Privacy Policy

August 16, 2022Updated October 1, 202620 min read

1. Introduction and Scope

Welcome to Browser.lol (the "Service"), operated by Zesiger.net ("we," "us," or "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, disclose, and safeguard your information when you visit our website https://browser.lol, use our services, or interact with us in any other way. It also describes your data protection rights and how you can exercise them.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023), the EU General Data Protection Regulation (GDPR) where it applies to us, the UK GDPR, and other applicable data protection laws. We apply Privacy by Design and Privacy by Default principles: the Service is built so that ordinary Browser.lol sessions are not routinely inspected for page content. If you choose to use a saved browser profile, browser state such as cookies and history is stored so that you can return to it. Guard.ch offers optional live analysis on the shared platform; its privacy policy explains that processing. We limit the data we keep to what is needed for the purposes described here.

One account, two services

Browser.lol and Guard.ch are operated by the same entity and share one account system, one API, and one database. A single account serves both services: the account, authentication, session-token, and billing records described in this Policy are stored once and are used for whichever of the two services you use. This Policy describes processing in connection with Browser.lol. Guard.ch features, including optional live analysis of a session, are covered by the privacy policy published on Guard.ch.

This Policy is a factual description of what we do today. Where we state targets or aims, they are targets and not guarantees unless a binding document says otherwise.

2. Responsible Entity and Contact Information

The entity responsible for the processing of your personal data (the "Controller") is:

Operator (registered name): Zesiger.net, trading as Browser.lol

Legal Representative: Janis Zesiger

Address: Mügeri 340, 5046 Schmiedrued, Switzerland

Legal Form: Einzelunternehmen (Sole Proprietorship)

Registered Office: Schmiedrued, Switzerland

UID (Enterprise Identification Number): CHE-488.503.816

CH-ID: CH-400-1610391-2

EHRA-ID: 1618337

For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Email: [email protected]

Postal Mail: Janis Zesiger, Mügeri 340, 5046 Schmiedrued, Switzerland

Website: https://browser.lol

We have not appointed a data protection officer because none of the thresholds that would require one applies to our processing. We have also not currently appointed an Article 27 GDPR representative in the EU or in the UK; if we appoint one, we will publish the representative's name, address, and contact details in this Section without delay.

Data Storage Location

Primary Data Storage: Our primary database, account and billing records, integrated-mail message records, and encrypted backups are stored in Hetzner's Helsinki datacenter, Finland (EEA). Integrated-mail attachments are stored separately in Hetzner Object Storage in Nuremberg, Germany (EEA). Where saved browser profiles are available and you choose to use one, browser state is stored separately with IDrive Inc. in IDrive e2 object storage in Frankfurt, Germany (EEA), as described in Section 3.3 and our Subprocessors List below. A working copy can remain on the browser node where the profile was last used so that the next session starts faster; that node may be outside the EEA, in which case the transfer mechanisms listed for its provider apply. We do not operate multi-region replication of the primary database.

Session Compute: For lower latency, the containers that run sessions operate in several regions, including Helsinki, Gravelines (France) and the edge regions listed in our Subprocessors List. The running container is removed when a session ends. If a saved profile is used, its browser state can be retained separately as described in Section 3.3, and a working copy can remain on the node where it was last used, including edge nodes outside the EEA.

3. Data We Collect and How We Use It

We collect and process your personal data only for specified, explicit, and legitimate purposes, and always on a valid legal ground (see Section 4). We practice data minimization: we only collect personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

3.1. Personal Data You Provide to Us

  • Account Registration:
    • Data: Email address and, if you set one, a password stored as a bcrypt hash. You may also provide a name, company name, country, default session language, keyboard layout, mail alias, or passkey for supported sign-in methods. If you sign in with Google or Microsoft, we receive your verified email address and basic profile information (such as your name) from the identity provider instead of a password.
    • Purpose: To create and manage your user account, provide access to our services, identify you as a user, and for security purposes.
    • Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR).
  • Contact and Communication:
    • Data: Email address and the content of your communications with us (e.g., support requests, feedback, reports).
    • Purpose: To respond to your inquiries, provide customer support, send service-related communications (e.g., updates, security alerts, administrative messages), and gather feedback.
    • Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR) in effective support and communication.
  • Payment and Billing Data:
    • Data: If you purchase a paid Browser.lol subscription (currently Plus or Premium), we record your plan, billing period and transaction records (order reference, amount, currency, date, the entitlement granted). Payment credentials are entered directly with our payment processor Mollie B.V. and never reach our servers; Mollie's processing is described in our Subprocessors List.
    • Historical records: For one-time purchases made in the past, we retain the transaction records that Swiss bookkeeping law requires us to keep. Card and payment credentials were entered with the payment provider of the time and never reached us.
    • Purpose: To provide and manage paid subscriptions, process refunds, and comply with bookkeeping obligations.
    • Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR), in particular Swiss bookkeeping law (Art. 957 et seq. of the Swiss Code of Obligations).

You are not obliged to provide personal data, but failure to provide data that is required for a feature may prevent us from providing it.

3.2. Data We Collect Automatically

  • Technical and Device Data:
    • Data: IP address, device type, operating system, browser type and version (User-Agent), browser language, screen resolution, session ID. Our server logs may also include a server ID or a session record ID when relevant to the event.
    • Purpose: To ensure the functionality, security, and stability of our website and services; for troubleshooting and abuse detection; and for security purposes such as fraud prevention and identifying malicious activity.
    • Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR) in operating and securing our services; performance of a contract (Art. 6(1)(b) GDPR) for essential functionality.
  • Usage Data:
    • Data: Pages visited on our website, features used, session timestamps (creation, update, expiration, last activity), and aggregated usage statistics.
    • Purpose: To understand how users interact with our services, improve service design and functionality, and identify areas for improvement.
    • Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR) in service improvement.

We do not ask for biometric data or special categories of personal data (Art. 9 GDPR) to operate Browser.lol. Content you choose to enter on third-party websites or retain in a saved browser profile may nevertheless contain sensitive information. Bot detection on our forms is performed by Cloudflare Turnstile (see Section 3.5); we do not build behavioral biometric profiles of our users.

3.3. Session Data

When you start a session, we record metadata about that session:

  • Data: Associated user ID (if logged in), session ID, browser image used, the server on which the session runs, session status (e.g., running, deleted), creation, last update and last activity (lastseen) timestamps, browser language, and keyboard layout settings.
  • Purpose: To provide and manage sessions, monitor resource usage and keep the service stable. Subscription charges are not calculated from browsing history; residential proxy data allowances and session limits are metered against the applicable plan.
  • Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR).
  • Retention: Session records are normally removed by periodic cleanup once their last update is more than one month old. A record may be kept longer while needed to settle a saved-profile lease or account for an active runtime-limited grant.

In ordinary Browser.lol operation, we do not routinely inspect or log the content of sites you visit or data you enter within a session. The isolated running container is removed when the session ends. If you choose a saved browser profile, browser state including cookies, logins, history and site storage is saved so that you can resume it later; deleting the profile starts its separate removal process. A saved profile is kept until you delete it, until your account is deleted, or until it has not been used for 30 days; pinned profiles are kept while they fit your plan's profile limit (Section 5.2 has the details). On the shared platform, Guard.ch can perform optional live analysis of a session when enabled, as explained in its privacy policy. For platform security, automated systems may analyze session resource and traffic patterns, and suspected abuse may prompt a manual review of metadata; that analysis follows our normal log retention.

3.4. Integrated Mail Service Data

  • Data: Sender and receiver email addresses, subject, message content (plain text and HTML), attachments, and your user ID. Inbound messages to your mail alias are received through Cloudflare Email Routing and attachments are stored in Hetzner Object Storage in Nuremberg, Germany.
  • AI Features: We may generate an AI-powered summary of a message and detect calls to action. For this, message content is processed through OpenRouter, which routes the request to the configured model provider (currently Google Gemini). OpenRouter is the channel used for optional AI processing of content in Browser.lol's integrated mail feature. We do not use that content to train models. Separately, Guard.ch's optional live analysis may process content from pages viewed in a session when enabled, as described in its privacy policy.
  • Purpose: To receive, store, and display your emails as part of the mail service; to provide AI-powered features for email management.
  • Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR).
  • Retention: Messages and attachments are subject to a 30-day retention period. Periodic cleanup removes message records older than 30 days and removes records beyond the newest 50 per user, oldest first.

3.5. Security and Fraud Prevention Data

To protect our platform and users from fraud, abuse, and security threats, we process certain data through security measures:

  • IP Address Analysis: IP addresses are checked against a locally hosted database for geolocation and network information. We may use those results, together with other security signals, to assess abuse risk, particularly for anonymous use.
  • Email Verification: During registration, email addresses are checked against a local database and, where needed, against the external Reoon Email Verifier API to detect invalid or disposable email addresses.
  • Bot Detection: Cloudflare Turnstile analyzes browser signals to distinguish between human users and automated bots on registration, sign-in and similar forms.
  • Hostname Reputation: Hostnames may be checked against Google Web Risk to detect known malware and phishing infrastructure. No account data is sent with these lookups.
  • Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR) in protecting our platform and users from fraud and abuse.

4. Legal Basis for Processing Personal Data

Under the Swiss FADP, processing of personal data by private parties does not require a specific legal basis for every operation; it must comply with the processing principles of Articles 6 and 8 FADP, and any overriding of a data subject's interests must be justified (Art. 31 FADP). Where the GDPR or UK GDPR applies, we rely on the following legal grounds under Article 6(1):

  • Performance of a Contract (Art. 6(1)(b) GDPR): Creating and operating your account, providing sessions and the integrated mail service, and providing support.
  • Legal Obligation (Art. 6(1)(c) GDPR): Bookkeeping and tax record-keeping (Art. 957 et seq. of the Swiss Code of Obligations) and responding to lawful requests from authorities.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Securing the platform, preventing fraud and abuse, enforcing our terms, defending legal claims, measuring and improving the Service, and funding the free tier through advertising on our website. When relying on legitimate interests, we balance them against your interests and fundamental rights.
  • Consent (Art. 6(1)(a) GDPR): Only where we ask for it for a specific purpose. We do not rely on consent for any processing that is necessary to run the Service.

We do not ask you to provide special categories of personal data (Art. 9 GDPR) to use Browser.lol. Sensitive information you choose to enter in a session or retain in a saved profile is handled as described in Section 3.3.

5. Data Processing Activities Overview

5.1. Automated Abuse Detection and Decision-Making

We use automated systems to detect abuse of the platform, such as rate-limit enforcement, IP reputation checks, and automated analysis of resource and traffic patterns. An automated system may temporarily block access (for example, refuse a registration or a session start) if highly suspicious activity is detected. Where such a decision significantly affects you, you have the right to obtain human intervention, to express your point of view, and to contest the decision (Art. 22 GDPR; Art. 21 FADP): contact [email protected] and we will review the decision manually. We do not perform automated decision-making that produces legal effects beyond these security measures, and we do not use profiling for advertising decisions about you.

5.2. Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements, or as long as necessary for the establishment, exercise, or defense of legal claims.

Data Type / Purpose Retention Period Justification
Account data Access ends when the account is disabled; the account record becomes eligible for deletion after more than 8 days and is deleted within 30 days of the deletion request, subject to records retained for legal obligations Service provision
Unverified accounts Periodic cleanup removes them once more than 7 days have passed without email verification Data minimization
Session records (metadata only) Periodic cleanup after more than 1 month since last update, except while needed for a saved-profile lease or active runtime ledger Service provision
Saved browser profiles Until you delete the profile or your account is deleted; a profile not used for 30 days is deleted, and pinned profiles are kept while they fit your plan's profile limit; at the limit, a new profile replaces the least recently used profile that is not pinned; after a downgrade or the end of your plan, profiles beyond the limit can no longer be started, lose their pin and are deleted 30 days after their last use Service provision
Integrated mail service messages 30-day retention for messages and attachments; periodic message cleanup also removes records beyond the newest 50 per user Service provision
Application and access logs 30 to 90 days, depending on log class; longer only if required for a specific security incident investigation Security, troubleshooting
Billing and transactional records (invoices, accounting evidence) 10 years from the end of the fiscal year Swiss bookkeeping law (Art. 958f Swiss Code of Obligations)
Support correspondence 3 years from the last message Service quality, dispute resolution
Backups Rotated within 35 days; a restore from backup is re-deleted on the next purge run Business continuity

Where no specific period is listed, we delete personal data when it is no longer necessary and no legal hold applies. Upon expiry of the applicable retention period, personal data is deleted or anonymized.

5.3. Data Security

We have implemented technical and organizational security measures (TOMs) appropriate to the risk to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include:

  • Encryption in transit: TLS (minimum version 1.2, TLS 1.3 preferred) for connections to our website and API; WebRTC media streams are additionally protected with DTLS-SRTP.
  • Encryption at rest: Block-level encryption on our primary storage in Helsinki; passwords are stored hashed with bcrypt.
  • Isolation: Each session runs in an isolated container with its own filesystem and network namespaces. The running container is removed at session end; saved browser profiles, where used, retain selected browser state separately.
  • Access control: Role-based access on the principle of least privilege; administrative access is restricted and logged.
  • Operations: Logging and monitoring of relevant system events, regularly exercised backup and recovery procedures, and a documented incident response process.

We are transparent about our certification posture: we are not ISO/IEC 27001 certified, we do not hold a SOC 2 report, and we do not claim any certification or external audit that does not exist. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach we follow the process described in Section 10.

5.4. Privacy by Design

  • Data Minimization: We collect and process only the personal data necessary for each specific purpose; ordinary temporary-session browsing content is not stored as a session recording. A saved browser profile retains browser state when you choose to use one.
  • Purpose Limitation: Personal data is processed only for the specific, explicit, and legitimate purposes for which it was collected.
  • Storage Limitation: Data is retained only as long as listed in Section 5.2.
  • No data mining: We do not use session or mail content for advertising or to train models. Optional mail summaries and Guard.ch live analysis are described in Section 3 and the Guard.ch privacy policy.

6. Third-Party Services and Data Sharing

We share personal data with third-party service providers (processors) only where this is needed to deliver the Service. These providers are contractually bound to protect your data and may only use it for the purposes for which we disclose it to them. We do not sell your personal data. The complete, current register of our vendors (including their roles, locations, and transfer safeguards) is published in our Subprocessors List; selected providers are listed below. Mollie B.V. processes Browser.lol subscription payments as described in Section 3.1:

  • Hetzner Online GmbH - hosting of the primary database and encrypted backups in Helsinki, Finland, and integrated-mail attachments in Nuremberg, Germany (both in the EEA).
  • IDrive Inc. - IDrive e2 object storage for saved browser profiles in Frankfurt, Germany (EEA).
  • OVHcloud and FiberState, LLC - compute for sessions in Gravelines, France (EEA), and in edge regions outside Europe; running containers are removed at session end. The node where a saved browser profile was last used, including the OVH SAS node in Gravelines and edge nodes outside Europe, can keep a working copy of that profile.
  • Cloudflare, Inc. - DNS, delivery of the web frontend, bot protection (Turnstile), and inbound email routing for the integrated mail service.
  • BunnyWay d.o.o. (bunny.net) - authoritative DNS for our API hostnames, which directs each lookup to a nearby browser server (EEA).
  • Google - "Sign in with Google" (OAuth), the Google Workspace SMTP relay used to send transactional email from [email protected], Google Web Risk hostname checks, and Google Analytics 4 on our website.
  • Microsoft Corporation - "Sign in with Microsoft" / Entra ID single sign-on for organizations that enable it.
  • OpenRouter, Inc. - AI gateway used for optional mail summaries (routing to the configured model provider, currently Google Gemini). This is the channel used for optional AI processing of Browser.lol mail content.
  • OpenAI OpCo, LLC - automated anomaly detection over aggregated server-side operational logs. Browser.lol does not send browsing or mail content to this log-anomaly process. Guard.ch offers optional live analysis on the shared platform; its privacy policy describes any AI processing of that analysis.
  • Axiom, Inc. - server-side log aggregation; log events can include IP addresses and user/session identifiers.
  • Reoon - email address verification at registration.
  • Playwire LLC - advertising on the free, ad-funded tier of the Service; the paid plans are ad-free (see Section 7.2).

We may also disclose your personal data if required by law, regulation, legal process (e.g., a court order), or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud. In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction, subject to this Policy and notification where required by law.

6.1. International Data Transfers

Switzerland is recognised by the European Commission as providing an adequate level of data protection, and by the United Kingdom under its adequacy regulations. Some of our providers process data outside Switzerland and the EEA, in particular in the United States. When we transfer personal data to such countries, we rely on the following safeguards:

  • Adequacy decisions of the European Commission and the Swiss Federal Council (e.g., for Canada).
  • The EU-U.S. Data Privacy Framework (DPF) and its Swiss-U.S. and UK extensions, for U.S. providers that are certified (e.g., Cloudflare, Google, Microsoft, OpenAI, IDrive).
  • The EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent, plus the UK International Data Transfer Addendum where required, for providers that are not DPF-certified (e.g., OpenRouter, FiberState).

Browser.lol itself is a Swiss entity and is not, and cannot be, certified under the Data Privacy Framework; we do not claim otherwise. We conduct transfer impact assessments where required and the per-vendor mechanisms are listed in the Subprocessors List.

6.2. Subprocessor Management

We assess vendors before engagement, put data processing agreements in place where they process personal data on our behalf, and review them periodically. Our current subprocessors are published in the Subprocessors List, together with the notification and objection process for changes.

7. Technical Aspects of Data Processing

7.1. Website Provision & System Log Files

When you access our website or use our services, our systems automatically record log entries. A log entry typically includes:

  • Timestamp, log title or category, the log message, log level, and the location in our code that generated the entry.
  • Identifiers where applicable: IP address of the requesting client, user ID (if authenticated), User-Agent string, non-secret session record ID, server ID, team Workspace ID.
  • HTTP request details (method, URL, status code) for access logs.

Purpose and Legal Basis: This data is processed to enable the use of the website and services, ensure system security and stability, perform technical administration and troubleshooting, and detect abuse. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in providing a functional, secure, and reliable service. We reserve the right to review this data retrospectively if we become aware of specific indications of illegal use.

Storage: Relevant application log entries are stored in our PostgreSQL database in Helsinki or sent to our log aggregation provider Axiom, Inc. (see Section 6). They are deleted according to the periods in Section 5.2.

7.2. Cookies, Local Storage and Advertising

Our own code does not use cookies for authentication. After sign-in, an opaque session token is kept in your browser's localStorage and sent to our backend as an authorization header. We also use localStorage and sessionStorage for functional entries such as your session token, session references, selected browser, preferred locale, and similar preferences. These entries are strictly necessary for the Service or store choices you have made; they are not used to track you across other websites.

The following third-party technologies are in use on our website:

  • Google Analytics 4 (measurement ID G-VLXBKHVENH): website usage analytics. Google sets cookies (e.g., _ga) and processes usage data; see Google's privacy policy. You can opt out with the Google Analytics Opt-out Browser Add-on.
  • Playwire (Ramp): the free tier is funded by advertising delivered by Playwire LLC and its demand partners. On ad-supported pages, Playwire and its partners may set cookies and process your IP address, device information and ad interaction data to deliver, cap, and measure ads; depending on your region, this may include personalised advertising with the disclosures and choices presented by the ad framework. Ads are shown where the free tier is supported; paid entitlements are ad-free. The ad loader also excludes sign-in (/auth), single sign-on (/sso), the shared-session route (/s), /upgrade, API-created sessions, unsupported countries and non-public domains. See the Playwire privacy policy.
  • Cloudflare Turnstile: bot protection on registration, sign-in and similar forms; Cloudflare may set operational security cookies.

Managing cookies: You can delete or block cookies and site data at any time in your browser settings; blocking strictly necessary entries may break sign-in.

US state privacy laws: We do not sell personal information for money. Depending on the definitions of your state's privacy law, the delivery of personalised advertising may qualify as "sharing" or "targeted advertising"; you can opt out of it through the choices offered in the ad framework, by using the Service without personalised ads where that choice is offered, or by contacting [email protected].

Do Not Track (DNT) and Global Privacy Control (GPC): Our own first-party storage is strictly necessary, so it is the same whether or not your browser sends such a signal. Where an opt-out preference signal must be honoured for third-party advertising under the law of your state, the consent and choice mechanisms of the ad framework apply.

8. Your Data Protection Rights

Under the Swiss FADP and the GDPR (for individuals in the EU/EEA) and the UK GDPR, you have the following rights regarding your personal data:

Your Rights

  • Right of Access (Art. 15 GDPR; Art. 25 FADP): Obtain confirmation as to whether personal data concerning you is being processed, and, where that is the case, access to the personal data and related information.
  • Right to Rectification (Art. 16 GDPR; Art. 32 FADP): Have inaccurate personal data corrected and incomplete data completed.
  • Right to Erasure (Art. 17 GDPR): Have personal data erased under certain conditions. You can delete your account at any time; deletion follows the schedule in Section 5.2.
  • Right to Restriction of Processing (Art. 18 GDPR): Obtain restriction of processing under certain circumstances.
  • Right to Data Portability (Art. 20 GDPR; Art. 28 FADP): Receive personal data you provided to us in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21 GDPR): Object, on grounds relating to your particular situation, to processing based on legitimate interests, and object at any time to processing for direct marketing purposes.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on consent, withdraw it at any time with effect for the future.
  • Rights related to automated decisions (Art. 22 GDPR; Art. 21 FADP): As described in Section 5.1, you can request human review of automated security decisions that significantly affect you.
  • Right to Lodge a Complaint (Art. 77 GDPR): With a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected] or by postal mail (Section 2). To protect your privacy, we may need to verify your identity before responding; we will only ask for what is proportionate to the request (for most requests, writing from the email address associated with your account is sufficient).

We respond without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR; 30 days under Art. 25(7) FADP). This period may be extended by two further months for complex or numerous requests; we will inform you of any extension within the first month, together with the reasons. If we do not act on your request, we will tell you why and inform you of your right to complain to a supervisory authority and to seek a judicial remedy.

Exercising your rights is free of charge. We may charge a reasonable fee or refuse to act only if a request is manifestly unfounded or excessive, in accordance with applicable data protection laws.

9. Children's Privacy

Our Service is not directed to individuals under the age of 16 (or a higher age threshold where applicable local law requires one). We do not knowingly collect personal data from children under 16. If you are a parent or guardian and you believe that your child has provided us with personal data, please contact us using the details in Section 2. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will take steps to delete that information promptly.

10. Data Breach Notification

We have implemented procedures to detect, investigate, and respond to personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it (Art. 33 GDPR); where notification is made later, it will be accompanied by reasons for the delay. Under Swiss law, we notify the FDPIC as soon as possible of breaches that are likely to lead to a high risk for data subjects (Art. 24 FADP).

When a breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you directly without undue delay (Art. 34 GDPR), unless:
  • the affected data was protected by measures that render it unintelligible to unauthorized persons, such as encryption;
  • we have taken subsequent measures that ensure the high risk is no longer likely to materialize; or
  • direct communication would involve disproportionate effort, in which case we will inform you through a public communication or similar equally effective measure.
Our notification will describe in clear and plain language the nature of the breach, our contact details, the likely consequences, and the measures taken or proposed to address it and mitigate its possible adverse effects.

11. Links to Other Websites

Our Service may contain links to other websites that are not operated by us, and you can use sessions to visit third-party websites. If you visit a third-party site, that site's own privacy policy applies to the data it collects from you. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. Websites you visit inside a session see the session's IP address and environment rather than your own device, but any data you actively submit to them (such as logging into your accounts) is governed by their terms and policies.

12. Policy Changes and Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post any changes on this page and update the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

Version Effective Date Summary of Key Changes
5.6 2026-10-01 Saved browser profiles: pinned profiles are kept only while they fit the plan's profile limit; after a downgrade or the end of a plan, profiles beyond the limit can no longer be started, lose their pin and are deleted 30 days after their last use.
5.5 2026-09-30 Premium available to new buyers again; saved browser profiles also included with Plus; saved browser profiles and programmatic access (MCP) offered as beta features; saved profiles now stored with IDrive Inc. (IDrive e2 object storage, Frankfurt, Germany) instead of Bunny Storage, with a working copy on the browser node where a profile was last used; OVH SAS (Gravelines, France) added for session compute; saved-profile retention documented; BunnyWay d.o.o. (bunny.net) added for DNS of the API hostnames.
5.4 2026-08-12 Paid subscriptions (Plus and Professional) introduced, with Mollie B.V. as the exclusive payment processor; payment and billing data collection documented again; advertising limited to the free tier.
5.3 2026-08-07 Browser.lol stopped selling paid plans and became free for everyone: payment processing removed entirely (Mollie B.V. removed as payment processor and subprocessor), no payment data is collected any more, and advertising now applies to all users.
5.2 2026-08-05 Card payments reintroduced via Mollie B.V. (EU-based processor) for one-time purchases and optional auto-renewing Premium; Mollie added as payment processor and subprocessor.
5.1 2026-08-04 Discontinued card payments: Stripe removed as payment processor and subprocessor (its checkout cookies no longer occur).
5.0 2026-06-11 Full accuracy revision: corrected the description of our security posture and removed unfounded certification claims; consolidated the privacy contact on [email protected]; documented the shared account system with Guard.ch; added Stripe, Microsoft sign-in, OpenRouter, Axiom and Cloudflare Email Routing; corrected the cookie and local-storage description and retention periods; updated international transfer mechanisms (DPF and SCCs with Swiss equivalent); clarified that no DPO and no Art. 27 representative are appointed.
4.1 2025-11-14 Swiss law compliance update: added complete company registration details (CH-ID, EHRA-ID, legal form); clarified data storage locations (durable data in Hetzner Helsinki, Finland) and edge compute usage.
4.0 2025-05-15 Updated data collection details (account registration, technical data, usage data, session data, mail data); updated retention for mail and logs; revised system log description; updated third-party services, AI processing and security verification disclosures.
3.0 2025-01-21 GDPR and Swiss FADP compliance update: added AI processing, Cloudflare Turnstile, analytics and advertising disclosures, and security and fraud prevention processing.
2.0 2024-10-24 Comprehensive update: full translation to English, expansion of all sections, new sections on children's privacy, breach notification and external links, more detail on legal bases, security measures, international transfers, and user rights.
1.0 2022-08-16 Initial version of the Privacy Policy.

Change Notification: For significant changes that materially affect your rights or the way we handle your personal data, we will provide prominent notice (e.g., at least 30 days' advance notice via email to registered users and/or a clear notification in the Service) before the changes take effect. For less significant changes, updating the "Last Updated" date and posting the revised policy is sufficient. Where a change requires your consent under applicable law, we will ask for it.

Last Updated: October 1, 2026

13. Governing Law and Dispute Resolution

This Privacy Policy and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of Switzerland, without regard to its conflict of law provisions.

Any disputes arising from or in connection with this Privacy Policy that cannot be resolved amicably shall be subject to the jurisdiction of the competent courts at our seat in Schmiedrued, Switzerland. This does not affect mandatory data protection rights or forum rules of the country in which you habitually reside, and it does not affect your right to lodge a complaint with a data protection supervisory authority as described in Section 8.