# Privacy Policy

**Last updated: September 11, 2026 · Version 2026-09-11**

> **Plain-language summary (not a substitute for the full policy below).** From the website
> and wait-list we handle your **email**, product choice, consent record and limited
> **sign-up context**: the source page and browser language. Earlier sign-ups may have saved
> the additional context described in §2. We use these records to operate the wait-list,
> provide account access notices and understand product interest. Hosting and account
> services also process ordinary network information needed to deliver and secure the Site.
>
> **Power Extension creates and runs personal apps.** App code, versions, instructions and
> ordinary saved data stay in local extension storage. Build and approved AI actions send
> relevant instructions, code and deliberately supplied context through Power and OpenRouter
> to model providers. A started build can finish after you close the panel. Private diagnostics
> can contain personal app data; they are downloaded locally, not uploaded automatically.
> Optional page tools, saved page placements, contact filling and an encrypted password vault
> have separate controls. The older browser-operator mode can send page text and, in the cases
> described in §2a, one unmasked screenshot. **Do not assume prompts, app data or exports are anonymous.**
>
> **If you subscribe**, payment is handled by Stripe — **we never see or store your card
> number**, only your plan status and Stripe's identifiers for you.
>
> We **don't sell your data**, we run no advertising and **no analytics or tracking cookies at
> all** ([Cookie Policy](/cookies)), and you can unsubscribe or ask us to delete your account at
> any time. Our providers (Supabase, Vercel, Resend, Stripe, OpenRouter and the AI providers
> behind it, and Google for the site's fonts) may process data in the United States.

This Privacy Policy explains how **Azamat Smailov**, a sole proprietor carrying on business
as **GENZAI** (Ontario Business Identification Number **1001692014**) ("**we**", "**us**",
"**our**") of Toronto, Ontario, Canada handles personal information in connection with the
**Power** website, wait-list, accounts, subscriptions, and the Power extension (together, the
"**Site**" and the "**Products**"). Canada's **Personal Information Protection and
Electronic Documents Act (PIPEDA)** governs applicable commercial handling of personal information.

---

## 1. Accountability and our Privacy Officer

We are accountable for the personal information under our control. Our Privacy Officer can
be reached at **privacy@power-extension.com**.

## 2. Information we handle

The Site handles information needed for the wait-list, your account and the purposes below.
The extension has separate data handling described in **§2a**:

- **Account & identity:** your email address (used for passwordless sign-in with a one-time
  code) and an internal user identifier.
- **Wait-list membership:** which product's page you first signed up from, every product
  wait-list you have joined, and when you joined.
- **Consent record:** the Terms version and acceptance details recorded by the relevant sign-up flow. The extension also records the version and hash of the exact extension notice you accept. A historical website record may identify only the Terms version, rather than a separate Privacy version.
- **Access record:** whether your account has access to a Product, when access was granted,
  and whether we sent an access notification. Eligibility, security checks, required notices
  and the plan you select can also affect which features are available.
- **Billing record (only if you subscribe):** your plan, its status, the current period end,
  and the identifiers Stripe assigns to you as a customer and to your subscription. **Card
  numbers are entered on Stripe's own payment page and never reach us** — we cannot see them,
  and we do not store them.
- **Sign-up context:** the current wait-list form sends its source (the landing site), page
  path without query parameters and browser language. It does not collect a referring URL,
  campaign query tags, time zone, screen dimensions, full user-agent string or a location
  lookup for that sign-up record. Ordinary network requests still disclose network and
  browser information to the services receiving them.
- **Earlier sign-up context:** older records may include the referring site, campaign tags,
  language, time zone, device/browser details, screen size and approximate country, region
  or city supplied by the earlier form. This website update does not silently delete or
  rewrite those account records. We handle them under the purposes, rights and retention
  provisions in this Policy; you may ask about or request deletion of your record. We do
  not collect precise GPS location through the wait-list.
- **Anti-abuse record:** so one address or one machine cannot flood strangers' inboxes through
  our sign-up form, we keep a short log of join attempts containing the email address and a
  **one-way cryptographic hash of the IP address** (the address itself is not stored and the
  hash is used as a pseudonymous identifier; hashing does not make a predictable address anonymous). It exists only for rate-limiting.
- **Website local storage:** sign-in state, a cached public feature configuration and an
  optional analytics preference record; extension storage is described separately in §2a. **We set no advertising, analytics or
  cross-site tracking cookies at all** — the full list of what is stored in your browser, and
  who else sees a request when you load a page, is in our [Cookie Policy](/cookies).

**What we do NOT collect from the Site:** no card numbers or bank details (Stripe collects
those on its own page), no browsing history, no page content, no contacts.

**The extension is different.** When you install and run Power, **§2a governs your
installation** and page content *does* leave your device. The list below summarizes how the
extension handles data; §2a is the full, binding description.

- **Page content goes to third-party AI models.** To act on a page, the extension builds a
  text map of it and sends that, with your request, to large-language-model providers reached
  through **OpenRouter** over an encrypted connection. Those providers process the content to
  reason about the task. This third-party processing is essential to the product's accuracy.
- **Redaction is partial, not full anonymization.** In the browser-operator text-extraction path, common identifiers —
  emails, phone numbers, card numbers, IBANs, Canadian Social Insurance Numbers and US Social
  Security Numbers — are masked and restored only on your device; password fields are excluded from this page-text extraction. Other page text, including names and
  addresses, is minimized but may still be sent. **Redaction is always on and cannot be switched
  off** — there is no setting for it.
- **A screenshot can be sent, in two cases.** If a page has no readable text, or two planned
  steps in a row did not change the page as expected, the extension may send ONE screenshot of the
  visible tab to the model provider for that step; identifiers on the screenshot are not masked;
  the task log records this before the frame is sent (§2a).
- **What can sync to your account** (only when you are signed in): your saved page annotations
  sync to your account in our database (private to you under row-level access); chat history
  syncs only if you enable end-to-end encryption, in which case we store ciphertext we cannot
  read. **Nothing you annotate is contributed to a shared library unless you turn on “Shared
  site knowledge” in Settings** — that setting is off by default, and while it is off the
  reusable site knowledge the extension downloads is written by our team, not collected from
  you. If you do turn it on, see §2a for exactly what would be contributed.
- **Diagnostics.** Local task logs and the separate private app-support download can contain personal information, including instructions, app source, ordinary saved data and model replies. Recognizable credentials are scrubbed from the private download, which is not anonymized; you choose whether to share it. Separately, when a task
  ends the extension sends us a short record of the run itself — the outcome, the step count, the
  duration, how many times you stepped in, and the product and version you run (§2a). It carries
  no page content.

## 2a. Product data — the Power extension

This section applies only if you install and use the Power browser extension.


### Personal apps, Build and local storage

Power stores personal app source, guides, versions, instructions, ordinary app data, preview
and conversation drafts, and navigation state locally in account-scoped extension storage.
Ordinary app storage is **not encrypted by Power with a user-held key** and is not protected by your password-vault master password. Signing
out does not delete it. A private support download can contain code and ordinary saved data;
a PNG export contains the image you approve. Downloaded files are outside Power's deletion
controls. General app-file import and export are not offered in the current interface.

Choosing Create, discussion or an AI revision sends your brief and answers, existing app code
when relevant, and any deliberately attached page excerpt through our AI gateway and
OpenRouter to model providers. Code and instructions can themselves contain private content.
The entire ordinary saved-data map is not automatically added to the Build prompt. An app's
own AI feature sends the specific text shown for approval. That text may include data the app
read from its own local records or an earlier approved page excerpt. Choosing a fast,
reasoning or code mode changes the eligible managed model, not the requirement for the
app's AI action and applicable approval. An app's capability list does not itself transmit data. Text minimization and recognizable
identifier masking do not reliably remove every secret or personal detail you supply.

AI is provided through the managed Power account and plan; personal AI API keys are not supported. Power chooses an eligible model and shows its name. Availability can change between requests.
Build, app discussion and in-app AI do not silently switch to a different model after failure.
A model name does not guarantee a particular infrastructure provider or processing country.
The legacy ordinary-chat fallback is described separately in §5.

An explicitly started build can continue after you close the panel and save a result locally.
Reopening Power shows stored progress or results. **Use Stop to cancel; closing the panel is
not cancellation.** Stopping cannot retract information already transmitted or reverse provider
usage already incurred. Interrupted requests are not automatically replayed as new paid builds.

Generated HTML, CSS and JavaScript run in an isolated sandbox. They have no direct network,
Chrome API or other-app storage access. Packaged Power controls mediate declared capabilities,
with the applicable user confirmations. Isolation does not guarantee that generated output is
correct or suitable for your purpose.

### Materials you attach to a project

You can attach your own images, UTF-8 text/CSV files and HTTPS reference links in Build or
an app revision. Power stores a processed copy with the local project version and relevant
Build drafts; your original file is not changed. Images are decoded and re-encoded locally
with size limits. Original file metadata is removed in that processed image. Text and links
are stored as supplied content. A reference link is saved as an address; it is not fetched
automatically and does not grant website account access.

When you choose Create or Generate update, relevant attached text and reference metadata
are sent to the model through Power. If the selected model supports images and the Build
interface indicates image previews, small processed previews are also sent. Full local image
payloads are not added to the model prompt. The app can use the materials belonging to its
own saved version. They are ordinary local project data, not an encrypted secret vault.
Private diagnostics include material text, reference links and image metadata; project image
pixels and AI vision previews are omitted because those pixels cannot be credential-redacted.

### Page tools, public catalogs and persistent page apps

After you grant access for an app and site, the app can receive selected readable page text, title and address when you invoke its page action. That permission is remembered until you revoke it in the app settings; new capabilities or a wider site scope require approval. This
path excludes editable, form and hidden content and bounds the text returned. The app may
save the received excerpt locally. Sending it to AI is a separate approval. Opening a website
window uses that Chrome profile's normal site session; opening alone does not read its content.

Approved catalog searches send the displayed query directly to Wikipedia or Open Library.
The catalog receives the query and your network address; Power does not attach account tokens,
cookies or a referrer. Results name the source. The lookup itself does not use your AI balance.

Approved local page appearance and floating widgets can remain after Power closes and return
after navigation, reload and browser restart. Saved state includes timer deadlines, positions,
settings and permitted site scope. Daily appearance schedules use the device's local time,
including overnight hours, and a browser alarm; no location lookup or cloud scheduler is used.
A sleeping device applies the current time range when it wakes. Turning off the app or revoking
its permission removes its effects. The rendering libraries are packaged with Power.
Choosing All websites grants that app the stated capability for current and future HTTP/HTTPS
sites after the browser permission, until revoked; choosing This website narrows the scope.

With a site-access grant, you can select a region and describe your request in the small trusted
Power panel at that location. Creation requires your answers and an explicit Create action.
Selecting a region alone does not call a model or transmit its text. A local hide action uses
packaged code without AI; creating or revising app code uses the AI flow described above.
Power can bind the saved app to that location using a local placement record: exact page URL
(including its query string and fragment when present), anchor attributes and a text fingerprint,
size, screen position where applicable, app identifier, active state and page/site/granted-site scope. A viewport placement stays at a screen position; an element placement follows its document anchor. An uncompleted placement request may retain your prompt.
URLs and anchor attributes can reveal page context; a text fingerprint is not anonymization.

On matching reloads and in-page navigation, a packaged content script checks the saved location.
A changed page can prevent an exact anchor match or leave an app at its saved document
coordinates. Review the location and reattach it in Power when needed. The embedded app can use its own local
saved data; AI, page reads, exports, vault and form actions require the trusted Power window.
**Restoring a page app does not make an AI request.** Deactivate, remove and reattach are available in Power app settings. After a browser restart, restoration uses the last verified local account only while the stored authentication identity still matches; signing out or changing accounts removes the effects. Browser site permissions can remain until you revoke them;
removing a placement does not itself revoke that Chrome permission. A page may detect the
visible placement or the packaged app host; we do not promise that Power is undetectable.

An app with the declared page-change capability can invoke an explicit element picker to hide a
chosen element locally. The saved rule uses the exact page and anchor, can be restored in Power,
and does not delete or change the website's server data.

### Clipboard slots

An app with the clipboard capability can read or replace text after recent interaction in
the visible, focused Power app. Browser activation applies to recent app interaction; it is
not a verification of a particular button label. Clipboard hub provides explicit Paste and Copy buttons. Power requests the browser clipboard
permission and app access when needed. The app-level grant is remembered on this device
until you revoke it in app settings, but each read or write still requires your interaction. It does not monitor the clipboard in the background.
Clipboard hub stores the text and slot names you save as ordinary local app data, including
when that text contains personal or confidential information. These values can appear in a
private support download and remain until you clear the slot or remove the app. Avoid placing
passwords, access tokens or recovery codes in ordinary slots; use the protected vault for
passwords. A Copy action changes the system clipboard, which other software on your device
may then read. Clipboard slots do not call AI automatically.

### Optional local camera and microphone capture

An app can request a photo or a short audio recording through trusted Power controls. Nothing
is captured when the dialog merely opens. You choose Start, grant the browser permission, and
review the result before sharing it with the app. The app receives only the approved still image
or recording, not a live media stream or device identifiers. Power stops the device when capture
ends or the dialog/app closes. Photos are bounded to 1280 pixels and audio to 15 seconds.

Capture and ordinary canvas filters run locally. This capability does not provide generative
image editing, face replacement, speech recognition or an automatic cloud upload. Photo studio
keeps a chosen photo in its current session and offers an explicit PNG export. It saves adjustment
settings, not the photo, by default. A different generated app may save data you explicitly choose
to keep; ordinary saved app data can then appear in your private app/support export. Capture
payloads are not automatically copied into Power's runtime diagnostics.

### Optional password vault and contact filling

The optional password vault stores an encrypted local envelope using PBKDF2-SHA-256 with
600,000 iterations, a random salt and AES-256-GCM. You choose a master password; Power does not
keep a server copy of it or provide master-password recovery. The vault locks after inactivity.
A separate encrypted backup is available; you are responsible for protecting that file.

With approval, an app can show login metadata such as sites, labels and usernames. Login
passwords, private notes and the master password are handled through Power's protected controls,
not delivered to generated app code. After unlock and confirmation, Power can fill a selected
login on the exact approved site. It does not press Sign in or verify a successful login.

Contact tools can store names, addresses, phone numbers and other fields as ordinary app data.
These records may appear in app exports and private diagnostics and are not protected by the
password-vault master password. **The website can read approved filled values immediately
through its own scripts, even if you do not press Submit.** Check the site and fields first.

Optional encrypted chat sync uses a separate encryption mechanism; it is not the password vault. Encryption does not protect against every compromise of an unlocked
device or trusted extension context, nor against the destination site after an approved fill.

### Private app diagnostics

Power keeps bounded local Build and support history for recovery and diagnosis. A private
support download includes this workspace's app code, guides, versions, instructions, ordinary
saved data, drafts, recent job inputs/results and support operations. It can include page
excerpts and model replies. **This file is not anonymized.** The exporter excludes account
credentials and dedicated password-vault storage and scrubs recognizable credential fields and
token formats. It cannot reliably remove every secret pasted into an ordinary field. The file
is created on your device and is not automatically uploaded. Review it before sharing it with
anyone. Support staff may inspect material you deliberately send for your support request;
contact us about the scope and handling before sending sensitive records.

### Browser-operator mode and older features

**What it reads.** When you start a browser-operator task, the extension takes a structured snapshot of the
page you are on — the interactive elements and their labels, the visible text, the title and
URL — and of the pages that task takes it to, inside its task tab group. **Password and hidden fields are excluded from this extraction path.** This differs from the optional protected vault fill above. The browser operator is not intended to bypass CAPTCHAs or bot protection.

**How it acts on the page.** To click and type, the extension injects its own content script
into the tab it is working in and dispatches the clicks and keystrokes there. It does not attach
to Chrome's debugging protocol: the published build asks for no `debugger` permission, so you
will not see the "started debugging this browser" bar. Some sites accept only input the browser
itself generated; on those a step can fail, and the extension reports it as not done rather than
pretending it worked.

**What leaves your computer, and what is masked.** To decide each next step, the extension
sends that page snapshot plus your task text to a large language model through OpenRouter.
Before the request leaves your device, six categories of identity-bearing value are replaced
with reversible placeholders — **email addresses, phone numbers, payment-card numbers, IBANs,
Canadian Social Insurance Numbers and US Social Security Numbers** — and restored locally in the
answer, so the assistant still types the right value into your system.

**Please read this part.** Masking covers those six categories and nothing else. **The rest
of the page reaches the model as written — including people's names, street and property
addresses, reference numbers, prices, and the body text of the emails and listings you point
the assistant at.** This is inherent to how the product works: the assistant cannot copy a
property address it is not allowed to read. If a page holds something you would not put in
front of a third-party AI service, do not run a task on it.

**Screenshots.** Some pages carry no readable text at all — the interface is drawn as a picture.
On others the page map turns out not to describe what is really on the screen, and the assistant's
planned steps keep missing.
**If a page has no readable text, or two planned steps in a row did not change the page as expected, the extension may send ONE screenshot of the
visible tab to the model provider for that step; identifiers on the screenshot are not masked; the
task log records this before the frame is sent.** The second case can happen on an ordinary,
text-rich page, so a screenshot may carry names, addresses and anything else visible on it. At most
one screenshot is sent in a whole task, and none at any
other point of a run. Taking it may briefly bring that tab to the front, and the tab you were on
is put back afterwards. There is no on-device vision model in the product: the local image model
was removed, and nothing on your pages is analysed by a model running on your machine.

**What we store.** Your requests pass through our proxy so you do not need your own API
key. The proxy meters **usage only** — token counts, cost, model name, and when
your account was last active — to manage credits, and a record of rejected or malformed requests
(kind and size, no content). **The proxy does not intentionally persist complete prompt/page/answer bodies in its application records.** This statement concerns our proxy, not local app diagnostics or independent provider retention.

**Diagnostics we do receive.** When a task ends, the extension sends us one short record of that
run: the outcome (finished, failed or stopped), the number of steps, how long it ran, how many
times you had to step in, the product and extension version, and the date you installed the
extension (we keep only the earliest we receive). **It carries no page content, no URLs and no task text.** This is how we know
whether runs finish at all; the step-by-step task log itself stays on your machine.

**What stays on your machine, and what does not.** Chat history, task logs, automations and
settings stay in the extension's local storage on your machine. **Page annotations are the
exception: when you are signed in, the page maps you save — the site, the URL pattern, your
notes and the annotations themselves — are stored in our database**, private to your account
under row-level access, so they follow you between machines. **They are not published to other
users unless you switch on “Shared site knowledge” in Settings**, which is off by default and
refused by our servers until you switch it on. If a page map contains something you would not
put on our servers, do not save it.

**If you do switch it on**, a page map is contributed only after it has worked on three pages,
and only this part of it: the site, the URL pattern, your page note, and the label and purpose
you wrote for each control — in your own words. Email addresses, phone numbers, payment cards,
national ID numbers and street addresses are stripped from that text first; the page title, the
element fingerprints and any values you saved are never contributed at all. **Names cannot be
stripped automatically**, so a client name you typed into a note would be contributed with it —
which is why the setting is off unless you choose it. Switching it off stops further
contributions; to have maps you already contributed removed, ask us (§9).

Uninstalling the extension removes the local data with it. **Signing out does not erase local
data** — it ends your session and stops the sync, and the chats and logs already on your machine
stay there until you uninstall the extension or clear them from Settings. To have the data held
in our database deleted, ask us (§9).

**Human in the loop.** Protected app actions have contextual approvals. The browser operator is designed to ask before sending, submitting, deleting or paying; this is a design commitment, not a guarantee of all behaviour on third-party sites. Review the action and use Stop when necessary.

## 2b. Chrome Web Store data disclosure

This section states, category by category, what the extension collects — in the same categories
the Chrome Web Store uses, so what you read here and what the store listing says are the same
thing. It restates §2a; where the two ever disagree, §2a is the fuller description.

**The extension's single purpose** is to create and use personal productivity tools with optional AI and approved browser capabilities. Older browser tasks support that purpose. Everything below exists to serve that purpose or to keep the service running,
secure and metered.

| Chrome Web Store category | Collected | What that means here |
|---|---|---|
| Personally identifiable information | **Yes** | Your email address, for the account and sign-in code. Names and street addresses that appear on a page you run a task on are sent to the model as part of the page (§2a). |
| Health information | **Yes, if you supply it** | Personal apps, prompts or approved page context may contain health information. We do not require it to use Power; avoid supplying it unless you have authority and the relevant processing is appropriate. |
| Financial and payment information | **Yes** | Recognizable card numbers and IBANs are masked in operator text extraction; arbitrary app content and screenshots are not guaranteed free of financial information. Stripe handles checkout card values. Other approved financial values may appear in app/page content. |
| Authentication information | **Yes** | Account sessions, protected API credentials and the optional encrypted local password vault. Approved exact-site fills disclose selected values to the destination site; generated apps do not receive vault password values. |
| Personal communications | **Yes** | If you point a task at your inbox, the email text on that page is part of the page snapshot sent to the model. |
| Location | **Yes, if supplied in content** | Power does not request GPS location. Addresses and location details may be in app data or approved page context; website sign-up separately derives approximate country/region/city (§2). |
| Web history | **Yes, for requested features** | Active task URLs/titles and saved page scopes identify pages used by Power. The extension does not request Chrome's history API or read the browser's complete history. |
| User activity | **Yes, limited to feature activity** | Local build/conversation records, app use data saved by the app, page placement choices and task logs. This is not general browsing or keystroke surveillance. The separate run report below is sent to our service. |
| Website content | **Yes** | The interactive elements, labels and visible text of the pages a task works on. This is the core of how the product works. |
| Diagnostics — not a Chrome Web Store category, stated here for completeness | **Yes** | When a task ends we receive the outcome, the step count, the duration, how many times you intervened, the product and extension version, and the date you installed the extension. No page content, no URLs, no task text (§2a). |

**What we certify, and mean:**

- We **do not sell** your data to third parties, in any sense of "sell", including the
  definitions used by consumer-privacy statutes.
- We **do not use or transfer** your data for any purpose unrelated to the single purpose
  above. There is no advertising, no profiling, and no data brokerage.
- We **do not use or transfer** your data to determine creditworthiness or for lending.
- We ask model providers **not to train on your data** — the request that carries your page
  content is sent with data collection set to `deny`, which restricts eligible providers according to OpenRouter's no-training/data-policy controls; it is not a zero-retention promise. This is enforced on our server, so it also covers older installed versions.
- Local apps, drafts and private diagnostics can store prompts, source and replies (§2a). Our proxy stores metering and rejection metadata, rather than intentionally persisting complete message bodies. Processor retention is separate (§5).
- Power's use and transfer of extension user data follows the [Chrome Web Store User Data Policy](https://developer.chrome.com/docs/webstore/program-policies/user-data-faq), including its [Limited Use restrictions](https://developer.chrome.com/docs/webstore/program-policies/limited-use). Information received from Google APIs, where a connector is enabled, is also subject to the Google API Services User Data Policy. Extension user data is used only for disclosed user-facing functionality, security and requested support; human access to supplied support material is limited to that request.

If any of this changes, we will say so here and notify you before the change takes effect,
rather than changing it quietly after you have installed the extension.

## 3. Why we use it (purposes)

We use personal information to provide the personal apps and approved browser/AI actions you request, save and recover your work, meter usage and diagnose requested support cases; operate the wait-list and your account; confirm you control
the address you gave us (the welcome email goes to it, and signing in requires a one-time code
we email you); **notify you when the Product you signed up for launches, and when your account
is granted access during closed testing**; send occasional
product updates (with your consent — unsubscribe anytime); understand aggregate product
interest from sign-up records, including the earlier context described in §2; keep the Site secure and prevent abuse; and meet legal obligations. We identify
our purposes at or before the time of collection, and we don't use your information for new
purposes without telling you.

## 4. Consent

The wait-list form has **two separate boxes**, and the second one is optional:

- **Required** — you accept the identified account Terms and acknowledge this Policy, an account is created, and we email you
  when your account is granted access during closed testing and when the product you signed up for launches, as stated on the form.
- **Optional, never pre-ticked** — occasional product updates beyond those notices. Leaving it
  unticked does not stop you joining the wait-list or using anything.

We record which boxes you ticked, when, from where, and **the exact wording you were shown**, so
that what you consented to can be shown later rather than asserted. You may withdraw consent at
any time — use the unsubscribe link in the relevant message or contact our Privacy Officer. Unsubscribing from marketing does not require deleting your account. We give effect to a commercial-message unsubscribe request within 10 business days; its mechanism remains available for at least 60 days after the message. Account and service messages, such as requested sign-in codes, security notices and legally
required notices, are handled separately from optional promotional updates. We never make consent to marketing a condition of anything beyond receiving those
emails.

The extension shows a versioned notice before protected use and asks for contextual approvals where an app needs them. Declining an optional page, vault or AI action does not approve a different action. We seek fresh consent where a material new purpose or disclosure requires it; accepting a notice does not waive statutory rights.

## 5. Service providers

The providers below receive information needed for the stated Site or Product functions.
Provider processing can also involve security, abuse-prevention, payment-compliance and
legal obligations, as described in their applicable policies and agreements:

| Provider | Purpose | Data involved |
|---|---|---|
| **Supabase** | Authentication, database (accounts, wait-list, consent records) | Email, user id, wait-list membership, consent record, sign-up context |
| **Vercel** | Website hosting and delivery; older sign-up flows used an approximate region lookup | Standard web-server request data, including IP address, requested path, browser details and delivery/security logs |
| **Resend** | Sending sign-in codes and wait-list / launch emails | Your email address and email content |
| **Stripe** | Payment processing for subscriptions | Your email and payment details you enter at checkout; we store only your plan status and Stripe customer/subscription identifiers, never card numbers |
| **Google Fonts** | Serving the typeface this site is set in | Your **IP address** and browser details, when your browser requests font files directly from Google's servers; browser caching can avoid repeat requests. Google states it does not use these requests to build advertising profiles. We name it because the request does reach Google, and a list of processors that quietly omitted it would not be a true one. A content blocker stops it; the site stays usable with a fallback typeface |
| **OpenRouter**, routing to eligible model providers | AI generation, discussion, revisions, app AI and older chat/operator reasoning | Briefs, supplied context, relevant app code and approved app-AI text. OpenRouter/model providers may process outside Canada. Build, discussion and app AI fail explicitly if the selected model is unavailable; ordinary legacy chat can make one fallback to OpenRouter's automatic free router. A model name does not pin an infrastructure provider or country. |
| **Wikipedia / Wikimedia** and **Open Library / Internet Archive** | Optional public-catalog searches | The approved query and network address; no Power account token or cookies attached. |

Managed model requests use OpenRouter's no-training/data-policy restriction. **This is not a
zero-retention setting or guarantee.** Security, abuse-prevention, legal and caching retention
can differ by processor. Optional provider-account logging is separate. See [OpenRouter's
privacy policy](https://openrouter.ai/privacy) and [data-retention controls](https://openrouter.ai/docs/guides/features/zdr).
Personal AI API keys are not supported. Any separate enabled connector has its own stated
purpose and authorization. Contact us before supplying data with a specific residency or
retention requirement; using Power does not establish one.


We **do not sell** personal information, we show no third-party ads in the Product or Site,
and we do not send visitor information to advertising pixels or data brokers. Our own
promotional films may use AI-generated actors and scenes alongside product demonstrations.
Those scenes are not footage of customer accounts and are not customer testimonials.
The website serves its product videos as ordinary media files; it does not embed a social
network player that tracks your visit on our behalf.

## 6. Cross-border transfers

Our providers store and process information **outside Canada, principally in the United
States**: Supabase, Vercel and Resend for the Site and your account; **Stripe** for payments;
**OpenRouter** as the gateway that routes the extension's requests, and behind it Anthropic,
Google and OpenAI for the AI reasoning itself (§5). When your browser loads the site's fonts from **Google**, Google also receives your IP address and browser details.

Model availability and routing can change between requests. The selected model is shown in
Power, but its name alone is not a guarantee of the country or infrastructure provider processing
it. Legacy chat's one free-router fallback can select a provider not known in advance; Build
and personal-app AI do not use that model fallback.

Information abroad may be accessible to local courts and authorities under applicable law.
We remain accountable for our own handling and service-provider arrangements. No-training
routing controls do not by themselves establish no retention or exclusive Canadian processing.

## 7. Retention and deletion

Local apps remain until you remove them or their extension storage. Up to five background
build records and 40 support operations are retained within size bounds; these are count/size
limits, not a fixed deletion period in days. Unsent app conversations and drafts are local.
Deleting an app through My apps removes its versions/data and attributable previews, terminal
builds, conversation drafts, support records and page placements. A related active build must
first stop. Compact identifier/hash receipts remain to prevent late work from recreating the
app. Older support events that lack a reliable app reference cannot be selectively attributed
and may remain until that bounded history rotates or you clear the extension's local storage.
Downloaded files, separate backups and information already sent to providers or websites are
not erased by deleting the app. Sign-out is not local deletion.

Account information is retained to operate your account and for the applicable support,
security, consent and legal purposes. Account deletion is handled on request at
**privacy@power-extension.com**, rather than by a self-service account deletion button.
We assess the records needed for those purposes and delete or de-identify information no
longer needed, subject to legal exceptions. Ask us for the applicable handling and retention
of a specific category before providing sensitive information.

A PIPEDA access request normally receives a substantive response within **30 days**, subject
to lawful extensions and exceptions; that response period is not a blanket erasure deadline.
We explain information we must retain and why. Tax transaction records generally remain for
**six years from the end of the relevant tax year**, subject to applicable requirements.
Breach records have the separate minimum in §8a. Closing an account does not delete copies
on your device or in files you downloaded. Truly de-identified aggregate statistics may remain.

## 8. Safeguards

Ordinary app records, clipboard slots, page notes and local chat caches are not encrypted with
a user-held key. Account scoping and sandbox isolation are access controls, not a promise of
full-disk encryption. Some dedicated credentials use encrypted local envelopes and a key kept
in the same browser profile; that protects against accidental exposure but does not protect
against every compromised device or trusted extension context. The optional password vault
and encrypted chat sync have the separate safeguards described in §2a.

We protect personal information with safeguards appropriate to its sensitivity: encryption
in transit (TLS), protected/encrypted stores where described in §2a, row-level access controls in our database so each account can
access the records belonging to it, and a strict content-security policy on the Site. A limited number of
authorized staff hold an administrative role that can access account and wait-list records for
support, troubleshooting, and aggregate analytics. We deliberately minimize what we collect —
the best safeguard is not holding data in the first place.

## 8a. If something goes wrong — breach notification

If personal information under our control is lost, or accessed or disclosed without
authorization, and the breach creates a **real risk of significant harm** to you, PIPEDA
requires us to report it to the **Office of the Privacy Commissioner of Canada** and to notify
you **as soon as feasible**. We will tell you what happened, what information was involved, what
we are doing about it, and what you can do to protect yourself. We also notify any other
organization that can reduce the harm.

We keep a record of **every** breach of security safeguards — including ones that do not meet
the notification threshold — for at least **24 months**, as the law requires, and we make those
records available to the Commissioner on request.

## 8b. Whose information is whose

For your own account — your email, your plan, your consent record — **we** are the organization
accountable under PIPEDA.

For personal information about **your** clients, leads and contacts that you put through a
Product — the names, addresses and correspondence on the pages you point the assistant at —
**you** are the accountable organization and we act on your instructions as your service
provider. You decide what is collected and why; you are responsible for having the consents and
giving the notices your own obligations require, including telling those people that their
information may be processed outside Canada. This allocation does not remove our own duties under applicable law. This is set out as a term of the agreement in
§13 of the [Terms of Use](/terms).

## 8c. What the extension asks Chrome for

Chrome explains required permissions at installation and optional permissions when requested.
Permission and feature availability depends on your installed release. The list below covers
the Power Extension personal-app build, version 2.5. The alarms, clipboardRead and clipboardWrite
permissions were added for that build; earlier installations may not request them or offer
their related features. A corporate edition can also omit a feature and its permission.
Your installed extension's Chrome permission list controls. Publishing this Policy neither
updates your extension nor grants a new permission; Chrome and the applicable Power controls
still govern installation, updates and optional access requests.

- **Websites you choose** — `<all_urls>` is an optional host-permission declaration. Features request website access when needed. Saved site grants persist until revoked in Chrome. Persistent page apps register a packaged script on the explicitly granted site to restore saved local placements; broader browser-operator tasks use their own access flow. Declining does not authorize the site action.
- **`activeTab`** — temporary access to the tab you deliberately invoke Power on.
- **`scripting`** — packaged page extraction, approved filling/appearance and page-placement scripts on authorized sites.
- **`tabs`** — identify the source tab, track navigation and open requested site/app windows.
- **`tabGroups`** — keep browser-operator tasks scoped to their task group; personal-app actions use their separately confirmed source tab.
- **`sidePanel`** — the main Power interface, alongside optional separate app windows.
- **`storage`** and **`unlimitedStorage`** — local settings, app source/versions/data, bounded recovery/support records and the optional encrypted vault. App-level bounds and acknowledged writes protect against storage failure; this is not a promise of unlimited device capacity.
- **`offscreen`** — a packaged worker continues explicitly started app generation while the panel is closed, and supports the optional long-lived assistant connector. Closing Power does not cancel an already started build.
- **`alarms`** — restore scheduled appearance changes and local focus-session boundaries
  while the main panel is closed. An alarm does not itself read a page or call AI.
- **`clipboardRead`** and **`clipboardWrite`** — optional permissions for clipboard actions after recent
  interaction in a visible, focused Power app; no background clipboard monitoring.

**What it does not ask for.** The published extension has no debugger permission: it does not
attach to Chrome's DevTools Protocol, and you will not see the "started debugging this browser"
bar. It has no identity permission either — that one exists only in our internal builds, is used
only if you connect Gmail, and the connect button is switched off during closed testing. It asks
for no access to your browsing history and no access to your bookmarks.

## 9. Your rights — access, correction, deletion

Subject to limited legal exceptions, you may ask us to **access** the personal information
we hold about you, **correct** inaccuracies, or **delete** your data and close your account.
Contact our Privacy Officer at **privacy@power-extension.com**; we respond within the
timeframes PIPEDA requires (generally 30 days). We may need to verify your identity first.

## 10. Children

The Site is not directed to individuals under the age of majority, and we do not knowingly
collect personal information from children.

## 11. Changes to this Policy

We may update this Policy when the Products or their data handling change, including changes
to providers or enabled features. We post the new version with an updated date and version
number and provide additional notice for material changes. A new purpose or disclosure that
requires consent will not be authorized merely by posting an updated policy. Where required,
we ask for your choice before it begins. You can revisit app permissions and withdraw optional
choices; a feature that needs the refused information may then stop working.

## 12. Complaints

If you have a privacy concern, contact our Privacy Officer first — we will investigate and
respond. If you are not satisfied, you may complain to the **Office of the Privacy
Commissioner of Canada** (priv.gc.ca · 1-800-282-1376), which oversees PIPEDA.

## 13. Contact

**privacy@power-extension.com** · **+1 437 258 2280** — Azamat Smailov, sole proprietor carrying
on business as GENZAI (Ontario BIN 1001692014), 113 Kingslake Rd, North York, Ontario M2J 3E9,
Canada.

We offer the Products to customers in **Canada, excluding Quebec** (see §3 of the
[Terms of Use](/terms)), and this Policy is written to Canadian federal law. See also our
[Cookie Policy](/cookies).

GENZAI is a business name registered in Ontario under the *Business Names Act* on July 28,
2026 (Business Identification Number 1001692014, sole proprietorship). It is **not** a
corporation: the person accountable for your personal information is the individual named
above. If we later incorporate, this Policy will name the new contracting entity. For a formal
privacy request or a complaint, use the postal address above.
