# Privacy and security

The full, binding text is the [privacy policy](/privacy/). This page explains it in practice.

## Your data

- **Recordings** ([what they contain](/docs/recording/#what-a-recording-keeps)): nothing leaves your
  browser until you press **Keep**. Kept recordings, your requests and your skins are stored in your
  project on the Skins service, which runs in Germany.
- **The AI:** bryo runs on Google's Gemini models, in the EU, and reads a project's recordings to
  work on it. If you add your own model in the web app's settings, your chats go to that model's
  provider instead.
- **The extension** sends no analytics.
- **Deleting:** a project and its skin, see [Managing your skins](/docs/managing/#removing-a-skin).
  Your account: [write to us](/docs/troubleshooting/#still-stuck).

## Sharing

A project is yours until you share it: from the web app's **Share** dialog, by email or with a share
link, or over MCP. Agents you connect over [MCP](/docs/mcp/) act as you, with your access.

| | Owner | `build` | `use` |
|---|---|---|---|
| Open the project in Studio | ✓ | ✓ | ✓ |
| Work on the skin with bryo, publish | ✓ | ✓ | |
| Get the skin in their extension | ✓ | ✓ | |
| Share the project | ✓ | ✓ | |
| Delete the project | ✓ | | |

Nobody can grant more access than they have. **Remove** a person or **Revoke** a link in the Share
dialog, and everyone who got access only through them loses it too.

## Extension permissions

| Permission | Used for |
|---|---|
| All websites (`<all_urls>`) | Applying your skins where they belong; while recording, downloading the page's images, fonts and stylesheets with your cookies, as the page does |
| User scripts (`userScripts`) | Running each skin's trigger and JavaScript. The **Allow User Scripts** switch. |
| Scripting (`scripting`) | Adding a skin's CSS and HTML, and the recorder |
| Debugger (`debugger`) | Recording the page's requests: only the tab you record, only while recording |
| Web navigation (`webNavigation`) | Applying skins as pages load or navigate |
| Tabs (`tabs`) | Showing the current page's skins; reloading tabs when a skin is switched |
| Identity (`identity`) | The sign-in window |
| Storage (`storage`, `unlimitedStorage`) | Your skins, settings, and a recording until you keep it |
| Side panel (`sidePanel`) | The Skins side panel |

The extension also adds a small script to every page, which lets a skin's JavaScript reach its own
project.