted origins inherit a user-configurable global default that currently ships as Auto, while explicit per-origin policies can set an origin to Off, Ask, or Auto. Audit-log retention is local and bounded, with export and clear controls available from the Control Panel.
+FSB is fully open source under the MIT License. You can audit every line of code to verify these privacy claims. The source code is available on GitHub.
+ +If this policy is updated, the changes will be reflected by the "Last updated" date at the top of this page. Significant changes will also be noted in the project's GitHub release notes.
+ +If you have questions about this privacy policy or FSB's data handling, please open an issue on GitHub Issues.
+Last updated: August 2026
+Last updated: September 2026
FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), kept only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.
+FSB v0.9.69 introduced an opt-out anonymous usage telemetry pipeline so the project can publish aggregate adoption numbers (see /stats) without ever touching the pages you browse. The only location signal is a coarse country/state label the server derives from your request IP at ingest (never from page content), published only in aggregate — see Region (state-level) metric below. Telemetry is on by default but can be disabled with a single toggle, and the per-install data can be erased on request.
Raw events are retained for 7 days. Daily rollups (one row per install per day) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.
+Raw events are retained for 7 days. Daily rollups (one row per install per day, including the coarse region label) are retained for 365 days. Global aggregates (one row per day, no per-install dimension) are retained indefinitely so historical charts on /stats remain stable.
Open the FSB Control Panel, scroll to Advanced Settings, and toggle Send anonymous usage data off. The change takes effect immediately; no further events will be sent from your install.
diff --git a/showcase/angular/src/app/pages/stats/stats-page.component.html b/showcase/angular/src/app/pages/stats/stats-page.component.html index aa292f364..8a2d82970 100644 --- a/showcase/angular/src/app/pages/stats/stats-page.component.html +++ b/showcase/angular/src/app/pages/stats/stats-page.component.html @@ -101,7 +101,7 @@