DFX General Browser Extension
Privacy Notice. Revision 1. Last updated July 22, 2026.
This notice describes how the DFX General browser extension (the "Extension") handles information. The Extension
is published by Deal Flow Xchange Inc, a Delaware corporation operating as DFX Intelligence ("DFX", "we", "us").
It lets an existing DFX customer allow their DFX General (an AI operator they already use and pay for) to carry
out browser tasks they asked for, inside their own browser, signed into their own accounts.
This notice is specific to the Extension. It supplements, and should be read with, the
DFX Privacy Policy and the DFX Terms of Service, which govern your use
of the Extension and of DFX Intelligence generally. The Terms of Service contain important disclaimers,
limitations of liability, and allocations of responsibility that apply to everything described here, including the
section titled "The DFX browser extension and browser operation".
The short version. The Extension only works after you install it and connect it to your own DFX
account. It reads the content of a page only while it is carrying out a task you asked for, and sends that content
to your own DFX workspace so your General can decide the next step and show you proof of what it did. It never
reads or transmits your passwords, cookies, or saved credentials, and it does not track the pages you browse
outside a task. Your data is not sold, not used for advertising, and not used to train generalized AI models.
1. What the Extension does
- It is inert until you install it and connect it, using an access token issued by your own DFX portal to your
own account.
- It dials out over HTTPS to your DFX workspace to ask whether you have approved any browser
work. It never opens an inbound port, exposes your browser to the public internet, or accepts connections from
anyone other than your configured DFX portal.
- When work is approved, it performs that work in a tab the Extension itself creates and owns,
not in the tab you are using, via the browser's developer tooling interface (the Chrome DevTools Protocol)
running locally on your machine. Your browser displays its own notice while that interface is attached.
- The actions it can perform are a fixed, structured set: open a web address, click, type, wait for an element,
read page text, read page markup, capture a screenshot, read the current address, and check that an expected
result is present. It refuses to run script supplied by our servers, and it refuses to navigate
to any address that is not an ordinary
http(s) web page.
- It refuses to operate on a hardcoded list of restricted domains covering banking, brokerage, payments,
payroll, and personal email, and it halts a run if a page it is on redirects onto one.
- A side panel lets you talk to your General, attach files, use voice, review activity, and approve or reject
proposed work.
- You can pause, disconnect, or uninstall at any time from the panel, the Extension's settings, or your DFX
portal.
2. What information is collected, and why
While a task you approved is running
- Page content. The visible text of the page or a selected element (currently truncated at
about 200,000 characters) and the page markup with scripts and styles removed (currently truncated at about
400,000 characters), so your General can read the result and decide the next step.
- Screenshots. Images of the working tab, used as the visual receipt you are shown as evidence
of what happened.
- Web addresses and step outcomes. The address of the page worked on, the success or error of
each step, timings, and a short non-reversible fingerprint of the page used to prove the page changed.
Page content and screenshots may include any information present on the pages you direct a task to, including
personal information, third-party data, and confidential business information. You choose those pages, and you are
responsible for ensuring you are permitted to disclose what is on them.
From the side panel
- Your messages and the conversation they belong to.
- The address and title of the tab you are currently viewing, sent with each message so that an
instruction like "add this person to the CRM" is complete. The content of that tab is not sent with a
message. Page content is read only while a task you asked for is running.
- Files you attach, transmitted with the message and processed to extract their text or, for
images, to be read visually.
- Voice. If you start a voice conversation, your microphone audio is streamed while the session
is active to our voice provider and to us, along with the resulting transcripts, and the duration is recorded
for usage metering. Audio capture stops when you end the session, and your browser shows its own microphone
indicator while it is running. Where simple dictation is offered instead, it uses your browser's own speech
recognition and is subject to your browser vendor's practices.
About the connection itself
- A device label you choose, the Extension version, the set of actions that version supports, and connection,
pause, and error state, so that your workspace does not send work an older version cannot perform.
- Basic health signals, so we can tell when the Extension stops working for people and fix it:
whether a connection succeeded or failed, whether a step failed, and a general category for the failure (for
example “network” or “timeout”), together with the Extension version. These signals never
include page content, addresses, titles, error messages, or anything you typed.
3. What the Extension does not do
- It does not read, collect, or transmit your passwords, saved credentials, cookies, session tokens for
other sites, autofill data, or browsing history. You stay signed in on your own machine.
- It does not monitor, log, or transmit the pages you visit outside a task you approved, and it does not build a
browsing profile.
- It does not run remote code. All logic ships inside the package, there is no
eval of
server-supplied script in your pages, and the content security policy is script-src 'self'.
- It does not sell your data, share it for cross-context behavioral advertising, or use it for advertising,
retargeting, or credit or lending decisions.
- It does not act on any site until you have connected it and work has been approved in your account.
These are design characteristics of the current version, described so you know what to expect. They are not
warranties. As set out in our Terms of Service, safety and containment controls are aids that may fail or be
circumvented, and no method of transmission or storage is completely secure.
4. What is stored locally on your device
In your browser's local extension storage, on your device only, the Extension stores: the DFX address it connects
to; the access token that identifies this browser to your workspace; short-lived session tokens; connection and
pause state; the identifier of its working tab; your recent panel conversation (kept for up to 24 hours so the
panel survives being closed); and, if a step's result could not be delivered because the network or the browser
interrupted it, a small bounded queue of undelivered results, which may contain extracted page text or a
screenshot until delivery succeeds. Nothing here is synced to another device by us.
Anyone with access to that browser profile can use the connection and direct work in your
workspace within your settings. Treat a connected browser as a credential. Disconnect immediately if the device is
lost, shared, serviced, sold, or accessed by anyone else. Uninstalling the Extension removes its local storage.
5. Where the information goes
Task content is transmitted over HTTPS to DFX Intelligence, to the same workspace you already use as a customer.
To plan the next step and interpret what is on a page, relevant content is transmitted to our AI model providers
(currently Anthropic, with OpenAI used as a failover to maintain availability). Voice audio is transmitted to our
voice provider (ElevenLabs). Hosting and storage are provided by our cloud infrastructure providers. These
providers process the information on our behalf under contractual obligations. We use enterprise arrangements with
our model providers under which your content is not used to train their general models. A fuller description of
our sub-processors is in the DFX Privacy Policy.
6. Limited use of data received through the extension platform
Our use of information received from the extension platform, including any Google user data, adheres to the
Chrome Web Store User Data
Policy, including its Limited Use requirements. Specifically, we:
- use the data only to provide and improve the single, user-facing purpose of the Extension, which is letting
your DFX General carry out browser work you asked for and report what it did;
- do not transfer the data except as necessary to provide or improve that purpose, to comply with applicable
law, or as part of a merger, acquisition, or sale of assets with notice to affected users;
- do not use or transfer the data for advertising, retargeting, personalized advertising, or to determine
creditworthiness or for lending purposes;
- do not sell the data; and
- do not use the data, and do not allow humans to read it, to train generalized or third-party AI or machine
learning models, except where necessary for security purposes, to comply with applicable law, where the data is
aggregated and de-identified, or where you give us express consent for a specific purpose such as investigating
a support issue you have reported.
7. Retention, your controls, and deletion
Browser-task records, including the addresses worked on, extracted content, screenshots, and step outcomes, are
retained as part of your DFX account activity so you can review what your General did, in line with the retention
practices described in the DFX Privacy Policy. You can pause browser work, disconnect this
browser from the panel or from your portal, revoke the connection so its token stops working, and uninstall the
Extension at any time. To request access to or deletion of your data, contact us at
hello@dfxintel.com.
8. Security, and what you are responsible for
We apply reasonable technical and organizational measures, including HTTPS transport, per-member scoping of every
request, storage of connection tokens as hashes rather than in plain text, short-lived session tokens, a refusal to
execute server-supplied script in your pages, and a restricted-domain floor enforced both on our servers and
independently inside the Extension. No product, transmission method, or storage method is completely
secure, and we do not warrant that information will be free from unauthorized access, loss, or misuse.
You decide which device, which browser, and which browser profile to connect, and therefore which signed-in
accounts and data are reachable. You are responsible for that choice, for the security of the device and profile,
for other extensions installed alongside this one, and for the pages you direct tasks to. We recommend connecting a
dedicated browser profile signed into only the accounts you intend your General to use, and never connecting a
profile with access to financial, payroll, health, or other sensitive systems.
9. Children
The Extension is a business tool, is not directed to children under 18, and we do not knowingly collect personal
information from them.
10. Changes to this notice
We may update this notice as the Extension changes. Material changes will be reflected by posting an updated
notice with a new date at this address. Continued use after the change takes effect constitutes acceptance.