Privacy Policy

Last updated: September 13, 2026 · Version 2026-09-13

Plain-language summary (not a substitute for the full policy below). From the website and wait-list we handle your email, product choice, consent record and limited sign-up context: the source page and browser language. Earlier sign-ups may have saved the additional context described in §2. We use these records to operate the wait-list, provide account access notices and understand product interest. Hosting and account services also process ordinary network information needed to deliver and secure the Site. Power Extension creates and runs personal apps. App code, versions, instructions and ordinary saved data stay in local extension storage. Build and approved AI actions send relevant instructions, code and deliberately supplied context through Power and OpenRouter to model providers. Sending an idea for AI questions can use Power credits before Create. An installed app can separately ask to record website domains and observation times locally from the active tab in its original window while that app is open; Stop, Pause and revoke controls are available. A started build can finish after you close the panel. Private diagnostics can contain personal app data; they are downloaded locally, not uploaded automatically. Optional page tools, saved page placements, contact filling and an encrypted password vault have separate controls. The older browser-operator mode can send page text and, in the cases described in §2a, one unmasked screenshot. Do not assume prompts, app data or exports are anonymous. If you subscribe, payment is handled by Stripe — we never see or store your card number, only your plan status and Stripe's identifiers for you. We don't sell your data, we run no advertising and no analytics or tracking cookies at all (Cookie Policy), and you can unsubscribe or ask us to delete your account at any time. Our providers (Supabase, Vercel, Resend, Stripe, OpenRouter and the AI providers behind it) may process data in the United States and other countries. The website serves its fonts itself. The regional rights in section 9 apply where the relevant law applies.

This Privacy Policy explains how Azamat Smailov, a sole proprietor carrying on business as GENZAI (Ontario Business Identification Number 1001692014) ("we", "us", "our") of Toronto, Ontario, Canada handles personal information in connection with the Power website, wait-list, accounts, subscriptions, and the Power extension (together, the "Site" and the "Products"). Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs applicable commercial handling of personal information. We operate from Ontario, Canada, and primarily serve Canada and the United States. Applicable provincial and foreign privacy requirements are not displaced by our location or by the Ontario governing-law clause in the Terms.


1. Accountability and our Privacy Officer

We are accountable for the personal information under our control. Azamat Smailov is the person responsible for privacy and can be reached at privacy@power-extension.com, or at the postal address in section 13. This contact handles access/correction requests, concerns about processing outside Canada, consent withdrawal and privacy complaints.

2. Information we handle

The Site handles information needed for the wait-list, your account and the purposes below. The extension has separate data handling described in §2a:

What we do NOT collect from the Site: no card numbers or bank details (Stripe collects those on its own page), no browsing history, no page content, no contacts.

The extension is different. When you install and run Power, §2a governs your installation and page content does leave your device. The list below summarizes how the extension handles data; §2a is the full, binding description.

2a. Product data — the Power extension

This section applies only if you install and use the Power browser extension.

Personal apps, Build and local storage

Power stores personal app source, guides, versions, instructions, ordinary app data, preview and conversation drafts, and navigation state locally in account-scoped extension storage. In version 2.5.2, the personal-app workspace is encrypted at rest with AES-256-GCM and a non-extractable device key stored separately in this Chrome profile. This covers app code, versions/data, workspace drafts and recovery/support records, saved page placements and services, app grants and saved contact profiles. The same local protection covers chat history, task journals and page maps, saved skills and job-search records, custom assistant instructions, onboarding details, recipes and stored authentication credentials. Upgrade startup converts recognized older records, including dormant local workspaces; opening a workspace also checks its conversion. A failed conversion preserves the original record and reports a storage-protection failure. Earlier releases and records awaiting successful conversion can remain unencrypted. Account identifiers, storage-key names, integrity markers and limited operational preferences remain visible; this is not encryption of every browser-profile file. It is not a workspace-password lock, hardware protection, or protection from a compromised Chrome profile or trusted extension context. Losing the device key can make protected local records unreadable; we cannot recover that key for you. The password-vault master password is separate. Signing out retains saved personal apps and account-scoped chat history, while clearing session data and certain legacy local caches. A private support download can contain code and ordinary saved data; a PNG export contains the image you approve. Downloaded files are outside Power's deletion controls. General app-file import and export are not offered in the current interface.

Sending a Build idea for AI clarification sends the instruction, previously supplied goal and work-surface answers, and optional placement mode, effect, dimensions and target count through Power and OpenRouter to model providers. This first clarification request does not include attached files, app code, images, website addresses or page text. It can consume Power credits before final Create. Answering cached questions or going Back does not itself make another AI request. An explicit new clarification or final Create/Generate update is separate. Final generation sends the brief, answers and question text, relevant existing app code, and supported materials you deliberately attached, as described below. New Build does not silently capture the active page as input. Historical saved briefs can still contain page excerpts supplied in an earlier version. Code and instructions can themselves contain private content. The entire ordinary saved-data map is not automatically added to the Build prompt. An app's own AI feature sends the specific text shown for approval. That text may include data the app read from its own local records or an earlier approved page excerpt. Choosing a fast, reasoning or code mode changes the eligible managed model, not the requirement for the app's AI action and applicable approval. An app's capability list does not itself transmit data. Text minimization and recognizable identifier masking do not reliably remove every secret or personal detail you supply.

AI is provided through the managed Power account and plan; personal AI API keys are not supported. Power chooses an eligible model and shows its name. Availability can change between requests. Build, app discussion and in-app AI do not silently switch to a different model after failure. A model name does not guarantee a particular infrastructure provider or processing country. The legacy ordinary-chat fallback is described separately in §5.

An explicitly started build can continue after you close the panel and save a result locally. Reopening Power shows stored progress or results. Use Stop to cancel; closing the panel is not cancellation. Stopping cannot retract information already transmitted or reverse provider usage already incurred. Interrupted requests are not automatically replayed as new paid builds.

Generated HTML, CSS and JavaScript run in an isolated sandbox. They have no direct network, Chrome API or other-app storage access. Packaged Power controls mediate declared capabilities, with the applicable user confirmations. Isolation does not guarantee that generated output is correct or suitable for your purpose.

Materials you attach to a project

You can attach your own images, UTF-8 text/CSV files and HTTPS reference links in Build or an app revision. Power stores a processed copy with the local project version and relevant Build drafts; your original file is not changed. Images are decoded and re-encoded locally with size limits. Original file metadata is removed in that processed image. Text and links are stored as supplied content. A reference link is saved as an address; it is not fetched automatically and does not grant website account access.

When you choose Create or Generate update, relevant attached text and reference metadata are sent to the model through Power. If the selected model supports images and the Build interface indicates image previews, small processed previews are also sent. Full local image payloads are not added to the model prompt. The app can use the materials belonging to its own saved version. They are ordinary local project data, not an encrypted secret vault. Private diagnostics include material text, reference links and image metadata; project image pixels and AI vision previews are omitted because those pixels cannot be credential-redacted.

Page tools, public catalogs and persistent page apps

After you grant access for an app and site, the app can receive selected readable page text, title and address when you invoke its page action. That permission is remembered until you revoke it in the app settings; new capabilities or a wider site scope require approval. This path excludes editable, form and hidden content and bounds the text returned. The app may save the received excerpt locally. Sending it to AI is a separate approval. Opening a website window uses that Chrome profile's normal site session; opening alone does not read its content.

Approved catalog searches send the displayed query directly to Wikipedia or Open Library. The catalog receives the query and your network address; Power does not attach account tokens, cookies or a referrer. Results name the source. The lookup itself does not use your AI balance.

Approved local page appearance and floating widgets can remain after Power closes and return after navigation, reload and browser restart. Saved state includes timer deadlines, positions, settings and permitted site scope. Daily appearance schedules use the device's local time, including overnight hours, and a browser alarm; no location lookup or cloud scheduler is used. A sleeping device applies the current time range when it wakes. Turning off the app or revoking its permission removes its effects. The rendering libraries are packaged with Power. Choosing All websites grants that app the stated capability for current and future HTTP/HTTPS sites after the browser permission, until revoked; choosing This website narrows the scope.

With a site-access grant, you can select a region and describe your request in the small trusted Power panel at that location. Sending the request for AI questions can use credits; final creation requires your answers and an explicit Create action. Selecting a region alone does not call a model or transmit its text. A local hide action uses packaged code without AI; creating or revising app code uses the AI flow described above. Power can bind the saved app to that location using a local placement record: exact page URL (including its query string and fragment when present), anchor attributes and a text fingerprint, size, screen position where applicable, app identifier, active state and page/site/granted-site scope. A viewport placement stays at a screen position; an element placement follows its document anchor. An uncompleted placement request may retain your prompt. URLs and anchor attributes can reveal page context; a text fingerprint is not anonymization.

On matching reloads and in-page navigation, a packaged content script checks the saved location. A changed page can prevent an exact anchor match or leave an app at its saved document coordinates. Review the location and reattach it in Power when needed. Embedded apps use their own saved data and the capabilities implemented by the trusted page host, including approved AI, page actions and Control/Research jobs where available. Packaged controls check the app, account, document and permission scope and show the applicable review. Some capabilities, including domain activity, require an installed app open in Power. Generated code does not gain direct Chrome API or website-script access. Restoring a page app does not make an AI request. Deactivate, remove and reattach are available in Power app settings. After a browser restart, restoration uses the last verified local account only while the stored authentication identity still matches; signing out or changing accounts removes the effects. Browser site permissions can remain until you revoke them; removing a placement does not itself revoke that Chrome permission. A page may detect the visible placement or the packaged app host; we do not promise that Power is undetectable.

An app with the declared page-change capability can invoke an explicit element picker to hide a chosen element locally. The saved rule uses the exact page and anchor, can be restored in Power, and does not delete or change the website's server data.

Optional local domain activity

An installed app can ask you to start recording website domains from the active tab in its original normal browser window. After approval, Power shares HTTP/HTTPS hostnames and the times they were observed with that app while it is open. These are observation times, not measurements of attention or reading duration. The feature does not share full addresses, query strings, page titles or content, and does not read earlier Chrome history or activity from other windows. It follows the original window even while another window has focus. Domain names can reveal sensitive interests or work context.

Pause or Stop ends observation; closing the app or revoking its access also stops it. Permission is remembered until revoked in Settings → App permissions. Recording does not restart merely because you reopen the app. The collector keeps a temporary buffer of up to 256 observations and does not upload these records automatically. An app can save received records as ordinary local app data, which remains after stopping or revoking until you clear it or delete the app. Saved records can appear in private diagnostics; a separately approved AI action or a file you choose to share may disclose relevant saved data. This feature uses Chrome tab metadata, not the Chrome history API or an all-websites content-reading grant.

App-requested Control and Research jobs

An app can present a goal for a Control or Research job through Power's fixed task interface. The trusted host shows the goal, relevant access and managed resource use before admission. The task uses the same browser/AI processing described below. Research can visit public sources and return source addresses and excerpts; Control may need approved page context and trusted confirmation for consequential actions. Declining a request does not start it.

Once accepted, a job may continue after its app closes. Use Stop to cancel; closing an app is different from cancelling an admitted job. Browser restart does not silently restart an interrupted paid job. Stop prevents further work when observed but cannot retract requests or external actions already dispatched. Requests, bounded progress, results, source links, status and timing are stored locally for that account and app version. Existing results can be read without another AI request. Current job access expires seven days after creation; expired completed records are removed during later job preparation, not at a guaranteed wall-clock deletion time. The registry permits up to 20 records per app and 100 per account. An app may separately save selected results in its ordinary local data until you remove them.

Clipboard slots

An app with the clipboard capability can read or replace text after recent interaction in the visible, focused Power app. Browser activation applies to recent app interaction; it is not a verification of a particular button label. Clipboard hub provides explicit Paste and Copy buttons. Power requests the browser clipboard permission and app access when needed. The app-level grant is remembered on this device until you revoke it in app settings, but each read or write still requires your interaction. It does not monitor the clipboard in the background. Clipboard hub stores the text and slot names you save as ordinary local app data, including when that text contains personal or confidential information. These values can appear in a private support download and remain until you clear the slot or remove the app. Avoid placing passwords, access tokens or recovery codes in ordinary slots; use the protected vault for passwords. A Copy action changes the system clipboard, which other software on your device may then read. Clipboard slots do not call AI automatically.

Optional local camera and microphone capture

An app can request a photo or a short audio recording through trusted Power controls. Nothing is captured when the dialog merely opens. You choose Start, grant the browser permission, and review the result before sharing it with the app. The app receives only the approved still image or recording, not a live media stream or device identifiers. Power stops the device when capture ends or the dialog/app closes. Photos are bounded to 1280 pixels and audio to 15 seconds.

Capture and ordinary canvas filters run locally. This capability does not provide generative image editing, face replacement, speech recognition or an automatic cloud upload. Photo studio keeps a chosen photo in its current session and offers an explicit PNG export. It saves adjustment settings, not the photo, by default. A different generated app may save data you explicitly choose to keep; ordinary saved app data can then appear in your private app/support export. Capture payloads are not automatically copied into Power's runtime diagnostics.

Optional password vault and contact filling

The optional password vault stores an encrypted local envelope using PBKDF2-SHA-256 with 600,000 iterations, a random salt and AES-256-GCM. You choose a master password; Power does not keep a server copy of it or provide master-password recovery. The vault locks after inactivity. A separate encrypted backup is available; you are responsible for protecting that file.

With approval, an app can show login metadata such as sites, labels and usernames. Login passwords, private notes and the master password are handled through Power's protected controls, not delivered to generated app code. After unlock and confirmation, Power can fill a selected login on the exact approved site. It does not press Sign in or verify a successful login.

Contact tools can store names, addresses, phone numbers and other fields as ordinary app data. These records may appear in app exports and private diagnostics and are not protected by the password-vault master password. The website can read approved filled values immediately through its own scripts, even if you do not press Submit. Check the site and fields first.

Optional encrypted chat sync uses a separate encryption mechanism; it is not the password vault. Encryption does not protect against every compromise of an unlocked device or trusted extension context, nor against the destination site after an approved fill.

Private app diagnostics

Power keeps bounded local Build and support history for recovery and diagnosis. A private support download includes this workspace's app code, guides, versions, instructions, ordinary saved data, drafts, recent job inputs/results and support operations. It can include page excerpts and model replies. This file is not anonymized. The exporter excludes account credentials and dedicated password-vault storage and scrubs recognizable credential fields and token formats. It cannot reliably remove every secret pasted into an ordinary field. The file is created on your device and is not automatically uploaded. Review it before sharing it with anyone. Support staff may inspect material you deliberately send for your support request; contact us about the scope and handling before sending sensitive records.

Support messages and local drafts

Support drafts and pending-send receipts are saved locally for the signed-in account and thread, encrypted with AES-GCM and a device key in that browser profile. This protects stored bytes, not a compromised or unlocked trusted browser context. Drafts do not send themselves when you reopen Support. When you press Send, Power sends the subject, message, account/thread identity and request identifier to our support service in Supabase. Authorized support staff can read the submitted conversation to address the request. Staff replies may also be sent to your account email through Resend. A mail problem does not erase an already saved message.

The local copy may include a last sent message or an uncertain pending request. Use Clear local copy or the provided recovery controls when available; this does not delete the server thread. Local drafts have no automatic time-based expiry. Submitted support threads and restricted delivery/idempotency receipts are retained for support, security and legal purposes under §7. A retry must be explicit; reopening or changing account does not automatically send or resend a message. Do not include passwords or unrelated sensitive records in a ticket.

Browser-operator mode and older features

What it reads. When you start a browser-operator task, the extension takes a structured snapshot of the page you are on — the interactive elements and their labels, the visible text, the title and URL — and of the pages that task takes it to, inside its task tab group. Password and hidden fields are excluded from this extraction path. This differs from the optional protected vault fill above. The browser operator is not intended to bypass CAPTCHAs or bot protection.

How it acts on the page. To click and type, the extension injects its own content script into the tab it is working in and dispatches the clicks and keystrokes there. It does not attach to Chrome's debugging protocol: the published build asks for no debugger permission, so you will not see the "started debugging this browser" bar. Some sites accept only input the browser itself generated; on those a step can fail, and the extension reports it as not done rather than pretending it worked.

What leaves your computer, and what is masked. To decide each next step, the extension sends that page snapshot plus your task text to a large language model through OpenRouter. Before the request leaves your device, six categories of identity-bearing value are replaced with reversible placeholders — email addresses, phone numbers, payment-card numbers, IBANs, Canadian Social Insurance Numbers and US Social Security Numbers — and restored locally in the answer, so the assistant still types the right value into your system.

Please read this part. Masking covers those six categories and nothing else. The rest of the page reaches the model as written — including people's names, street and property addresses, reference numbers, prices, and the body text of the emails and listings you point the assistant at. This is inherent to how the product works: the assistant cannot copy a property address it is not allowed to read. If a page holds something you would not put in front of a third-party AI service, do not run a task on it.

Screenshots. Some pages carry no readable text at all — the interface is drawn as a picture. On others the page map turns out not to describe what is really on the screen, and the assistant's planned steps keep missing. If a page has no readable text, or two planned steps in a row did not change the page as expected, the extension may send ONE screenshot of the visible tab to the model provider for that step; identifiers on the screenshot are not masked; the task log records this before the frame is sent. The second case can happen on an ordinary, text-rich page, so a screenshot may carry names, addresses and anything else visible on it. At most one screenshot is sent in a whole task, and none at any other point of a run. Taking it may briefly bring that tab to the front, and the tab you were on is put back afterwards. There is no on-device vision model in the product: the local image model was removed, and nothing on your pages is analysed by a model running on your machine.

What we store. Your requests pass through our proxy so you do not need your own API key. The proxy meters usage only — token counts, cost, model name, and when your account was last active — to manage credits, and a record of rejected or malformed requests (kind and size, no content). The proxy does not intentionally persist complete prompt/page/answer bodies in its application records. This statement concerns our proxy, not local app diagnostics or independent provider retention.

Diagnostics we do receive. When a task ends, the extension sends us one short record of that run: the outcome (finished, failed or stopped), the number of steps, how long it ran, how many times you had to step in, the product and extension version, and the date you installed the extension (we keep only the earliest we receive). It carries no page content, no URLs and no task text. This is how we know whether runs finish at all; the step-by-step task log itself stays on your machine.

What stays on your machine, and what does not. Chat history, task logs, automations and settings stay in the extension's local storage on your machine. Page annotations are the exception: when you are signed in, the page maps you save — the site, the URL pattern, your notes and the annotations themselves — are stored in our database, private to your account under row-level access, so they follow you between machines. The current release does not publish them to other users. The shared-site-knowledge setting and contribution path are disabled, including when an older preference remains true. Private sync and team-authored reusable knowledge are separate from publishing your notes. This update does not silently delete any historical contribution; ask us about it under §9. If a page map contains something you would not put on our servers, do not save it.

Uninstalling the extension removes the local data with it. Signing out does not erase local data — it ends your session and stops the sync, and the chats and logs already on your machine stay there until you uninstall the extension or clear them from Settings. To have the data held in our database deleted, ask us (§9).

Human in the loop. Protected app actions have contextual approvals. The browser operator is designed to ask before sending, submitting, deleting or paying; this is a design commitment, not a guarantee of all behaviour on third-party sites. Review the action and use Stop when necessary.

2b. Chrome Web Store data disclosure

This section states, category by category, what the extension collects — in the same categories the Chrome Web Store uses, so what you read here and what the store listing says are the same thing. It restates §2a; where the two ever disagree, §2a is the fuller description.

The extension's single purpose is to create and use personal productivity tools with optional AI and approved browser capabilities. Older browser tasks support that purpose. Everything below exists to serve that purpose or to keep the service running, secure and metered.

What we certify, and mean:

If any of this changes, we will say so here and notify you before the change takes effect, rather than changing it quietly after you have installed the extension.

3. Why we use it (purposes)

We use personal information to provide the personal apps and approved browser/AI actions you request, save and recover your work, meter usage and diagnose requested support cases; operate the wait-list and your account; confirm you control the address you gave us (the welcome email goes to it, and signing in requires a one-time code we email you); notify you when the Product you signed up for launches, and when your account is granted access during closed testing; send occasional product updates (with your consent — unsubscribe anytime); understand aggregate product interest from sign-up records, including the earlier context described in §2; keep the Site secure and prevent abuse; and meet legal obligations. We identify our purposes at or before the time of collection, and we don't use your information for new purposes without telling you.

4. Consent

The wait-list form has two separate boxes, and the second one is optional:

We record which boxes you ticked, when, from where, and the exact wording you were shown, so that what you consented to can be shown later rather than asserted. You may withdraw consent at any time — use the unsubscribe link in the relevant message or contact our Privacy Officer. Unsubscribing from marketing does not require deleting your account. We give effect to a commercial-message unsubscribe request within 10 business days; its mechanism remains available for at least 60 days after the message. Account and service messages, such as requested sign-in codes, security notices and legally required notices, are handled separately from optional promotional updates. We never make consent to marketing a condition of anything beyond receiving those emails.

The extension shows a versioned notice before protected use and asks for contextual approvals where an app needs them. Declining an optional page, vault or AI action does not approve a different action. We seek fresh consent where a material new purpose or disclosure requires it; accepting a notice does not waive statutory rights.

5. Service providers

The providers below receive information needed for the stated Site or Product functions. Provider processing can also involve security, abuse-prevention, payment-compliance and legal obligations, as described in their applicable policies and agreements:

Managed model requests use OpenRouter's no-training/data-policy restriction. This is not a zero-retention setting or guarantee. Security, abuse-prevention, legal and caching retention can differ by processor. Optional provider-account logging is separate. See OpenRouter's privacy policy and data-retention controls. Personal AI API keys are not supported. Any separate enabled connector has its own stated purpose and authorization. Contact us before supplying data with a specific residency or retention requirement; using Power does not establish one.

We do not sell personal information, we show no third-party ads in the Product or Site, and we do not send visitor information to advertising pixels or data brokers. Our own promotional films may use AI-generated actors and scenes alongside product demonstrations. Those scenes are not footage of customer accounts and are not customer testimonials. The website serves its product videos as ordinary media files; it does not embed a social network player that tracks your visit on our behalf.

Browser tracking signals. We do not sell personal information or share it for cross-context behavioural advertising, and do not use this Site to track you across unrelated websites. We do not change those practices in response to a Do Not Track signal. Global Privacy Control does not enable optional tracking; there is no sale, targeted-advertising or cross-context sharing activity to opt out of in this release. Necessary provider requests described here still occur. External sites you deliberately open have their own practices; their unrelated collection is not controlled by Power. If our practices change, we will provide the notice, choice and recognition of opt-out signals required by applicable law before starting the affected activity.

6. Cross-border transfers

Our providers store and process information outside Canada, principally in the United States: Supabase, Vercel and Resend for the Site and your account; Stripe for payments; OpenRouter as the gateway that routes the extension's requests, and behind it Anthropic, Google and OpenAI for the AI reasoning itself (§5). Current Site fonts are delivered by our own host. Earlier Site versions requested font files directly from Google; that historical request was disclosed in the earlier policy.

Model availability and routing can change between requests. The selected model is shown in Power, but its name alone is not a guarantee of the country or infrastructure provider processing it. Legacy chat's one free-router fallback can select a provider not known in advance; Build and personal-app AI do not use that model fallback.

Information abroad may be accessible to local courts and authorities under applicable law. We remain accountable for our own handling and service-provider arrangements. No-training routing controls do not by themselves establish no retention or exclusive Canadian processing. You may ask our privacy contact about the countries, purposes and contractual safeguards relevant to your information. We assess the protection required for an applicable transfer; a provider's public privacy page is not a claim that we hold a particular certification, data-residency contract or completed international-transfer agreement.

7. Retention and deletion

Local apps remain until you remove them or their extension storage. Up to five background build records and 40 support operations are retained within size bounds; these are count/size limits, not a fixed deletion period in days. Unsent app conversations and drafts are local. Deleting an app through My apps removes its versions/data and attributable previews, terminal builds, conversation drafts, support records and page placements. A related active build must first stop. Compact identifier/hash receipts remain to prevent late work from recreating the app. Older support events that lack a reliable app reference cannot be selectively attributed and may remain until that bounded history rotates or you clear the extension's local storage. Domain activity stops when its app closes; temporary collector state is discarded when its runtime is disposed. Saved domain records follow ordinary app-data retention. Job access and cleanup have the separate bounds in §2a. Downloaded files, separate backups and information already sent to providers or websites are not erased by deleting the app. Sign-out is not local deletion.

Account information is retained to operate your account and for the applicable support, security, consent and legal purposes. Account deletion is handled on request at privacy@power-extension.com, rather than by a self-service account deletion button. Purchase, tax, cancellation, renewal-consent and dispute evidence may need to remain after account deletion. Restricted billing records include the exact accepted contract and acceptance evidence, the purchased price and the agreement copy sent to you, which can include your name, email, billing address, amounts and dates. These records are reviewed under the applicable retention purposes; we do not currently promise an automatic timed purge of billing evidence. We assess the records needed for those purposes and delete or de-identify information no longer needed, subject to legal exceptions. Ask us for the applicable handling and retention of a specific category before providing sensitive information.

A PIPEDA access request normally receives a substantive response within 30 days, subject to lawful extensions and exceptions; that response period is not a blanket erasure deadline. We explain information we must retain and why. Tax transaction records generally remain for six years from the end of the relevant tax year, subject to applicable requirements. Breach records have the separate minimum in §8a. Closing an account does not delete copies on your device or in files you downloaded. Truly de-identified aggregate statistics may remain.

8. Safeguards

The versioned personal-app encryption described in section 2a protects stored records using a device key rather than a user-held workspace password. Account scoping and sandbox isolation provide additional access controls, not a promise of full-disk encryption. The coverage, upgrade limits and visible metadata are described in §2a. Some dedicated credentials also use an inner encrypted envelope with a key in the same browser profile. These controls do not protect against every compromised device or trusted extension context. The optional password vault and encrypted chat sync have the separate safeguards described in §2a.

We protect personal information with safeguards appropriate to its sensitivity: encryption in transit (TLS), protected/encrypted stores where described in §2a, row-level access controls in our database so each account can access the records belonging to it, and a strict content-security policy on the Site. A limited number of authorized staff hold an administrative role that can access account and wait-list records for support, troubleshooting, and aggregate analytics. We deliberately minimize what we collect — the best safeguard is not holding data in the first place.

8a. If something goes wrong — breach notification

If personal information under our control is lost, or accessed or disclosed without authorization, and the breach creates a real risk of significant harm to you, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to notify you as soon as feasible. We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. We also notify any other organization that can reduce the harm.

We keep a record of every breach of security safeguards — including ones that do not meet the notification threshold — for at least 24 months, as the law requires, and we make those records available to the Commissioner on request.

If another applicable law requires a different assessment, deadline, recipient or notice format, we follow that additional requirement. For example, the Canadian significant-harm threshold does not determine whether a US state requires notification. We assess where affected people reside and the relevant information rather than applying one Canadian threshold to every incident. A provider's incident does not automatically remove our duties.

8b. Whose information is whose

For your own account — your email, your plan, your consent record — we are the organization accountable under PIPEDA.

For personal information about your clients, leads and contacts that you put through a Product — the names, addresses and correspondence on the pages you point the assistant at — you are the accountable organization and we act on your instructions as your service provider. You decide what is collected and why; you are responsible for having the consents and giving the notices your own obligations require, including telling those people that their information may be processed outside Canada. This allocation does not remove our own duties under applicable law. This is set out as a term of the agreement in §13 of the Terms of Use.

8c. What the extension asks Chrome for

Chrome explains required permissions at installation and optional permissions when requested. Permission and feature availability depends on your installed release. The list below covers the Power Extension personal-app build, version 2.5. The alarms, clipboardRead and clipboardWrite permissions were added for that build; earlier installations may not request them or offer their related features. A corporate edition can also omit a feature and its permission. Your installed extension's Chrome permission list controls. Publishing this Policy neither updates your extension nor grants a new permission; Chrome and the applicable Power controls still govern installation, updates and optional access requests.

What it does not ask for. The published extension has no debugger permission: it does not attach to Chrome's DevTools Protocol, and you will not see the "started debugging this browser" bar. It has no identity permission either — that one exists only in our internal builds, is used only if you connect Gmail, and the connect button is switched off during closed testing. It asks for no Chrome history API access and no bookmark access. Approved live domain recording uses current tab events only; it does not read earlier or complete browser history.

9. Your rights — access, correction, deletion

Subject to limited legal exceptions, you may ask us to access the personal information we hold about you, correct inaccuracies, or delete your data and close your account. Contact our Privacy Officer at privacy@power-extension.com; we respond within the timeframes PIPEDA requires (generally 30 days), subject to lawful extensions and exceptions. We request only information reasonably necessary to verify your identity and authority; do not send a password, payment-card number or government identification unless we explain why a particular secure verification step is necessary. There is no need to delete your account to withdraw optional marketing or an optional app permission.

Canada. You may ask about our purposes, recipients and international processing, withdraw consent subject to legal/contractual restrictions, challenge accuracy, and complain about our handling. We explain any restriction, refusal or information retained by law and the available complaint route. Applicable provincial rights remain available; our Ontario location is not a waiver of them.

United States. Where an applicable state privacy law gives you rights to know/access, correct, delete or obtain a portable copy of information, to appeal a denied request, or to use an authorized agent, you may exercise those rights through the contact above. We assess the law's scope and exemptions rather than claiming every state statute applies to every business. We do not discriminate against you for exercising a protected right. We do not sell personal information, share it for cross-context behavioural advertising, or conduct targeted advertising. We do not use account information for automated decisions producing legal or similarly significant effects about you. Our ordinary account security, abuse and allowance controls remain as described in this Policy. If you dispute such a control, contact us for review.

The categories, sources, purposes, recipients and retention criteria in sections 2–7 cover our disclosed handling, including applicable California notice requirements. An applicable law may allow exceptions for security, contract enforcement or legally required retention; we do not treat an exception as permission to keep every record indefinitely. Where a statutory appeal is available, reply to the decision with “privacy appeal”; we provide the applicable response and regulator contact. This section does not assert that Power meets the thresholds of every comprehensive US state privacy law.

Other regions. If EU/EEA, UK or another mandatory privacy law applies to our handling, the rights it provides remain available, including restriction, objection and portability where applicable. Withdrawal of consent does not invalidate earlier lawful processing. You may complain to the competent supervisory authority. Processing needed to provide a requested service, comply with an applicable legal obligation, or protect legitimate security interests is assessed under the appropriate lawful basis; optional consent is not a blanket substitute for those assessments. A publicly accessible website does not represent that all paid products are offered in every region or that we have appointed a local representative there. Contact us before a business use requiring a specific processing agreement or transfer arrangement; the general Terms are not a signed DPA or SCCs.

10. Children

Power is intended for adults: at least 18 and the age of majority where they live. The Site and Products are not directed to children, and we do not knowingly collect their personal information. A playful included app does not authorize a child's account or child-targeted use. If you believe a child has supplied information, contact privacy@power-extension.com so we can assess and address it. Do not use Power to collect children's information without the authority and safeguards required by applicable law.

11. Changes to this Policy

We may update this Policy when the Products or their data handling change, including changes to providers or enabled features. We post the new version with an updated date and version number and provide additional notice for material changes. A new purpose or disclosure that requires consent will not be authorized merely by posting an updated policy. Where required, we ask for your choice before it begins. You can revisit app permissions and withdraw optional choices; a feature that needs the refused information may then stop working.

12. Complaints

If you have a privacy concern, contact our Privacy Officer first — we will investigate and respond. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca · 1-800-282-1376), which oversees PIPEDA, or the applicable provincial privacy commissioner, US state authority or other competent regulator. Contacting us first does not remove a right to complain directly.

13. Contact

privacy@power-extension.com · +1 437 258 2280 — Azamat Smailov, sole proprietor carrying on business as GENZAI (Ontario BIN 1001692014), 113 Kingslake Rd, North York, Ontario M2J 3E9, Canada.

We operate from Ontario, Canada, with Canada and the United States as our primary markets. Actual product availability is explained in §3 of the Terms of Use. Mandatory privacy rights are not conditional on being eligible for a paid plan. See also our Cookie Policy.

GENZAI is a business name registered in Ontario under the Business Names Act on July 28, 2026 (Business Identification Number 1001692014, sole proprietorship). It is not a corporation: the person accountable for your personal information is the individual named above. If we later incorporate, this Policy will name the new contracting entity. For a formal privacy request or a complaint, use the postal address above.

Earlier policy editions

This edition describes the current release. It does not rewrite earlier acceptance records. Preserved policies: September 11, 2026 and September 11, 2026, edition 2.