Privacy Policy — AG-UI DevTools
Browser extension published by Soverius AI · effective
Summary
AG-UI DevTools is a developer tool that displays, inside your browser's DevTools, the AG-UI protocol traffic of a web page you select. It processes that traffic locally only after you approve capture. Captured data is not transmitted to Soverius AI or any third party, stored remotely, sold, used for advertising or used for profiling. There are no accounts, analytics, telemetry or developer-operated data servers.
Your choice before capture
Opening the panel does not start capture. Before attaching the Chrome debugger or reading tabs for the standalone tab picker, the extension prominently describes the data it will process and requires you to click Start AG-UI capture. The standalone picker then asks for Chrome's optional tab-access permission; if you decline, no tab title or URL is queried. WebSocket inspection has a separate checkbox, is off by default, and also requires one user-entered endpoint origin or path prefix. You can stop capture at any time; this immediately detaches the debugger.
What the extension processes
After approval, the extension attaches to the selected tab through the Chrome DevTools Protocol and processes the selected page's title and URL plus network requests and responses that carry recognized agent event streams: Server-Sent Events, the AG-UI binary transport, and recognized CopilotKit responses. AG-UI inputs and events can contain user prompts, agent responses, message history, shared state, tool definitions, tool arguments and tool results. Under the Chrome Web Store disclosure categories this processing includes Website content and Web history. Because the inspected payload can contain prompts, responses and message history, it also includes Personal communications. It can contain personal or sensitive information if the inspected application places such information in its agent traffic.
Unrelated HTTP traffic is ignored. In the Web Store release, WebSocket inspection considers only secure wss: sockets inside the exact origin/path boundary entered by the user. Sockets outside it are not tracked. A socket inside it is retained only after a complete AG-UI input or an identified RUN_STARTED event proves that it carries AG-UI. Generic JSON objects, unknown event types, binary frames and insecure ws: sockets are discarded and never shown or stored.
Nothing is injected into the page. Processing happens entirely inside your browser and stops when you click stop capture, close the last panel on the tab, or close the tab.
Request headers named Authorization, Cookie, X-Api-Key and Proxy-Authorization can contain Authentication information. Their values are processed transiently only so they can be replaced immediately with redacted; raw values are never displayed, placed in the capture buffer or retained in storage.
Storage
Captured events, selected page metadata and recognized endpoint URLs are kept in the extension's memory and session storage so the panel can show recent history; session storage is cleared automatically when the browser session ends. Panel layout preferences (panel sizes and selected view) are kept in local storage. You can delete captured data at any time with the panel's clear button.
Permissions
- debugger — the user-approved capture channel: used after an explicit click to observe recognized agent streams on the selected tab, including streams consumed inside Web Workers. Chrome shows a notice while it is active. It is released when stopped, when the last panel closes, or when the tab closes.
- tabs (optional) — requested only when you use the standalone tab picker after accepting the disclosure. If granted, reads titles and URLs so you can choose the tab being debugged. If declined, it does not query that metadata.
- storage — as described above.
Export
The panel can export a captured session as a JSONL file at your request. The file is created locally; nothing is uploaded.
Use, sharing and Limited Use
Captured data is used only to provide the extension's single purpose: inspecting and debugging AG-UI protocol traffic for the selected page. It is not transferred to Soverius AI or third parties, used for advertisements, combined with other data, used for credit decisions, or made available for human review by Soverius AI.
The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes
If this policy changes, the new version is published at this address with an updated effective date.
Contact
Soverius AI · soverius.ai · soverius.ai/contact · rainer.hahnekamp@soverius.ai