Privacy Policy
Laspoh browser extension & service · effective 26 July 2026 · contact: info@samstar.org
The short version. Laspoh is a browser agent that works missions you explicitly start, in your own browser session. It reads pages only while working your mission, thinks on Laspoh's managed AI brain by default (bring-your-own key available on Pro), keeps your profile in your browser's local storage, and never sells data or shows ads. Delete your data any time.
1. What Laspoh does
You state an outcome ("apply to these jobs", "research X and report back"). The extension plans the mission, operates the pages in your browser, verifies the result independently, and reports back with evidence. Everything it does is in service of the mission you started — it has a single purpose and does not run in the background on pages you haven't delegated.
2. Data the extension processes
- Page content of the working tab. While a mission runs, the extension observes the mission's tab (text, structure, and a screenshot per step) to decide the next action and to verify results. Pages you are not delegating are not read.
- Your profile vault. Facts you give it (name, experience, answers for forms) are stored in the extension's local browser storage on your machine. They are used to fill forms you ask it to fill.
- Mission records. Goals, plans, notes, evidence and verification verdicts are stored so missions can resume and results can be shown with receipts.
3. Where data goes
- The Laspoh API. Mission observations are sent to the Laspoh service to plan and verify steps, and mission state is persisted there so work can resume.
- The AI brain. By default the "brain" runs on Google's Gemini API under Laspoh's own key — mission observations are forwarded there, under Google's API terms, solely to plan and verify your mission. On the Pro tier you may instead connect your own provider and key (e.g. Google, OpenAI); observations then go to the provider you chose, under your key and their terms.
- Failure diagnostics (anonymized). When a mission fails, the extension sends Laspoh a thin technical report — action types, outcomes, timing buckets, and the site's hostname — so defects get found and fixed. It is built from an allow-list that structurally cannot include page content, form values, element labels, your goal text, or your profile. On by default; turn it off any time in Settings → "Share failure diagnostics".
- No one else. No sale of personal data, no advertising, no third-party analytics in the extension.
4. What we never do
- Sell or rent your data.
- Act without a mission you started — including payments and publishing, which additionally require explicit approval in the panel unless you have turned on autopilot for that category.
- Bypass sites' authentication, CAPTCHAs, or payment gates.
- Bake your API key into the product — keys are stored server-side for your account and used only to call the provider you chose.
5. Permissions, honestly
- Access to sites — the agent must be able to work whatever site your mission names; it only acts on the mission's tab.
- Tabs & scripting — to open the working tab, observe it, and dispatch clicks/typing for the mission.
- Storage — your local profile vault, settings and mission ledgers.
- Downloads — to save deliverables (reports, CSVs) you asked for.
- Debugger (optional, on request) — only if a page provably ignores normal input, Chrome asks you first, and the permission is dropped as soon as the step completes.
6. Retention & deletion
Mission records persist so you can review results with their evidence. You can delete missions and your profile vault from the panel at any time, and uninstalling the extension removes all local data. To have server-side records deleted, email info@samstar.org and we will remove them.
7. Security
Provider keys are held server-side, never in the shipped extension bundle. The service runs on managed cloud infrastructure with secrets isolated from source and images. Forensic repair packets (a debugging tool) are redacted, generated only on demand, and downloaded to your machine — never auto-uploaded.
8. Changes
If this policy changes materially, the effective date above changes and the current version is always at this URL.