Privacy.
One policy for all three co10x extensions: Agent P2P, Jira Dashboard for Edge, and Trace.
We operate no servers. We collect nothing, receive nothing, and store nothing about you or your work. Everything a tool saves stays in your own browser; the only requests it makes go to servers you choose, directly.
Information we collect
None. We operate no backend that receives your data. There are no accounts, no analytics, no telemetry, no tracking pixels, no ad identifiers, and no cookies set by these extensions.
Stored on your device
Each extension keeps its settings, the server URLs and any keys you enter, and the content it produces in your browser's own storage. It stays on your device until you delete it or uninstall. Only Jira Dashboard uses synced storage: for configuration only, never credentials.
Credentials
Any token, key, or password you enter is stored locally and sent only to the host it belongs to, to authenticate you. Never sent to us, never to third parties, never written to logs.
Network requests
Requests go only to destinations you configure, only when you act, and directly from your browser: no proxy or relay we run. Once you point a tool at a third-party service, that provider’s policy governs the data you send there.
Permissions & host access
No blanket web access. Host permission is requested at runtime, one origin at a time, when you save a server URL, and you can decline. No page content is read for our purposes, and no remote code is ever fetched or executed.
AI features
Optional, and off or on-device by default. Text is sent to a model only after you configure an endpoint and grant permission. Choose a local endpoint and nothing leaves your machine.
Children
These are developer and workplace tools, not directed at children, and they collect no information from anyone.
Agent P2P
Stores your display name, connection/room settings, and optional AI-agent config locally. Chat travels directly to peers over an encrypted WebRTC channel; an optional signaling server (yours) sees only handshake metadata; an optional AI agent runs on the configuring peer’s machine and shows a banner to everyone in the room. QR / code mode grants no host permission.
Jira Dashboard for Edge
Configuration (URLs, JQL, panel defaults, theme, AI provider) syncs with your browser profile: never credentials. Tokens, saved AI memory, and a ~150 MB query cache stay device-local. Muni and ticket analysis run on-device by default via the browser’s built-in AI; pointing them at an OpenAI-compatible endpoint sends ticket text there, with a warning first.
Trace
Recordings, annotations, transcripts, and logs live in IndexedDB / OPFS on your device. Network access only on your action: a one-time opt-in Whisper model download from huggingface.co, an AI Check to an endpoint you configure, or attaching a recording to your Jira. Never logs typed text, passwords, payment fields, or URL query strings. Keeps recordings until you delete them, or auto-deletes after 7 / 30 / 90 days.