Legal & Privacy Architecture

Privacy Policy

Our privacy framework is built on cryptographic security, scoped accessibility tree inspection, and zero telemetry collection.

Last Updated: August 25, 2026Version: 2.4

1. Overview & Privacy Principles

Runexa ("we", "our", or "the Service") provides an autonomous web agent that operates within Chromium-based browsers to execute user-directed web tasks. We recognize the profound sensitivity of browser data and operate under three non-negotiable principles:

Data Minimization

We only inspect the minimum structural elements necessary to fulfill the specific prompt given by the user.

Client-Side Isolation

The agent runs exclusively within the active tab group you explicitly designate. Unrelated tabs and browsing history are completely invisible to Runexa.

Zero Data Commercialization

We do not sell, license, share, or broker your personal data, browser state, or queries to any third-party advertising networks.

2. AXTree Perception vs. Screen Recording

Traditional AI automation tools frequently rely on continuous full-screen recording or streaming video frames to cloud servers. Runexa uses a fundamentally more private architecture based on the W3C Accessibility Tree (AXTree) standard:

  • Semantic Tree Snapshots: Instead of transmitting pixel feeds, Runexa reads the hierarchical semantic structure (button labels, input fields, links, and headings) of the active tab.
  • No Background Continuous Observation: Element perception is triggered strictly when an agent step is scheduled. When the agent is idle or finished, all DOM inspection listeners are terminated.
  • Ephemeral Perception Data: Accessibility snapshots are converted to structured step instructions and immediately discarded. No visual recordings of your pages are stored on our servers.

3. Tab Group Isolation & Zero Cross-Tab Leaks

Runexa implements strict browser sandbox boundaries via Chrome's Manifest V3 API:

Scoped Tab Group Binding

When Runexa is launched, it attaches exclusively to a designated Chrome Tab Group. If you switch to your personal email, banking portal, or social media tab outside the group, the extension sidepanel automatically disables interaction and stops all execution.

4. BYOK Vault & AES-256 Encryption

For users on the Starter (BYOK) Plan who provide their personal API keys (DeepSeek, Anthropic Claude, OpenAI, Google Gemini, or custom OpenAI-compatible proxies):

AES-256-GCM Standard

API keys are encrypted server-side with unique initialization vectors (IVs) and authenticated cipher tags prior to database storage.

Zero Plaintext Exposure

Keys are never returned in plaintext to the browser dashboard after save. Decryption occurs strictly inside isolated API execution contexts.

5. AI Inference & Zero Model Training

When you initiate a browser action, the agent prompt and the active tab's AXTree structural snapshot are sent to the foundation model provider of your choice (DeepSeek, Anthropic, OpenAI, or Google):

  • Zero Training: In accordance with standard Commercial & Enterprise API agreements, providers do not use your prompt or browser data to train public LLM weights.
  • Encrypted In-Transit: All data transmissions utilize TLS 1.3 encryption with strict certificate validation.
  • Direct BYOK Invoicing: When using your own keys, LLM token consumption is billed directly to your account with the respective provider.

6. Information We Collect

We collect only the essential technical and account data required to operate the service:

CategoryExamplesPurpose
Account CredentialsEmail, Google Profile Name & AvatarAuthentication and profile personalization.
Billing RecordsStripe Customer ID, Subscription TierSubscription verification and invoice access.
Encrypted KeysAES-256-GCM ciphertextsDirect inference calls on BYOK starter tier.
Local CacheSession token, tab group stateStored locally in Chrome extension storage.

7. Data Retention & Account Deletion

You retain complete sovereignty over your data. We retain account metadata only for as long as your account remains active.

One-Click Complete Account Erasure

You can permanently delete your account at any time directly from the Dashboard → Settings → Danger Zone. Upon deletion, your user profile, stored API keys, and session records are immediately purged from our active databases with cascade deletion.

8. GDPR, CCPA & International Rights

Under the European General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and applicable global privacy laws, you possess the right to:

  • Access and obtain an export copy of your stored account data.
  • Request rectification of incorrect profile information.
  • Demand permanent erasure ("Right to be Forgotten") of all stored data.
  • Opt-out of any future automated processing.

9. Contact & Security Inquiries

If you have questions, feedback, or security disclosure reports regarding this Privacy Policy, please contact our dedicated security team: