Privacy
Variant AI explores your website, proposes A/B test variants, and measures the ones you ship. This page says what it reads, what it sends, and what we store.
Last updated 30 August 2026.
The short version
- We send a redacted summary of the pages you point the agent at, plus a screenshot of what is on screen.
- Anything you have typed into a form never leaves your browser. Neither do passwords, hidden tokens, or anything shaped like an email address, phone number, or card number.
- The extension can only read the one site you name and grant access to. It cannot see your browsing.
- Page summaries and screenshots are deleted after 90 days.
- We never use your data to train models, and we do not sell it.
What the extension sends
When you point the agent at a page, the extension builds a digest. That is a short list of the visible elements that matter: headings, links, buttons, inputs, images, and text blocks. For each one it records the tag, the role, the visible text, the layout box, a few style properties, and a way to find it again. The digest stops at roughly 250 elements. We also send the page URL, the page title, and a downscaled screenshot of what is on screen.
We also store your conversation with the agent, the variants it proposes, the site you named, and an anonymous install identifier made on first run. Until you create an account, that identifier is all we know about you. No name, no email.
What never leaves your browser
Redaction runs inside the page, before anything is sent. It is not a filter on our servers. The data is removed on your machine, so it never leaves.
- Values you have typed into any form field. Not just the sensitive-looking ones. We record that a field is filled, never what is in it. Nothing reliably tells a search box apart from a field someone typed their address into, so we do not try.
- Passwords, hidden fields, and payment inputs. For these, not even the fact that they are filled is reported.
- Anything shaped like personal data, wherever it appears: visible text, attributes, or URLs. Email addresses, card numbers, phone and account numbers, and long opaque strings such as API keys, signed URLs, and session tokens are all replaced before sending.
This over-redacts. A product name that happens to be a long code becomes a placeholder and the agent loses some context. That trade is deliberate.
Pages that hold other people’s records
Being signed in is not what stops the agent. You are signed in to your own site, and the pages you are signed in to — your dashboard, your account, the app you are trying to improve — are usually the whole reason you opened Variant. It reads those.
What it refuses is the back office: an admin panel, an order list, invoices, a customer list. On those the extension refuses at the point of capture, and all the agent is told is that the page was refused. It has to ask you in the chat, with a reason. If you approve, that covers this session only. Nothing carries over to the next one.
Redaction above runs on every page either way, whichever side of that line it falls on.
Which sites the extension can read
The extension asks for no website access when you install it. When you type a site and press Start, Chrome asks about that one origin. The extension can read nothing else: not your other tabs, not your history, not your browsing. You can take that access back at any time from chrome://extensions.
The pixel on your site
If you run a test, you put a small script on your own website. It assigns each visitor to a variant and reports which one they saw and whether they converted. To do that it stores a random identifier in a first-party cookie on your domain, mirrored to local storage, so a returning visitor keeps seeing the same variant.
That identifier is random, scoped to your domain, and never joined to an identifier from any other site. The pixel sends us three kinds of event: a visitor saw a variant, a visitor converted, and a change could not be applied because the page had changed. It collects no names, no emails, no form contents, and no browsing history. We do not use it to build profiles or to advertise.
Your visitors’ data is yours. We process it to run your tests and for nothing else.
What we do with all of this
We use it to run the product: to let the agent understand your site and propose variants, to pick a session back up where you left it, to show your results, to bill for the traffic your tests receive, and to tell you when a change stops applying because your site changed. We use aggregate numbers to keep the service running and to stop abuse.
We do not use your data to train machine-learning models, ours or anyone else’s, and we do not sell it or share it for advertising.
How long we keep it
- Page summaries and screenshots: deleted 90 days after the session they belong to, automatically.
- Experiments, variants, and results: kept while your account exists, because they are the record of what you tested.
- Unclaimed anonymous sessions: expire on their own if you never create an account.
- On account deletion: everything above is removed.
Who else touches it
A few processors, each for one job, each under contract. None of them may use your data for their own purposes:
- OpenRouter — routes our model requests to the provider that serves them.
- OpenAI — the model that reads page digests and writes variants. Sent through the API, which is not used for training.
- Vercel — application hosting.
- Neon — the database.
- Resend — sending email you asked for: sign-in links, the install snippet, and alerts.
- Stripe — payments, if you subscribe. Card details go to Stripe directly and we never see them.
- Cloudflare — an anti-abuse challenge, shown only if traffic from your install looks automated.
We give data to anyone else only when the law requires it. We will tell you unless we are barred from doing so.
Your choices
- Stop the agent at any time from the panel; nothing is captured after that.
- Revoke site access from
chrome://extensions. - Decline a back-office page and the agent will work around it.
- Ask for a copy of your data, or its deletion, by emailing us. If you are in the UK, EU, or California, your local law gives you rights. We honour them for everyone.
- Uninstall, which removes the extension’s local storage; email us to delete what is on our side.
Children
Variant AI is a tool for people who run websites. It is not directed at children and we do not knowingly collect data from anyone under 16.
Chrome Web Store Limited Use
Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We collect only what the product’s single purpose requires. We transfer it only as described above. We do not use it for advertising, for creditworthiness or lending decisions, or to train models.
Changes
If we change what we collect or what we do with it, we update this page and the date at the top. Material changes are announced in the product before they take effect, not after.
Contact
Questions, requests, or complaints: support@withvariant.com.