Decosa for Chrome: privacy policy
Last updated 29 September 2026. It covers the Decosa extension for Chrome and its helper app (the decosa-browser package).
The extension carries out a task you start on the page you're signed into, such as filling in a form from your own notes or reading something from the page. Anything that would be sent waits for you to approve it. This page says exactly what data that involves and where it goes.
The short version
- The extension itself sends nothing to any server. Its own pages are not allowed to make network requests.
- The helper app on your computer makes one kind of network call: the AI model call, to the one model endpoint you or your organisation chose. That can be Decosa's hosted API, or a model running inside your own network, in which case nothing reaches Decosa.
- Passwords, cookies, your other tabs and your browsing history are never sent anywhere.
- Decosa's hosted model route doesn't store your prompts or the model's answers. It keeps only a receipt (hashes, token counts, cost).
- We don't sell data, show ads, or use your data to train models.
What the extension handles
Only while a task you started is running, and only on the tab you started it on:
- The page's content. The text and controls on screen (an element table) and, unless screenshots are turned off, a screenshot of the tab. The page can include personal or health information if you use Decosa on such a site.
- Your task and your sources. The words you type into the side panel, and the files or text you add there.
- Network requests the page tries to send. The extension holds them until you approve. For its log it notes each one's method, host, path, query keys, size and a hash of its body, never the body itself.
What it never handles: passwords (on a sign-in page Decosa hands you the tab and can't see it until you press Continue), cookies and sign-in headers (the helper is not allowed to read them), your other tabs, and your history.
Where it goes
| Data | Where it goes | How long |
|---|---|---|
| Page content, task and sources, for the model call | The model endpoint that was configured. For a model inside your network: that server only. For Decosa's hosted API (api.decosa.ai): Decosa's own GPUs. | Decosa's hosted route doesn't store prompts or answers. It keeps a receipt: hashes of the request and response, token counts and cost. |
| Screenshots | Sent with the model call only when screenshots are on. Your organisation can turn them off (observation_mode: text). Decosa's hosted API takes text only today. | As above. |
| The signed record of each task | Your computer only. It's never uploaded. | Until you delete it. With record_images: false it keeps only screenshot hashes. |
| The helper's log | Your computer only. | Event names and timings only: no page text, values or keys. |
| Your settings (sites you confirmed, your name on approvals) | Chrome's storage for the extension, on your computer. | Until you remove the extension. |
Health and other sensitive data
Decosa has no business associate agreement (BAA) and doesn't offer one today. Don't send patient data to Decosa's hosted API. For health data, point the helper at a model inside your own network, where nothing reaches Decosa.
What we never do
- Sell or rent data, or share it with advertisers or data brokers.
- Use it for anything other than the task you started, including profiling, credit decisions or advertising.
- Train models on it.
- Read cookies, saved passwords, other tabs or your browsing history.
Permissions, in plain words
- Debugger: to operate the one tab you start a task on, and to hold sends until you approve. Chrome shows its "debugging this browser" bar the whole time, and closing it stops the task.
- Side panel: the panel where you start, watch and approve.
- Native messaging: to talk to the helper app on your computer, which runs the engine.
- Storage: your settings and your organisation's policy.
- Declarative net request: while a task runs, your other tabs can't send to that site, so nothing gets around the approval.
Your choices
- Stop any task with the Stop button or by closing Chrome's debugging bar.
- Turn screenshots off, keep only hashes in the record, or use a model inside your network.
- Delete records from your computer (
~/Library/Application Support/Decosa/helper/recordson macOS). Remove the helper withdecosa-browser uninstall, and the extension from Chrome.
Children
Decosa for Chrome is a work tool and isn't meant for children under 16.
Changes and contact
If this policy changes, we'll update the date above and describe the change here. Questions or requests: contact us. For security reports, write to security@decosa.ai.