Privacy Policy — Agiliton Sitebridge

Last updated: 2026-10-01

This privacy policy applies to the Agiliton Sitebridge browser extension ("the Extension", "Product"), published by Agiliton Ltd., Kalopsidas 8, 8575 Pegeia, Paphos, Cyprus ("Agiliton", "we", "us", "data controller").

It comprehensively discloses how the Extension collects, handles (uses), stores, and shares user data — including personal and sensitive user data — and the choices you have. No required section is omitted. This policy is the source of truth for the Chrome Web Store listing privacy URL (https://sitebridge.agiliton.cloud/privacy).

1. What Sitebridge is

Sitebridge is a browser-control layer for AI assistants. It exposes your own signed-in Chrome session to an AI assistant that you run (via the Model Context Protocol, "MCP"), so the assistant can read pages and perform actions you could perform yourself — click, type, fill forms, extract tables, take screenshots, search your history or bookmarks, read a message you point it at — on the sites you already have open.

Two facts define how the Extension handles your data:

A built-in integration for CAT translation editors (Smartling, Phrase, and similar) runs on top of this same surface; it is one feature, not the whole product.

2. Data collection

2.1 What we collect and when

The Extension requests broad browser permissions because you point it at whatever site you are working on. Each capability below is used only in response to an explicit tool call in your own session, and only for the tab or resource that call names. Nothing here is collected in the background, on a schedule, or from tabs you have not directed the assistant to.

Data collectedWhen it is collectedChrome Web Store data-use category
Page content — text, DOM, form field values, and screenshots of the tab you point the assistant atWhen a read / screenshot / extract tool runs on that tabWebsite content
Cookies and session state — read, set, or delete cookies for a siteWhen the cookie tool runs, or to detect that a sign-in you started has completedAuthentication information
Browsing history — search your visited pages (URLs, titles, visit times)When the history-search tool runsWeb history
Bookmarks — read, add, or removeWhen a bookmark tool runsWebsite content
Clipboard — read what you copied, or write generated text for you to pasteWhen a clipboard tool runsWebsite content
On-page activity — clicks, keystrokes, and scrolling dispatched via the Chrome DevTools Protocol; network requests (URLs, methods, headers, status, timings, and response bodies) captured for a tabWhen you drive the page through the assistant, or run the network-capture tool between an explicit start and stopUser activity
Email messages — content of a specific message you direct the assistant toWhen the Gmail message-reading tool runs on a message you point it atPersonal communications
Account identity — your Agiliton account email and customer IDOn sign-in and thereafter to authenticate requestsPersonally identifiable information
Chat / conversation content — messages you send the assistant and the assistant's replies (cloud-bridge mode)When you use the cloud-hosted assistantPersonal communications / user-generated content
Technical / diagnostic data — Extension version, error stack traces, and incidental page URLs in error breadcrumbsWhen a crash or handled error is reported to SentryPersonally identifiable information; website content only if a URL appears in an error string
Downloads metadata — filenames of artifacts the Extension savesWhen a tool produces a file to save—

2.2 What we do not collect

The Extension does not: scan your history, bookmarks, cookies, mailbox, or other tabs in bulk; run collection on a schedule or in the background without a tool call; collect precise location, health information, or payment-card / financial-account numbers as a product feature (see Sensitive user data); include third-party advertising, usage-analytics, or device-fingerprinting SDKs.

2.3 How collection happens

Collection occurs through: (1) Chrome extension APIs and the Chrome DevTools Protocol, invoked only by named tools in response to your assistant session or a direct UI action; (2) Account sign-in via Google or Microsoft single sign-on (SSO) against Agiliton identity (id.agiliton.eu), which yields your account email and name, your customer ID, and authentication tokens; (3) Optional OAuth you grant for Google Workspace export / Chrome UX Report features; (4) Error reporting via @sentry/browser (EU region) after automatic scrubbing of tokens and secrets.

3. Data handling (use)

We handle collected data only to operate Sitebridge for you. We use data to: perform the tool action you (or your assistant) requested; return results to your connected MCP client (local or cloud bridge); run the cloud-hosted AI assistant if you enable the cloud bridge; route model requests to the LLM provider configured for your account, via the LiteLLM proxy (agiliton-account) — a routing/metering gateway that forwards your prompt for inference and does not itself store your content; build an on-device semantic index so you can search across your open tabs (embedded locally, never uploaded); authenticate you and authorize API calls; translate / generate / design content when you invoke those features; export work to Google Docs/Drive or fetch CrUX metrics when you grant Google OAuth; diagnose and fix Extension failures via scrubbed error reports; billing and account administration.

We do not use user data for advertising, ad targeting, creditworthiness, lending, or sale to data brokers. We do not build cross-user profiles for marketing. Limited-use commitments under the Chrome Web Store User Data Privacy program apply.

4. Data storage

4.1 On your device (local storage)

The Extension stores locally in chrome.storage and IndexedDB: Authentication tokens (Agiliton account JWT(s) and the LiteLLM virtual key), plus your tasks, UI preferences, and per-tenant configuration; the on-device semantic index (stays in this browser, never uploaded); Flow recordings you record (local only, sensitive input values redacted before save); an action/audit log (hash-chained, in IndexedDB) and an undo log; userscripts you save and a cached copy of runtime configuration. Signing out clears your tokens; uninstalling removes all locally stored Extension data.

4.2 On Agiliton systems (server-side storage)

If you use Agiliton cloud features: Account records (SSO identity, customer ID, tenant membership, token balance, encrypted LiteLLM key) stored encrypted at rest on EU-hosted backends (primary processing in Germany / EU regions); Conversation history in cloud-bridge mode stored under your account until you delete it (/v1/conversations); Personal tasks stored server-side only if you enable task sync (/v1/todos); SSO refresh token held encrypted server-side only, never stored in the Extension; Request content used to fulfill a live turn is not retained beyond what is needed for that purpose and for security/abuse logs; Error reports in Sentry (EU) follow Sentry's standard retention.

4.3 Data retention

DataRetention
Local Extension storageUntil you sign out or uninstall
Cloud conversation historyUntil you delete it, or your account is deleted
Account / billing recordsFor the life of the account and as required by tax/commercial law
Live request payloadsOnly as needed to fulfill the request and operate secure logs
Sentry error reportsSentry's standard EU retention for the project
LLM provider logsGoverned by the provider's terms for that hop; we do not instruct providers to train on your data as a product feature

You can request deletion of account-level data by emailing service@agiliton.eu. Deleting your account cascades to the server-side data associated with it, subject only to data we must retain to meet legal obligations.

5. Data sharing

We do not sell your data. We share user data only with the parties below, each receiving only the data required for its role.

RecipientWhat is sharedWhen / why
You / your local MCP clientTool results (page content, screenshots, cookies when requested, history hits, bookmarks, clipboard, network capture, email content)Always, when a tool completes
Agiliton backend — agiliton-account.agiliton.cloudAuthenticated WebSocket traffic on /v1/mcp-bridge; tool results when cloud bridge enabled; chat messages and conversation context; account, balance, billing callsOnly if you sign in and use cloud features
Related Agiliton servicesFeature-specific payloads: translate.agiliton.cloud, generator.agiliton.cloud, design.agiliton.cloud, crm.agiliton.cloud, id.agiliton.eu, plus runtime-configuration JSON from Agiliton object storage at Hetzner (Germany)Only when you use the corresponding feature
Your chosen LLM provider (e.g. Anthropic, OpenAI, or a customer-supplied model)Prompt and context needed for the model response, routed through Agiliton's LiteLLM proxy gateway (forwards the request, does not itself store your content)When the assistant generates a model response
Google APIs (Docs, Drive, Chrome UX Report)Content you export, or origins you query for CrUX, using an OAuth token you grantOnly for those optional features, with your consent
Sentry (EU region)Crash/error reports: account email, customer ID, Extension version, technical stacks (tokens/API keys scrubbed; no session replay; no page screenshots)On Extension errors

No other third-party analytics, advertising, or fingerprinting service is included. If required by law to disclose data, we will share only what is legally required and notify you when legally permitted.

6. Sensitive user data

Under the Chrome Web Store User Data Privacy program, sensitive user data includes authentication information, precise personal communications, web history, user activity, and personally identifiable information tied to those categories. Sitebridge can encounter sensitive user data because it operates inside your already-signed-in browser at your direction.

6.1 Categories the Extension may handle

Authentication information (session cookies, account JWT, LiteLLM virtual key; SSO refresh token kept encrypted server-side only, never in the Extension); Personal communications (email bodies via the Gmail reader; chat content in cloud-bridge mode); Web history (URLs and titles from history search); User activity (keystrokes, clicks, scrolls, and network request/response data when capture is on); Website content that may itself be sensitive; Personally identifiable information (Agiliton account email and customer ID; names/contacts in page content or messages you ask to read).

6.2 How sensitive data is handled

On-demand only (no bulk export, no background harvesting); Purpose limitation (used solely to fulfill that tool call/feature); Minimization in local recordings (sensitive input values redacted before save); Minimization in error reports (Sentry scrubs auth tokens, OAuth codes, API keys; no page DOM, screenshots, cookie jars, history dumps, or mailbox content on crash reports); Transmission security (TLS/HTTPS/WSS everywhere); Access control (cloud data keyed to your authenticated account); Your controls (disconnect cloud bridge, revoke Google OAuth, sign out, or uninstall at any time).

6.3 Categories we do not target

We do not build features whose purpose is to collect health information, payment-card numbers, or government-ID numbers. If such data appears on a page you ask the assistant to read, it is treated as ordinary page content for that single tool call under the same minimization and non-sale rules — not classified, catalogued, or retained as a separate sensitive-data dataset.

7. Security practices

Encryption in transit (modern TLS; HTTPS for HTTP APIs, WSS for the MCP bridge; third-party API calls likewise HTTPS); Encryption and protection at rest (device tokens in Chrome extension storage; server-side account and conversation data on EU-hosted infrastructure with access controls; we do not log raw JWTs, cookie values, or API keys into error reporting); Secret scrubbing before error reports leave the device; No remote code execution (runtime configuration is schema-validated JSON, not executable code); Scope control (CDP/debugger attachment is per-tab, on demand; content scripts inert until sign-in and a tool call); Local-only mode (run against a purely local MCP client so tool results never leave your machine).

8. Your rights and choices

Agiliton is established in the EU (Cyprus). Subject to applicable law (including the GDPR), you have the right to: access the personal data we hold; correct inaccurate personal data; export your data (portability); request deletion; object to or restrict certain processing; withdraw consent where processing is consent-based (e.g. optional Google OAuth) without affecting the lawfulness of prior processing. To exercise any of these, contact service@agiliton.eu. In-product choices (no email required): disconnect the cloud bridge; revoke the Extension's Google authorization; sign out from the side panel (clears local tokens); uninstall the Extension (removes local storage). You may also lodge a complaint with your local supervisory authority.

9. Children

Sitebridge is a professional tool intended for business users and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact service@agiliton.eu and we will delete it.

10. Permissions

For a per-permission explanation of why each browser permission is requested and how it maps to a tool, see the permissions justification document (PERMISSIONS.md). Agent-driven browser control — not the translation integration — is the justification for higher-scrutiny permissions (debugger, host access to the sites you use).

11. Changes to this policy

If we materially change this policy, we will update the "Last updated" date above and the published policy page at https://sitebridge.agiliton.cloud/privacy, and the Extension will surface a notice directing you to the updated text. Continued use after notice constitutes acceptance where permitted by law.

12. Contact

Agiliton Ltd. — Privacy. Kalopsidas 8, 8575 Pegeia, Paphos, Cyprus. Email: service@agiliton.eu. Chrome Web Store item: Agiliton Sitebridge (item ID ibmbcljeimbfckhfdficeknlbgakoddo).