Legal
Omnesis Browser Extension Privacy Policy
Last updated: 2026-09-05
Summary
Omnesis Browser Capture reads supported HTTPS pages only after you explicitly grant Chrome page access. It extracts readable text and visit metadata and sends them directly to the HTTPS Omnesis gateway you pair with the extension. Ordinarily that gateway runs on hardware you control. If you deliberately select a developer-operated gateway, the developer receives the data as that gateway's operator. The extension contains no analytics, advertising, or crash-reporting SDK.
What the extension accesses
- Readable page content — the page title and readable text converted to Markdown. Raw HTML, scripts, images, and page pixels are not sent. Form controls and editable regions are removed before extraction. Readable page text, titles, and URLs can still contain sensitive information, so review the disclosure and exclusions before enabling capture.
- Visit metadata — the normalized page URL, domain, title, visit time, and focused dwell duration.
- Pairing information — the gateway HTTPS URL, one-time pairing code, a browser device identifier, the Chrome profile name you enter during pairing, and a bearer token limited to writing the browser-capture source. Chrome does not expose its local profile name to extensions; the entered label and stable device identifier are attached to each visit. A page document is one snapshot per URL, so its metadata records the profile whose capture most recently changed that snapshot. The code is sent to the selected gateway for redemption. If that request times out, the same code is sent again with the same request identifier so the gateway can return the credential it already issued; the extension keeps only a hash of the code and that identifier, for at most fifteen minutes, and never the code itself.
- Local controls and delivery state — Chrome profile label, the paired gateway's reported version, recent status, a bounded retry queue, and a copy of the capture settings the paired gateway holds (pause, excluded domains, pages you deleted for good).
The extension does not run in incognito windows. Chrome-internal pages, pages on the domains you exclude, pages you deleted for good, sign-in, registration, checkout and payment pages, and pages carrying a password field are not captured. These capture settings are stored on your paired gateway and apply to every browser paired with it. Domains a dedicated Omnesis source already covers are also skipped, so a page is not collected twice.
Because a signed-in page can contain identifying details, communications, financial or health information, authentication-related text, or location information, readable text from those categories may be included when you allow capture on that page. Omnesis does not target or infer these categories in the extension. Exclude sensitive domains, pause capture, or remove page access whenever you do not want a page captured.
Where data goes
Captured content and visit metadata are sent over HTTPS directly to the gateway you approve during pairing. Pair only with an endpoint and operator you trust. The extension developer does not receive this data merely because you installed the extension. The developer does receive it if you deliberately pair with a developer-operated gateway.
If the gateway operator enables a cloud model for indexing or agent features, the gateway may send the inputs needed for that configured role to the selected model provider. The extension does not choose or contact that provider; the gateway operator controls that processing and the provider's terms apply.
Chrome permissions
- Optional HTTPS page access lets the extension read rendered pages. It is requested during pairing, not at installation, and removed when unpairing.
- Storage retains pairing, a copy of the gateway's capture settings, bounded queued captures, and status in the extension profile.
- Alarms lets the Manifest V3 worker retry queued delivery and refresh health while Chrome is running.
-
Scripting lets the extension register the capture script after page
access is granted. The popup uses that same optional page grant to report capture
status; the extension does not request the
tabsoractiveTabpermission.
Retention and control
Successfully delivered queue entries are removed from local extension storage. Pending entries — which hold the captured page text itself — survive browser and worker restarts so temporary outages do not lose data, but the queue has fixed item and byte limits and evicts old entries when those limits are reached. Credential-bearing query parameters (tokens, signatures, one-time codes, passwords, session ids) are removed from a page's address before it is recorded, so a password-reset link or a signed download link is stored without its secret. The pairing credential remains until you unpair or clear the extension's data.
- Pause capture from the extension popup; the pause applies to every browser paired with the same gateway.
- Exclude any domain from the options page or the popup. The exclusion is stored on your gateway and applies to every browser paired with it; you can also delete the pages the domain already contributed.
- Unpair to remove the gateway credential, pending captures, recent delivery state, the copy of the capture settings, and the extension's HTTPS page-access grant. The Chrome profile label and random installation identifier remain so your browser identity survives a later re-pair; removing the extension or clearing its data removes them. Excluded domains stay on the gateway.
- Remove the extension or clear its data to remove its remaining local storage.
- Delete data already delivered using the controls provided by the paired gateway.
Data practices
We do not sell, rent, or use extension data for advertising, credit, lending, profiling, or unrelated purposes. We do not transfer extension data to data brokers. Data is handled only to provide pairing, browser capture, delivery, status, and the controls described above. The extension's use and transfer of data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
The developer does not permit humans to read extension user data. Any exceptional access is limited to cases allowed by the Limited Use requirements: your affirmative consent for specific data, security or abuse investigation, legal compliance, or internal processing of aggregated and anonymized data. For gateways not operated by the developer, the extension does not provide the developer with a channel into your paired gateway.
Changes and contact
Material changes will be reflected here and the last-updated date will change. Questions and security reports can be sent to contact@omnesis.dev.