Babtab Privacy Policy

Effective date: September 28, 2026
Extension: Babtab — Trusted Browser Runtime
Contact: GitHub Issues

Babtab is a local-first browser extension. This policy explains what data the extension touches, where it goes (nowhere outside your machine by default), and what choices you have.

1. What Babtab does

Babtab lets AI agents you choose and connect yourself (e.g. Cursor, Copilot, Claude Code via a locally-run relay, npx @babtab/relay) observe and operate web pages in your Chrome browser through semantic commands. The extension performs no reasoning and makes no autonomous decisions — it executes, guards, and verifies actions requested by your agent, under rules you control (approvals, pause/takeover, per-site grants).

2. Data the extension processes

To do its job, the extension reads page structure on sites you have explicitly granted: page structure (roles, names, and references of elements), action outcomes, and screenshots of the visible tab when needed to verify an action — all processed on your device. Sensitive values are redacted before display: passwords, payment fields, and token-like values are never shown in plain text, never written to logs, and the relay never persists request bodies.

3. Where your data goes

Nowhere, by default. All processing happens in your browser and in the relay on your own machine (http://127.0.0.1:3000 by default). The relay forwards routing metadata only (device/client IDs, method names such as browser_click) — never DOM, screenshots, credentials, or input values. The developer operates no servers, no accounts, no analytics, and no telemetry. If you choose to run the relay on your own remote server (advanced multi-machine setup), traffic flows to infrastructure you control under your own responsibility.

4. Local storage

The extension stores settings only in your browser (chrome.storage.local / chrome.storage.session) or in a token file on your disk: relay URL, device ID, per-site grants, approval decisions, and pairing tokens. Uninstalling removes browser-side data; delete your token file to revoke relay access.

5. Data sharing

We do not sell, share, or transmit your data to any third party — we never receive it in the first place.

6. Permissions and why each is needed

activeTab (act on your current tab), scripting (on-page semantic index on granted sites only), storage (on-device settings), sidePanel (control-center UI), tabs (list/switch tabs, on-device verification screenshots), and optional per-site host access that you grant explicitly.

7. Your choices

Revoke a site's grant, pause or disconnect agents, or uninstall at any time — all take effect immediately. Run everything on localhost (default) so no traffic leaves your computer.

8. Children

Babtab is a developer tool and is not directed at children under 13.

9. Changes to this policy

If data practices change, this policy will be updated with a revised effective date before the corresponding version is published.