Privacy Policy
Laspoh browser extension & service · effective 26 July 2026 · contact: info@samstar.org
The short version. Laspoh works missions you explicitly start, in your own browser session. It reads pages only while working your mission, thinks on Laspoh's managed model by default (bring-your-own key available on Pro), keeps your working knowledge in your browser's local storage, and never sells data or shows ads. Delete your data any time.
1. What Laspoh does
You state an objective ("apply to these jobs", "research X and report back"). Laspoh plans the mission, operates the pages in your browser, verifies the result independently, and hands back a receipt with the evidence. Everything it does is in service of the mission you started — it has a single purpose and does not run in the background on pages you haven't delegated.
2. Data the extension processes
- Page content of the working tab. While a mission runs, Laspoh observes the mission's tab (text, structure, and a screenshot per step) to decide the next action and to verify results. Pages you are not delegating are not read.
- Your working knowledge. Facts you give it (name, experience, answers for forms) are stored in the extension's local browser storage on your machine. They are used to fill forms you ask it to fill.
- Mission records. Objectives, plans, notes, evidence and verification verdicts are stored so missions can resume and results can be shown with their receipts.
- Your documents — only if you turn this on. Laspoh can answer form questions from your own files instead of asking you for details you have already written down. It is off until you press “Choose folder” and pick one folder in your browser’s own file dialog — there is nothing to install. Then: the folder listing reads file names only; the text of a file is read and parsed on your machine, by fixed pattern-matching code — no AI model, no server, no network. Your files are never uploaded. Access is enforced by the browser itself: Laspoh holds a handle to that one folder and cannot address anything outside it, and it additionally skips hidden files and credential, key and browser-profile locations inside it. Nothing it finds is saved until you approve it, item by item. Remove the folder any time from the panel, or revoke it in your browser’s site settings.
Sensitive values are sealed. Passport, national-insurance/SSN, and bank/card numbers — however Laspoh learned them — are held encrypted on your device and treated differently from everything else: they are excluded from what is sent to the model, are never stored on Laspoh's servers, and are never filled in automatically. They leave only when Laspoh asks a question one of them answers and you tap to release that single value for that single answer.
3. Where data goes
- The Laspoh API. Mission observations are sent to the Laspoh service to plan and verify steps, and mission state is persisted there so work can resume.
- The model. By default Laspoh thinks on Google's Gemini API under Laspoh's own key — mission observations are forwarded there, under Google's API terms, solely to plan and verify your mission. On the Pro tier you may instead connect your own provider and key (e.g. Google, OpenAI); observations then go to the provider you chose, under your key and their terms.
- Failure diagnostics (anonymized). When a mission fails, the extension sends Laspoh a thin technical report — action types, outcomes, timing buckets, and the site's hostname — so defects get found and fixed. It is built from an allow-list that structurally cannot include page content, form values, element labels, your objective text, or your working knowledge. On by default; turn it off any time in Setup → “Share failure diagnostics”.
- Local failure records. When a mission fails, the extension keeps a redacted technical record on your device so the cause can be found and fixed properly. It is a structured timeline of what Laspoh did — no screenshots and no images of any kind — and passwords, cookies, tokens, API keys, request headers and network bodies are excluded by construction, then re-checked by a secret scan before anything is written. It is never uploaded: sending one to us is always a deliberate act by you. On by default; turn it off any time in Setup → “Record failures on this device”.
- No one else. No sale of personal data, no advertising, no third-party analytics in the extension.
4. What we never do
- Sell or rent your data.
- Act without a mission you started. Payments and publishing always wait for your explicit approval in the panel — Autopilot never covers them.
- Bypass sites' authentication, CAPTCHAs, or payment gates.
- Bake your API key into the product — keys are stored server-side for your account and used only to call the provider you chose.
5. Permissions, honestly
- Access to sites — Laspoh must be able to work whatever site your mission names; it only acts on the mission's tab.
- Tabs & scripting — to open the working tab, observe it, and dispatch clicks/typing for the mission.
- Storage — your working knowledge, your Setup choices and mission records.
- Downloads — to save the results you asked for (reports, CSVs).
- Debugger (optional, on request) — only if a page provably ignores normal input, Chrome asks you first, and the permission is dropped as soon as the step completes.
- Folder access (optional, on request) — only if you turn on Documents. Your browser asks you to pick one folder and enforces the boundary itself; Laspoh never receives a general filesystem permission. Remove it from the panel, or revoke it in your browser’s site settings.
6. Retention & deletion
Mission records persist so you can review results with their evidence. You can delete missions, and your working knowledge with “Forget my profile”, from the panel at any time; uninstalling the extension removes all local data. To have server-side records deleted, email info@samstar.org and we will remove them.
7. Security
Provider keys are held server-side, never in the shipped extension bundle. The service runs on managed cloud infrastructure with secrets isolated from source and images. Forensic repair packets (a debugging tool) are redacted and stay on your machine — never auto-uploaded.
8. Changes
If this policy changes materially, the effective date above changes and the current version is always at this URL.