YOUR CONTROL

Privacy & page context

YourKawai works without sending browsing context. Sharing is optional and off by default.

01

What you can choose to share

For each message sent while enabled, the extension may send the website hostname, page title, meta description, and first H1.

Selected text is never included unless you separately enable it for that message. It is read only when you send that message.

02

What page context does not collect

  • The full page, DOM, article text, or background page content.
  • Form fields, passwords, payment details, cookies, authentication tokens, or editable content.
  • Browsing history, inactive tabs, or data in the background.
03

Control and safeguards

  • The setting is off by default and can be turned off at any time.
  • No additional Chrome permissions are requested. The setting is stored locally in the extension.
  • Context is sanitized and limited before leaving the page. The API does not persist it and sends it over HTTPS only as part of the AI request.

When enabled, this context is included in the request to the configured AI provider. Do not enable it on pages whose metadata you do not want to share.

04

Optional accounts

If you create an account, the server stores your email address, a password hash, revocable session records, your tier and minimal security events. Session, verification and reset tokens are stored as hashes. Your local conversations and page-context preferences are not uploaded into the account database.

Security audit events are scheduled for deletion after 90 days. Expired session records are removed after 30 days, and expired one-time tokens are removed during maintenance. Daily account usage stores counts, not message content. Operational web-server logs may contain connection metadata.

You can sign out or revoke individual sessions from Account. Cloud synchronization, payments and self-service account export/deletion are not enabled in this test phase.