Scope
This notice covers act.nodelane.net and NodeLane Act 0.2.0. The project is provided by NodeLane maintainers; contact [email protected] about privacy. Your AI client, browser, GitHub, email service, and the websites you operate have their own data practices.
Browser and MCP processing
When tools are called, the extension identifies supported website tabs and performs the requested read or interaction in a selected page. Results may include tab titles and URLs, account details, list entries, full text, comments, private messages, and action outcomes, depending on the operation and website permissions.
Website login cookies and CSRF values are used within the browser session and are not exported to the model as credential fields. The local MCP server and extension exchange instructions and results over loopback. The current code has no telemetry flow that sends operation content to a NodeLane-hosted backend.
Your AI client receives results
Tool requests and results are provided to your chosen MCP or AI client. If it uses a cloud model or stores conversations, content may leave the device and be handled under that service’s settings and policies. NodeLane Act cannot control that provider’s retention, training, or sharing settings for you.
Execution in a local browser does not mean that read content never leaves the device. Before requesting personal, private, or organizational data, confirm you have permission to provide it to your chosen AI service.
Local storage and caches
The local runtime directory stores bridge configuration and generated connection authentication data. Extension storage keeps the last successful connection port and recent write request IDs and times used to prevent replay.
The MCP process caches oversized results in memory, up to 30 entries for ten minutes. Site pagination may use short-lived page caches. The extension also retains recent statuses, errors, and completed results while running. These caches can contain returned data and are not a separate secure storage system.
Clearing extension data, ending the relevant browser or MCP processes, and removing runtime configuration affect different local data. Uninstalling does not remove website content, AI conversations, system backups, or diagnostic files you saved.
Website access and security services
The website currently has no product accounts, advertising trackers, analytics scripts, or optional analytics or marketing cookies. Cloudflare provides delivery and security services. Hosting and security systems may process basic access information such as IP addresses, request times, paths, status codes, browser details, and security events.
These records support delivery, troubleshooting, and abuse prevention. Exact log fields and retention depend on deployment and security configuration; this project does not claim that visiting the website generates no data. Cloudflare cookie use depends on enabled security features. See the cookie notice.
Contact records and requests
GitHub issues are generally public and are handled under GitHub’s policies. If you email maintainers, your address and message are received for support and investigation. Do not post credentials or private website content publicly.
To ask about, correct, or delete contact records held by maintainers, or exercise relevant rights under applicable law, email with the data and request concerned. Proportionate identity verification may be needed; website login credentials are not required. Ask the relevant website or AI provider directly about records it holds.
Material changes will be reflected by an updated date and explanation on this page. New telemetry, accounts, or processing purposes should be accompanied by an updated notice.