GreyOrange
AI-SRO — Privacy Policy
Last updated: 14 September 2026
AI-SRO · observation and in-browser execution
AI-SRO is an enterprise Chrome extension. It is deployed by an organisation for its own staff, and it observes how work is done in the browser so that repetitive work can later be proposed for automation. This policy describes exactly what the extension records, what it never records, where that data goes, and how it can be switched off or deleted.
Who controls the data
The organisation that deploys AI-SRO is the controller of everything the extension records. Data is sent only to that organisation’s own AI-SRO backend, under a tenant that belongs to them. The extension does not send observations to any advertising network, analytics provider, data broker or other third party, and observations are never sold.
Observation is off until it is switched on
Passive observation is disabled by default. It stays off until the organisation enables it for its tenant, which is a deliberate administrative act. An individual operator can additionally pause capture at any time, and an administrator can disable it remotely through the policy delivered on the extension’s regular heartbeat.
Whether capture is currently running is always visible in the extension badge and side panel. The extension does not record while presenting itself as idle.
What the extension records
When capture is enabled, on pages that are not excluded, it records:
- Interactions — clicks, typed input, selections, key presses, uploads and scrolls, together with a description of the element acted on (tag, role, accessible name, visible text, test id, CSS path, XPath, position and component metadata) and the page URL.
- Network exchanges made by the page — method, URL, resource type, headers, status and timing, and request and response bodies up to a configured size limit. A larger body is stored as a separate artifact rather than inline.
- Navigation and lifecycle events — page navigated, loaded, dialog opened or handled, download started, frame attached or detached, popup opened.
- Screenshots of the page, rate-limited by policy, when screenshot capture is enabled.
- An accessibility tree of the page — only in the higher-fidelity teaching mode described below, never during passive observation.
Because this is a record of real work in a real browser, it will include business data shown on the pages being worked on, and it may incidentally include personal information if personal browsing happens in the same browser. The exclusions, the pause control, the delete control and the retention window below all exist to limit that.
What the extension never records
- Credential values. The value of a credential field is dropped at the point of capture and never reaches storage. Credential-named fields in request and response bodies are replaced before the body is written. Fields are identified by name, never by inspecting the value.
- Anything on an excluded site. Exclusion works by never registering a content script on that host — an excluded page is not touched at all, rather than captured and then filtered. The default exclusion list covers banking, health, HR and payroll, and webmail content. An operator can add sites to the list themselves; they cannot remove one the administrator has set.
Teaching mode
Separately from passive observation, an operator can deliberately record a specific task to teach it to the system. This mode attaches Chrome’s debugger to the tab, which makes Chrome display its own visible banner for as long as the recording runs, and it additionally captures the page’s accessibility tree and fuller network detail. It is started by the operator, it is visible while it runs, and it is short.
Retention and deletion
Observations are retained for a window configured per organisation, with a default of 30 days, after which they are removed automatically by a storage lifecycle rule.
An operator can open what was captured in the recent past directly in the extension panel and delete it themselves, without going through an administrator. Deletion requests can also be made to the organisation that deployed the extension, as the controller of the data.
Permissions, and why each is needed
- Host access to all sites — work spans many internal systems, and the extension cannot know in advance which ones matter. Excluded hosts are never accessed.
scripting— to register the recorder on pages that are in scope for capture.webNavigation— to record navigation and page lifecycle events.storage— to hold the extension’s own settings, policy and pending batches locally.alarms— to schedule the heartbeat and periodic upload.debugger— used only in teaching mode, for the accessibility tree and fuller network detail. Chrome shows its own banner whenever it is attached.sidePanel— to show capture state and the review and delete controls.
Monitoring, stated plainly
This extension observes staff at work, and it should be treated as monitoring. Where works councils, union agreements or local employment law apply, written agreement should be in place before it is switched on. The per-organisation opt-in exists for that reason and is deliberately not a default.
Contact
For questions about this policy, or to request access to or deletion of recorded data, contact the organisation that deployed AI-SRO to your browser, or write to devansh.j@greyorange.com.
GreyOrange · AI-SRO