Scope: this page describes the intended and currently implemented product boundaries. It is not a certification, penetration-test report, uptime promise, or guarantee that a security incident can never occur.
Local by default
The browser capture queue is stored in the user’s Chrome profile by default. After website access is granted, a lightweight Framnova content script can load on regular pages so the optional quick dock and explicit capture actions are available; it does not continuously scan browsing history. Chrome permissions and the dock setting can be reviewed or revoked by the user.
Explicit delivery boundaries
User-initiated attachment
The selected originals are prepared for the supported AI website the user chooses. The destination provider then controls its own processing.
User-selected workspace
The capture set is exported locally to the folder chosen by the user; it does not require hosted Direct MCP storage.
Explicit sync
A selected set crosses the network only when the user syncs it or separately enables automatic sync in extension settings.
Read-only retrieval
The MCP tools expose stored capture-set material for retrieval and inspection; they are not designed to control the browser or edit the source webpage.
Pro Token handling
The Pro Token is shown once after successful payment and is used as a Bearer credential. The billing service stores a one-way SHA-256 representation for entitlement lookup rather than the original Token. The Token itself should be stored locally in a password manager or a client’s secure secret facility.
- Never paste a real Token into an AI conversation, issue, screenshot, or support request.
- Never commit a Token to
mcp.json, shell history, or a public repository. - If a Token is exposed or lost, stop using it and contact support with a checkout or receipt identifier.
Transport and hosted infrastructure
Direct MCP endpoints use HTTPS. Hosted service components run on Cloudflare infrastructure. These controls reduce risk in transit but do not make confidential data suitable for upload by default. Users should redact secrets and sync only what is needed.
Payment separation
Stripe hosts checkout and handles payment-card entry. Framnova receives billing references, subscription status, plan, and provider identifiers needed to activate and manage Pro; it does not receive or store full payment-card numbers through this flow.
Retention and deletion
Local captures stay in the Chrome profile or selected workspace until the user removes them. Direct MCP capture sets are stored in the Token-scoped hosted workspace needed for retrieval. A precise default hosted-retention schedule has not yet been published; do not sync material that requires a retention guarantee. The self-service deletion page authenticates with the Pro Token and deletes only the specified capture-set ID, including unfinished staging for that ID.
Responsible reporting
When the active security mailbox is published, reports should include the affected URL or component, reproduction steps, impact, and a safe proof of concept. Do not access other users’ material, disrupt the service, publish Tokens, or include confidential capture content.
support@framnova.example Security-contact placeholder · replace when the verified mailbox is supplied · not monitored