What EXFILTR Collects Today
The current public website is static. It does not run an account system, database-backed waitlist, analytics tracker, marketing pixel, or active form submission flow.
If you email EXFILTR, we receive the information you choose to send, such as your email address, message content, and any product or workflow details you include.
What EXFILTR Does Not Collect Today
- We do not sell personal data.
- We do not sell browsing data.
- We do not use hidden tracking on the current static site.
- We do not collect credentials, passwords, payment card numbers, or authentication codes.
- We do not collect page content through the current public website.
Email And Newsletter Data
EXFILTR does not currently operate a working newsletter or waitlist form on the website. If email capture is added later, the provider, storage location, unsubscribe path, deletion request path, and anti-abuse controls must be documented before collection begins.
Any future email list should collect only what is needed to send requested updates.
Website Contact
Contact currently happens through email links to hello@exfiltr.ai. Email is handled by the email systems used by the sender and EXFILTR.
Browser Extension Principles
EXFILTR browser extensions should request the narrowest permissions practical, explain those permissions plainly, and keep workflow data local unless a sync or cloud feature is explicitly added and disclosed.
TabRest session data should remain local unless sync is deliberately added. The `tabs` permission exists to save and restore tab/session state such as URLs, titles, tab order, pinned state, and windows. TabRest should not collect page body content unless a future product feature specifically requires it and discloses it first.
Refine should prefer `activeTab` and user-triggered access. Readability processing should happen locally where practical. Broad host permissions should not be added unless the product scope justifies them and the permission explanation is updated.
Local-First Defaults
Where practical, EXFILTR products should process and store data on the user's device. Cloud behavior should be added only when it clearly supports sync, backup, continuity, or another user-visible workflow.
Social Automation
EXFILTR may use simple internal tooling to draft or schedule posts for EXFILTR-owned public channels. Current policy prohibits autonomous replies, DMs, likes, follows, fake metrics, fake users, fake launch claims, or fake testimonials.
Deletion And Support Requests
You can request deletion of information you intentionally provided to EXFILTR, such as support or future newsletter information, by emailing hello@exfiltr.ai.
Policy Updates
This policy must be updated before major product launch, paid subscriptions, user accounts, analytics, browser extension submission, or working public email capture.
These documents are operational policies for EXFILTR's current early-stage state and are not a substitute for legal advice.