Effective date: 2 August 2026 · Last updated: 2 August 2026
The AgentValet browser extension exists to help you create and connect a scoped API credential for an AI agent. Every permission it requests, and everything described below, serves that one purpose. The extension helps you create a new credential; it does not capture your existing logins.
When you check a box next to a product in the popup, that selection is held in the popup's memory for as long as the popup stays open, so it drives what "Detect automatically" and "Connect" act on. It is not written to disk: closing the popup discards it, and reopening the popup starts with nothing ticked. It never leaves your browser on its own.
This button is off by default and requires its own permission grant, requested at the moment you press it, scoped only to the products you already ticked. Pressing it checks whether a sign-in cookie exists for each ticked product's own site. The extension reads only whether the cookie is present, never its value. The result is held in the same popup-session memory as your ticks, shown to you, and discarded when the popup closes. It is not sent anywhere.
When a product's token page shows you a newly created token, the extension reads that one value and sends it once to your AgentValet account over an encrypted connection, so the connection can be set up. The extension does not keep a copy: it is not written to browser storage, not logged, and not retained by the extension after that single transmission.
The extension caches this published catalog locally in the browser so the popup has something to show before it can reach the network. It describes AgentValet's product support, not you, and contains no information about which products you use or have ticked.
The platform ids you tick and the signed-in booleans stay only in the popup's in-memory state while it is open. They are not written to disk, not written to persistent browser storage, and not transmitted anywhere. Closing the popup discards them.
Your AgentValet sign-in uses your account's own sign-in flow. The extension never sees your password and holds only a short-lived, in-memory session token that is cleared when the browser closes.
The credential you create is sent once, to your AgentValet account, over an encrypted connection, at the moment you create it. It is not sent to, or processed by, anyone else.
Before the "Detect automatically" button can be pressed, the popup shows this text, which describes the same behaviour as above:
Detect automatically checks whether a sign-in cookie exists for the products you ticked. It never reads the contents of any cookie, and it never looks at products you did not tick.
Questions about this disclosure: [email protected]