CHROME EXTENSION PRIVACY POLICY

NewMax 浏览器桥接隐私政策

本政策说明 NewMax Browser Bridge Chrome 扩展如何处理用户明确选择交由 NewMax 操作的浏览器数据。

生效及最后更新:2026 年 8 月 11 日

Read in English
01

适用范围与运营主体

本政策仅适用于 NewMax 浏览器桥接(NewMax Browser Bridge,以下简称“扩展”)。扩展是 NewMax 桌面客户端的可选配套组件,不能独立运行。NewMax 桌面客户端和网站的其他数据处理活动适用NewMax 隐私政策

扩展由北京红玖智能科技有限责任公司运营。英文译名为 Beijing Hongjiu Intelligent Technology Co., Ltd.,英文译名仅供识别,法律主体以中文登记名称为准。

02

扩展的单一用途与启动条件

扩展的单一用途,是在用户明确请求使用已配对 Chrome 完成浏览器任务时,将用户选择的 Chrome 标签页连接到本机 NewMax 桌面客户端,使 NewMax 能执行页面读取、导航、点击、输入、滚动、上传、下载和截图等用户要求的操作。

浏览器控制只有在用户完成本机配对、主动启用扩展,并明确要求某项任务使用已配对 Chrome 后才会开始。普通网页任务默认使用 NewMax 内置浏览器,不会静默切换到 Chrome。

03

扩展可能处理的数据

为完成用户明确请求的浏览器任务,扩展可能处理以下数据。具体范围取决于用户选择的标签页、网页内容和任务要求:

  • 受控或候选标签页的网址与导航状态,包括页面 URL、标题、标签页标识和窗口状态;
  • 理解或操作页面所需的网页内容与资源,包括页面文字、结构、可访问性信息、截图和页面返回结果;
  • 完成任务所需的用户活动,例如点击、输入、滚动、上传和下载;
  • 登录页面中可见且任务确有需要的信息,可能包括账户资料、表单数据、身份验证信息或会话信息;
  • 在消息、邮箱或协作页面中完成用户请求时,页面中可见的个人通信;
  • 通过 Chrome DevTools Protocol 产生的浏览器控制事件、命令参数、执行结果和错误信息。

扩展不会为了建立用户画像、广告定向或与任务无关的分析而持续收集浏览历史。仅当网页浏览活动是商店页面和扩展界面明确说明的浏览器控制功能所必需时,才会在当前任务中处理。

04

本地保存的配对设置

扩展使用 chrome.storage.local 在当前 Chrome 用户的本地扩展存储中保存:启用/停用状态、本机 WebSocket 连接地址和配对令牌。这些设置不会通过 Chrome Sync 同步。

配对地址限定为 127.0.0.1 本机回环地址。配对令牌是 NewMax 在本机随机生成的凭证,只用于验证连接到本机 NewMax 的扩展。请勿把配对令牌发送给他人或粘贴到网页中。

05

数据如何使用与传输

扩展只通过本机回环接口上的 WebSocket 与同一台计算机中的 NewMax 桌面客户端通信。扩展处理的数据不直接发送到 NewMax 运营的服务器、广告网络或数据经纪商;扩展不会把浏览历史、网页内容、配对信息或浏览器控制结果直接发送到这些远程服务。

NewMax 桌面客户端使用浏览器任务数据执行用户请求。根据任务内容以及用户选择或配置的 AI 模型,NewMax 桌面客户端可能把完成任务所必需的页面内容发送给用户选择的 AI 服务商。该传输由 NewMax 桌面客户端发起,不由扩展直接发起,并受用户的 NewMax 配置、相关服务商条款和隐私政策约束。

扩展不加载或执行远程托管代码。所有可执行 JavaScript 均包含在提交至 Chrome Web Store 的扩展包中。

06

共享、出售与禁止用途

我们不会出售扩展处理的数据,也不会将其用于:

  • 个性化广告、再营销、兴趣广告或广告画像;
  • 向广告平台、数据经纪商或其他信息转售商提供数据;
  • 信用评估、贷款资格、保险定价或其他与扩展单一用途无关的决定;
  • 任何与用户明确请求的浏览器任务无关的目的。

只有在完成用户请求的单一用途、遵守适用法律、保护用户和服务免受恶意软件/欺诈/滥用,或在取得用户明确事先同意后完成合并、收购或资产转让时,才可能进行必要的数据转移。

我们不会允许人工读取扩展处理的用户数据,除非用户明确同意为支持目的读取特定数据、为调查安全事件所必需、为遵守法律所必需,或数据已经聚合和匿名化并仅用于合法的内部运营。

07

保存期限与用户控制

扩展不会在 NewMax 服务器上维护受控页面或浏览历史。配对设置保留在 Chrome 本地扩展存储中,直到用户修改设置、重置配对或卸载扩展。禁用扩展会停止新的浏览器控制;重置配对会立即使旧令牌失效;卸载扩展会删除其本地扩展存储。

NewMax 桌面客户端可能根据用户的本地设置保存任务或对话信息,用户可在 NewMax 中管理或删除这些信息。用户选择的 AI 服务商可能采用自己的保存规则,详情请查阅相应服务商的隐私政策。

08

访问、更正与删除请求

用户可以在扩展设置中停用连接,在 NewMax 中重置配对令牌,在 Chrome 中卸载扩展,并在 NewMax 中管理或删除本地任务和对话数据。

如需提出访问、更正、限制处理、撤回同意或删除请求,请发送邮件至yangyi@newmax.ai,并说明请求涉及 NewMax 浏览器桥接。为防止未经授权的删除或披露,我们可能需要验证请求人与相关账户或数据的关系,并将依照适用法律处理请求。

09

安全措施

本地桥接服务只监听本机回环接口,并要求随机配对令牌。NewMax 会校验 Chrome 扩展来源、扩展版本和协议版本后才接受控制连接。扩展只申请当前功能所需的 debugger、tabs 和 storage 权限,不申请网站 Host permissions。

标签页被控制时,Chrome 会显示调试提示条。任务结束后,扩展会释放用户已有标签页的调试连接而不会关闭页面;只有任务自身创建的标签页才可能在清理时关闭。

10

Chrome Web Store Limited Use

对通过 Chrome API 获得的信息,我们遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。相关信息仅用于提供或改进本政策所述、由用户明确请求的浏览器控制功能;除政策允许的必要情形外,不会转移、出售、用于广告、信用评估或允许人工读取。

官方政策可参阅Chrome Web Store Limited Use

11

未成年人

扩展不是面向未成年人设计的产品。我们不会故意为了扩展单一用途以外的目的收集未成年人的个人信息。如发现扩展相关数据被不当处理,请通过本政策的联系方式通知我们。

12

政策更新与联系我们

当扩展功能、数据处理方式或法律要求发生变化时,我们可能更新本政策,并在本页面标注新的生效日期。重大变化将按适用要求在生效前通过扩展界面、商店页面或 NewMax 产品内作出提示。

运营主体:北京红玖智能科技有限责任公司
隐私联系与请求邮箱:yangyi@newmax.ai

ENGLISH VERSION

NewMax Browser Bridge Privacy Policy

Effective and last updated: August 11, 2026

01

Scope and operator

This policy applies only to NewMax Browser Bridge (the “Extension”), an optional companion to the NewMax desktop app. The Extension does not operate independently. Other processing by the NewMax desktop app and website is governed by the general NewMax Privacy Policy.

The Extension is operated by 北京红玖智能科技有限责任公司 (Beijing Hongjiu Intelligent Technology Co., Ltd.; the English name is provided for reference, and the registered Chinese name controls).

02

Single purpose and activation

The Extension’s single purpose is to connect user-selected Chrome tabs to the NewMax desktop app on the same computer so NewMax can perform browser actions explicitly requested by the user, such as inspection, navigation, clicking, typing, scrolling, uploads, downloads, and screenshots.

Browser control starts only after the user pairs locally, enables the Extension, and explicitly requests a task using the paired Chrome browser. NewMax does not silently switch ordinary browser tasks to Chrome.

03

Data the Extension may handle

Depending on the selected tab and requested task, the Extension may handle:

  • URLs, titles, identifiers, window state, and navigation state of eligible or controlled tabs;
  • website content and resources needed to understand or operate a page, including text, structure, accessibility information, screenshots, and page results;
  • user activity needed for the task, including clicks, typing, scrolling, uploads, and downloads;
  • information visible in signed-in pages when required for the task, which may include account details, form data, authentication or session information;
  • personal communications visible on messaging, email, or collaboration pages when required by the user’s request;
  • browser-control commands, parameters, events, results, and errors produced through the Chrome DevTools Protocol.

The Extension does not continuously collect browsing history for profiling, advertising, or unrelated analytics. Browsing activity is handled only to the extent required for the user-facing browser-control feature disclosed in the Extension interface and Chrome Web Store listing.

04

Local pairing settings

The Extension stores the enabled state, local WebSocket address, and pairing token in chrome.storage.local for the current Chrome profile. These settings are not synchronized through Chrome Sync.

The connection address is restricted to the 127.0.0.1 loopback interface. NewMax generates a random pairing token on the local computer to authenticate the Extension. Users should not share the token or paste it into websites.

05

Use and transfer

The Extension communicates only with the NewMax desktop app on the same computer through a loopback WebSocket. The Extension does not directly send browsing history, page content, pairing information, or browser-control results to NewMax-operated servers, advertising networks, or data brokers.

The NewMax desktop app uses browser-task data to perform the user’s request. Depending on the task and the AI model selected or configured by the user, the desktop app may send task-relevant page content to the user-selected AI provider. That transfer is made by the desktop app, not directly by the Extension, and is governed by the user’s NewMax configuration and the applicable provider terms and privacy policy.

The Extension does not load or execute remotely hosted code. All executable JavaScript is included in the package submitted to the Chrome Web Store.

06

Sharing and prohibited uses

We do not sell data handled by the Extension. We do not use or transfer it for:

  • personalized, retargeted, interest-based, or behavioral advertising;
  • data brokers, advertising platforms, or other information resellers;
  • creditworthiness, lending, insurance pricing, or unrelated decision-making;
  • any purpose unrelated to the user-requested browser task.

We transfer data only when necessary to provide or improve the Extension’s single purpose, comply with applicable law, protect users and the service from malware, fraud, or abuse, or complete a merger, acquisition, or asset sale after obtaining explicit prior consent where required.

We do not allow humans to read user data unless we obtain the user’s explicit consent to read specific data for support, access is necessary for security or legal compliance, or the data is aggregated and anonymized and used only for lawful internal operations.

07

Retention and user controls

The Extension does not maintain a server-side history of controlled pages. Pairing settings remain in local extension storage until the user changes them, resets pairing, or uninstalls the Extension. Disabling stops new browser control, resetting pairing invalidates the previous token, and uninstalling removes the Extension’s local storage.

The NewMax desktop app may retain task or conversation data locally according to the user’s settings. Users can manage or delete that information in NewMax. A user-selected AI provider may apply its own retention policy.

08

Access, correction, and deletion

Users can disable the connection in Extension settings, reset the pairing token in NewMax, uninstall the Extension in Chrome, and manage or delete local task and conversation data in NewMax.

To submit an access, correction, restriction, consent-withdrawal, or deletion request, emailyangyi@newmax.aiand identify the request as relating to NewMax Browser Bridge. We may verify the requester’s relationship to the relevant account or data before acting and will process the request under applicable law.

09

Security

The local bridge listens only on the loopback interface and requires a random pairing token. NewMax validates the Chrome extension origin, Extension version, and protocol version before accepting control traffic. The Extension requests only the debugger, tabs, and storage permissions required for its current functionality and requests no website host permissions.

Chrome displays its debugger banner while a tab is controlled. Existing user tabs are released rather than closed when a task ends; only tabs created by the task may be closed during cleanup.

10

Chrome Web Store Limited Use

Our use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use such information only to provide or improve the user-requested browser-control feature described in this policy. Except where the policy permits, we do not transfer or sell the information, use it for advertising or credit purposes, or allow humans to read it.

11

Children

The Extension is not designed for children. We do not knowingly collect children’s personal information for purposes unrelated to the Extension’s single purpose. Please contact us if you believe Extension-related data has been handled improperly.

12

Changes and contact

We may update this policy when the Extension’s functionality, data practices, or legal requirements change. We will post the new effective date on this page and provide any additional notice required for material changes.

Operator: 北京红玖智能科技有限责任公司 (Beijing Hongjiu Intelligent Technology Co., Ltd.)
Privacy contact and requests: yangyi@newmax.ai