Skip to main content
Last updated: September 8, 2026

Scope and contact

This policy covers Browser MCP, the Chrome extension published by ricsam, and the managed preview at https://browser-mcp.click (formerly https://browser-mcp-fzftomuy8592.r5d.app, now retained only for safe page redirects and retirement responses). For privacy or account-deletion requests, contact privacy@browser-mcp.click. For support, use support@browser-mcp.click; for security reports, use security@browser-mcp.click. Please do not send passwords, access tokens, or sensitive page captures by email. If you connect to a self-hosted or third-party upstream, that operator controls its server and database and is responsible for its own handling of your data. Your MCP client and AI/model providers are also separate services. Review their policies before connecting.

Data we handle and why

Browser MCP’s purpose is to connect a browser you explicitly authorize to a trusted MCP client for browser inspection and automation.
  • Account and authentication: signing in to the managed service with GitHub supplies your account identifier, name, email address, and profile image. The server stores account/session records and encrypted OAuth credentials to authenticate you. Browser connection and MCP credentials are stored as hashes server-side; pending device credentials are encrypted. Session records may include IP address and user-agent information.
  • Local extension settings: your chosen upstream, browser name, consent/paused state, connection credential, and temporary device-pairing proof are stored in chrome.storage.local in your Chrome profile, not Chrome Sync. These support pairing and reconnecting after the popup or service worker closes. Local profile access can expose these credentials.
  • Browser metadata and activity: the server stores browser registrations, last-seen times, credential metadata, and audit events containing tool name, status, and time. Authorized commands may list open tab URLs/titles, navigate tabs, click, type, press keys, and scroll. The extension does not passively log all your keystrokes or read Chrome’s history database.
  • Website content: when an authorized MCP client requests a snapshot, screenshot, or JavaScript evaluation, page text, images, links, form contents, and results are relayed to that client through the selected upstream. The extension can also send client-supplied input and JavaScript to a page. Access can include signed-in websites.
  • Sensitive information: depending on the pages and tasks you authorize, relayed website content may contain personal identifiers, health information, financial/payment information, authentication information, personal communications, location information, and other private content. Tab URLs/titles may reveal browsing history. Browser MCP does not need you to provide health or financial information to create an account; these categories are disclosed because requested page access can expose them. Password values are omitted from structured snapshots, but screenshots and arbitrary page JavaScript are not a general sensitive-data filter.
The managed application does not intentionally persist page contents, screenshots, tool arguments, or JavaScript results in its database/audit log. Results exist transiently while requests are processed. Infrastructure may process IP addresses and operational/security logs. This is not a promise that data is invisible to infrastructure operators or third-party clients.

How data moves and who receives it

HTTPS/WSS protects traffic in transit for HTTPS upstreams. Loopback HTTP is supported for local development only. This is not end-to-end encryption that hides browser results from the upstream operator. Recipients include:
  • The upstream operator you select; for the managed preview this is ricsam and the hosting infrastructure used to operate the service (R5D-managed Kubernetes hosting and Cloudflare public ingress).
  • MCP clients with a valid credential for your browser, and AI/model services those clients use. You choose these integrations; their separate policies govern their copies of data.
  • GitHub, which provides managed sign-in and receives the OAuth login interaction. Browser tool results are not sent to GitHub by the authentication integration.
  • Service providers needed to deliver hosting, transport, and security, and authorities when disclosure is legally required.
Cloudflare R2 distributes public extension/chart downloads. Mintlify hosts documentation. Requests to those separate sites are subject to those providers’ policies; browsing documentation or downloading a ZIP is separate from relaying your browser’s tool results.

Limited use

We use data only to provide the disclosed browser automation, account authentication, reliability, and security features. We do not sell user data, use it for advertising, train models on it, or use it to determine creditworthiness or for lending. Transfers are limited to delivering these features at your direction, necessary service providers, and legally required disclosures. We do not use or transfer data for purposes unrelated to Browser MCP’s single purpose. Browser MCP’s use and transfer of information received through Chrome APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Selecting an external AI provider does not make its retention/training policies the same as ours.

Retention and deletion

  • Extension connection settings and credentials remain locally until you choose Disconnect & forget, remove the extension, or clear its local profile data. Pausing retains the credential for reconnection. Browser-granted origin permissions may remain until removed in Chrome’s extension settings.
  • Account records and browser/audit metadata remain in the managed database until deleted through available dashboard controls or an approved deletion request. There is currently no automatic account/audit purge deadline. Token expiration or revocation prevents access; it does not itself delete all associated metadata.
  • Deleting a browser in the dashboard removes that registration and its associated tokens and audit events from the live application database. To delete your managed account, email privacy@browser-mcp.click from the account address. We may need to verify ownership. We do not promise a fixed deletion-completion deadline; any legally required retention will be explained when applicable.
  • The application does not define an automatic backup/log deletion deadline. Retained infrastructure logs or backups, if present, may outlive a live database deletion. Ask the operator about such copies when making a deletion request.
  • Self-hosted operators, MCP clients, and AI providers set their own retention and deletion policies. Revocation cannot recall results already delivered to those recipients or undo completed browser actions.

Your controls and risks

Connection requires an explicit full-browser-access consent gesture. Managed pairing also requires a signed-in user’s explicit device approval. Browser-scoped MCP tokens are separate from extension connection credentials and can be revoked in the dashboard. Pause stops accepting new commands and detaches active debuggers. Disconnect & forget also removes local connection credentials. Canceling Chrome’s debugger banner pauses remote access. Already-executed JavaScript may have scheduled tasks that cannot be undone by pausing. Privileged/non-HTTP(S) pages and the upstream control-plane origin are excluded, but these checks are not a sandbox against arbitrary authorized JavaScript. Use a separate Chrome profile and trusted clients. Never authorize an upstream merely because a web page or an untrusted message asks you to. Read the security guidance for the limits of this access model.

Changes

We will update this page and its date when these practices change. Material changes may require updated in-product disclosures or consent. The managed service is a preview, without a hosted-service SLA or claim of regulatory certification.