Privacy Policy
Last updated: September 2, 2026
1. Scope and Controller
IME Labs LLC ("IME Browser", "we", "us", or "our") is responsible for the Personal Data described in this Privacy Policy. This Policy applies to our website, desktop application, browser extension, cloud services, early-access program, support channels, and related services (collectively, the "Service").
This Policy is a notice about our data practices, not a request for blanket consent. Where consent is required, we will request it separately. If you use the Service through an organization, that organization may separately control information in its workspace and should provide its own privacy notices where required.
2. How the Service Handles Data
The Service combines local browser storage with optional cloud and third-party processing. Ordinary Chromium profile data, such as browsing history, website cookies, and saved website credentials, is generally kept in the browser profile on your device. We do not receive that data merely because you browse a website.
Workspace information used for account access, collaboration, synchronization, workflows, and configuration may be stored by our cloud services. A feature you invoke may also transmit page content, URLs, screenshots, accessibility or document-object model data, prompts, or workflow inputs when that transmission is needed to run an automation, AI, synchronization, or support function.
Removing cloud data does not automatically remove copies stored on your devices, and removing local application data does not automatically delete your account or cloud workspace.
3. Personal Data We Collect
- Account and identity data: name, email address, avatar, password hash, account identifiers, session information, and authentication status.
- Connected-account data: the identity, account identifier, scopes, and access or refresh tokens supplied by an authentication provider such as Google, GitHub, Apple, or a configured OpenID Connect provider.
- Workspace and collaboration data: workspace names, documents, uploaded files or blobs, membership and roles, browser-profile names and settings, tags, notes, device assignments, last-activity information, notifications, and other content you or a teammate submits.
- Connection and secret configuration: proxy server settings and credentials, model-provider settings and API keys, and similar secrets that you choose to save. IME integrates connections you provide; it does not provide proxy IP addresses.
- Workflow and AI data: workflow definitions, schedules, run status, errors, summaries, node results, prompts, instructions, selected page content, screenshots, and model usage information such as provider, model, token counts, cost, and credits.
- Billing data: Stripe customer and subscription identifiers, plan and subscription status, invoice amounts and status, and hosted invoice links. Stripe, not IME, directly processes your payment-card or bank-account details.
- Device, network, and usage data: IP address, user agent, browser and operating-system information, device and application identifiers, application version, locale, time zone, session identifiers, timestamps, feature events, diagnostic data, and, where website analytics is enabled, page URL and referrer.
- Early-access and communications data: email address, requested product, submission and last-seen times, anti-abuse verification data, and the content of support, privacy, legal, or other messages you send us.
We obtain this data from you, your device and use of the Service, people in your workspace, authentication and payment providers, and services you choose to connect.
4. How and Why We Use Personal Data
- Provide authentication, local and cloud workspaces, synchronization, collaboration, workflows, AI features, subscriptions, and support.
- Route requests to providers and connections you select, measure usage, enforce plan limits, and calculate charges or credits.
- Maintain, troubleshoot, secure, and improve the Service and prevent fraud, abuse, unauthorized access, and violations of our Terms of Service.
- Send transactional notices and, where permitted, early-access or product communications that you can opt out of.
- Comply with tax, accounting, legal, and regulatory duties and establish, exercise, or defend legal claims.
Depending on the applicable law and context, our legal bases are performance of a contract, compliance with law, our legitimate interests in operating and securing the Service, or your consent. You may withdraw consent at any time, without affecting processing already performed.
5. AI Features and Connected Services
When you use an AI feature, the information needed for the request may be sent either through an IME-managed AI gateway or directly to a provider using credentials you supply. Depending on your configuration, providers may include OpenAI, Anthropic, Google, Amazon Web Services, Microsoft Azure, DeepSeek, xAI, Groq, or a custom endpoint. The selected provider processes the request under its own terms and privacy policy.
Only submit data that you are authorized to process. Workspace administrators can configure integrations that affect other workspace members. We retain usage and billing metadata for managed AI requests; the content made available to a model depends on the feature you invoke and the context you select.
6. Cookies, Analytics, and Anti-Abuse Tools
Our website and Service may use cookies or similar storage for authentication, security, preferences, and measurement. Where analytics is enabled, analytics providers may receive device, event, page, and referral data. We will provide choices where required by law.
The early-access form uses Cloudflare Turnstile to distinguish people from abusive automated traffic. Cloudflare receives browser and network signals used for that verification, and we may send the requesting IP address when validating a Turnstile token.
7. When We Disclose Personal Data
We disclose Personal Data only as needed for the purposes in this Policy, including to:
- Other members and administrators of a workspace, according to workspace roles and the features used.
- Hosting, storage, content-delivery, email, analytics, security, and customer-support providers that help operate the Service.
- Stripe for payment processing; Cloudflare for early-access infrastructure and anti-abuse verification; authentication providers you choose; and AI, proxy, or custom service endpoints you configure or invoke.
- Authorities, professional advisers, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or address legal claims.
- A buyer, investor, or successor in connection with a merger, financing, reorganization, or sale of all or part of our business, subject to appropriate confidentiality measures.
We do not sell Personal Data or share it for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act.
8. Security
We use administrative, technical, and organizational safeguards designed to protect Personal Data. These include hashing IME account passwords, encryption in transit, access controls, and encryption for certain stored proxy and model-provider secrets. No method of storage or transmission is completely secure. You are responsible for protecting your devices, IME credentials, third-party credentials, and workspace access.
9. Retention and Deletion
We retain each category of Personal Data only for as long as reasonably necessary for the purposes described above. The period depends on whether your account or workspace remains active, contractual and support needs, security and dispute considerations, and applicable tax, accounting, and other legal requirements.
- Account and cloud workspace data: generally retained while the account or workspace is active. Canceling a paid subscription does not delete the account or workspace. Account deletion removes workspaces you solely own, subject to the exceptions below; content in a workspace owned by another person or organization may remain available to that workspace.
- Local data: remains on your device until you delete the relevant profile or application data. Some local workflow and chat history is cleaned according to the retention option configured in the application.
- Billing, usage, and security records: kept for the period needed for billing, tax, accounting, fraud prevention, auditing, dispute resolution, and legal compliance.
- Early-access data: kept until the program and related updates end, you unsubscribe, or you ask us to delete it, unless a limited suppression record is needed to honor an opt-out.
Deleted information may remain temporarily in backups, caches, security records, or pending deletion systems until those systems are rotated. We may retain limited information for longer when required by law or reasonably necessary to protect the Service, users, or legal rights. We may aggregate or de-identify information so that it can no longer reasonably be linked to you and use that information without time limit.
10. Your Privacy Rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a portable copy of your Personal Data; to object to or restrict certain processing; to withdraw consent; and to appeal our response. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
You can change certain account details in the Service. To make another request, email privacy@imebrowser.com. We may need to verify your identity and authority before acting. An authorized agent may submit a request where applicable, but we may require proof of authorization and direct verification with you. We will respond within the time required by applicable law.
You may opt out of marketing messages using the unsubscribe method in the message or by contacting us. You may also have the right to complain to your local data-protection authority.
11. International Data Transfers
We are based in the United States and use providers that may process information in the United States and other countries. Those countries may have different data-protection laws from your country. Where required, we use an approved transfer mechanism or another lawful basis for the transfer.
12. Children
The Service is intended for business and professional users and is not directed to anyone under 18. We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data to us, please contact us so that we can investigate and take appropriate action.
13. Changes to This Policy
We may update this Policy to reflect changes to the Service, law, or our data practices. We will post the updated Policy and revise the date above. If a change materially affects your rights or how we use Personal Data, we will provide additional notice where required.
14. Contact Us
For questions, complaints, or privacy-rights requests, contact:
Email: privacy@imebrowser.com
Address:
IME Labs LLC
30 N Gould St Ste N
Sheridan, WY 82801
USA