Data Minimization
EXFILTR should collect only what is needed to provide a clearly stated workflow, support a user request, or operate a deliberately added product feature.
Local-First Where Practical
When a browser workflow can work locally, local behavior should be the default. Cloud behavior should be reserved for sync, backup, cross-device continuity, collaboration, or another explicit user benefit.
Browser Extension Data
TabRest session data should remain local unless sync is explicitly added. Refine should prefer user-triggered active-page access and local readability processing where practical.
EXFILTR products should not collect page body content, browsing history, credentials, or unrelated browsing data unless a product specifically requires it and discloses it before launch.
Email And Newsletter Handling
If email collection is added later, EXFILTR should document the provider, storage location, unsubscribe path, deletion process, and anti-abuse controls before collection begins.
Telemetry
No product telemetry is planned for V1. If telemetry is ever proposed later, EXFILTR must update this policy first, explain the exact purpose, and avoid raw browsing data unless a product genuinely requires it and passes privacy review.
Data That Should Never Be Collected Silently
- Credentials, passwords, payment card numbers, or authentication codes.
- Raw browsing history for advertising.
- Page body content unrelated to a user-triggered feature.
- Private extension data for resale.
- Cross-site ad tracking data.
Contact
Questions or deletion requests can be sent to hello@exfiltr.ai.