360 AI Research

VisFlow Privacy Policy

This policy explains how the VisFlow browser extension handles user data during AI execution, recording and replay, task storage, model configuration, and issue feedback.

User initiated

Webpage content, screenshots, recorded steps, and AI execution data are processed only when the user initiates the relevant feature.

Purpose limitation

Data is used only to provide or improve user-facing VisFlow features such as AI execution, recording and replay, task storage, and troubleshooting.

Sensitive-information protection

The recording pipeline masks high-risk fields such as passwords, verification codes, API keys, tokens, and card security codes.

01

Data we process

The following data is not collected continuously in the background. It is processed only when the user initiates a feature and only as needed to provide that feature.

Account and authentication information

Data

User ID, username, display name, QID, email address, phone number, profile image, sign-in source, access credentials, and authorization status.

Purpose

To verify sign-in, identify the account, associate saved records with their owner, authorize services, and manage user model configuration.

User instructions and task content

Data

Task descriptions, AI conversations, user prompts, execution results, saved records, Bad Case feedback, notes, and runtime logs.

Purpose

To generate automation actions, save tasks, reproduce workflows, export data, and troubleshoot issues.

Webpage content and browsing context

Data

The URL, title, page structure, DOM summary, element selectors, iframe path, window dimensions, and page state of the current tab selected by the user.

Purpose

To identify elements, support AI visual understanding, generate steps, validate replay, and automate across pages.

Recording, replay, and form data

Data

Actions such as clicks, text entry, scrolling, keyboard input, opening links, and waits, plus ordinary form input the user chooses to record. Passwords, verification codes, API keys, tokens, card security codes, and similar fields are masked.

Purpose

To generate replayable steps, debug workflows, save workflow assets, and reproduce actions recorded by the user.

Screenshots, captured frames, and page images

Data

Current-page screenshots, captured frames, before-and-after state images, and image dimensions when the user starts AI execution, recording, or replay.

Purpose

To support AI visual recognition, compare states before and after an action, create step thumbnails, debug execution, and diagnose failures.

Local settings and cache

Data

Sign-in mode, model selection, side-panel state, recording state, replay state, temporary steps, screenshot cache, and UI state.

Purpose

To restore runtime state, reduce repeated input, and keep long-running recording and replay workflows reliable.

Custom model configuration

Data

The model name, base URL, provider information, and wrapped API key entered by the user.

Purpose

To call the model service selected by the user and associate the configuration with the relevant account.

02

How data is used

AI execution

To generate automation actions such as clicking, typing, scrolling, and navigation from the user’s instruction, target-page screenshot, URL, window dimensions, and page context.

Recording and replay

To record user-initiated browser actions and generate step data that can be viewed, saved, exported, and reused.

Task storage and synchronization

To save recorded steps, screenshots, DOM summaries, JSON data, and task descriptions for later review, reuse, and debugging.

Issue feedback and quality improvement

To process Bad Cases, service failures, recording failures, and replay discrepancies submitted by users, and to diagnose and fix product issues.

03

Sharing and service providers

VisFlow backend services

Used for sign-in, task storage, step processing, screenshot/HTML/JSON uploads, saved records, user model configuration, and Bad Case feedback.

360 account sign-in service

Used to verify identity and sign-in state and to issue access credentials.

AI execution service

Generates structured automation actions from the user’s instruction, page screenshot, URL, window dimensions, and page context.

User-configured model service

Called only after the user configures a base URL and API key, and used only to run the model capabilities selected by the user.

We do not sell user data or provide it to advertising platforms, data brokers, information resellers, or for credit or lending assessments.

04

Browser permissions

Extension permissions are used only for sign-in, AI execution, recording, replay, screenshots, task storage, export, and feedback initiated by the user.

storage

Stores local settings, sign-in state, task steps, screenshot cache, and temporary runtime state.

tabs / activeTab

Identifies the target tab selected by the user, reads its title and URL, and accesses the current page after user initiation.

scripting

Injects scripts for recording, replay, element highlighting, and automation into the target webpage.

sidePanel

Displays the AI execution, recording, replay, logs, and configuration workspace.

tabCapture / offscreen

Captures the target tab and processes screenshot frames when the user starts recording, replay, or AI execution.

debugger

Uses the Chrome DevTools Protocol for screenshots, input, clicks, and dialog handling when the user starts AI execution or replay.

windows

Locates, focuses, or opens browser windows required by the automation workflow.

notifications

Notifies the user about long-running tasks, recording, replay, or execution status.

unlimitedStorage

Supports larger temporary screenshots, steps, and long-workflow cache, with cleanup initiated by the user or when the task ends.

host permissions

Allows users to initiate recording, replay, and AI automation on ordinary webpages.

05

Storage, transmission, and retention

  • Local data is stored in chrome.storage.local, extension memory, or temporary object URLs.
  • Server-side data is used for task synchronization, screenshot/HTML/JSON storage, AI action generation, model configuration, and troubleshooting.
  • A custom-model API key is used only to call the model configured by the user. The user may delete or replace the configuration.
  • Users can clear local data, delete saved records, or contact us to request handling of account-related data.
06

User choices and controls

  • Users may sign in with a 360 account.
  • Users can stop recording, clear recorded data, export JSON, sign out, or delete local extension data.
  • Users decide whether to save a task, submit a Bad Case, or configure a custom-model API.
  • For high-risk actions such as submitting, approving, deleting, or paying, the product seeks user confirmation or takeover.
07

Data not proactively collected and prohibited uses

A target page selected by the user may contain sensitive information. The extension processes it only for the user-initiated feature and masks high-risk fields during recording.

Does not proactively read complete browsing history through the Chrome History APIDoes not proactively read cookiesDoes not proactively collect precise locationDoes not proactively collect contactsDoes not proactively collect health informationDoes not proactively collect financial-account information or payment credentialsDoes not sell user dataDoes not use user data for personalized advertising, cross-product profiling, or credit or lending assessments
08

Chrome Web Store Limited Use Statement

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Our use of user data complies with the Chrome Web Store User Data Policy and Limited Use requirements and is limited to providing or improving user-facing VisFlow features.

09

Contact

360ai@360.cn Privacy, data, security, and store compliance support
010-52448983 Monday–Friday, 09:30–18:30 (China Standard Time)
No. 6 Jiuxianqiao Road, Chaoyang District, Beijing Electronics City · International Electronics Headquarters