Legal

Privacy Policy

This Policy explains how Shell Browser collects, uses, stores, shares, and protects personal data when you visit the website, create an account, or use the desktop app, and how you can exercise your rights.

Effective and last updated: August 17, 2026

Key points

  • We process only what is reasonably needed and do not sell personal data.
  • Registration needs a phone number, verification code, and password. Profile, team, task, or payment data is processed only when you use the related feature.
  • The website uses necessary local storage for language, theme, and invite codes. Tencent Captcha checks security when you request a code.
  • You may ask to access, copy, correct, or delete personal data, withdraw consent, or close your account.

1. Scope and controller

This Policy covers the Shell Browser website, desktop app, browser profiles, teamwork, automation workflows, desktop agent, downloads, subscriptions, and related support. The controller is the Shell Browser operator identified in the product, order, invoice, or other transaction record that provides the Services to you (“we,” “us,” or “our”).

Independent websites, platforms, proxies, extensions, and payment channels follow their own privacy notices. When a business customer invites you to a team, that customer may separately decide how some member and business data is used. Ask that customer about its rules.

2. Data we process

CategoryExamplesWhen
AccountCountry or region code, phone number, verification result, password, invite code, account and team IDs, member role, and contact details you enterRegistration, sign-in, account recovery, or team management
Profiles and resourcesProfile name, group, tag, fingerprint and network settings, proxy and account fields, cookies, local storage, extensions, and related settingsWhen you create, import, save, sync, share, or use the feature
Teams and tasksProjects, members, roles, access, workflows, schedules, run state, logs, results, screenshots, files, and errorsWhen you use teamwork, sync, automation, or agent tools
Device and logsIP address, device and OS type, app version, language and time zone, network state, request time, errors, crashes, and security logsWebsite access, service connection, update checks, or errors
Orders and plansPlan, capacity, amount, currency, order and payment time, payment state, billing, and invoice detailsPricing, checkout, payment, refund, or invoicing
SupportMessages, contact details, issue history, and screenshots, logs, or files you choose to sendQuestions, complaints, research, or support
Necessary web dataLanguage, theme, invite code, local-storage data, and standard server records such as IP, browser type, access time, and request resultWebsite use, setting changes, or invite registration

3. Why we use data

  • create and protect accounts, send codes, check identity, and manage sign-in, invites, teams, and access;
  • provide profile isolation, fingerprint and proxy settings, extensions, sync, automation, agents, downloads, and updates;
  • calculate plan capacity and handle orders, payment, refunds, billing, invoices, and support;
  • fix errors, restore service, protect networks and accounts, and prevent fraud and misuse;
  • respond to questions and complaints, provide support, and improve the product with de-identified or combined data; and
  • perform contract, tax, accounting, network security, and other legal duties or respond to a lawful authority.

We mainly rely on performing our contract, meeting legal duties, protecting people and property, and your consent where required. If the purpose, method, or data type changes materially, we will give notice again and obtain consent where law requires it.

4. Cookies and local storage

The website currently uses necessary browser storage for language, theme, and invite codes so settings remain stable and registration can be completed. Servers may also keep standard access logs for page delivery, troubleshooting, and security. These tools are not used for cross-site advertising profiles.

You can clear or block local storage in browser settings, but language, theme, invite registration, or some security tools may stop working. If we later add optional analytics or advertising tools, we will give the related notice and choice before use.

5. Device access and local data

File import and export, downloads, screenshots, notices, automation, or agent features may need access to files, windows, or system tools. The feature or operating system will explain the purpose. You may refuse or withdraw access in system settings, but the related feature may not work.

Some profile data, browsing records, cookies, cache, task files, and schedules may be created or stored on your device. They are sent only when you turn on sync, sharing, backup, support, or another connected feature, as explained for that feature. Protect your device and local files.

6. Processors and sharing

We do not sell personal data. We let a needed provider process data, or share it with permission, only to deliver a named feature, perform the contract, protect security, or follow law. Main cases are:

Recipient or typePurposeData
Tencent Captcha (Tencent Cloud)Bot checks and abuse prevention before registrationIP, device and browser details, interaction, and captcha ticket, subject to its notice
SMS providerRegistration, sign-in, or security code deliveryPhone number, region code, code content, and delivery state
Cloud, storage, and download providersHost APIs, deliver pages and installers, back up data, and protect securityNetwork requests, device and log data, and data you choose to sync or upload
Payment and invoice providersPayment, refunds, billing, risk checks, and invoicesOrder, amount, payment ID, billing, and invoice data; full payment credentials are normally handled by the provider
Team members you inviteProfile, project, and task collaboration under your settingsMember, profile, account field, task, and result data you choose to share

We will update this list as providers change and require a processor to follow our instructions, use security controls, and return or delete data when work ends. Proxies, extensions, websites, and platforms you choose to connect are not our processors.

7. Transfers, public use, and regions

If a merger, split, reorganization, asset sale, or insolvency requires personal data to move, we will identify the recipient and require it to follow this Policy. A recipient must obtain new consent where law requires it for a changed purpose or method.

We do not normally publish personal data. Where publication is needed, we will explain the purpose and type and obtain separate consent where required. For a lawful demand or an urgent need to protect people or property, we verify the request and provide only what is needed.

The Services support global business and overseas platforms. Before we transfer personal data collected in China abroad, we will explain the recipient, purpose, method, data type, and rights channel, and use any required assessment, certification, standard contract, or other legal process. A transfer caused by your own visit to an overseas site or use of an overseas proxy is decided by you and that third party.

8. Storage and retention

We store data under applicable law and the actual service setup, and only for as long as reasonably needed. Account and service data is usually kept until account closure or the end of service. Orders, invoices, and dispute records follow tax, accounting, and claim rules. Security and error logs are kept for a reasonable troubleshooting and risk period. A website invite code remains locally until registration, clearing, or code removal.

After the period ends, we delete or anonymize data. If backup rotation, law, a dispute, or technical limits prevent immediate deletion, we stop unnecessary use and protect the data until safe deletion is possible.

9. Security

We use controls suited to the risk, such as access limits, identity checks, transport protection, backups, log review, and least access, and restrict staff and provider access. No system is perfectly secure. Keep the app current, protect your device, use a unique strong password, and set team access carefully.

If data may have been leaked, changed, or lost, we will start response work, limit the impact, and give users and authorities any notice required by law, including known effects, steps taken, and practical protection advice.

10. Your privacy rights

  • access and copy personal data, and request transfer where law allows;
  • correct or complete inaccurate or incomplete data;
  • delete data that is no longer needed, was processed unlawfully, or relies on consent you withdrew;
  • limit or object to certain use and withdraw consent, without affecting earlier lawful use;
  • close your account and ask for an explanation of this Policy or a rule with a major effect on you; and
  • make a complaint or appeal a result.

Start with account, team, access, and local-data tools in the product, or send a request through Help or Support in the app or an official channel published on our website. To protect the account, we may check identity, account ownership, and request scope. We respond within the time required by law and explain if law permits us to refuse or retain data.

11. Teams, children, and external links

Team owners and admins may view member details, assign profiles and projects, change access, and view related activity under role settings. Before joining, review your organization's rules. Admins should invite only needed members and give notices required for staff, customers, and partners.

The Services are built for business and professional users and are not directed to children under 14. We do not knowingly process a child's personal data. If a child sent data without guardian consent, contact us so we can verify and delete it or take another lawful step.

External links, third-party sign-in pages, extensions, proxies, and websites have their own privacy practices. Read them and check the risk before leaving our Services or sending data to a third party.

12. Updates and contact

We will update this Policy and its date when law, the product, or data use changes. We will give notice through the website, app, SMS, or another reasonable method if a change materially affects purposes, data types, recipients, or your rights, and obtain consent again where required.

To exercise a privacy right, ask a question, make a complaint, or report a security event, contact us through Help or Support in the Shell Browser app or the official channel then published on our website. We will respond after checking the minimum information needed.