Know where your data goes

Data handling & privacy

ToolBraid 0.2.0 release candidate · 12 September 2026

What ToolBraid processes

ToolBraid connects an MCP-compatible AI client to browser pages using a Windows companion. It can process the URL, title, visible text, links, forms, field values, accessibility information and media on pages to which the extension has access. Depending on the pages you permit, this content can include personal information, private communications, location, health or financial information.

Requested visual features can process screenshots, images, video frames and audio from the selected page. The form extractor omits password and recognized payment-field values; this does not guarantee that sensitive information elsewhere in page text or captured media is removed.

Browser tools can manage tabs, navigate pages, fill or submit forms, inspect downloads and attach a user-selected file. The companion also provides desktop accessibility controls and bounded file operations. File and folder grants use local selectors and opaque handles; granting access permits the corresponding tool to process that content.

Where the data goes

The browser-to-companion connection uses native messaging. The companion-to-client connection uses an authenticated local named pipe. The distributed runtime does not include a ToolBraid analytics or advertising endpoint.

Tool results and requested page content are returned to the MCP client you configure. If that client uses a cloud AI provider, that provider may receive this data under its own terms and privacy policy. Local transport is not a promise that all AI processing is local.

An optional OpenAI-compatible multimodal endpoint can be configured in the extension. When enabled, captured media and analysis requests are sent to that endpoint. The endpoint and model configuration are stored locally; an entered API key is stored in browser session storage, not in the persistent settings record. Browser session storage is not an encrypted password vault.

Normal browser requests to the websites you visit still occur. Submitted forms, uploads and other actions send data to those websites as part of the requested action.

Limited use: proposed publisher policy

ToolBraid uses the data it handles to provide the browser, media and local workflow features the user enables. The distributed software contains no mechanism for selling page data, advertising profiles or publisher-side model training, and no publisher endpoint that receives page contents. Transfers to the user's selected MCP client, AI endpoint or target website are made to carry out those features.

Before publishing, the publisher must confirm that its actual support, hosting and data practices comply with the Chrome Web Store User Data Policy, including its Limited Use requirements. This draft does not certify practices outside the inspected local software. Data sent to a separately configured AI provider is also subject to that provider's policy.

Storage, retention and removal

The extension stores local preferences, approval and audit records, workflow state and explicitly saved semantic memory. Live page bindings, nonces and captured-media handles are transient. The companion stores authentication configuration and local job, schedule, workflow or media-job records in its installation data directories. Retention is feature-dependent; this release does not promise automatic deletion after a fixed number of days.

Removing the extension through the browser removes its browser-local storage. The companion uninstaller removes program files and registrations but deliberately preserves settings, authentication configuration, backups and local data. Remove the retained installation data separately if you no longer need it. Removing local data does not remove copies held by websites, the MCP client or its AI provider.

Your controls

The public edition starts with AI control paused. Its side panel explains direct control and requires an explicit checkbox and enable action. Enabling control permits the connected AI to use available tools without repeated approval, including form submission. The choice persists across browser restarts. Site access is requested for the selected origin; advanced browser debugger access is a separate optional choice.

Pause control blocks new extension commands and disconnects the companion connection. Actions already dispatched, including long-running local jobs, may finish; pause cannot undo them. Review or revoke site and debugger permissions in the browser. Configure only trusted MCP clients and only connect AI endpoints whose data handling you accept.

This website

This website's code uses no analytics scripts, advertising scripts, cookies, browser storage or sign-up forms. Its images and styles are served from the website itself. The intended hosting provider is Cloudflare; hosting a public site requires that provider to process ordinary web requests. Final hosting and support disclosures must be confirmed before publication.

Publisher contact

For privacy questions or support, email dumitrescu91dan@gmail.com. Never include API keys, authentication tokens, private page contents or personal documents in a support report.