Privacy Policy — Agent Socket

Effective date: 2026-10-05

This privacy policy describes how the Agent Socket Chrome extension and its companion services, the relay (agentsocket.dev) and the tool registry (registry.agentsocket.dev), handle data.

What Agent Socket is

Agent Socket lets the user expose one browser tab of their choosing as a set of HTTP tool endpoints, so an AI chat (such as Claude, ChatGPT, or Gemini) can read and interact with that tab. The extension does nothing until the user explicitly clicks "Connect this tab" in its popup. It has no access to any website at install time: Chrome asks the user to grant site access the first time they click Connect, and that access is used only for the one tab the user connects.

What data is processed

When the user starts a session, the following data may flow from the user's browser through the relay (agentsocket.dev) to whichever AI chat the user pastes the session URL into:

This data is sent only in response to tool calls that arrive on the user's one-time session URL.

What we do NOT collect

Where the data goes

  1. Browser → Relay (agentsocket.dev): Tool-call payloads travel over a WebSocket from the extension to the relay. The relay is a Cloudflare Worker with one Durable Object per session that holds the WebSocket open and forwards messages. It does not store tool-call payloads (no database, no logs in production), except the result of a long-running ("async") tool call, kept until the AI fetches it or the session ends. It does store the session's setup, as described under "How long data is retained".
  2. Relay → AI chat: The relay forwards tool-call results to whoever is holding the user's session URL — by design, the AI chat the user pasted the URL into. What that AI chat does with the data is governed by the AI chat's own privacy policy (e.g. Anthropic's, OpenAI's, Google's).

Tool registry (registry.agentsocket.dev)

The registry is a public catalog of "site profiles": notes and ready-made tools for particular websites, so the AI doesn't have to work out each site from scratch. The extension uses it in these ways:

The registry runs on Cloudflare Workers with Cloudflare's request logging turned on, so requests (including the hostname in the request URL) also appear in the operator's Cloudflare logs for Cloudflare's log-retention period. The registry URL can be changed in the extension's Settings (for example to a self-hosted registry), in which case these requests go there instead.

How long data is retained

Third parties

We do not sell, rent, or share user data with third parties for advertising, marketing, or any other purpose unrelated to making the active session work. The relay and the registry are hosted on Cloudflare Workers; Cloudflare's data-handling practices are governed by its own privacy policy at https://www.cloudflare.com/privacypolicy/.

User control

Changes to this policy

If we change this policy, we will update the Effective date above and publish the change in the same repository.

Contact

Questions about this policy: open an issue at https://github.com/blitzdotdev/agent-socket/issues or email contact@agentsocket.dev.