ARMORY BROWSER COMPANION · VERSION 0.1Privacy Policy
Effective: September 23, 2026
Publisher: Jay Qin
Contact: jayqin04@gmail.com
Armory Browser Companion helps you capture web research and optionally deliver it to agents through a relay you configure. This page describes the extension and its companion relay. The application source is private; this public site contains only this policy.
1. What is processed
- For tasks you authorize: the requested URL and purpose, page title, visible page text, derived Markdown, links, capture time, truncation/quality flags, and job status. Captured content may contain personal or sensitive information if present on the page.
- Connection settings: the relay address and a separate browser access token. The extension does not ask for your Claude, Codex, or website passwords.
- Local task metadata: URLs, task purposes, status, timestamps, tab identifiers and brief error messages. The extension does not collect general browsing history outside its tasks.
The extension does not read cookie stores, browser passwords, input-field values, or authentication tokens from website storage. It does not capture screenshots or audio. Page credentials stay in the website's own browser login flow. Do not authorize collection of pages whose content you do not want your chosen relay or agent to receive.
2. Consent and automatic operation
Before automatic collection and transfer, you approve a website origin for the displayed relay. This approval lasts for at most eight hours in the current browser session and can be paused or revoked in the side panel. A new origin needs separate approval. Within an approved scope, tasks run and upload results automatically; a separate click is not required for each result.
If accessible content is blocked, the extension asks you to handle login in the browser. At the task's deadline it returns to an anonymous request without website credentials. Usable partial content is labeled degraded; an empty or detected login-wall response is not reported as a successful capture. An open side panel is required for queue processing; closed/offline time may delay the fallback until reconnection.
3. Recipients and purposes
By default the extension has no built-in cloud endpoint. Authorized results are sent to the relay you configure and may then be retrieved by the agent connected to that relay. Both the relay address and scope are visible before you approve automatic transfer. A local-only capture is retained locally unless you export it. The publisher does not operate a hosted relay as part of this candidate release and does not receive your captures by default.
Data is used to perform and deliver the requested capture, show task status, and coordinate human assistance. The publisher does not sell extension data, use it for advertising, or train models on it. Your selected agent and relay operator may have their own policies and retention practices; review those before connecting them. Support email is used to answer your request; do not send passwords, access tokens or confidential captures.
4. Storage and retention
- The browser token, origin approvals and recent content previews are in Chrome session storage, not synced extension storage. They are cleared when that browser session is cleared. Session approvals expire within eight hours. The extension keeps up to 12 task previews for the current relay and a local capture preview.
- The relay address and up to 100 task metadata records per configured relay are stored locally until you clear the extension's data or uninstall it. Disconnecting removes the active token and current consent but does not erase existing task history or previously transmitted data.
- The companion relay uses a local SQLite database with restrictive file permissions. Task records and results expire after seven days by default and are removed lazily on later requests, not by a guaranteed scheduled deletion. Filesystem backups may retain copies.
- The development relay does not encrypt the database itself. Use an encrypted device/disk; a remote operator must add HTTPS, encrypted storage, access controls and appropriate retention before handling sensitive or production data. A file permission is not encryption.
5. Security and control
Remote relay connections require HTTPS; HTTP is allowed only on loopback for local development. Browser and agent credentials are separate. Website access is optional and requested for a selected origin; remote agents cannot grant site permissions. No remote executable code is downloaded by the extension. You can pause automation, revoke a session's site consent, disconnect, remove website permissions in Chrome's extension settings, export local data, or uninstall the extension.
To delete local extension data, remove the extension or clear its storage through Chrome. To delete relay records immediately, contact your relay operator; on a self-hosted instance stop the relay and remove its job database and associated journal/backup files. Deleting local data does not delete copies already delivered to an agent. Ask that recipient separately. No security measure can guarantee absolute security.
6. This policy website
This static page has no analytics, tracking pixels, cookies set by its code, forms, or third-party scripts. It is hosted on GitHub Pages; GitHub may process request logs under its own privacy statement.
7. Changes and contact
Updates will be posted here with a revised effective date. Contact Jay Qin at jayqin04@gmail.com with privacy questions. For data held by a self-hosted relay or a third-party agent, contact that operator as well.
中文摘要
发布者:Jay Qin,邮箱:jayqin04@gmail.com。扩展的主要流程是自动抓取 → 必要时请求人工登录 → 等待超时后匿名自动回退。首次对站点与中继进行会话授权后,在最多 8 小时内自动采集并回传,不要求每个任务都点击批准。
扩展会处理任务 URL、目的、页面可见正文、标题、链接和状态;不读取 Cookie 库、网站密码或表单输入值。正文可能含个人信息,请仅授权你愿意交给所选中继和 Agent 的内容。默认不连接发布者服务器,无广告或遥测。私有源码不在此公开页面发布。
Token、授权和预览保留在浏览器会话存储;任务元数据保存在本地。中继默认保留 7 天并在后续请求时清理;开发版 SQLite 本身未加密,生产远程部署需另行配置 HTTPS、加密存储与访问控制。暂停或撤销授权不撤回已经传出的内容;删除外部副本需联系对应中继或 Agent 运营方。侧栏关闭时任务处理暂停,重连后处理已到期任务。