Privacy policy
Remixlet has no server and no accounts. Your data stays in your browser. When you chat, your message and content from the page you're working on go to the AI provider you chose, and nowhere else. This page spells that out precisely, so you don't have to take it on faith.
This policy covers the Remixlet browser extension and this website, remixlet.com. Remixlet is an open-source project maintained by one person. "We" on this page means that maintainer. The source is public, so every claim here can be checked against the code.
The short version
- We collect nothing. There is no Remixlet server and no account. Your data never reaches us.
- Everything the extension stores stays on your machine. Provider keys, conversations, remixlets and their history, and page captures all live in your browser.
- One thing leaves your device. When you chat, Remixlet sends your message and content from the page you're working on, meaning text, structure, and sometimes a screenshot, to the AI provider you configured, using your own key or account. Nothing from your pages is sent anywhere else.
- This website sets no cookies.
What the extension keeps on your device
Everything Remixlet stores lives in your browser's local storage, on your machine:
- Provider credentials. API keys you enter, and the sign-in tokens created if you connect a ChatGPT subscription, are kept in the extension's local storage. Each is sent only to the provider it belongs to, is never placed in a URL, and never touches the pages you visit.
- Conversations. Every chat with the agent, stored as local log files.
- Remixlets. The code of every remixlet you make, with its full version history.
- Page captures. Snapshots the agent takes of the page it's working on: text, structure, the page's URL and title, and screenshots.
None of it is uploaded, synced, or backed up anywhere by us. We couldn't read it if we wanted to.
What leaves your device, and where it goes
One kind of data leaves your machine, and only while the agent is working. When you chat, Remixlet sends your message and content captured from the page you're working on to the AI provider you configured, under your own key or account. That content is text, structure, and sometimes a screenshot, along with the page's URL and title. The request goes straight from your browser to that provider, with no Remixlet server in between. Sending happens only at your initiative. You choose the provider, you connect it yourself, and content is sent only when you ask the agent to work.
Which provider that is, is your choice:
- OpenAI, with an API key or by signing in with a ChatGPT subscription. Sign-in happens on OpenAI's own pages, and the resulting tokens stay in your browser. See OpenAI's privacy policy.
- Anthropic. See Anthropic's privacy policy.
- Google. See Google's privacy policy.
- xAI. See xAI's privacy policy.
- Any OpenAI-compatible endpoint you enter yourself, for example OpenRouter, or a local server such as Ollama running on your own machine. Traffic to a local server stays on your machine but is plain, unencrypted HTTP by nature of that setup.
Your provider processes what it receives under its own privacy policy and your agreement with it. How long chats are kept, whether they're used for training, and the controls you have all live there. And because the capture is of the page you're on, if a page shows things you wouldn't share with your provider, don't point the agent at it.
Beyond this, the extension makes one kind of request of its own: when a chat starts on a site, and when the control center lists a site it has no icon for, it fetches that site's front page and its favicon to show the site's icon. Those requests carry no cookies and nothing from your pages. There are no update pings, no remote configuration, and no crash reports. In the Chrome Web Store's disclosure categories, everything above is the extension handling authentication information, meaning your keys and sign-in tokens; website content, meaning page text, structure, and screenshots; and web history, meaning the captured page's URL and title. Each of them only as this page describes.
Requests remixlets make to websites
A remixlet you build can be granted the power to call a website itself, through a fetch capability scoped to named hosts or network rules confined to its own sites. Those powers run only after you approve them for that specific remixlet, in plain language, and every request they make happens locally, from your browser, on your behalf. Nothing about it is routed through us or reported to us. The security architecture page explains how those grants are enforced.
This website
remixlet.com is a static marketing site. It sets no cookies. Cloudflare serves it, and delivering any web page means the host briefly processes technical request data, such as your IP address and the URL you asked for, to serve and protect the site. That handling is described in Cloudflare's privacy policy. Hosting also gives us short-lived operational logs and aggregate counts, which we use only to keep the site up.
One third-party detail, for completeness: the demo bar on the homepage shows site icons loaded from Google's favicon service, so your browser requests those small images directly from google.com, which sees the ordinary technical data any image host sees. The site sends it nothing else.
Pages here link out to other sites: GitHub, the Chrome Web Store, the providers above. Following a link takes you to a site with its own privacy policy, which we don't control.
Retention and deletion
There is no retention schedule, because there is no collection. Your data lives where you can see it and is gone when you say so:
- Deleting a remixlet deletes its code, its history, and every grant it held.
- Deleting a conversation deletes its log.
- Uninstalling the extension removes everything it stored, keys included.
Whatever you already sent to a provider is governed by that provider's retention rules and account controls. Deleting things locally can't reach into your provider account, and neither can we.
What we never do
The Chrome Web Store's Limited Use rules restrict what developers may do with user data. They are easy for us to certify, because we never possess your data in the first place:
- We don't sell user data or transfer it to third parties. No data brokers, no partners, nobody.
- We don't use or transfer user data for purposes unrelated to what this page describes.
- We don't run ads or use your data for advertising.
- We don't use or transfer user data to determine creditworthiness or for lending purposes.
Security
Local-first is the security model. Data that never travels can't be intercepted, and a server that doesn't exist can't be breached. Your keys are stored locally, sent only to the one provider they belong to, never placed in URLs, and never exposed to the pages you visit. A lint rule fails the build if the background worker or the page bridge reference a key at all, or if any code puts one in a URL, a log line, or an error message. Hosted providers are reached over HTTPS. A local endpoint you configure yourself is the one exception, as noted above. The code the agent writes runs sandboxed, behind named capabilities you approve, and the security architecture page walks through the whole design. No software can promise perfect security, but our worst case is deliberately small. What isn't collected can't leak.
Children
Remixlet isn't directed at children, and we collect no personal information from anyone, children included. There is no account to create, and nothing is stored outside the user's own browser. If you're a parent or guardian with a concern, write privacy@remixlet.com.
International transfers
We don't transfer your data across borders, because we don't have it. The only cross-border movement is the one you initiate: your browser's request to the AI provider you chose, which may process it in the United States or elsewhere. That transfer runs directly between you and the provider, under its privacy policy and terms.
Notice to European users
This section is for people in the European Economic Area and the United Kingdom, and adds to the rest of the page. "Personal information" here includes everything the GDPR and UK GDPR call "personal data".
Controller. To the extent the processing described on this page has a controller under the GDPR, it is Remixlet's maintainer, reachable at privacy@remixlet.com. In practice we never receive your personal data: it stays in your browser, or goes directly to the AI provider you chose, which handles it under its own privacy policy and your agreement with it.
Legal bases. Where the GDPR requires a legal basis for processing, ours are simple:
- Sending your chat message and page content to the provider you chose happens only at your request. It is the service itself working, which is performance of a contract under Article 6(1)(b), and it rests on your consent under Article 6(1)(a), given by connecting a provider and choosing to chat. You can withdraw it at any time by disconnecting the provider or uninstalling. Withdrawal doesn't undo what a provider already received. The provider's own controls cover that.
- Serving this website rests on our legitimate interest under Article 6(1)(f) in delivering and protecting a website, and covers the short-lived technical data described under "This website".
No profiling, no automated decisions. We don't profile you, and we make no automated decisions about you that produce legal or similarly significant effects.
Your rights. European law gives you rights over personal data a controller holds about you: access, correction, deletion, restriction of processing, portability as a machine-readable copy, objection to processing based on legitimate interests, and withdrawal of consent. The honest caveat is that we hold no personal data about you, so there is usually nothing for us to access, correct, hand over, or delete. The data those rights are about lives in two places you control directly. One is your browser, where you can read and delete everything Remixlet stores. The other is your provider account, where the provider's own privacy process applies. If you believe we do hold something, or you want to exercise any right regardless, email privacy@remixlet.com and we will answer plainly.
Transfers out of Europe. We make none ourselves. The only cross-border flow is your browser's own request to the provider you chose, as described under "International transfers". The provider's privacy policy covers its safeguards.
Complaints. If you're not happy with how we've handled something, you can complain to the data protection authority where you live. The EEA authorities are listed by the European Data Protection Board, and the UK's is the Information Commissioner's Office. We'd appreciate the chance to fix it first, but that's your right either way.
US state privacy rights
Several US states give their residents privacy rights, among them California, Colorado, and Connecticut. The short, truthful form for Remixlet: we do not collect, sell, or share personal information, and we do not process it for targeted advertising or profiling. There is nothing to opt out of. Signals like Global Privacy Control and "Do Not Track" ask a site to stop tracking. There is no tracking here for them to switch off. If your state gives you rights to know, access, correct, or delete, you can exercise them at privacy@remixlet.com. Expect the honest answer that we hold nothing about you, and that anything in your browser or provider account is already directly in your hands.
Changes to this policy
When this policy changes, the new version appears here with a new effective date at the top. If a change ever adds a real data flow, such as a server, telemetry, or sync, we won't bury it. It will be stated in the release notes, and the extension will tell you before anything new leaves your machine. This version took effect on August 28, 2026, and is the first.
Contact
For anything on this page, whether questions, rights requests, or a claim you'd like to check against the code, write to privacy@remixlet.com. If you email us we will, unavoidably, have your email address; we use it to reply, and for nothing else.