brawsr.
ProductDevelopersCompany
DocumentationOpen console
PRIVACY / EFFECTIVE AUGUST 10, 2026

Browser state is sensitive.We treat it that way.

This policy explains what brawsr receives when you sign in, what a managed browser session can contain, and how we use, share, retain, and delete that information.

IDENTITY

Google account

Verified email, name, profile image, and a stable account ID.

Used to sign you in and identify your brawsr account.
BROWSER

Session state

Pages, cookies, storage, memory, and explicit checkpoints.

Used only to run the browser operations you request.
SERVICE

Operational data

Identifiers, timestamps, usage, diagnostics, and security events.

Used to operate, secure, and support the service.
ON THIS PAGE
ScopeInformation we collectHow we use informationGoogle sign-inCookiesWebsite analyticsWhen we share informationRetention and deletionSecurityYour choices and rightsChanges and contact
PRIVACY REQUESTS[email protected]
SCOPE

What this policy covers

This Privacy Policy applies to the brawsr website, documentation, console, APIs, SDKs, MCP server, managed browser sessions, and related support communications (collectively, the “Service”). brawsr is the operator of the Service. In this policy, “brawsr,” “we,” and “us” refer to that operator.

The Service lets customers create remote browser sessions, checkpoint browser state, rewind to a checkpoint, and fork new sessions from captured state. Customers decide which websites their sessions visit and what information those sessions process. Third-party websites have their own privacy practices, which this policy does not cover.

COLLECTION

Information we collect

Google sign-in information

When you choose Sign in with Google, brawsr requests only the OpenID Connect scopes openid, email, and profile. We receive your Google account’s stable identifier, verified email address, display name, and profile image URL. We do not receive your Google password or access your Gmail, Drive, contacts, calendar, or other Google Workspace content.

Account and workspace information

We store information needed to operate your account and workspace, such as organization and project names, memberships, roles, invitations, quota settings, and API-key metadata. API-key plaintext is shown once when a key is created; the service stores a non-reversible verifier rather than a recoverable copy.

Browser-session and checkpoint content

A live browser session or checkpoint may contain visited URLs, rendered page content, form values, cookies, authentication state, local and session storage, IndexedDB, Cache Storage, service-worker state, JavaScript memory, and other browser-process state. This content may include personal data or credentials belonging to you or third parties. We process it to provide the session, checkpoint, rewind, fork, inspection, and deletion operations you request.

Usage, device, and security information

We may collect IP address, user agent, request and operation identifiers, timestamps, session duration, resource consumption, lifecycle results, error categories, and security events. We use this information to enforce quotas, diagnose failures, prevent abuse, and keep the Service reliable. Page bodies, screenshots, cookies, browser storage, checkpoint contents, CDP messages, authorization headers, and reusable credentials are excluded from application telemetry.

Communications

If you contact us, we receive the information you include in the message and any technical details you choose to share. Do not send browser credentials, API keys, OAuth tokens, or checkpoint content in a support message unless we explicitly provide a secure method.

USE

How we use information

  • Authenticate users and maintain secure console sessions.
  • Provide and operate projects, browser sessions, checkpoints, rewind, fork, and inspection.
  • Measure usage, apply service limits, and plan capacity.
  • Detect abuse, investigate security incidents, and protect users and infrastructure.
  • Diagnose failures, provide support, and improve service reliability.
  • Comply with legal obligations and enforce applicable agreements.
No ads. No data brokerage. No model training.

We do not sell personal data, use Google identity data for advertising, or use browser-session and checkpoint content to train machine-learning models.

GOOGLE SIGN-IN

How Google data is handled

Google identity data is used only to authenticate you, create or connect your brawsr account, display your identity in the console, enforce workspace access, and maintain your signed-in session. Provider tokens are stored encrypted on the server and are not sent to browser JavaScript. Your browser receives an opaque, secure session cookie instead.

We share Google identity information only as described in this policy—for example, with infrastructure providers that process it on our behalf, with members or administrators of workspaces you join, or when legally required. We do not transfer it to data brokers or advertising platforms.

You can revoke brawsr’s Google access from your Google Account’s third-party connections page. Revocation prevents future token refreshes but does not by itself delete your brawsr account; contact us to request account deletion.

COOKIES

Essential cookies only

The console uses essential cookies for OAuth flow integrity, authentication, session security, and sign-out. The primary brawsr session cookie is opaque, HttpOnly, and not available to browser JavaScript. We do not currently use advertising cookies, analytics cookies, or third-party behavioral tracking cookies.

WEBSITE ANALYTICS

Cookieless, anonymous site measurement

The public website and documentation use PostHog in cookieless mode to understand aggregate traffic and whether important links and documentation controls are useful. The analytics client does not set cookies or use local or session storage, create person profiles, record sessions, collect copied text, or capture form values.

Analytics events can include the page path, referring domain, campaign parameters, coarse browser and device information, and a named interaction such as opening the documentation, console, or an external example. Heatmaps can aggregate click positions, pointer movement, and scroll behavior. Search terms, code contents, URL query strings, email addresses, browser-session content, and console activity are excluded.

PostHog processes the request IP address and user agent to derive a privacy-preserving server-side hash used for aggregate visitor and session counts. The analytics client does not store that hash in your browser, and brawsr does not use analytics data for advertising or to identify public-site visitors.

DISCLOSURE

When we share information

We may disclose information in these limited circumstances:

  • Service providers. Hosting, network, storage, database, security, analytics, and support providers process information under our instructions to operate the Service. Cloudflare provides edge networking, Google provides identity services, and PostHog provides cookieless public-site analytics.
  • Your workspace. Organization members may see your name, email address, role, and activity or resource metadata needed to collaborate and administer the workspace.
  • Safety and law. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, enforce agreements, or protect users, the public, or the Service from fraud, abuse, or security threats.
  • Business changes. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal requirements.
RETENTION

Retention and deletion

We retain account and workspace information while your account is active and as needed to provide the Service, resolve disputes, protect the Service, and meet legal obligations. Authentication sessions expire or are revoked; Google provider tokens are deleted when no longer needed, when the related account is deleted, or when deletion is otherwise required.

Live browser state exists for the session lifecycle. Checkpoints remain available according to the configured retention period and until they expire or are deleted. A checkpoint that is still referenced by session lineage or an active operation may not be immediately eligible for deletion. Operational logs are retained only as long as reasonably needed for security, support, service integrity, and legal obligations.

To request deletion of your account and associated personal data, email [email protected]from your verified account address. We may need to verify your identity and may retain limited records where required for security, fraud prevention, legal compliance, or transaction integrity.

SECURITY

How we protect information

We use technical and organizational safeguards designed for the sensitivity of managed browser state. These include encrypted transport, encrypted OAuth tokens, opaque session credentials, project- and session-scoped access controls, one-time API-key disclosure, restricted infrastructure access, and telemetry redaction. No security measure is perfect, and we cannot guarantee absolute security.

You are responsible for protecting your brawsr API keys, limiting access to your projects, choosing lawful browser destinations, and avoiding collection of information you are not authorized to process.

CONTROL

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, or to object to certain processing. You may also sign out, revoke Google access, revoke API keys, close sessions, and delete eligible checkpoints using the Service.

Send privacy requests to [email protected]. We may request information needed to verify your identity. If you use brawsr through an organization, that organization may be the best contact for requests concerning browser content it controls.

brawsr is a developer infrastructure service and is not directed to children under 13. We do not knowingly collect personal data from children under 13.

UPDATES

Changes and contact

We may update this policy as the Service and our legal obligations change. We will update the effective date above and provide additional notice when a material change requires it.

Questions or privacy requests can be sent to [email protected].

brawsr.

Save the state.
Keep the progress.

ProductDocumentationConsoleWorkflows
View on GitHub↗
© 2026 BRAWSR
ContactPrivacyTerms