Unbrowse is operated by Unbrowse AI Pte. Ltd., a company incorporated in Singapore (UEN 202425961N) (“we”, “us”). This policy covers unbrowse.ai, the remote MCP server at unbrowse.ai/mcp, the API, the unbrowse CLI and SDK, and our emails. Questions or requests: hello@unbrowse.ai.
Your choices, right here
A browser that sends Global Privacy Control turns both off automatically. The sharing of the tools you learn is controlled in your workspace under Connections. To delete your account or any data below, email hello@unbrowse.ai from the address on the account.
What we collect
Your account
- Your email address, a user id, and when you signed up. You sign in with a one-time link (valid 15 minutes, usable once).
- A session cookie (
ub_session, 30 days) and, for MCP clients, OAuth tokens (1 hour, refreshable for 30 days). - API keys, stored as a hash; we can show a key only once, when you create it.
- Optionally: how you heard about us, and whether you want product news (an unticked box on sign-in; we record when and where you ticked it).
Passwords and logins you save
If you save logins (username, email, password, 2FA seed, recovery codes, API tokens or a site’s session cookies), they are encrypted with AES-256-GCM under keys specific to your workspace before they are stored. A saved value is used only to sign in to the site it belongs to, through a single-use, audited lease; it is not placed in tool results, traces or AI model prompts. You can reveal or delete a saved login in your vault. We never record the vault pages.
What happens when Unbrowse learns or uses a site for you
- To turn a website into a tool, our cloud browser visits it and records the network requests and responses involved. These traces are encrypted and kept private to your workspace.
- Cloud-browser sessions are recorded so you and we can review what happened: a replay of the page with every input field masked and password fields blocked, a screenshot per step (screenshots are not masked), the console output, the actions taken and the task you gave. Values typed into pages are stored only as their length. These recordings belong to your workspace and are deleted after 30 days; you can delete one sooner.
- Shared tools. By default, a tool you learn that only reads public pages, and needs no login or secret, is added to the public registry so others can use it. Before it is shared we remove cookies, authorisation and session data, tokens, passwords, your input values, examples and the task you typed, and we re-check it in a clean context. Tools that need a login are never shared. You can turn sharing off in Connections.
How you use the site
- Our own analytics. A first-party cookie (
ub_vid, 400 days) links your visits. We record which pages you view, the campaign you came from (UTM parameters, ad click ids, referring site) and product milestones such as signing up, creating a key, connecting MCP or running a first tool. We store a SHA-256 hash of your email with these events, never the email itself. We also use this identifier to run simple A/B tests. - Session replay. We record how visitors use the site, to find and fix problems: page structure and interactions with all input fields masked and password fields blocked, plus console errors, the page title, your country (from Cloudflare) and a device class. Pages with password fields, the vault and admin pages are never recorded. Emails, card numbers and tokens are removed from the text of a recording before it is indexed. Recordings are deleted after 30 days; the list of sessions, their text timelines and short written summaries are kept until deleted. We summarise sessions with an AI model (see Codegraff below). Adding
?replay=0to a page address, or the switch above, stops recording. - Umami. We use Umami Cloud (umami.is) for aggregate page analytics.
- Advertising conversions. If you arrived from an ad, we tell that ad platform (Meta, Google Ads, X or LinkedIn) when you sign up, run your first tool, or start or complete a purchase, so we can measure our ads. We send a SHA-256 hash of your email and user id, the ad’s click id and the event; Meta also receives your IP address and browser user agent. You can turn this off above.
- Referrals. If you follow a referral link (
?ref=), we record which referrer sent you.
Payments
Unbrowse is free during the beta and card payments are off. When they are on, payments are handled by Stripe; we pass it your workspace id, the pack you chose and your email, and we never see or store your card details.
Why we use it
- To provide the service you ask for: sign you in, run and learn tools, use the logins you saved, meter free usage.
- To keep it working and secure: debugging (including replays), abuse prevention and rate limits.
- To improve Unbrowse and understand which channels bring people in, including measuring ads.
- To email you: sign-in links, service notices, and a few onboarding emails. We send product news only if you ticked the box; every onboarding email has a one-click unsubscribe.
Who we share it with
- Cloudflare hosts Unbrowse (compute, storage, databases, email delivery and logs).
- Codegraff (gateway.codegraff.com) runs the AI models behind the chat, the indexing agent and replay summaries; it receives the page content, tool results and task text needed for those.
- TypeSafe (typesafe.ai) receives sanitised task text and tool context to route requests. A workspace can turn external inference off.
- Umami, and the ad platforms above for conversions.
- Stripe, only when payments are on.
- The websites you ask Unbrowse to use, which see the requests our cloud browser makes on your behalf, including the logins you saved for them.
- Organisations. If you use Unbrowse through an organisation, its admins can see your email, usage counts, API key prefixes and the hostnames of the sites you connected, not your saved logins.
- The law. We disclose information when required by law or to protect people and the service.
We do not sell your personal data.
Who at Unbrowse can see it
Unbrowse staff with administrator access can see account and usage data and review session replays, to operate and support the service. They cannot read the values of your saved logins.
How long we keep it
- Sign-in links: 15 minutes. Sessions: 30 days. Replay recordings: 30 days.
- Your account, workspace, saved logins, private tools and traces: while your account exists, until you delete them or ask us to.
- Analytics events, and replay session lists, timelines and summaries: until you ask us to delete them. We delete them on request.
Your rights
You can ask us for a copy of your personal data, to correct it, or to delete it, and you can withdraw consent (for example to product news) at any time. Email hello@unbrowse.ai; we reply within 30 days. Depending on where you live (for example under Singapore’s PDPA or the EU/UK GDPR) you may also complain to your data protection authority.
Security
Saved logins and learned traces are encrypted at rest; lookup keys for sessions, sign-in links and emails are hashed; identity passed inside our systems is signed and short-lived; sign-in and other endpoints are rate limited. Report security issues to security@unbrowse.ai.
International transfers
We are based in Singapore and our providers operate globally, so your data may be processed outside your country. We rely on our providers’ safeguards for these transfers.
Children
Unbrowse is not for children under 16 and we do not knowingly collect their data.
Changes
We will post changes here with a new effective date, and email account holders about material changes.
Unbrowse AI Pte. Ltd. · Singapore · hello@unbrowse.ai