WalkCroach Chrome Privacy Policy
WalkCroach Chrome is a page-reading SME copilot. It helps you summarize pages, ask questions, draft text, and save notes you choose to keep. It is not a background scraper and does not upload page content just because you browse.
1. What we collect
Only when you take an explicit action (summarize, ask, draft, propose, save, or recall):
- Page URL and title of the active tab
- Extracted main text from that page (Readability-style extract), truncated for size
- Optional structured fields you review and accept before save (e.g. price, candidate summary)
- Workspace names and saved captures you create
- Screenshots, only if you ask for one. When you tick “Add a screenshot” on a save, WalkCroach captures the visible area of the current tab, shows it to you, and stores it only if you then confirm. It never captures the full scrollable page, another tab, or anything you have not been shown first.
- Connected-account data, only for actions you confirm. If you connect Google Calendar, Gmail, Slack or Stripe, WalkCroach reads or writes only what a specific confirmed action needs — the events in a date range you asked about, the email you approved, your balance. It does not browse your mailbox, calendar or account in the background.
- Device session identifiers for try-before-sign-in, and Cognito account id when you sign in
- Technical logs: route name, latency, error codes, character counts — not full page bodies
We do not collect:
- Passwords, payment card numbers, or other credentials from pages
- Browsing history of sites you never act on
- Audio, microphone, or camera
- Continuous or background capture of your screen. Screenshots are single, still images of the visible tab, taken only when you ask for one on a specific save
- The contents of your mailbox, calendar or Slack history
- Contacts, bookmarks, or downloads
2. How we use it
- To run the AI features you requested (summarize, ask, draft, propose, recall)
- To store captures and embeddings so you can recall them later
- When you choose to link a workspace to a WalkCroach Web project, to make those saves available in that project
- To operate, secure, and improve the service (rate limits, crash/error metrics)
3. Where it is stored and who can access it
- Data is processed by WalkCroach backend services (API Gateway / Lambda) and stored in CockroachDB in the WalkCroach cloud environment.
- Model inference uses Amazon Bedrock (or equivalent configured provider). Page text you send for a request is used to generate the response for that request.
- Access is scoped to your device session or signed-in account. Support operators may access operational logs (without plaintext page bodies) to diagnose outages.
- We do not sell personal data. We do not use extension data to train third-party advertising models.
4. Permissions and Limited Use
At install, WalkCroach requests storage,
activeTab, scripting, sidePanel,
identity (used only to complete sign-in to your WalkCroach
account — we do not read your Chrome profile identity),
contextMenus, and a
single host permission for the WalkCroach HTTPS API
(our backend only — not arbitrary websites).
Page access is granted one site at a time. The extension
declares http://*/* and https://*/* as
optional host permissions. None of them are granted at install, and
no install warning about your browsing is shown. The first time you use
WalkCroach on a site, Chrome asks you about that one site. Every
site you have allowed is listed under Account in the side
panel, and withdrawing one takes effect immediately and clears anything
cached for it.
WalkCroach declares no persistent content script. Page text is read by a
one-shot extraction that runs only when you click summarize, ask, draft,
save or insert, on a site you have allowed.
Site profiles. WalkCroach may download an updated list of
which sites map to which shortcut. That list is signed data describing
match patterns and button labels; it is never executed as code, and if it
cannot be verified the version inside the extension is used instead.
Limited Use: The use of information received from Chrome APIs and from
pages you explicitly act on will adhere to the
Chrome Web Store User Data Policy, including the Limited Use requirements. We use that data only to provide or improve
WalkCroach Chrome’s disclosed single purpose (SME page copilot: summarize, ask, draft,
save, recall). We do not sell user data, use it for personalized advertising, or allow
humans to read page content except for the limited exceptions in that policy (security,
law, or with your explicit consent for support).
5. Retention and deletion
- Device sessions and captures remain until you delete them or request account deletion.
- You can delete individual captures and workspaces from the extension.
- Screenshots are deleted with the capture they belong to, and expire automatically 90 days after they are stored even if you keep the capture.
- Connected accounts. Access tokens are held in AWS Secrets Manager, never in our database and never sent to the extension. Disconnecting from the panel or from WalkCroach Web deletes the stored token immediately. A record that an action was proposed, confirmed or declined is kept so you can audit what was done on your behalf; it holds the action and its outcome, not your credentials.
- Cached page text inside the browser is cleared when the tab navigates or closes, when you withdraw a site, and when the browser session ends.
- To delete an account and associated Chrome/Web data, contact privacy@walkcroach.com.
6. Children
WalkCroach Chrome is intended for business users. It is not directed at children under 13 (or the equivalent age in your jurisdiction).
7. Changes
We may update this policy. Material changes will update the effective date on this page. Continued use after the effective date means you accept the updated policy.
8. Contact
Privacy questions:
privacy@walkcroach.com
Product:
https://walkcroach.rinegansolutions.com
This policy:
https://walkcroach.rinegansolutions.com/chrome-privacy.html