Terms Agent

Privacy & Support

Effective August 24, 2026 · Policy version 0.11.0

Plain-language summary: policy analysis and initial receipt saving remain local. Development build 0.11.0 sends receipt or account-preference data only when the user presses the separate sync control.

What Terms Agent does

Terms Agent helps people assess Terms of Service, privacy policies, cookie notices, and related agreements before recording their own decision.

Information the extension handles

When the user clicks the extension, Terms Agent temporarily reads website content and the page address in that active tab so it can identify potentially important clauses, link findings to their source text, and locate related policies. This processing occurs locally on the user’s device; Terms Agent does not persistently access every website.

When a user records a decision, Terms Agent stores a local Trust Receipt using Chrome’s local extension storage. A receipt may contain the website domain and policy address, policy title and effective date, the user’s Agree or Disagree decision or per-purpose Allow and Deny choices, detected threat categories, source excerpts, a hash of the assessed policy text, the analyzer version, the provider manifest identifier and declared purposes shown during review, and the time of the decision. If the user presses Remember these choices, the extension also stores a versioned preference profile containing a device-only or pseudonymous account owner, provider and service identifiers, exact manifest ID and hash, purpose semantics, selected choices, sync revision, and update time. The extension shows only preferences belonging to the current device-only context or connected account. The extension also stores local appearance preferences and the time and app version when the user completes the onboarding guide.

Account session storage

Short-lived access tokens and the Clerk refresh credential remain in temporary extension session storage by default. A user may explicitly select Across restarts, which stores the rotating refresh credential in local extension storage restricted to trusted extension contexts; selecting Session only removes that persistent copy without ending the current session. Existing users who had already established persistent login retain that choice during migration. Signing out requests refresh-token revocation from Clerk and removes both credentials from the device, while reporting if Clerk cannot confirm revocation.

How information is used

The information is used only to provide the extension’s policy-assessment, source-linking, theme, and Trust Receipt features. Terms Agent does not use browsing activity or website content for advertising, profiling, creditworthiness, or unrelated purposes.

Optional sync

Policy analysis and the initial Trust Receipt save remain local. Development build 0.11.0 offers separate, optional Sync signed receipt and Sync preferences actions. Remembered preferences are read back and verified after local saving. Pressing Sync preferences transmits the current account’s provider/service scope, exact manifest semantics and hashes, selected choices, timestamps, and revision metadata to the Terms Agent staging API over HTTPS. The API stores them under a pseudonymous account identifier. A changed server revision produces a visible conflict and is not silently overwritten; the user must choose the account or device version. Applying either version only fills editable suggestions. It never saves a receipt, accepts terms, or operates website controls.

A signed receipt sync sends the selected decision, registered manifest ID, and receipt evidence to the Terms Agent staging API only after the user presses Sync signed receipt. Receipt evidence may contain the policy-text hash, analyzer version, detected threat categories, and source excerpts already shown in the local receipt. The staging API uses the user’s Clerk account token to authenticate the request, derives a provider-specific pseudonymous subject, stores and signs the receipt, and returns receipt and verification identifiers. Clerk processes authentication data and Cloudflare operates the staging API and storage. Terms Agent does not sell this data or use it for advertising, profiling, creditworthiness, or unrelated purposes.

The staging API creates short-lived operational security logs in Cloudflare Workers Logs. Terms Agent’s custom logs contain a random request identifier, fixed route category, request method, response status, duration, environment, and fixed security-event category. They are designed not to contain full request paths, query strings, receipt or manifest identifiers, account or subject identifiers, authorization credentials or hashes, request or response bodies, IP addresses, or user-agent strings. Automatic invocation logs and automatic traces are disabled. Cloudflare may still process ordinary network and security metadata, including IP addresses and device or connection information, as the infrastructure operator delivering and protecting API requests. Terms Agent’s custom operational logs are not keyed to a Terms Agent account and therefore are not included in account export or erasure controls. Cloudflare retains them according to the staging account’s logging configuration and platform limits.

Storage and deletion

Information is stored in Chrome’s local extension storage on the user’s device. Users can delete individual local Trust Receipts from the Trust Receipts page, delete all local receipts from Settings, or delete remembered preference profiles individually from Settings. Deleting a synced preference from Settings also deletes the matching account copy after a revision check; if it changed elsewhere, deletion stops and asks the user to sync first. Removing the extension through Chrome also removes local extension storage according to Chrome’s behavior, but does not by itself delete an account-synced preference. Deleting a preference does not delete a receipt, and local receipt deletion does not alter a synced staging receipt.

Settings provides separate authenticated controls to count synced receipts and account preferences, withdraw an individual synced receipt recorded on this device, export account-synced preferences, or permanently erase this account’s receipts across all registered staging providers and all account-synced preferences. For receipt export and erasure, the server derives a different pseudonymous subject for each registered provider from the authenticated account; the extension does not choose or transmit a provider identifier. Withdrawal preserves a server record in withdrawn state; erasure permanently deletes the matching server records and removes the active account’s local preference copies.

Permissions

Terms Agent uses activeTab and scripting to temporarily assess the current page and highlight exact source passages only after the user clicks the extension. It uses storage for local preferences and Trust Receipts and identity to open the user-initiated Clerk login flow. It does not request persistent access to every website or access to payment information, contacts, or files.

Security

Terms Agent minimizes stored information, keeps policy analysis local, uses encrypted HTTPS transport for explicit sync, keeps short-lived access tokens in browser session storage, and restricts the persistent Clerk refresh credential to trusted extension contexts. No security method can guarantee absolute protection.

Changes

If a future release introduces external data transmission or materially different data practices, this policy and the Chrome Web Store disclosures will be updated before that functionality is released, and any required user notice or consent will be provided.

Support

Questions, bug reports, and privacy requests may be sent through the support contact provided on the Terms Agent Chrome Web Store listing.

Chrome Web Store Limited Use

The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.