Privacy Policy — FactChat Apps
Last updated: 2026-06-30
This policy covers the two FactChat client applications published by Mindlogic, Inc.:
- FactChat for Office — an add-in for PowerPoint, Word, and Excel.
- FactChat Browser Agent — a Google Chrome extension.
Both are AI assistants that, at your request, read the document or web page you are working in and carry out a task you describe. They connect to the FactChat backend, operated by Mindlogic, which runs the agent; the client only performs a fixed, local set of document or browser actions. This page describes exactly what each app accesses, what leaves your device, and the controls you have.
1. What the apps access, and why
Both apps
- Your FactChat sign-in. You sign in with your email and password or via your organization's SSO. Passwords are encrypted in your browser (RSA-OAEP) before transmission and are never stored or logged by the app. The session token is kept in the app's local storage only to keep you signed in.
- Your prompts and the content you act on. When you start a task, the relevant content (see below per app) and your prompt are sent to the FactChat backend so the agent can read it and decide what to do. This happens only for the task you initiate.
FactChat for Office
- Your document content. When you give the add-in a task, the relevant document content (slides, paragraphs, or cells) is sent to the FactChat backend so the agent can read and edit it.
-
Permissions. The add-in requests
ReadWriteDocument— the standard Office permission to read and edit the active document. It accesses only the document you have open, only while you use it.
FactChat Browser Agent
- The active tab's content. When you give the agent a task, the content of the current page (text, structure, and a screenshot used to locate elements) is sent to the FactChat backend so the agent can decide what to do.
- An existing FactChat web session (optional). The extension can read your existing FactChat web-session cookie for a workspace you are already signed into, so you can connect without re-entering credentials. No other sites' cookies are read for any other purpose.
- Browser actions via the debugger. To send reliable clicks and keystrokes, the extension attaches Chrome's debugger to the active tab. Chrome shows a "being debugged" banner while the agent is active. The debugger is used solely to dispatch input and capture screenshots for the agent — never to read other extensions or browsers.
-
Host access (
<all_urls>). Because you may ask the agent to act on any website, the extension requests broad host access. It only reads or acts on a site (1) when you start a task and (2) after you allow that site for the session. -
Text you select (optional). If you use the right-click "Ask FactChat
about this" menu or the in-page selection bubble, the highlighted text is stored
locally (
chrome.storage.local) only to pre-fill the side panel's question box. It is not sent to any server unless you submit it as a task.
2. What is sent off your device, and to whom
- To the FactChat backend (Mindlogic): your sign-in credential, the workspace subdomain, and — only for tasks you start — the relevant document or page content and your prompts.
- The backend may pass your prompts and the relevant content to LLM providers to generate the agent's responses, subject to FactChat's terms.
- The apps do not sell data, do not use analytics or ads, and do not run remotely-hosted code.
3. Your controls
- First-run consent. Each app discloses the above before any sign-in.
- Per-action approval (Browser Agent). Each browser action waits for your approval, unless you turn on "Auto-approve" for a session.
- Per-site allow (Browser Agent). The agent cannot act on a site until you allow it.
- Sign out clears the stored session token.
4. Data retention
The apps themselves store only your local session token and settings, on your device. Backend processing and retention are governed by your FactChat workspace's agreement with Mindlogic.
5. Terms of service
Use of the FactChat service is governed by the FactChat Terms of Service, available at factchat.bot/en/legal/terms.
6. Contact
Questions about this policy or your data: privacy@mindlogic.ai