Skip to content

Data held by the extension

The extension stores its data in browser local storage, not browser sync. API credentials, model keys, cloud connection tokens, pending OAuth state, and PKCE verifiers are encrypted using a key derived from your vault passphrase. Run history, labels, origins, agent settings, and setup defaults are stored as unencrypted local metadata.

Keypilot does not request browser cookie or history permissions. Provider pages use the session already maintained by your browser. Removing the extension or profile may permanently delete this local data.

Data processed by a planner

A planning request contains your task, provider recipe, approved origins, confirmed public setup details, recent action history, credential labels, and a redacted page observation. The observation can include page text, labels, links, roles, and option names.

Login and challenge pages are withheld. Input values, captured credentials, cookies, vault contents, and the vault passphrase are excluded. Redaction is heuristic and may not identify every secret displayed as ordinary page text.

When you select Keypilot's hosted cloud planner, Cloudflare Workers AI processes the planning request. Keypilot does not write planning request or response bodies to its application database or ordinary application logs. When you configure another model endpoint or local CLI, that provider's terms and data practices apply.

Website account data

The website stores your email address, hashed sign-in sessions, hashed browser connection tokens, keyed hashes of network addresses used for short-window abuse limits, subscription status, Stripe customer and subscription identifiers, monthly action counts, and operational timestamps in Cloudflare D1. Raw sign-in and browser access tokens are not stored.

Cloudflare Email Service sends requested sign-in links. Cloudflare serves the website and processes network information needed to provide and protect it. Stripe processes checkout, subscription, tax, payment, and customer-portal information. Keypilot does not receive complete card numbers.

The website uses one essential, HttpOnly session cookie named kp_session. It does not currently use advertising cookies, third-party analytics, browser fingerprinting, or marketing trackers.

Retention and deletion

Unused sign-in links expire after 15 minutes. Website sessions expire after 30 days. Browser connection tokens expire after 90 days unless revoked earlier. Expired records may remain briefly until routine cleanup.

You can revoke browser connections and delete an inactive account from the account page. An active subscription must be canceled first. Account deletion removes Keypilot user, session, usage, and connection records. Stripe and infrastructure providers may retain billing, fraud-prevention, security, and legal records under their own obligations.

Choices and contact

You can use Keypilot without a website account by selecting bring-your-own-key or a local CLI. You control the provider origins granted to each browser run and can revoke extension site access through browser settings.

For privacy questions or requests, email privacy@isolated.tech. Do not email credentials or vault exports.