Privacy
KiteGhost is a Chrome extension and a hosted bridge at kiteghost.lbframe.com. An agent you connect can drive the Chrome profile already open on your machine. Last updated 20 August 2026. Operator: LB FRAME.
What this product does
You pair a browser with your account. Agents (Cursor, Claude Code, a script) send commands to that browser through our bridge. The extension executes them with Chrome’s debugger API, only on sites your approval settings allow.
Page content is not stored on our servers. It is read in your Chrome and forwarded, while the command runs, to the agent you authorized. That agent is a third party. What it keeps is its policy, not ours.
Account data we hold
- Email, password hash, and optional display name (better-auth).
- OAuth clients for each paired browser and each agent (ids, hashed secrets, label, site policy).
- Account-level site allowlist and blocklist.
- Sessions and short-lived access tokens. Tokens expire; revoking a device or agent cuts access immediately.
/healthz exposes process uptime and how many browsers and agents
are connected. No emails, no device ids.
What we do not collect
- Cookies, passwords, or form values from sites you visit — except what an agent reads after you allowed that host, and then only in that agent’s session.
- A history of pages for our own analytics.
- Payment data. There is no billing in this product today.
Chrome debugger permission
The extension requests the debugger permission because that is
how Chrome exposes the DevTools Protocol to an extension: attach, snapshot,
click, type, screenshot. There is no other MV3 API that drives a real tab
this way.
We attach only to tabs the permission engine allowed for that agent. Chrome
shows its own infobar while a tab is attached. We do not attach to
chrome:// pages, other extensions, or the store. We do not
download extra script from the network to run as the debugger; commands come
from the paired bridge over the WebSocket you already opened to
kiteghost.lbframe.com.
Detach a machine on Devices and that browser cannot be driven until you pair it again.
Network the extension talks to
The store build opens an outbound WebSocket to kiteghost.lbframe.com only. It does not listen on a port. It does not call third-party page-to-markdown APIs. Optional localhost permissions exist for unpacked development against a loopback bridge, and are off unless you grant them.
Who sees page content
The operator of kiteghost.lbframe.com sees connection metadata (that a device or agent is online). Command payloads transit the bridge in memory to reach the extension; they are not written to a page-content log.
The LLM or MCP client you pointed at KiteGhost sees whatever that client requested: snapshots, screenshots, typed text. If you do not want a site in that loop, decline the ask or put the host on the blocklist.
Retention and deletion
Account rows stay until you ask us to delete the account or you stop using the service and we purge unused accounts. Revoke a device or agent at any time; that secret stops working at the next request.
To delete the account or export what we hold, write from the email on the account to the operator of LB FRAME (public releases: github.com/lbframe/kiteghost). We will delete or export within 30 days.
Cookies
The website uses a session cookie after you sign in, so pairing and device
management stay on your account. The extension stores pairing credentials
and site grants in chrome.storage on the machine, not in a
third-party cookie.
Children
KiteGhost is not directed at children under 13.
Changes
Material changes to this policy will be dated on this page. Continued use after that date is acceptance of the new text.