Privacy Policy

OverShoulder Browser Reader (Chrome Extension) by OverShoulder
Effective Date: August 9, 2026
Policy URL: https://overshoulder.web.app/privacy-extension

This Privacy Policy explains how the OverShoulder Browser Reader extension handles data. The extension is used with the OverShoulder desktop app to help AI understand browser context and provide step-by-step guidance.

1. Data We Collect

The extension collects page context data only after first-run consent and while screen sharing is active in the OverShoulder desktop app. When screen sharing is off, no browser page context is collected or transmitted.

When active, the following data may be collected:

  • Webpage structure (buttons, links, inputs, and similar UI elements), up to 150 elements
  • Page text, up to 2,000 characters
  • UI labels, placeholders, and visible values from input fields that are not classified as sensitive by the extension
  • The current page URL and page title. Chrome Web Store classifies this as Web history. The extension does not collect a separate list of previous visits.
  • Personal or sensitive information that is visible within the collected page content may be included before the client-side redaction described below is applied.

2. Automatic Client-Side Redaction

Before transmission, the extension applies client-side redaction to recognized sensitive patterns in collected page text, UI labels, selectors, placeholders, non-sensitive input values, and page titles. It also redacts common sensitive URL query parameters. Redaction includes:

  • Email addresses
  • Phone numbers
  • Credit card numbers
  • U.S. Social Security numbers (SSN)
  • Korean resident registration numbers
  • JWT tokens and API keys

Redaction is a risk-reduction measure based on recognized patterns. URLs and page identifiers may contain arbitrary values, so it cannot guarantee that every personal, confidential, or sensitive value will be detected or removed.

3. How Data Is Used

Redacted page context is sent to the local service used by the OverShoulder desktop app. When needed to answer your request, relevant browser context may then be included in an encrypted request to the AI provider selected or configured in the desktop app. It is used to understand what you are viewing and provide the requested guidance, not for advertising or sale.

4. Service Providers, Data Sharing, and No Sale

Depending on the model selected or configured in the OverShoulder desktop app, relevant browser context may be processed by one of the following AI service providers solely to provide the requested AI functionality:

We do not sell or rent Browser Reader data, and we do not share it for advertising, creditworthiness, lending, or purposes unrelated to the extension's single purpose.

The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser Reader data is used or transferred only as necessary to provide or improve the extension's single disclosed purpose, and not for advertising or unrelated purposes.

5. Data Retention

Turning screen sharing off immediately stops new Browser Reader collection and transmission and clears the current DOM/page-context snapshot from the active in-memory Browser Reader state. It does not delete extension-local consent, the local session identifier, screen-sharing state, or every record that may already have been created through use of the desktop app.

  • Browser context already included in a conversation, generated response, or Memory Box entry may remain in local desktop-app storage until you delete it using the app's controls.
  • AI service providers may process and retain submitted requests according to their applicable API terms and privacy policies.
  • Limited operational logs may retain technical metadata, including request time, status, element count, and page URL or title, under normal security and troubleshooting retention practices. The Browser Reader endpoint does not intentionally write raw page text or full DOM snapshots to long-term logs.

6. User Controls

You have full control over data collection:

  • First-run consent and screen sharing toggle — browser page context is collected only after consent and while screen sharing is on; turning it off immediately stops new Browser Reader page-context collection and transmission and clears the active in-memory Browser Reader page snapshot
  • Per-site permissions — you grant access to each website individually via a runtime permission prompt
  • Remove or clear the extension — removing the extension or clearing its local data removes its consent, session identifier, and sharing state; local conversation and Memory Box records are managed separately in the desktop app

7. Security

The extension sends Browser Reader context to the OverShoulder desktop app through a device-local loopback connection (http://localhost:4173), which does not leave your device. Requests from the desktop app to configured external AI service providers are protected in transit using HTTPS/TLS.

8. Contact

Company: OverShoulder
Product: OverShoulder Browser Reader
Contact: support@overshoulder.ai

개인정보처리방침

OverShoulder의 OverShoulder Browser Reader (Chrome 확장 프로그램)
시행일: 2026년 8월 9일
정책 URL: https://overshoulder.web.app/privacy-extension

본 개인정보처리방침은 OverShoulder Browser Reader 확장 프로그램이 데이터를 어떻게 처리하는지 설명합니다. 본 확장 프로그램은 OverShoulder 데스크톱 앱과 함께 사용되며, AI가 브라우저 맥락을 이해하고 단계별 가이드를 제공하도록 돕습니다.

1. 수집하는 데이터

본 확장 프로그램은 최초 실행 동의 후 OverShoulder 데스크톱 앱에서 화면 공유가 활성화된 동안에만 페이지 맥락 정보를 수집합니다. 화면 공유가 꺼져 있으면 브라우저 페이지 맥락 정보는 수집 또는 전송되지 않습니다.

활성화 시 다음 데이터가 수집될 수 있습니다.

  • 웹페이지 구조 정보(버튼, 링크, 입력창 등 UI 요소), 최대 150개 요소
  • 페이지 텍스트, 최대 2,000자
  • 확장 프로그램에서 민감 항목으로 분류되지 않은 입력란의 UI 레이블, 안내 문구 및 화면에 보이는 값
  • 현재 페이지 URL 및 페이지 제목. Chrome 웹 스토어에서는 이를 웹 기록으로 분류합니다. 본 확장 프로그램은 과거 방문 기록의 별도 목록을 수집하지 않습니다.
  • 수집되는 페이지 콘텐츠에 표시된 개인 정보 또는 민감 정보는 아래의 클라이언트 측 마스킹이 적용되기 전에 포함될 수 있습니다.

2. 클라이언트 측 자동 마스킹

데이터 전송 전에 수집된 페이지 텍스트, UI 레이블, 선택자, 안내 문구, 비민감 입력값 및 페이지 제목에서 인식 가능한 민감정보 패턴을 클라이언트 측에서 자동으로 마스킹합니다. 일반적인 민감 URL 쿼리 매개변수도 마스킹합니다. 대상은 다음과 같습니다.

  • 이메일 주소
  • 전화번호
  • 신용카드 번호
  • 미국 사회보장번호(SSN)
  • 대한민국 주민등록번호
  • JWT 토큰 및 API 키

마스킹은 인식 가능한 패턴을 기반으로 위험을 줄이기 위한 조치입니다. URL과 페이지 식별자에는 임의의 값이 포함될 수 있으므로 모든 개인 정보, 기밀 정보 또는 민감한 값을 탐지하거나 제거한다고 보장할 수 없습니다.

3. 데이터 사용 목적

마스킹된 페이지 맥락 정보는 OverShoulder 데스크톱 앱이 사용하는 로컬 서비스로 전송됩니다. 사용자 요청에 답하는 데 필요한 경우 관련 브라우저 맥락은 데스크톱 앱에서 선택 또는 설정된 AI 제공업체에 암호화된 요청으로 포함될 수 있습니다. 이 정보는 현재 화면을 이해하고 요청한 가이드를 제공하는 데 사용되며 광고 또는 판매에 사용되지 않습니다.

4. 서비스 제공업체, 제3자 처리 및 비판매

OverShoulder 데스크톱 앱에서 선택 또는 설정한 모델에 따라 관련 브라우저 맥락은 요청한 AI 기능을 제공하기 위한 목적으로만 다음 AI 서비스 제공업체 중 하나에서 처리될 수 있습니다.

당사는 Browser Reader 데이터를 판매하거나 대여하지 않으며, 광고, 신용도 판단, 대출 또는 확장 프로그램의 전용 목적과 관련 없는 용도로 제공하지 않습니다.

Google API에서 수신한 정보의 사용은 Limited Use 요구사항을 포함한 Chrome Web Store 사용자 데이터 정책을 준수합니다. Browser Reader 데이터는 공개된 단일 목적을 제공하거나 개선하는 데 필요한 범위에서만 사용 또는 전송되며, 광고나 관련 없는 목적으로 사용되지 않습니다.

5. 보관 기간

화면 공유를 끄면 Browser Reader의 새로운 수집과 전송이 즉시 중단되고 현재 DOM/페이지 맥락 스냅샷이 활성 메모리의 Browser Reader 상태에서 삭제됩니다. 다만 확장 프로그램 로컬에 저장된 동의 상태, 로컬 세션 식별자, 화면 공유 상태나 데스크톱 앱 사용 중 이미 생성된 모든 기록이 함께 삭제되는 것은 아닙니다.

  • 대화, 생성된 응답 또는 Memory Box 항목에 이미 포함된 브라우저 맥락은 사용자가 앱의 제어 기능으로 삭제할 때까지 로컬 데스크톱 앱 저장소에 남을 수 있습니다.
  • AI 서비스 제공업체는 적용되는 API 약관 및 개인정보처리방침에 따라 전송된 요청을 처리하고 보관할 수 있습니다.
  • 제한된 운영 로그에는 일반적인 보안 및 문제 해결 보관 정책에 따라 요청 시각, 상태, 요소 수, 페이지 URL 또는 제목 등의 기술 메타데이터가 남을 수 있습니다. Browser Reader 엔드포인트는 원본 페이지 텍스트나 전체 DOM 스냅샷을 장기 로그에 의도적으로 기록하지 않습니다.

6. 사용자 제어

데이터 수집에 대한 완전한 제어권을 보유합니다.

  • 최초 실행 동의 및 화면 공유 토글 — 동의한 뒤 화면 공유가 켜져 있는 동안에만 브라우저 페이지 맥락을 수집하며, 끄면 Browser Reader 페이지 맥락의 새로운 수집과 전송이 즉시 중단되고 활성 메모리의 페이지 스냅샷이 삭제됩니다
  • 사이트별 권한 — 런타임 권한 요청을 통해 각 웹사이트에 개별적으로 접근을 허용합니다
  • 확장 프로그램 제거 또는 데이터 삭제 — 확장 프로그램을 제거하거나 로컬 데이터를 삭제하면 동의 상태, 세션 식별자 및 화면 공유 상태가 삭제됩니다. 로컬 대화 및 Memory Box 기록은 데스크톱 앱에서 별도로 관리됩니다

7. 보안

확장 프로그램은 기기 외부로 나가지 않는 로컬 루프백 연결(http://localhost:4173)을 통해 Browser Reader 맥락을 OverShoulder 데스크톱 앱으로 전송합니다. 데스크톱 앱에서 설정된 외부 AI 서비스 제공업체로 보내는 요청은 HTTPS/TLS로 전송 중 보호됩니다.

8. 문의처

회사명: OverShoulder
제품명: OverShoulder Browser Reader
문의: support@overshoulder.ai