Privacy
Operator: Boonwerks, a Wyoming corporation, operates TabWorker. Contact team@tabworker.com for privacy and data requests.
TabWorker Relay processes pairing information and the page data needed for authorized browser tasks. This policy also covers retained services used by existing integrations. It does not sell personal data or collect unrelated browsing history.
What this policy covers
This policy covers TabWorker’s website, developer applications, API and TabWorker Relay. The application you connect has its own data practices and privacy policy. Historical service records are described separately below.
The current launch is TabWorker Relay. Installing Relay authorizes neither human access to your task content nor enrollment in other services.
Information processed
- Account records: email, authentication session and organization membership.
- Application credentials: hashed server API keys issued to a product backend. Customer Nodes receive separate device credentials. Browser extensions never receive an application key or Node credential.
- TabWorker Relay: during an authorized session, tab URLs, relevant page text and structure, form values (with password and hidden input values omitted from structured outlines), screenshots, action results, and signed task evidence are sent to the paired automation service. Screenshots can include personal information and embedded frame content. The destination, permitted sites and actions are shown before access is granted. TabWorker Core also processes pairing, lease, and attestation records; where Core hosts a job runtime, it can retain job state and page summaries. A third-party service may use its own infrastructure or model providers to perform the requested task. This data flow is not limited to the local computer.
- Local host bridge: an install-scoped token sent only as a request header to
127.0.0.1.
Information not collected
Relay does not export the browser profile or cookie jar. It inspects some page signals locally to select interaction behavior. Page contents and screenshots from an authorized tab may contain sensitive information; Relay does not promise universal redaction. Other tabs are not included unless separately authorized. Relay executes structured remote browser instructions through Chrome’s debugger API using helpers packaged in the extension. Pairing a service alone does not authorize page access.
How information is used
Pairing records are used to authorize, maintain, cancel, reconnect and revoke browser tasks. Relay observations and results are sent during the authorized automation session so the paired service can plan the next step and complete the requested browser task; there is no separate confirmation for every observation.
Sharing
TabWorker shares authorized task data with the paired application and infrastructure providers that host the service. It does not sell personal data. Relay human-access restrictions are set out below.
Relay use and recipients
Authorized website content can include names and contact details, health or financial information, personal communications, location information, and authentication-related information visible on the page. Relay also handles its own pairing credentials and authorized task URLs/actions. These categories are disclosed because they can occur in the pages you choose, not because Relay collects a separate health, financial, location or browsing-history dataset. Password and hidden-input values are omitted from structured outlines; screenshots and other page content are not universally redacted.
TabWorker's use of information obtained through Relay complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Relay data is used only to provide the disclosed browser-automation function and related necessary operations. We do not use or transfer Relay content or derived data for general-purpose model training, advertising, resale, or unrelated profiling. Production developers must disclose their recipients and data practices and meet these restrictions before admission; an application key never replaces the customer's browser grant.
Cloudflare, Inc. provides TabWorker's proxy, application hosting, database and object-storage infrastructure. The application you pair receives the authorized observations at the service destination shown in Relay; its applicable privacy policy and connection disclosures describe its processing and downstream recipients. Developer admission is manual. We do not claim that every possible future application has already been reviewed. Local development connections use literal 127.0.0.1 and send data to the user's local service.
Relay content is not dispatched to TabWorker marketplace workers or annotation pools in this launch. Staff may read specific content for support only with the user's explicit consent to that content. Access necessary for security investigations or legal compliance is restricted to authorized personnel and the necessary data, with an access record. Installing Relay or accepting this policy does not grant blanket permission for staff to read task contents.
TabWorker demonstration
The hosted demonstration at demo.tabworker.com is operated by Boonwerks on Cloudflare and uses fictional form data. Its live connection receives authorized outlines, action results and screenshots; the demo does not write those payloads to application storage or logs and makes no model-inference calls. Core retains the ordinary pairing, identity and lease records. The demo's connection ends within 15 minutes. This does not imply that Core records or other applications' task data are deleted after 15 minutes. Only use the provided fictional data in the demo.
Retention and control
Account holders can close a session, cancel or revoke device work, clear an extension task, or uninstall an extension. Product retention for receipts and audit evidence follows TabWorker’s operating records. Exact country, tax, and legal-hold periods remain operator policy. Relay tab grants are kept in browser session storage and expire within one hour or earlier when the pairing expires. A grant may optionally cover later jobs from the same service within the disclosed tab, site, and action scope. Stop revokes access, blocks subsequent actions and observations, and discards late results; Stop all covers every Relay job. Stopping or uninstalling does not delete records already transmitted. Pairing and cryptographic identity records are stored locally until removed through Relay controls or extension removal. Core job snapshots and evidence have no blanket automatic deletion period. A registered application can request erasure of Core Relay history for a customer it identifies with the exact external reference used when minting jobs; Core then keeps only a content-free job-id fence so deleted content cannot be restored. That request does not delete records already sent to the paired application, and it does not establish deletion of backups or logs. Contact us for access or other deletion requests. Third-party service retention and processing are governed by that service’s disclosed practices.
Developer applications
The developer application form sends your contact details, company and application information, data-practice answers, acknowledgments and demo instructions to team@tabworker.com for manual review and follow-up. Cloudflare processes the form and sends the application to our Google-hosted team mailbox. These application records are separate from Relay page observations. Applications are retained in review correspondence; there is no automatic deletion deadline. Contact us for access or deletion. We use a hashed network address for submission rate limits. Do not submit secrets or customer page content. Submitting an application does not issue credentials or grant browser authority.
Historical service records
Earlier Work Programs, Human Resolution, Guide and Capability Bank services are outside the Relay launch. Retained records may include tasks, assignments, explicitly submitted proof, reviews, disputes and receipts. They were used to deliver and audit that work, including sharing with its requester and authorized reviewers. Guide collected its active task, local progress, worker-entered token, task URL and explicitly recorded text or proof. Those historical disclosures do not authorize human access to Relay content. Contact team@tabworker.com about retained records.
Contact
Privacy questions: team@tabworker.com. Product and developer support: Support.
Policy revision prepared: 10 September 2026.