Privacy version 2026-01
Privacy Policy
Boostro reads only the page content you ask it to analyze. It does not collect passwords, OTPs, payment information or complete browsing history.
The Chrome extension runs only after you click it and grant access to the current site. It does not continuously monitor browsing.
Information we process
We process account details, institution relationships, saved notices, reminders, usage records and the education content you explicitly submit for analysis. For security, IP addresses are stored only as one-way hashes where required.
Information excluded from extraction
Password and OTP inputs, hidden authentication tokens, card/CVV and bank data, browser cookies, unrelated local storage, private messages and browsing history are excluded.
AI processing
Sanitized content may be sent server-side to the AI provider selected by Boostro administrators. Provider keys remain on the server. Webpage text is treated as untrusted and cannot override Boostro's analysis instructions.
Retention and control
Temporary PDFs are deleted after analysis unless you explicitly save a document. You can delete saved notices, revoke extension devices, request account deletion and export basic account data from the data controls page.
Security
Passwords use salted PBKDF2 hashing. Sensitive requests use access controls, audit logs, rate limits and encrypted transport. No online system is risk-free, so report suspected issues promptly.
Contact
Use the contact page for privacy questions or a deletion request.