A LITTLE CLARITY

Privacy policy

What WebAct processes, why it is needed, where it goes, and the choices available to you.

Draft updated: September 21, 2026

Policy preview. This page describes the current product and proposed terms. The operator’s legal identity, address, contact details, and final policy terms must be completed before public release. It is not a finalized agreement.

What this policy covers

WebAct is the product name. The operator’s legal name, country, business address, and designated privacy contact have not yet been finalized in this preview. See Contact & support for the currently available preview contact route.

This policy covers the public WebAct website, automation guides, account service and browser extension. The website’s illustrative examples and the extension’s AI-assisted tasks have different data flows.

Website and free tools

Public pages load static HTML, CSS, JavaScript, fonts, and images from the website host. The host may process connection details such as IP address, request time, browser information, and requested URL to deliver and protect the site.

The free-tool pages show illustrative examples and copyable task instructions. They do not extract data from your pages. Tasks run through the extension after you activate it on a source page; context shared with a task is processed by the selected AI provider. The website’s example CSV contains only synthetic data.

The contact composer also prepares text locally. It does not create a ticket or send an email. If you copy, download, or send the prepared message, the destination you choose receives it.

This website uses Google Analytics to measure visits and page views. The Google tag loads when a page opens and may set analytics cookies to distinguish visitors and sessions.

Account and service records

The account service processes your email address, verification status, account identifiers, session records, and security events. Passwords are stored as salted hashes. Verification codes and reset links are stored as challenge hashes and expire after their permitted use period.

When Google sign-in is available and you choose it, the service processes the identity claims needed to verify your account. WebAct account sign-in is separate from your selected AI provider’s browser session.

The service records plan and subscription status, task-allowance usage, managed AI usage and spending, and billing-provider references. Payment checkout and subscription management use Stripe when billing is configured; card entry happens in the payment provider’s flow.

Page content and AI assistance

When you activate WebAct and request assistance, the extension can process your instructions, selected or visible page content, source URL, relevant page controls, images or attachments you choose, and observations of task results. Share only the context you intend the assistant to use.

Browser mode uses the selected provider session, currently ChatGPT. Managed AI uses the configured API connection. Prompts, shared context, and task observations can be sent through the WebAct service and to the selected AI connection. Their retention and provider data controls differ.

Automation state can persist in the WebAct service, including the instruction, latest observation, action receipts, pending steps, and result summary. Some approved code actions can return additional page data or make network requests using the page’s signed-in access. Review the code and scope before approving it.

Deleting local WebAct history does not delete a conversation stored by an AI provider. Use the provider’s own controls for provider-held records.

Why the data is used

Service data is used to authenticate accounts, provide the requested assistance, keep tasks resumable, check outcomes, enforce usage allowances, process subscriptions, deliver account emails, troubleshoot reported problems, and protect the service against abuse.

Page content is not used by this website to build advertising profiles. This implementation contains no advertising integrations. Provider processing is governed by the selected provider’s own terms and controls.

Where data-protection law requires a lawful basis, the applicable basis depends on the operation: delivering a requested service, maintaining proportionate security, meeting legal duties, or obtaining consent for an optional activity. The operator must confirm the applicable jurisdiction and processing bases in the finalized policy.

Providers and destinations

  • AI providers: the selected browser connection or configured managed API receives the information required for the requested assistance.
  • Brevo: the configured transactional email service receives the recipient address and email content for verification, password recovery, welcome, and account-security messages.
  • Stripe: configured billing flows process checkout, subscription, and payment information.
  • Google: when Google sign-in is configured and chosen, the identity flow verifies the account.
  • Hosting and storage: the selected deployment providers operate the website and service infrastructure. Their names, locations, and backup practices must be included in the finalized deployment policy.
  • Your integrations: a webhook destination you configure receives the task instruction, result summary, source-page URL, and verification explanation. It does not receive page snapshots or file attachments through this result payload.

Information may also need to be disclosed to meet applicable legal obligations, address abuse or security incidents, or respond to a request you authorize. Data already delivered to another service follows that service’s controls and retention.

How long information remains

  • Contact-composer input: held in the current page; not saved by the site. Your own downloads, clipboard, and browser restoration are separate.
  • Local extension library: retained in the browser profile until you remove records, reach history limits, clear extension data, or uninstall. Signing out hides account-scoped local work; it does not delete that library.
  • Login: account sessions last up to 30 days and can be revoked earlier. OAuth state is short-lived. See Cookies & storage.
  • Automation state: active execution expires after 24 hours, but expiry or cancellation is not deletion. Recent task state is kept under the service’s storage limits; the operator must confirm any additional time-based retention.
  • Webhook delivery: payloads can remain for up to 7 days; deduplication receipts can remain for up to 30 days. Removing a destination does not withdraw an accepted delivery.
  • Account, billing, security, and backups: retention must reflect the deployed system and applicable legal duties. The final policy must identify those periods or the criteria that determine them; this preview does not promise an unimplemented deletion schedule.

Your choices and requests

You can choose the context you share, review or stop tasks, clear local history, remove connected destinations, sign out, and uninstall the extension. Canceling a task, signing out, uninstalling, canceling billing, and requesting account deletion are different actions.

Depending on applicable law, you may be entitled to request access, correction, deletion, restriction, portability, or to object to particular processing. Where processing relies on consent, you may withdraw it. You may also be able to complain to your relevant data-protection authority. Rights and exceptions depend on your location and the processing involved.

Use Data controls & deletion to distinguish local records from service and provider records, and prepare a privacy request. Identity verification may be needed, but never provide a password or verification code to support.

Processing locations and children

Your AI, email, payment, and integration providers may process information in countries different from your own. Exact hosting regions, recipients, and applicable transfer safeguards depend on the deployment and must be confirmed before this policy is finalized. This preview makes no data-residency guarantee.

WebAct is designed for general productivity and is not directed to children. Provider age requirements also apply. If you believe a child has supplied personal information inappropriately, use the privacy contact route so the situation can be assessed.

Updates to this policy

This page will show the date of the current policy. Material changes to data use should be reflected in the policy and relevant product disclosures before the new processing begins.

Read the related cookie information and security overview for more detail about the current implementation.