Privacy Policy
This policy explains what data Twin Browser processes when you use our service, why, and the choices you have.
Last updated · June 27, 2026
1. Who we are
Twin Browser (“Twin Browser”, “we”, “us”) provides an authenticated browser-execution platform for AI agents. This policy covers our marketing site, dashboard, and API. For data-processing questions or a Data Processing Addendum (DPA), contact legal@twin-browser.com.
2. Data we collect
- Account data: name, email, and authentication identifiers you provide at signup.
- Billing data: processed by our payment provider (Stripe); we store a customer reference and plan, not full card details.
- Run data: the targets, goals, success conditions, compiled skills, and run history generated when you use the engine.
- Credentials you vault: secrets you store for automated logins are encrypted at rest (AES-256-GCM) and filled only at run time.
- Usage & diagnostics: API request metadata, credit ledger entries, and audit events used to operate and secure the service.
3. How we use data
- To provide, maintain, and secure the service and your account.
- To meter usage and process billing.
- To enforce our terms and acceptable-use policy.
- To debug, monitor reliability, and improve the product.
- To communicate with you about your account and service changes.
4. Sharing & subprocessors
We do not sell personal data. We share data with infrastructure and service subprocessors that help us run the platform — including hosting, database, payment, and (where you enable them) proxy and CAPTCHA providers — under contractual data-protection obligations. A current subprocessor list is available on request.
5. The shared skill corpus
When a task succeeds, a sanitized structural skeleton of the skill may join a cross-tenant library to improve cache performance. Your typed values, credentials, run results, page content, and exact compiled path are never shared. See the security page for the precise boundary.
6. Retention
We retain account and run data for as long as your account is active and as needed to comply with legal obligations, resolve disputes, and enforce agreements. You can request deletion of your account and associated data as described below.
7. Security
We enforce database-level tenant isolation (Row-Level Security), hashed API keys, encrypted credential storage, and audit logging. No system is perfectly secure, but security is built into the architecture rather than bolted on. See our security overview.
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact privacy@twin-browser.com.
9. International transfers
We may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
10. Changes
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify you.