Legal

Privacy Policy

Last updated: October 5, 2026

This policy is a template written to match how Flexbot is built. It has not yet been reviewed by a lawyer, and bracketed items still need to be filled in.

The short version

  • Your flexes live on your device. Flexes (code and metadata), run logs and per-flex data live in chrome.storage.local on your device. They're never uploaded or synced.
  • Data leaves your device only when you ask Flexbot to create or change a flex, or when a script you saved calls flex.ai(). Form field values and password fields are never included.
  • We don't keep that content. It goes to our server and our AI provider, Anthropic, to produce the result. Our server keeps only billing metadata (credits, token counts, timestamps), not prompts, page content or code.
  • With your own Anthropic key, nothing goes to Flexbot's servers at all. Requests go straight from your browser to Anthropic, and you don't need a Flexbot account.
  • We don't sell your data, show ads, profile you, or use your content to train AI models.

1. Who we are

Flexbot is an open-source Chrome extension, an optional web service at flex.bot, and this website, operated by [Company legal name], [registered address] (“Flexbot”, “we”, “us”). We are the controller of the personal data described here. Questions: hello@flex.bot.

Flexbot is an AI-assisted userscript manager: when you ask, it writes a small JavaScript program (a “flex”) for the page you're on and shows it to you. A draft may run once as a preview on the tab you're looking at; nothing is saved or registered until you click Save.

2. What stays on your device

The extension keeps the following inside your browser, on your computer:

  • in chrome.storage.local: every flex you save (its code, name, description, the sites it runs on, when it runs, its version history), values your flexes store with flex.store, a log of recent runs, your settings and paused sites, your email address if you signed in, and a cached copy of your plan and credit balance. After you sign out, the extension keeps the email address of the account last signed in on this device, so it can offer to sign you back in rather than start a new trial; it's removed when you switch to a different Flexbot server or remove the extension;
  • in the extension's private IndexedDB storage, which web pages and Flexbot's in-page UI can't read and which only the extension's background process uses: your Flexbot session token (if you signed in) and your Anthropic API key (if you chose to use your own key).

None of this is uploaded or synced. Saved flexes run on your device, and so do scheduled checks: a scheduled flex opens its page in a background tab in your own browser, runs, and closes the tab. Removing the extension deletes this data. You can also delete flexes, or export them to a file, from the Library.

3. When you ask for a flex

Nothing about the pages you visit is sent anywhere until you ask Flexbot to create or change a flex (by sending a request in the composer, pointing at something, or clicking “Ask AI to fix”). Before your first request, Flexbot shows what it sends and asks for your agreement. Each time you send a request, the extension sends:

  • your prompt (what you typed);
  • the page URL without its query string or fragment, and the page title;
  • a compact text outline of the page: its structure, short pieces of visible text, and selectors for elements;
  • if you pointed at something: that element's HTML (trimmed, with query strings and token-like values redacted), a selector for it, its position and size, and some of its computed styles;
  • the names and descriptions of flexes already on that page, and when they run, so follow-up requests make sense;
  • when you're changing an existing flex or a draft: its code, name, the sites it runs on, when it runs and the request it was made from (and, when you click “Ask AI to fix”, the error message it produced and the ID of the request that wrote it);
  • your browser window size, and whether you chose Standard or Smart.

Form field values and password fields are never included. The request is sent in the body of an encrypted (HTTPS) request, never in a URL. It goes to our server and our AI provider, Anthropic, to produce the result. If you ask for a flex on a personal page (for example your email or a chat), the outline can include parts of what's on screen, such as message text; it's used only to answer that request.

Our server does not store your prompt, the page outline, element HTML or code after the response is returned. It keeps only billing metadata about the request: when it happened and finished, whether it was Standard, Smart, a free fix or an AI call, the credits charged, the AI model used, the number of input, output and cached tokens, the ID of the flex or earlier request it relates to (a flex's ID is a random code, not its name), and an error code if it failed. For a flex it writes, it also keeps a one-way fingerprint (SHA-256) of the site, your request and the code returned, used only to check that a free “Ask AI to fix” is about that result; the fingerprint can't be turned back into the content.

4. AI calls from your scripts (flex.ai)

A flex can ask Flexbot AI something while it runs, for example to summarize a thread. This includes a draft's one preview run. Each flex.ai() call sends only:

  • the prompt and the data that script passes to it (up to about 30,000 characters), and the answer format it asks for, if any;
  • which flex made the call (its random ID);
  • the daily limit on AI calls you set for each flex, and your time zone offset, so that limit resets at your midnight.

Flexes that do this are marked “Uses AI” in review, and their approval card says that they send page content and use credits each run. The content is handled exactly like a flex request: processed to produce the answer, not stored by us. The ledger entry for the call records the flex's ID, as described in section 3; your time zone offset is used only to count that day's calls and isn't stored.

5. Using your own Anthropic key

If you choose My Anthropic key in Flexbot's settings, nothing goes to Flexbot's servers at all. Requests go from your browser straight to Anthropic with your key, and no Flexbot account is needed. The key is stored only in the extension's private storage on your device; we never see it. When you save a key, the extension checks it with a small request to Anthropic.

The content listed in sections 3 and 4 is sent, but directly to Anthropic under your own agreement with Anthropic, and Anthropic's own policies apply to it. The flex ID, daily limit and time zone offset in section 4 are only for our server's credit accounting, so they aren't sent in this mode. Flexbot receives nothing about those requests, including no usage or billing metadata.

If you set a Custom server URL (for example a Flexbot server you host yourself), requests in credits mode go to that server instead of ours, and its operator, not us, decides what it keeps. Flexbot shows a warning before you switch.

6. Your account and billing

  • Email address. You sign in with your email address and a 6-digit one-time code. We use it to identify your account, send sign-in codes, give each person one free trial (we compare a normalized form of the address, ignoring capitalization, +tags, and dots in Gmail addresses), and contact you about your account or billing.
  • Sign-in codes and sessions. Codes are stored only as one-way hashes and expire after 10 minutes. Session tokens are stored on our server only as hashes, with when they were created and last used. Signing out revokes the token.
  • Plan and credits. Your plan, subscription status, billing period, pending plan changes and a credit ledger (time, request type, credits, model, token counts, the ID of the flex or request each entry relates to, and an error code if it failed).
  • Billing. Payments are handled by Stripe. You enter card details with Stripe, never with us. We receive and store your Stripe customer ID, subscription ID, subscription status and invoice status. We never see full card numbers.
  • Server logs. [State exactly what the server and hosting provider log (for example request path, status, time), for how long, and whether IP addresses are stored. Never log page URLs from scheduled or on-load runs.] We use IP addresses briefly, in memory, to rate-limit sign-in attempts and requests.

7. Your scripts

Flexes are code that you asked for, reviewed and saved, or wrote or imported yourself. They run inside Chrome's user-script sandbox on the sites you chose, with network access blocked by default for their own requests; a flex that needs the network must be approved by you for the specific sites it names. A flex can read and change the pages it runs on, which is how it does its job, so review what it can do before you save it. We don't receive anything from your flexes' runs, except the flex.ai() calls described in section 4.

Our server never pushes, updates or replaces a flex you saved. When you import flexes from a file, they arrive switched off until you review them.

8. What we don't collect

  • Your browsing history. Flexbot reads a page only when you ask for a flex on it, or when a flex you saved calls flex.ai().
  • Keystrokes, form entries, passwords or cookies.
  • Your flexes, their stored values, schedules or run results; those stay on your device.
  • Analytics or advertising data, in the extension or on this website.

9. How we use data

Only to:

  • generate or change the flexes you ask for, and answer flex.ai() calls;
  • run your account, plan, credits and billing;
  • secure the service and prevent abuse (for example rate limits and one trial per person);
  • provide support when you ask for it.

We don't use your data for advertising or profiling, don't sell it, and don't use it to train AI models. [Add legal bases for processing (for example contract, legitimate interests, consent) where required.]

10. Who we share it with

We use a small number of providers who process data on our behalf, only for the purposes above:

ProviderWhat they doData involved
Anthropic (AI provider)Writes or changes flexes; answers flex.ai() callsThe request content in sections 3 and 4. Per Anthropic, API inputs and outputs are deleted within 30 days (kept up to 2 years if flagged for Usage Policy violations), and API data isn't used for training unless the customer opts in. [Confirm current Anthropic terms and our account settings.]
StripePayments, subscriptions, invoices, customer portalEmail, payment details you give Stripe, customer and subscription IDs
[Email provider, e.g. Resend]Sends sign-in codesEmail address and the code
[Hosting provider]Runs our server and databaseThe server-side data in section 6
Google FontsServes this website's fontsIP address and browser information sent with the font request

We may also disclose information when required by law, or to protect the rights, safety or property of our users or others. If Flexbot is involved in a merger or acquisition, we'll tell you before your data becomes subject to a different privacy policy.

11. How long we keep it

  • Flex request and flex.ai() content: not stored after the response is returned.
  • Account record: until you ask us to delete your account. We delete accounts within 30 days of a request.
  • Sign-in codes: expire after 10 minutes. Session tokens: until you sign out or we revoke them.
  • Credit ledger and billing records: [as long as needed for billing, tax and fraud prevention, e.g. N years].
  • Server logs: [N days].
  • Data on your device: until you delete it or remove the extension.

12. Human access

People at Flexbot don't read your requests or data, except with your explicit consent (for example when you send us details in a support request), for security investigations, or when required by law. Request content isn't stored, so in most cases there's nothing to read.

13. Security

All connections to our server use TLS (HTTPS), and data we store is encrypted at rest [confirm hosting/database encryption]. Your content is sent in request bodies, never in URLs. Sign-in codes and session tokens are stored only as hashes. On your device, the session token and your Anthropic key are kept in the extension's private storage and used only by its background process; web pages and Flexbot's own in-page UI never receive them. No system is perfectly secure: if you think your account has been compromised, sign out in Flexbot and contact us.

14. This website

This website uses no analytics, advertising or tracking cookies. It loads fonts from Google Fonts, so your browser requests them from Google's servers. The interactive demo on the homepage runs entirely in your browser: nothing you type into it is sent anywhere, and its demo flexes and credits are kept in your browser's local storage (use “Reset demo” to clear them). Our hosting provider may keep standard server logs [as described in section 6].

15. Your choices and rights

  • AI features run only when you ask. You can withdraw your consent in Flexbot's Library under Privacy (“Withdraw consent”); AI requests then stop until you agree again. Your saved flexes keep running.
  • Use your own key to keep all requests between your browser and Anthropic.
  • Export or delete flexes from the Library at any time; remove the extension to delete everything stored on your device.
  • Access, correct or delete your account data: email hello@flex.bot from the address on your account. We'll respond within [30] days.
  • Stop billing: cancel from Plans & billing → Manage billing in Flexbot.

Depending on where you live, you may have more rights, such as objecting to or restricting processing, data portability, or complaining to a data protection authority. [Add jurisdiction-specific disclosures, e.g. GDPR/UK GDPR and CCPA/CPRA notices, as applicable.]

16. Children

Flexbot isn't directed to children under 13 (or 16 where that is the applicable age), and we don't knowingly collect their personal information. If you believe a child has created an account, contact us and we'll delete it.

17. International transfers

Our providers may process data in countries other than yours, including the United States. [Describe the transfer safeguards relied on, if applicable.]

18. Changes to this policy

If we change what data Flexbot collects or how it's used, we'll update this page and tell you in the extension before the change applies. Before any new kind of data is sent, Flexbot will ask for your consent again.

19. Chrome Web Store Limited Use

Flexbot's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

20. Contact

Questions or requests: hello@flex.bot
[Company legal name, postal address]