doeverything

Privacy Policy

Last updated: July 10, 2026

doeverything is a “bring your own key” AI browser agent. You provide an API key for an AI provider you choose, and the extension uses that provider to read and operate web pages on your behalf. Most of your data stays on your device or is sent only to the AI provider you selected. This policy explains what we collect, how it is used, where it is stored, and who it is shared with.

1. Data stored on your device

The extension keeps the following on your device only. It is not sent to doeverything.

  • Your API keys — the keys you enter for your AI provider are stored locally and encrypted at rest. They are never sent to us; a key leaves your device only as the authorization on requests to the provider you configured.
  • Your activity — conversation history, saved skills, per-site memory, and settings are stored locally in your browser. You can view, export, or delete them in the extension's settings, and uninstalling the extension removes them.

2. Data sent to the AI provider you choose

To carry out a task, the extension sends your instructions along with the page content it reads, screenshots it captures, and the related conversation context to the AI provider you configured, authenticated with your own key. Because the agent operates a real browser for you, this content can include personal or sensitive information on the pages you use it on.

This data goes directly to your chosen provider — it is never routed through, received by, or stored by doeverything — and its handling, including any retention or use for model training, is governed by that provider's own privacy policy. You control this transfer by choosing which provider to use and which pages to run the agent on. The extension redacts common sensitive request headers where it can, but you should treat any page you direct the agent to as content that may be sent to your provider.

3. Voice input (optional)

If you use the microphone button to dictate a message, your browser's built-in speech recognition sends your audio to Google's speech service to convert it to text — regardless of which AI provider you use for the agent — and that transfer is governed by Google's privacy policy. doeverything does not receive or store your audio. If you don't use dictation, no audio is captured.

4. Connecting external apps (optional)

doeverything can expose its browser tools to another application (a Model Context Protocol client) — such as a desktop AI app or a coding assistant — so it can drive the browser for you. This is off until you set it up, and you choose how the connection is made:

  • A local address on your own machine (for example a local bridge at localhost) — the traffic stays on your device and never reaches our servers.
  • Our hosted relay — your tool calls and their results, including page snapshots and screenshots, pass through the relay in real time to reach the connected client. The relay only holds this data briefly in memory to pass it along and does not store it.

You choose the connection address, and you can change it, disconnect, or rotate its access token at any time. If you don't set up a connection, none of this happens.

5. Anonymous diagnostics

To understand which features are used and to improve reliability, doeverything can send anonymous diagnostic events — an anonymous install identifier plus non-content signals such as which tools ran, the AI provider and model name, and error types. These events never include your prompts, page content, keystrokes, screenshots, or credentials, and are not linked to your identity.

6. Configuration

The extension periodically checks our servers for configuration settings — for example, whether a particular feature is turned on. These checks don't send your identity or any personal data, and we don't log them.

7. Feedback you send us

If you send us feedback — for example through the short survey shown when you uninstall — we receive what you submit, such as the reason you select and any comments you write, along with your IP address. We use it only to understand problems and improve the product. Sending feedback is voluntary.

8. How we use data

  • To operate the agent — your prompts, page content, and screenshots are sent to the AI provider you chose so it can perform the task you asked for. This is the extension's core purpose.
  • To transcribe voice — if you use dictation, your audio is sent to Google's speech service to turn it into text.
  • To connect external apps — if you enable relay mode, to route tool calls and results between the extension and the app you connected.
  • To improve reliability — anonymous diagnostics show which features are used and where errors occur.
  • To improve the product — feedback helps us understand what to fix.

We do not sell your data, share it with advertisers or data brokers, or use it for advertising or profiling. No one at doeverything reads your prompts, page content, or conversations — that content is never sent to us.

9. Who we share data with

We share data only in the specific cases below, and never with advertising networks or data brokers.

  • The AI provider you choose — receives your prompts, page content, screenshots, and conversation context, plus your API key as authorization, to perform your task. Governed by that provider's privacy policy.
  • Google — receives your microphone audio if you use voice dictation, to transcribe it. Governed by Google's privacy policy.
  • Our analytics provider (Segment, a Twilio service) — receives the anonymous diagnostics described above. Governed by Twilio's privacy notice.

We may also disclose data if required by law or to protect against fraud, abuse, or security threats.

10. Data retention

  • On-device data — kept until you delete it or uninstall the extension.
  • Diagnostics — retained by our analytics provider for a limited period.
  • Feedback — kept only as long as needed to act on it, and no longer than 24 months.
  • Data sent to your AI provider, Google, or through the relay — not retained by us; the relay stores nothing, and provider retention is governed by their policies.

11. Your choices and rights

  • Type instead of using voice dictation if you prefer not to send audio to Google.
  • Use a local-only address for the MCP connection, or disconnect it or rotate its token, at any time.
  • View, export, or delete your conversations, memory, skills, and settings from the extension.
  • Add or remove your provider API keys at any time.
  • Uninstall the extension (Chrome → Extensions → Remove doeverything) to delete all local data and stop future collection.

Depending on where you live, you may have rights under the GDPR, CCPA/CPRA, or similar laws to access or delete personal data we hold. The main personal data we hold is any feedback you submit and the IP address attached to it. To make a request, contact us at privacy@doeverythi.ng.

12. Limited Use

doeverything's use and transfer of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

13. Children's privacy

doeverything is not intended for children under 13, and we do not knowingly collect data from children. If you believe a child has provided information through the extension, please contact us and we will take appropriate steps.

14. Changes to this policy

We may update this policy as the product changes. When we do, we will update the date at the top of this page, and we encourage you to review it periodically.

15. Contact

For any questions or requests about this policy, email us at privacy@doeverythi.ng.