Privacy Policy
How the BNBot Chrome extension processes your information.
Read this document together with our Terms of Use.
Effective date: September 10, 2026.
In this policy, "BNBot", "we", and "us" refer to BNBot.
This policy explains how the BNBot Chrome extension and the BNBot cloud services used by that extension process information. It covers the Side Panel, webpage assistance, translation, video and subtitle tools, social workflows, and the New Tab workspace. It does not describe Google Chrome itself or unrelated BNBot products. Contact support@bnbot.ai with privacy questions or requests.
1. How the extension works
The Side Panel can work independently of a desktop application. Cloud features require a BNBot account and may use credits or a paid plan. Browser actions use your existing session on the website you choose.
Installing the extension gives it the permissions described by Chrome. A permission is not a statement that every feature is running or that every page is sent to an AI provider. Processing depends on your requests, enabled features, site access, and automatic-processing choices.
2. Information processed
- Account information: email address, account identifiers, basic sign-in profile information, verification and session information, credits, and plan status. Google or email-code sign-in is used for supported account features.
- Page content and browser context: relevant text, selections, page URLs and titles, links, images, visible captures, social posts and metrics, video information, and captions. Prompts, attachments, selected editor content, drafts, and task results can also be processed. These can contain personal communications or sensitive information, including when you ask for help with an email thread or upload a screenshot.
- Voice and media: microphone recordings when you enable voice input, and audio, transcripts, reference images, and generated media used by the selected transcription or media feature. Microphone or screen-sharing access uses Chrome's permission and source-selection controls.
- Tabs and activity records: open-tab URLs, titles, groups, saved tabs, settings, conversations, drafts, plans, and task status. Local tab organization does not itself require sending every open tab to an AI model. Reading a selected tab with the Agent can send its relevant context to the cloud. The extension does not request Chrome's full browsing-history API; URLs processed for its features are nevertheless browser activity data.
- Website authentication: supported actions use the website session in your browser. For authenticated X requests, the extension uses the X
ct0CSRF cookie locally. BNBot account credentials are handled by the trusted extension background, rather than exposed to ordinary webpages for AI requests. - Service and payment records: network requests expose an IP address to the receiving service. Request, error, security, and rate-limit records may be processed alongside account and transaction status. Hosted Stripe checkout handles payment details when used; the extension does not provide a card-number form in its Side Panel.
This information supports the features you request or allow: answers, translation, research, summaries, writing, media processing, account access, task continuity, browser actions, and service operation.
3. Automatic processing and your choices
Automatic YouTube summaries, scheduled cloud plans, and automatic translation have separate, account-specific choices under Settings → Automatic AI processing. You can allow, decline, or revoke these categories. Missing or outdated choices require a new choice before the corresponding automatic cloud processing. Explicit one-time requests, such as asking for a translation or running a task, are handled as those requests.
Once allowed and enabled, an automatic feature can process relevant content when a page appears, captions change, or a schedule runs, including while the Side Panel is closed. A YouTube summary can be prepared before you expand its card. Some built-in plans start enabled, but an enabled plan does not replace the automatic-cloud-processing choice. Pause individual schedules in Plan. Local tab management and local review-item creation are distinct from cloud processing.
Revoking a choice stops subsequent automatic processing for that category and cancels its applicable in-progress work. It does not recall content already transmitted or delete stored records. Chrome's site-access, microphone, disable, and uninstall controls provide additional control.
4. Where information goes
Relevant information is sent to BNBot's backend at api.bnbot.ai and the services needed for the selected feature. Not every provider receives every request. Models, routing, fallback services, and the tool you select determine which processors are involved.
| Service | Purpose and information involved |
|---|---|
| OpenAI, Google, and models reached through Vercel AI Gateway or OpenRouter | AI answers, research, translation, summaries, or generation using relevant prompts and task content. Gateways route requests to the selected model's hosting provider. |
| Alibaba Cloud DashScope | Supported translation and transcription routes, including relevant text or audio. |
| ElevenLabs | Supported audio transcription, including audio retrieved by the backend for the task. |
| Supadata | Transcript retrieval when needed, using the YouTube video URL, requested language, and transcript request. Website account credentials are not sent for this lookup. |
| Tavily | Server-side search queries derived from the requested task, and the returned search results. Queries can contain context from your request. |
| fal and its selected model providers | Image and video generation parameters, prompts, and reference media or retrieval URLs. |
| Cloudflare R2 | Storage and delivery of uploaded audio and generated or processed media. Media can be available through a delivery URL such as cdn.bnbot.ai; treat a shareable URL as accessible to anyone who has it. |
| Google and Purelymail | Supported sign-in and account-email delivery, including the information needed for that process. |
| Stripe | Hosted payment processing and related checkout, subscription, and transaction status. |
| Websites you use | The content and action results needed for your requested browser workflow. |
Cloud Agent diagnostics can also include prompts and tool results in tracing sent to OpenAI. Such diagnostics are separate from the AI model selected for a response. A setting for one analytics tool should not be understood as disabling every backend diagnostic system.
Cloud services can process information outside your country. Their applicable terms, service settings, and processing arrangements govern their handling of information. This policy does not promise that all model routes have identical retention settings or that providers offer zero retention.
5. Local storage, retention, and deletion
Settings, session and workflow state, saved tabs, conversations, drafts, and caches are stored in your Chrome profile using extension or browser storage. You can remove records through the available controls or clear extension data. Uninstalling removes extension-local storage, but does not remove files saved outside the extension, your BNBot account, or existing cloud records.
Some caches have reuse limits: structured YouTube summaries can be reused for up to 180 days, and cached timed text for up to 30 days, subject to size limits. These limits do not guarantee physical erasure from disk on that date, or deletion of server, provider, or backup copies.
Account and workflow records, full transcripts, uploaded or generated media, service logs, and payment-related records can persist in cloud storage independently of the browser. Do not assume that an audio transcript expires automatically, that an expiring upload URL deletes the uploaded file, or that signing out deletes stored content. Local delete and clear controls do not erase copies already sent to a provider. Account deletion is not a promise of immediate removal of every media object, log, backup, or processor copy.
For access, correction, or deletion requests, contact support@bnbot.ai from the email associated with your account and identify the account or content concerned. Do not send passwords or verification codes. The applicable scope can depend on the record, operational and legal requirements, and copies held by service providers; this policy does not establish a fixed universal retention or deletion deadline.
6. Chrome user data and limited use
BNBot's use of Chrome-derived user data is limited to providing or improving the user-facing extension features described in its listing and interface, subject to the Chrome Web Store User Data Policy, including its Limited Use requirements.
No model training. BNBot does not use user data to train AI models. This includes prompts, attachments, page content, personal communications, recordings, and task content processed through BNBot. AI services may process this information to provide the features you request or allow. This commitment does not mean zero retention, no caching, or no permitted security or legal access.
Chrome-derived user data is not for sale, personalized advertising, or creditworthiness or lending decisions. Transfers must serve the disclosed feature or another purpose permitted by those requirements. Human access is limited to the permitted cases, such as your explicit agreement to inspect specific content, security investigations, legal obligations, or appropriately aggregated and anonymized internal operations. These restrictions apply to the handling of this data through service providers as well as BNBot.
7. Security, children, and changes
BNBot cloud API requests use HTTPS. Extension credentials are handled by trusted extension code. No software or storage system is completely secure. Avoid sending secrets or sensitive content that is unnecessary for your task.
BNBot is not intended for children under 13. If you believe a child has supplied personal information, contact support so the situation can be addressed.
Updates to this policy will appear at this URL with an updated effective date. Read it together with the Chrome Extension Terms of Use. BNBot is independent of Google and the websites and AI providers used by its features.