How Rowbot collects, uses, stores, and protects data. In short: your data stays in your workspace, is never sold, and is never used to train AI models.
Effective July 21, 2026
This policy applies to the Rowbot browser extension and the Rowbot hosted service operated at userowbot.com. Rowbot is a workplace automation tool: it records a browser task once and runs it for you across the websites you choose, on a schedule, over the rows of a spreadsheet.
Rowbot is sold to organizations and used by their provisioned employees. Where an organization deploys Rowbot to its staff, that organization is the controller of its employees' work data and this policy describes how Rowbot processes it on the organization's behalf.
Page content you direct Rowbot to act on. To perform a task, Rowbot reads the content of the pages you point it at. This is used only to carry out the task you recorded and is not retained beyond what the task requires.
Your automations and settings. The tasks you save, their schedules, and your preferences.
Run and audit logs. A record of which automation ran, when, and whether it passed or failed. This audit trail is a core feature and is scoped to your workspace.
Account information. The email address and identity from the Google sign-in you use to access your workspace.
Passwords, card numbers, and other secrets. The extension refuses to type credentials and asks you to enter them yourself. They are never captured or transmitted.
Your general browsing. Outside an active Rowbot task, Rowbot does not observe the sites you visit. The network capture used during automation is installed only while Rowbot is actively driving a tab, never globally.
Data is used to run the automations you create, to show you and your administrators an audit trail of what ran, and to operate and secure your workspace. Rowbot does not use your data for advertising.
To decide the next step in a task, Rowbot sends the relevant page content to a large language model provider through Rowbot's own server. That content is used only to run your task.
Rowbot's hosted backend (Supabase). Your automations, settings, and audit logs are stored in your own workspace, isolated per workspace with row-level security. Supabase is our infrastructure processor.
Model provider. During an automation turn, page content is sent to Rowbot's rowbot-chat server function, which composes the prompt and calls the model provider server-side to determine the next action.
No sale, no sharing beyond your workspace. Rowbot does not sell your data, does not share it with third parties for their own purposes, and does not use it to train AI models.
Rowbot requests only the browser permissions its features need, and each is used solely to run your tasks: host access so a saved task can run on the sites you choose; scripting to inject Rowbot's bundled automation helpers into the tab it is driving; tabs and tab groups to open and label the working tab; the debugger permission solely to send trusted keystrokes into Microsoft Excel on the web and to read the accessibility tree, attached to a single tab per operation and detached immediately after; storage for your saved automations; and alarms to run them on schedule.
Rowbot ships no remotely-hosted code and uses no dynamic code execution.
Your automations, settings, and audit logs are retained for as long as your workspace is active. You can delete an automation, clear your run log, or request deletion of your workspace data at any time.
Page content processed to run a task is not retained after the task step completes, beyond the audit record of what action ran.
You can pause any automation, remove a site from its allow-list, export your run log, or revoke Rowbot's access entirely at any time, with no waiting period. Depending on your region you may have rights to access, correct, or delete your personal data. To exercise them, contact us through the details below or ask your organization's Rowbot administrator.
Access is gated by Google sign-in, workspace data is isolated per workspace with row-level security, and every action Rowbot takes is logged and attributed. The network interceptor and the debugger attachment are on-demand and scoped to the tab being automated.
We may update this policy as the product changes. When we do, we will revise the effective date above and, for material changes, notify workspace administrators.
Questions about this policy or your data can be sent through userowbot.com/contact, and we will route them to the right person on our team.