Privacy

KiteGhost is a Chrome extension and a hosted bridge at kiteghost.lbframe.com. An agent you connect can drive the Chrome profile already open on your machine. Last updated 20 August 2026. Operator: LB FRAME.

What this product does

You pair a browser with your account. Agents (Cursor, Claude Code, a script) send commands to that browser through our bridge. The extension executes them with Chrome’s debugger API, only on sites your approval settings allow.

Page content is not stored on our servers. It is read in your Chrome and forwarded, while the command runs, to the agent you authorized. That agent is a third party. What it keeps is its policy, not ours.

Account data we hold

/healthz exposes process uptime and how many browsers and agents are connected. No emails, no device ids.

What we do not collect

Chrome debugger permission

The extension requests the debugger permission because that is how Chrome exposes the DevTools Protocol to an extension: attach, snapshot, click, type, screenshot. There is no other MV3 API that drives a real tab this way.

We attach only to tabs the permission engine allowed for that agent. Chrome shows its own infobar while a tab is attached. We do not attach to chrome:// pages, other extensions, or the store. We do not download extra script from the network to run as the debugger; commands come from the paired bridge over the WebSocket you already opened to kiteghost.lbframe.com.

Detach a machine on Devices and that browser cannot be driven until you pair it again.

Network the extension talks to

The store build opens an outbound WebSocket to kiteghost.lbframe.com only. It does not listen on a port. It does not call third-party page-to-markdown APIs. Optional localhost permissions exist for unpacked development against a loopback bridge, and are off unless you grant them.

Who sees page content

The operator of kiteghost.lbframe.com sees connection metadata (that a device or agent is online). Command payloads transit the bridge in memory to reach the extension; they are not written to a page-content log.

The LLM or MCP client you pointed at KiteGhost sees whatever that client requested: snapshots, screenshots, typed text. If you do not want a site in that loop, decline the ask or put the host on the blocklist.

Retention and deletion

Account rows stay until you ask us to delete the account or you stop using the service and we purge unused accounts. Revoke a device or agent at any time; that secret stops working at the next request.

To delete the account or export what we hold, write from the email on the account to the operator of LB FRAME (public releases: github.com/lbframe/kiteghost). We will delete or export within 30 days.

Cookies

The website uses a session cookie after you sign in, so pairing and device management stay on your account. The extension stores pairing credentials and site grants in chrome.storage on the machine, not in a third-party cookie.

Children

KiteGhost is not directed at children under 13.

Changes

Material changes to this policy will be dated on this page. Continued use after that date is acceptance of the new text.