Legal
Privacy Policy
Rexa Pilot is an AI sidebar that reads what you ask it to and nothing more. This page explains exactly what data is processed, where it goes, and the choices you have.
Last updated: June 4, 2026
The short version
- We only process page content, selections, files, or audio when you trigger an action — Rexa Pilot does not read pages in the background.
- Your prompts and the context you share are sent to AI providers solely to generate your response.
- Knowledge Base files are stored privately and used only to answer your questions.
- We collect anonymised product analytics (feature usage, errors) to improve the product. We do not sell your data and do not use your private content to train AI models.
Information we process
Account information
You sign in with Google. We receive your name, email address, and profile photo via Google Sign-In to create and secure your account. Authentication is handled by Firebase Authentication (Google).
Content you ask Rexa Pilot to act on
When you use a feature, the relevant content is sent to our backend and on to an AI provider to produce a result. Depending on the action, this may include:
- Page context — text from the current tab, only when you ask a question about the page.
- Selections & field text — text you highlight, or the contents of a text field when you use the writing assistant or instant replies.
- Knowledge Base files — documents you upload (PDFs, slides, docs, web clips) to chat with.
- Screenshots — a region you capture to ask a vision model about.
- Voice audio — streamed in real time during a live voice call (Gemini Live) or a voice recording / dictation session (Deepgram). Audio is not retained after the session ends.
- Screen frames — low-frame-rate images streamed only if you share your screen during a live call. Not retained after the call ends.
- Video links — a public video URL you choose to summarize. We fetch the public transcript; we do not access private videos.
Usage & analytics
We collect anonymised product-usage events (for example, which features you activate, error counts, and session interactions) to understand how the product is used and to improve it. These events are linked to your account ID but do not include the content of your prompts, documents, or conversations. We also record UI interactions inside the sidebar for product improvement — typed text is always masked and never recorded.
Error diagnostics
When the extension or backend encounters an error, a report including a stack trace and limited technical context may be sent to our error-monitoring service. We take care not to include prompt content in error reports, but stack traces may occasionally contain request metadata.
Device storage
The extension stores preferences, per-site settings, and temporary session state in your browser's local storage (chrome.storage.local and chrome.storage.session). This data never leaves your device unless you explicitly trigger a feature that sends it.
How your data is processed — sub-processors
Rexa Pilot is a thin client: the extension sends your request to our backend, which calls the appropriate provider, and streams the result back. We use these sub-processors strictly to deliver the features you invoke:
- Amazon Web Services — Bedrock — generating chat, reply, summary, vision, and agent responses.
- Amazon Web Services — S3 & Textract — storing Knowledge Base files and extracting text from them for indexing.
- Google — Firebase — user authentication, and storing your account data, chats, usage counters, and Knowledge Base metadata in Firestore.
- Google — Gemini Live — real-time voice call processing. Audio is processed via a short-lived ephemeral token; it is not retained.
- Deepgram — real-time speech-to-text for the voice recording / dictation feature. Audio is streamed directly to Deepgram via a short-lived grant token; it is not retained by us.
- Tavily — fetching live web search results to ground answers.
- Supadata — retrieving public video transcripts for the video summary feature.
- PostHog — product analytics and anonymised session interaction recording (typed text masked). Used to understand feature usage and improve the product.
- Sentry — error monitoring and crash reporting to maintain reliability.
We choose providers whose default terms do not use API-submitted content to train their foundation models. We never sell your personal information.
Where your data is stored
- Account, chats & usage — stored in Firestore (Google) under your account, secured by Firestore security rules that allow only you to read or write your own data.
- Knowledge Base files — stored privately in Amazon S3, with searchable text chunks indexed to your account only in Firestore.
- Live voice & screen content — processed in real time and not retained after the session ends.
- Browser storage — preferences and session state stored locally in your browser; never uploaded unless explicitly used in a feature.
Your choices & controls
- Every in-page feature (instant replies, writing assistant, summaries, quick access, agent, and more) can be turned on or off — globally or per site — in the extension Settings.
- You can delete Knowledge Base files and folders at any time from the Library. Deletion removes the file and all indexed text associated with it.
- You can clear your chat history at any time from the extension.
- To request deletion of your account and all associated data (chats, Knowledge Base files, usage records), contact us at privacy@rexapilot.com. We will process the request within 30 days.
- The do-it-for-me agent always asks for confirmation before submitting forms or taking other consequential actions.
Data retention
We retain account information, chats, and Knowledge Base files until you delete them or request account deletion. Daily usage counters are reset automatically each day (UTC). Transient request data (voice audio, screen frames, page text sent to AI providers) is not stored by us beyond the duration needed to stream the response.
Children's privacy
Rexa Pilot is not directed to children under 13, and we do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, an in-product notice. Continued use after a material change constitutes acceptance of the updated policy.
Contact
Questions about privacy? Email us at privacy@rexapilot.com or use our contact page.