Jev × WebMCP Privacy Policy

Effective September 19, 2026

Jev × WebMCP is a Chrome extension: a side panel where you type what you want, and it picks one of the WebMCP tools the current website offers and fills in its arguments. This policy explains what the extension stores, what leaves your browser, and the choices you have. The short version: we don't run a server and we never receive your data. The extension talks to one service, TypeSafe, using your own API key, and only on sites you have turned it on for. There are no ads, no analytics and no trackers.

Data stored in your browser

The extension keeps three settings in Chrome's local extension storage (chrome.storage.local):

  • Your TypeSafe API key, which you paste into the panel's settings.
  • Your "Run read-only tools while I type" preference (on or off).
  • The name of the model the extension asks for.

Nothing else is stored. There is no browsing history, no page content, no record of what you typed and no record of tool results. These settings are not synced to your Google account, so they stay in this browser profile.

Data sent to TypeSafe

To work out which tool you mean, the extension sends a request to TypeSafe's API (api.typesafe.ai) as you type. This only happens on a site you have enabled, and only when that site offers WebMCP tools. Each request contains:

  • What you typed into the panel's text box.
  • The site's tool definitions: the names, descriptions and input schemas of the WebMCP tools the page has registered. When a site's tools first load, these definitions are also sent once on their own, to check whether any description looks like it is trying to manipulate an AI agent.
  • The hostname and title of the page you are on, as context for the request.
  • Your API key, as the request's authorization header. It is also sent once when you save it, to check that it works.

These requests go straight from your browser to TypeSafe, under your own TypeSafe account. They do not pass through any server of ours, and we never see them. How TypeSafe handles that data is covered by TypeSafe's privacy policy.

If you click "Open in playground", the same request (what you typed, the page's hostname and title, and the questions built from the tool definitions) is opened in TypeSafe's playground in a new tab. That only happens when you click it.

Data that never leaves your browser

  • Tool results. When a tool runs, its result is shown to you in the panel and goes nowhere else.
  • Page content. The extension does not read the text, forms, cookies or storage of the pages you visit. It only asks the page which WebMCP tools it offers, and runs the tool you choose.
  • Your other tabs. The extension looks at the address and title of the active tab only, to know which site the panel is pointed at and to ask you for access to that one site. It does not list your other tabs or keep a record of the sites you visit.

Data we don't collect

  • We don't run a server, so we receive nothing from the extension.
  • No advertising, analytics, telemetry or crash reporting.
  • No sale of data, and no sharing of data for anyone's own use.
  • No location data.

Site access

The extension has no access to any website when you install it. When you open the panel on a site and press "Enable", Chrome asks you to grant access to that one site. The access is used only to list that site's WebMCP tools and to run the ones you choose. Tools that change something only run when you press Enter or click them, and tools a site marks as consequential ask you to confirm first.

Your choices

  • Remove a site's access at any time from chrome://extensions, under the extension's Details, in Site access.
  • Stop tools running as you type by turning off "Run read-only tools while I type" in the panel's settings.
  • Replace your API key by pasting a new one in the panel's settings. You can revoke a key from your TypeSafe account.
  • Delete everything the extension stored by removing the extension from Chrome. That erases its local storage, including your API key.

Limited use

The extension's use of information received from Chrome's APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the extension's single purpose, described above.

Children

Jev × WebMCP is a developer tool. It is not directed at children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

If this policy changes, the updated version will be posted at this page with a new effective date.

Contact

Questions or requests? Email sarah.drasner@gmail.com.