Last updated August 8, 2026

Privacy, without the fine-print maze.

Web Automator is a user-directed browser automation extension. This policy explains what it handles, why it is needed, where it goes, and how you can delete it.

The short version

During a task you explicitly start, your instruction and relevant content from the active webpage are sent directly to OpenAI to generate automation actions. The Web Automator developer operates no backend and does not receive this data.

Data Web Automator handles

  • Task instructions: the text entered in the side panel.
  • Active-page data: the selected tab's URL, title, relevant page content, labels, controls, form state, and relevant embedded-frame content.
  • Automation activity: proposed and completed actions, action results, model output, errors, and token-usage counts for the current run.
  • ChatGPT account data: an OpenAI account identifier, email address when present in the sign-in token, and OAuth access, refresh, and identity tokens.
  • Local settings and history: preferences and, when enabled, up to 50 redacted run summaries containing the instruction, page origin/title, actions, status, usage, and timestamps.

Because the extension works on user-selected websites, page content can include personal information, form data, communications, or other sensitive information visible there. Web Automator masks password values, hidden inputs, recognizable authentication tokens, and entered payment values before model preparation. This reduces exposure but cannot guarantee every sensitive value on every website will be recognized.

How data is used

During a user-started task, Web Automator sends the instruction and relevant active-page data directly to OpenAI over HTTPS. OpenAI returns model output used to choose and perform the next page action. This is necessary for the extension's single purpose: executing browser automation requested by the user.

The extension does not inspect unrelated tabs, start automatically, collect background browsing history, or send page content when no task is running. Website access is an optional Chrome permission requested with an in-product explanation and consent step.

Sharing and external parties

Instructions, relevant active-page data, and model requests are shared with OpenAI solely to authenticate the user's ChatGPT account and generate automation actions. OpenAI's handling of data is governed by the terms and privacy choices associated with the user's OpenAI account.

The developer receives no page content, instructions, credentials, history, or model responses. Web Automator has no analytics, advertising identifiers, advertising integrations, or cloud synchronization. It does not sell user data or transfer it for advertising, creditworthiness, lending, or unrelated purposes.

Storage and retention

  • OAuth access tokens remain in trusted extension session storage.
  • Persistent OAuth credentials are encrypted with AES-GCM using a non-extractable Web Crypto key in extension-origin IndexedDB and remain until disconnect or deletion.
  • Settings and optional history are stored locally. History is enabled by default, retains at most 50 summaries, and excludes raw DOM snapshots and complete model payloads.
  • Temporary OAuth flow state is removed after the callback is completed or rejected.

Users can clear history, disconnect ChatGPT, or select Delete all local data from Settings. Uninstalling also removes extension-local storage under Chrome's normal uninstall behavior.

User control and safety

Restricted mode asks before submitting, sending, purchasing, deleting, uploading, changing account access, or accepting terms. Fully Autonomous mode skips those approvals only after it is selected and confirmed for that run. A run can be stopped at any time.

Web Automator cannot bypass website authorization, Chrome restrictions, browser security, or operating-system security.

Chrome Web Store Limited Use

Web Automator's use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's single user-facing purpose. It is not used for personalized advertising, retargeting, lending, or unrelated purposes. Humans are not permitted to read it except with specific user consent for support or where required for security or legal compliance.

Changes and contact

Material changes will be disclosed prominently in the extension before the new practice begins, and this policy's date will be updated. For privacy questions, contact the developer through the support contact published on Web Automator's Chrome Web Store listing or visit the support page.