Browser Bridge privacy

Flame Browser Bridge Privacy Policy

How the Chrome extension handles browser data when you connect it to Flame IDE.

Effective date and last updated: August 8, 2026

Single purpose: Flame Browser Bridge connects your Chrome profile to Flame IDE running on the same computer so explicitly approved AI agent actions can inspect, debug, and control browser tabs.

Data the extension can process

After the user pairs and enables the bridge, the extension can process the following data when needed for an approved browser action:

  • Browser activity and tab metadata, including tab identifiers, URLs, titles, navigation state, and limited interaction metadata such as clicks, focus changes, scrolling, submitted forms, special keys, and input length.
  • Website content, including rendered text or HTML, accessibility-oriented element details, page JavaScript results, screenshots, and console output or errors.
  • Network information, including request and response URLs, methods, status, resource type, timing, and—when explicitly requested—request or response headers.
  • Authentication and site data, including cookies, only when an approved action requests reading, setting, or deleting them.
  • Values that an approved agent action explicitly types, fills, selects, or evaluates on a page.
  • Extension configuration consisting of the local Flame server address, whether the bridge is enabled, a scoped pairing token, and temporary header-rule identifiers.

Passive activity records never include the values typed into inputs. An activity event may include the target's element type or accessible label and the input's character count. Page content, screenshots, cookies, console output, and network data can nevertheless contain personal or sensitive information depending on the website being controlled.

Collection and use

The extension processes data only to provide its disclosed browser-control purpose. It does not use browser data for advertising, profiling unrelated to the requested feature, credit or lending decisions, or sale to any party. The extension contains no analytics, advertising SDK, or developer-operated telemetry endpoint.

Activity and browser data are transmitted only while the extension is paired, enabled, and connected. The configured server is technically restricted to an http://localhost or http://127.0.0.1 address. The extension does not allow a remote Flame server URL.

Data sharing

The extension sends browser data over the computer's loopback interface to the user's local Flame IDE server. Flame's permission system controls agent access to powerful browser actions.

Depending on the AI provider the user selects and configures in Flame, browser tool results may be included in requests to that provider so the agent can complete the user's request. Data sent to a selected provider is governed by that provider's terms and privacy practices. The extension does not independently send data to Flame's developer or to any other third party.

No human is permitted to read user data unless the user gives explicit consent for a specific support purpose, access is required for security or legal compliance, or the data has been aggregated and anonymized for permitted internal operations.

Storage and retention

  • Chrome local storage retains the loopback server address, enabled state, and scoped pairing token until the user forgets the pairing, clears extension data, or uninstalls the extension.
  • Chrome session storage retains only temporary header-rule identifiers. Header rules are removed when the bridge pauses or disconnects.
  • Console and network buffers are held in extension memory, bounded by entry limits, and cleared on pause, disconnect, tab closure, or extension process termination.
  • Flame retains a bounded activity trail in server memory until access is revoked or the Flame process exits. Browser tool results can also appear in the user's local Flame conversation history.
  • Any retention by a user-selected AI provider is controlled by that provider and the user's provider configuration.

The extension does not use Chrome Sync for bridge credentials or browser data.

Security

  • Pairing requires a high-entropy, short-lived, single-use code created inside Flame.
  • The extension receives a dedicated bridge token that is accepted only by the local browser-control WebSocket. Flame stores only a hash of that token.
  • The local server rejects non-loopback pairing and WebSocket connections.
  • Users must approve powerful agent tool calls through Flame's permission system.
  • Pausing or disconnecting detaches Chrome debugger sessions, deletes temporary header rules, and clears extension console and network buffers.
  • Chrome internal and other restricted pages cannot be controlled.

User choices and deletion

Users can pause the bridge from the extension popup, select Forget to remove the local pairing token, revoke access from Flame Settings → Browser Control → Chrome Browser Bridge, clear the extension's data in Chrome, or uninstall the extension. Revoking access clears the Flame server's in-memory activity trail and invalidates the bridge token.

Chrome Web Store Limited Use disclosure

Use of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's single disclosed purpose. It is not transferred except as necessary to provide or improve that purpose, to comply with applicable law, to protect against security threats or abuse, or as otherwise directed with the user's explicit consent.

Changes to this policy

If the extension's data practices materially change, this policy and the in-product disclosure will be updated before the new practices take effect. The effective date above will also be updated.

Contact

For privacy questions or requests, email support@flame-ide.com.