CopperOS

Privacy policy

Last updated: 3 October 2026

In the cloud

Your chats, memories and settings are stored on AWS in the US. Your API key is encrypted. Delete it all from Settings.

On your computer

The extension talks only to the broker on your machine. We receive nothing.

Never sold

No ads, no analytics, no tracking. Used only to run CopperOS for you.

CopperOS is an open-source Chrome extension that lets an AI agent carry out tasks in your browser. The agent runs in one of two places, which you choose when you first open it and can change in Settings:

  • in the cloud: CopperOS's hosted service, which you sign in to, or
  • on this computer: the CopperOS broker, a program you run yourself.

This policy explains what CopperOS reads, where it goes, and what the developer of CopperOS ("we", "us") receives in each case.

What the extension reads

Only while carrying out a task you gave it, and only in the tabs it is working in:

  • Page content: text, links, buttons and form fields from the page's accessibility tree. Password fields are the exception: their values are withheld.
  • Screenshots of the page, when the text view isn't enough.
  • Tab titles and URLs: of the tab a task starts in, the pages it visits, and your open tabs when it needs to find or switch to one. The side panel also shows the site of the tab a task would start in.
  • Google Sheets data, read with your own Google login, when you ask it to work with a spreadsheet.
  • Page loading activity, used only to tell when a page has finished loading. It is not recorded or sent anywhere.

The agent also uses what you give it: your tasks, rules you set for its supervisor, your answers to its questions, your approvals, and facts you ask it to remember.

In the cloud

Your account

You sign in with your Google account, through Amazon Cognito. Google tells us your email address, and we keep it with a sign-in ID. We don't receive your Google password or anything else from your Google account.

What we store

Our service runs on Amazon Web Services (AWS) in the United States (N. Virginia). It stores:

  • your chats: what you asked, what the agent did, and the page text it read (screenshots are not kept);
  • memories, which are lasting facts about you the agent saved so it doesn't have to ask again (for example the email address you use for job applications);
  • the progress of your tasks, and any rules you gave the supervisor;
  • your settings, including the AI provider API key you entered. The key is encrypted with AES-256, under a key that is itself protected by AWS Key Management Service, and is never sent back to your browser.

Who else processes it

To carry out a task, our service sends the conversation (your task, page content and screenshots) to:

  • the AI provider you chose in Settings (OpenRouter or OpenAI), using your API key. That provider's own privacy policy covers what it does with the data;
  • Jev (typesafe.ai), which runs the checks that keep the agent safe and on track: whether a detail it is about to enter was given by you, whether it is still doing what you asked, whether the task is finished, and which of your memories are relevant. Jev receives the parts of the conversation, page content and memories each check needs.

We use AWS, your AI provider and Jev only to run CopperOS for you.

Service logs

To find and fix problems, our service keeps logs for 14 days. They can include short excerpts of tasks, of the agent's actions, and of values it entered into pages.

On this computer

The extension talks only to the broker at 127.0.0.1 on your own machine. That connection never goes over the internet, and we receive nothing.

  • The broker keeps your chats (without screenshots), memories, task progress and settings, including your API keys, in its storage folder on your computer.
  • It sends the conversation to the AI provider you selected (OpenRouter, OpenAI or Ollama) over HTTPS. With a model running in Ollama, nothing leaves your computer.
  • If you add a Jev API key to the broker's settings, parts of the conversation, page content and memories are sent to typesafe.ai for the checks described above. Without a key, nothing is sent to Jev.

Suggestions

If you use Send a suggestion in Settings, we receive what you wrote, the CopperOS version and whether you run it in the cloud or on your computer. If you are signed in, we also receive your email address so we can reply. Suggestions arrive by email. To stop the form being abused, your IP address is kept for about an hour.

What we don't do

We don't sell your data, show ads, or use analytics or tracking. We don't use your data for anything except running CopperOS for you. We look at stored data only when we have to in order to keep the service running or fix a problem, or when you ask us for help.

Stored by the extension itself

  • In Chrome's local storage: your cloud sign-in (its tokens and your email address), whether you chose the cloud or this computer, and your "Ask before" setting.
  • In Chrome's session storage: which chat is open, the recent steps of a task in progress, which tabs belong to which chat, and where its on-page frame is shown. Chrome clears this when the browser closes.

Deleting your data

  • Cloud: Settings → Delete my account permanently deletes your chats, memories, task progress, settings, API keys and your sign-in, straight away. Our database backups can hold a copy for up to 35 days before it is gone for good, and service logs expire after 14 days.
  • This computer: delete the storage folder in your CopperOS download, or single files in it.
  • Uninstalling the extension removes what it stored in Chrome. Data already sent to an AI provider or to Jev is covered by their own retention policies.

Security

Everything between the extension, our service, your AI provider and Jev travels over encrypted connections (HTTPS and secure WebSockets). Your API key is stored encrypted, and each account's data is kept apart from every other's. On your own computer, the broker stores API keys in plain text in its storage folder, so keep your computer account secure.

Limited Use

CopperOS's use of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. It is used only to carry out the tasks you ask for. It is never sold, never used for advertising, and never used for anything unrelated to that purpose.

Where your data is processed

Our service and its data are in the United States. If you use the cloud from elsewhere, your data is transferred there.

Children

CopperOS is not directed at children under 13, and they may not create an account.

Changes

We will post any changes on this page with a new date. If a change affects how we use data already stored, we will say so in the extension first.

Contact

jasmeetsingh0502@gmail.com · GitHub