Legal

Privacy Policy

This policy describes how Venxo processes information when two trusted Chrome browsers use the Venxo extension and relay service to synchronize browsing actions and HTML5 media playback.

Operator: Denys Kladkevych, operating Venxo
Effective date: [EFFECTIVE DATE — OWNER CONFIRMATION REQUIRED]
Last updated: July 25, 2026

1. Scope and product design

Venxo is not screen sharing or remote desktop software. It does not transmit page pixels, audio, video files, cookies, or an entire HTML document. It does transmit synchronization commands and the limited page, element, navigation, and media information described below. Venxo traffic is protected in transit by HTTPS/WSS between the extension and the Venxo server. Venxo does not currently provide end-to-end encryption between room participants.

2. Information processed by the extension

The extension creates and processes the following information when it is installed, connected, invited to a room, or actively synchronizing:

Venxo does not capture or synchronize form-control values, editable content, keyboard events, or selected page text. A click on a button, checkbox, or radio control may still be relayed as an ordinary click, without reading or sending that control’s value or form state.

3. Information sent through the Venxo server

The browser code, display name, room membership, synchronization commands, full navigation/shared-page URLs, page titles, element metadata with minimized contextual URLs, media state, verification results, and timestamps pass through the Venxo WebSocket server. The server uses these values to validate and manage room membership, relay commands, maintain the current in-memory room state, reject duplicates, correct media drift, and restore state after a temporary reconnection.

Because a full navigation URL can contain query parameters or fragments, it may contain identifiers added by the website being visited. Venxo needs the destination URL to reproduce an explicitly shared page or top-level navigation. Users should not share pages with secrets in their URLs.

4. Information visible to another room participant

An invited participant can receive the Host’s browser display name and code, room state, shared URL and title, synchronization commands, target-element context, media state, and action results required for the shared session. Venxo does not send one participant’s IP address to the other participant. Room codes and browser codes should be shared only with people the user trusts.

5. Local Chrome storage

chrome.storage.local stores the randomly generated browser code and browser display name until the user clears extension data or uninstalls Venxo. chrome.storage.session stores the selected Host and Guest tab IDs for the current extension service-worker session. Current room, media, and connection state is otherwise kept in extension memory.

6. Server storage and retention

The current Venxo API has no database and does not write WebSocket message bodies to an application log. Connected-client information and room state are held in server memory. A room is removed when its last participant explicitly leaves, or when the server process restarts. If participants disconnect without leaving, the in-memory room can remain until a later reconnection/leave or server restart.

IP addresses and connection times are held in process memory for active connections and protected operational administration. Admin login session tokens are random, HttpOnly cookies backed by server memory; their configured lifetime is currently 12 hours and they are also removed by a server restart. Local browser data remains until the user removes it.

7. Server and security logs

The Go API intentionally does not log page URLs, action payloads, cookies, or WebSocket message bodies. The hosting system and reverse proxy may record standard security and access information such as IP address, timestamp, requested API path, response status, and user agent. WebSocket payload content is not part of a normal HTTP access log. The current retention period for infrastructure logs is [LOG RETENTION PERIOD — OWNER CONFIRMATION REQUIRED].

8. Sensitive data and data minimization

Venxo does not request, target, or use personal communications, financial information, health information, passwords, one-time codes, or payment-card values as product data. Venxo 0.3.0 does not read or synchronize form values or editable content.

Limited website content is still processed when needed to identify an action target, including short visible element text, ARIA labels, page titles, DOM hints, and shared/navigation URLs. Users should synchronize only pages and actions they intend to share and should not click or share URLs that expose sensitive information. Venxo does not transmit screen captures, microphone/camera data, browser cookies, video/audio content, or form values. It does not include advertising, third-party analytics, or cross-service tracking identifiers.

9. Infrastructure and service providers

Venxo uses Hostinger infrastructure. Production server infrastructure is located in Boston, Massachusetts, United States, where synchronized commands, in-memory room state, and connection metadata may be processed. This is an infrastructure location, not the operator’s residence or business address. Additional Hostinger subprocessors: [HOSTINGER SUBPROCESSORS — OWNER CONFIRMATION REQUIRED]. Chrome and the Chrome Web Store are provided by Google under Google’s own terms and privacy practices.

10. Sharing and sale

Venxo does not sell personal information and does not use synchronized data for advertising. Information is shared with an invited room participant as necessary to provide synchronization, with infrastructure providers as necessary to operate the service, and when required by applicable law. Protected operational statistics can be viewed by the Venxo operator through the authenticated admin panel.

11. Security and limitations

Venxo uses WSS/HTTPS in production, validates room membership and protocol messages, limits message size and rate, and prevents replayed actions from being sent back as new user actions. No system is completely secure. Venxo is early-access software, room participants are trusted peers, and synchronized data is not end-to-end encrypted.

12. User controls and deletion

13. Children and minors

The minimum age for Venxo is [MINIMUM AGE — OWNER CONFIRMATION REQUIRED]. The operator does not knowingly seek information from children. Contact support@venxo.app if you believe a minor has provided information through Venxo.

14. International processing

Denys Kladkevych operates Venxo from Ontario, Canada. Information may also be processed on Hostinger production server infrastructure in Boston, Massachusetts, United States. Venxo does not claim that all information remains in Canada.

15. Changes to this policy

This policy may change as Venxo develops. Material changes will be posted on this page with a revised “Last updated” date. Where required, additional notice or consent will be provided.

16. Contact

Denys Kladkevych, operating Venxo
support@venxo.app
Ontario, Canada
Mailing address: [MAILING ADDRESS REQUIREMENT — OWNER CONFIRMATION REQUIRED]