Terry Privacy Policy
Last updated: October 9, 2026. Applies to Terry Chrome extension 0.x in bring-your-own-API-key mode, and visits to its product, support and privacy pages.
Terry helps you read pages, organize information and perform browser tasks. This version has no Terry-operated backend and creates no Terry account. The agent runs inside the extension, but model requests go directly to your chosen model provider. Task data therefore does not all remain on your device.
Data handled
| Data | Source and purpose | Storage or recipient |
| API keys | Entered in model settings to authenticate model requests | Current browser profile's chrome.storage.local; sent to the selected model endpoint for authentication |
| Provider, model, endpoint and image-support settings | Your model configuration | Local extension settings; requests go to the configured endpoint |
| Model data-consent record | Your consent for a provider and endpoint; includes disclosure version, provider, normalized endpoint and consent time | chrome.storage.local; only one current consent record is retained |
| Task inputs, model replies, plans, authorization information and tool results | Task execution, progress, continued conversation and history | Extension memory and local IndexedDB; conversation context and relevant tool results go to the selected model provider |
| Session tab URLs, titles, page text and structure | Understanding pages and browsing context within the session | Model requests and local session history; not background collection of your complete browsing history |
| Page screenshots | Captured when a task invokes the screenshot tool for page understanding and targeting | Model requests when images are supported, and local session history |
| Form content you ask Terry to enter or submit | Supplied by your task or page for a website operation | May appear in model context and local history; submitted content goes to the target website |
| Site permissions, notification preferences and shortcut prompts | Preferences you configure | chrome.storage.local; a shortcut used in a task becomes task input |
| Session-to-tab-group mappings, approved plans and temporary page state | Keeping sessions and browser tools operational | chrome.storage.session and extension memory; session storage is cleared when the browser session ends |
Pages and task inputs can include identifying information, private communications, health, financial or location information. Terry does not require you to supply these categories, but processing such pages or tasks can include them in screenshots, tool results, model requests and history. Use Terry only with information you are permitted to provide to the selected service.
Use and transmission
Data supports the browser tasks you request, model replies, authorization, history restoration, export and notifications. Terry includes no developer-operated analytics, advertising or telemetry service. The extension does not automatically upload tasks or history to its developer, sell data, use task data for advertising or determine creditworthiness.
Model requests go directly from the extension to your chosen provider, including custom OpenAI-compatible endpoints. They include the system prompt, tool definitions, task context and relevant tool results. Conversation compression sends earlier conversation content to the same model to produce a summary. Automatic retries after temporary errors can send context again. The provider also receives network information such as your IP address through the connection. Its retention, training use, international processing and human access depend on its policies, your contract and account settings. Terry does not promise to delete third-party copies or disable a provider's training use.
Model settings prominently disclose these data categories, API-key authentication, provider policies and potential request charges. For first use or a changed provider/endpoint, the consent checkbox starts unchecked. Read the disclosure, check it and click Save to enable requests. Each model request, including retries and summaries, checks current consent; existing installations without a consent record must also confirm before sending. Revoke data consent in Model settings to block subsequent model requests; revocation is synchronized to other open settings pages. Saving another page with its previously saved checkbox does not restore revoked consent. Revocation does not recall requests already sent or delete third-party copies.
Terry acts inside websites where you may already be signed in, using those existing website sessions. Navigation, search, form entry and submission can transmit corresponding information to target websites. Each website and model provider's own privacy policy governs the data it receives. Remote model endpoints must use HTTPS. HTTP is permitted only for local endpoints at localhost, 127.0.0.1 or [::1]; local HTTP does not encrypt traffic. Model endpoint URLs cannot contain credentials, query parameters or fragments. Still check the operator and security of custom endpoints before use.
Custom OpenAI-compatible requests go only to the confirmed normalized endpoint plus /chat/completions, do not follow HTTP redirects, and check consent again immediately before sending. Built-in providers use their respective official SDKs and are not subject to this single-request-URL restriction.
Local storage and security boundaries
Settings and API keys are stored in this browser profile's local extension storage. Session records, which may contain screenshots, are stored in IndexedDB. Terry does not synchronize these stores through Chrome Storage Sync and does not implement additional application-level encryption at rest. Browser and device protections are not an encrypted vault supplied by Terry.
Configured API key text is replaced with [REDACTED] before conversation display, storage and export. Some suspected credentials in JavaScript tool results are also masked. These measures reduce accidental exposure, but cannot identify every private value, credential, encoded value or secret shown in an image. They are not encryption or a guarantee against disclosure. Inspect exports and screenshots before sharing them.
Scripts execute through Chrome's Debugger API in the target page environment and can read and change page content and application state. Plan approval authorizes sites and action categories, rather than automatically identifying and confirming each sensitive action. The plan approval interface includes a script permission option selected by default. You can deselect it or restrict actions and scripts separately in site settings. Running tasks continue after the sidebar closes; use Stop in the sidebar or on-page task control to stop them.
Retention, access and deletion
Terry sets no automatic expiry for local settings or history. Data normally remains until you delete it, clear the browser profile or uninstall the extension. Local storage is not a backup.
- Export the current session from the sidebar menu, or all sessions as JSON from Settings → Data.
- Clear history in Settings → Data. Running, loading and sidebar-open sessions are retained. Stop tasks and close their sidebars before clearing again, and check the reported retained count.
- Select a provider in Settings → Model and use Delete API key. Delete keys for other providers separately.
- Change or remove site permissions, notifications and shortcut prompts in settings. Clearing history does not delete API keys or other settings.
- The browser handles extension storage on uninstall. Downloaded export files are separate and must be deleted from your filesystem yourself.
These actions do not recall information already sent to model providers or websites. Request access or deletion of third-party copies from the relevant service.
Limited use and support
Terry's use of user information obtained from Chrome/Google APIs follows the Chrome Web Store User Data Policy, including Limited Use requirements. Data is used only for the disclosed browser-task functionality and transferred as needed for that functionality; it is not used for advertising, resale or credit assessment. The developer cannot remotely read your local task data through the extension. Specific information you voluntarily provide for support is used to handle that request.
Contact for privacy and support: terry23188@gmail.com. When you send an email, the relevant email providers receive your address, message, attachments and email transmission information. The developer uses that information to respond to and handle your request. Email providers process information under their own policies. Include only necessary, inspected and redacted content; do not send API keys, private page content or unchecked session exports. You may use this address to ask about or request deletion of support information you voluntarily provided to the developer. This does not replace requesting deletion from model providers or other third parties.
Public website visits
Product, support and privacy pages at browser.terrytu.dev are static files hosted on Cloudflare Workers. When you visit them, Cloudflare receives your IP address, HTTP request and related network information to deliver, secure and operate the website. Its handling of information it receives is described in the Cloudflare Privacy Policy. The website has no endpoint for submitting tasks or uploading sessions. Hosting these pages does not mean extension tasks, API keys or history are sent to Cloudflare through this website; extension model requests continue to go directly to your configured model endpoint.
Changes
When product data flows or practices change, this policy, its date and store disclosures will be updated. Future developer-operated servers, accounts or proxy modes are not part of the current version described here.