Chrome Web Store Compliance

VisFlow Compliance & Support Center

This page explains the VisFlow browser extension’s single purpose, required permissions, data-handling scope, user controls, and review testing path for Chrome Web Store reviewers, users, and legal review.

Single purpose Record, replay, and AI-assisted execution of browser workflows
User initiated Page data is processed only when the user initiates a feature
Limited use Data is used only to provide or improve user-facing features
Support contact Privacy, security, and review support channels are available
OFFICIAL PURPOSE STATEMENT

Single-purpose statement

VisFlow’s single purpose is to help users record, replay, and debug browser automation workflows they initiate. With user authorization, the steps, screenshots, DOM locator data, task results, and model configuration required for those workflows may be used to save, reproduce, execute, and troubleshoot them.

FUNCTIONAL SCOPE

Feature scope and boundaries

Every capability below supports recording, replaying, and debugging browser automation workflows or AI-assisted execution initiated by the user.

Record user actions

After the user starts recording, VisFlow captures browser actions such as clicks, text entry, scrolling, keyboard input, waits, and opening links, and creates viewable step data.

VisFlow does not continuously record browser activity when the user has not started the relevant feature.

Replay and debug workflows

After importing or selecting steps, users can automatically replay them, step through them, pause, stop, reset, inspect logs, and highlight elements from the side panel.

Replay is bound to the page selected by the user and is not used to bypass website access controls.

Generate actions with AI assistance

After the user explicitly starts AI execution, VisFlow uses the current-page screenshot, URL, window dimensions, and user instruction to generate structured action proposals or execution steps.

Users should review AI execution results for the relevant context. VisFlow does not replace user judgment for final submission actions.

Manage tasks and configuration

After the user authorizes or saves an operation, VisFlow synchronizes task steps, screenshots, DOM summaries, processing results, user model configuration, and issue feedback.

User data is not sold or used for advertising, profiling, credit assessment, or data brokerage.
Illustration of VisFlow enterprise workflow automation
CONTROL MODEL

Controlled execution and risk safeguards

VisFlow limits execution to pages selected by the user and permissions already held by the user’s account. User initiation, target-tab binding, sensitive-field protection, logs, and human takeover reduce the risk of unintended or out-of-scope actions.

User initiated

Recording, replay, screenshots, AI execution, saved records, and model configuration are initiated by the user in the extension interface.

Target-tab binding

AI execution and replay remain bound to the target tab selected at launch, reducing the risk of operating on another page.

Sensitive-field protection

The recording pipeline masks high-risk fields such as passwords, verification codes, API keys, tokens, and card security codes.

Human takeover

Users can pause, stop, inspect logs, or take over during execution. Critical actions should proceed only after user review.

PERMISSIONS MATRIX

Why each permission is required

Extension permissions are used only for user-initiated recording, replay, screenshots, AI execution, sign-in, task saving, export, and feedback.

Permission Purpose When it is used

storage

Stores recording state, replay state, sign-in sessions, step cache, user model summaries, and extension UI state.

Used when a user signs in, records, replays, saves a record, or changes configuration.

tabs / activeTab

Identifies the selected target tab, URL, title, and window information, and accesses the current page after user initiation.

Used when the user opens the extension or starts recording, replay, AI execution, or sign-in.

scripting

Injects scripts for recording, replay, element highlighting, and automation into the page and iframes selected by the user.

Used when the user starts recording, replay, debugging, or AI execution on the target page.

sidePanel

Displays AI execution, recording results, step replay, logs, saved records, and configuration workspace.

Used when the user opens the extension workspace or reviews results after recording.

tabCapture / offscreen

Captures the target tab when the user starts recording, replay, or AI execution, and processes step screenshots or visual input.

Used when the user starts a feature that requires a screenshot, captured frame, or visual understanding.

debugger

Sends browser-level mouse, keyboard, screenshot, and page-state commands when the user explicitly starts AI execution or replay.

Used only when an automation workflow requires browser-level control or a screenshot fallback.

windows / notifications

Locates or focuses the target window and sends a local notification during long tasks, recording, replay, or when the user needs to return to the browser.

Used when the user starts a long-running workflow, an assisted sign-in window, or needs a status notification.

host permissions

Enables cross-site recording, replay, screenshots, and AI automation on ordinary webpages selected by the user.

Used when the user explicitly starts a VisFlow feature on an ordinary webpage.

DATA LIFECYCLE

Data lifecycle

Page data, screenshots, task steps, and model configuration are processed only for user-facing features. See the VisFlow Privacy Policy for the complete scope.

Local processing

The extension stores settings, recording state, temporary steps, screenshot cache, and UI state in chrome.storage.local, extension memory, or temporary object URLs.

Server synchronization

When a user saves a task, submits feedback, runs a processing workflow, or uses account or model configuration, the required task data is synchronized with the VisFlow backend.

Model configuration

A custom model name, base URL, provider information, and wrapped API key are used only to call the model service specified by the user.

Deletion and control

Users can stop recording, clear local data, delete saved records, sign out, or contact us to request handling of account-related data.

REVIEW NOTES

Review testing path

These steps cover the primary review path for installation, sign-in choice, recording, side-panel review, replay, and AI execution.

  1. After installing the extension, select its toolbar icon and choose account sign-in or guest mode.
  2. Open an ordinary HTTPS page, start recording, perform a click, text entry, and scroll, then stop recording.
  3. The extension opens a side panel containing steps, screenshots, DOM summaries, replay controls, and execution logs.
  4. After Replay or AI Execute is selected, the extension performs automation only on the target tab selected by the user.
  5. To test sign-in, complete QHPass sign-in or registration on the SassWeb account page that opens in a new tab.
SUPPORT & CONTACT

Support and contact information

For privacy, data, security, review, or product support, contact us through an official channel below.

Email 360ai@360.cn

Privacy, data, security, and store compliance support

Phone 010-52448983

Monday–Friday, 09:30–18:30 (China Standard Time)

Office No. 6 Jiuxianqiao Road, Chaoyang District, Beijing

Electronics City · International Electronics Headquarters

Last updated: 2026-07-07