General provisions
This Policy describes how the 2I Chrome extension processes information as part of the 2I corporate SaaS product. Each customer receives an isolated workspace on its own subdomain, such as client1.2i.pro. The customer's employees may connect Chrome to 2I agents to carry out confirmed tasks in permitted tabs.
Data controller
The data controller and product owner is 2I AVTOMATIZATSIYA Limited Liability Company (official Russian name: ООО «2И АВТОМАТИЗАЦИЯ»).
- Russian Taxpayer Identification Number (INN): 6164148656
- Tax Registration Reason Code (KPP): 616401001
- Primary State Registration Number (OGRN): 1266100010263
- Registered address: Apt. 199, 28 Siversa Avenue, Rostov-on-Don, 344011, Russian Federation
Scope
This Policy applies to the extension, device connection process, data exchanged between the extension and a customer workspace on a 2i.pro subdomain, and agent activity in connected tabs. The extension is intended only for employees of corporate customers. Each customer determines which employees may access its workspace and the data within it.
Data we process
Depending on the feature being used, we may process:
- the 2I user and workspace identifiers;
- a one-time connection code valid for 30 days, a device identifier, and a separate device token;
- connection status, extension version, browser version, and device platform information;
- the URL, title, and visible text of a permitted tab;
- the page accessibility tree, including interface element roles and names;
- a screenshot of the visible tab area with temporary markers for available elements;
- agent commands and the results of page actions confirmed by the user;
- messages the user sends to the agent through the 2I interface;
- de-identified technical security events that do not contain page content, screenshots, or messages.
Access covers tabs that an employee explicitly adds to the 2I group and new tabs opened by the agent within a confirmed task. The exact data involved depends on page content and the selected action.
Data we do not intentionally collect
The extension is not designed to collect complete browser history, content from tabs that have not been connected, cookies, website local storage, clipboard contents, data from internal Chrome pages, or data for advertising or profiling. 2I Chrome is not intended to perform banking or payment transactions. Users should not connect tabs containing information unrelated to the agent's task.
Purposes of processing
- connecting an individual device to the customer's isolated workspace;
- reading the interface and carrying out user-confirmed actions in permitted tabs;
- displaying connection status and task results;
- protecting accounts and investigating errors and security events;
- maintaining stable operation of the extension's core functionality.
Legal bases
Processing is performed as necessary to provide the service under the user agreement or the contract with a 2I customer, on the basis of user consent, and to meet obligations imposed by law. An employee connects a device using a one-time code and grants tab access through an action in the extension interface. Agent actions that must be carried out on a page are performed after user confirmation.
Storage and disclosure
Visible page text, the accessibility tree, tab screenshots, and action results are processed only while a task is being performed and are not retained in persistent storage. They are sent to 2I's own locally hosted LLM infrastructure in the Russian Federation. The model does not retain prompts or responses and does not use them for training.
User messages to the agent are retained for 30 days. Encrypted backups are stored in the Russian Federation for the same period. Technical security events are retained for 90 days and do not include page content, tab screenshots, or user messages. No cross-border transfer takes place.
Data is not disclosed to third-party AI model providers. The backup infrastructure provider receives access only to the extent required to store encrypted backups. Data may be disclosed to public authorities only where required by law. 2I does not sell user data.
Security
We use the following safeguards to protect connections and user data:
- data is transmitted only over HTTPS and WSS;
- the one-time connection code expires after 30 days or upon first use;
- each device receives a separate token;
- only a strong adaptive hash of the token is stored on the server; the plaintext token is stored locally in the Chrome profile;
- databases and backups are encrypted;
- customers are isolated using row-level security (RLS) and internal access-control mechanisms;
- agent processes run in an isolated environment;
- access is limited to permitted tabs and tabs opened by the agent;
- tabs and page elements receive temporary random identifiers within a Chrome session;
- the connection can be revoked immediately;
- 2I employees do not have access to customer content;
- administrative access and security events are logged.
The extension does not download or execute remote JavaScript or WebAssembly code. All executable code is included in the published extension package.
User rights
Users have the right to:
- obtain information about how their data is processed;
- correct inaccurate data;
- revoke a device connection;
- remove an individual tab from the managed group;
- delete conversation history;
- request deletion of all data associated with the user and device;
- request restriction of personal-data processing;
- withdraw consent to processing;
- uninstall the extension from Google Chrome.
Users may disconnect through the button in the extension, the 2I integration settings, or Chrome’s extension management page. Requests to delete associated data are fulfilled within three business days.
Limitations
The extension cannot access internal Chrome pages, the Chrome Web Store page, or other addresses that the browser does not permit extensions to control. Actions may not work on pages that use CAPTCHA, additional security checks, or technical interface restrictions.
The agent does not perform banking or payment transactions. The service requests user confirmation before sending a form, message, or email; deleting data; placing an order; or performing another consequential action.
Chrome Web Store compliance
Data is used only for the extension's core functionality: carrying out user-confirmed actions in permitted tabs within a corporate workspace.
2I complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. ↗
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
2I confirms that it:
- does not sell user data or disclose it except in permitted circumstances;
- does not use data for purposes unrelated to the extension's core functionality;
- does not use data for advertising or creditworthiness assessment;
- does not use tab content, screenshots, or messages to train models;
- does not give 2I employees access to user-data content.
Policy changes
We may update this Policy when extension functionality, data-processing practices, or legal requirements change. The current version is always published on this page. Users will be notified before material changes to data-processing practices take effect.
Contact details
2I AVTOMATIZATSIYA LLC. INN 6164148656 · OGRN 1266100010263 · KPP 616401001.
Apt. 199, 28 Siversa Avenue, Rostov-on-Don, 344011, Russian Federation.
support@2i.pro ↗
Please use “2I Chrome Extension Privacy” as the subject of your message.