Where page data goes

Browser Bolt runs as a local MCP process. Your host supplies a goal and observed page context. In public v0.1.0, Jev decision requests go through OpenRouter. Qwen field text goes directly to Cerebras when its key is configured, or through OpenRouter on the one-key route. Requests may contain page text, field values, URLs, and recent actions.

Your host controls the browser

The MCP proposes an operation against an observed target. Your host decides whether it is authorized, executes it, reads the changed page, and verifies the outcome. The MCP does not receive screenshots or control the browser by itself. A DONE choice is not proof of completion.

Evaluate with synthetic data

There is no universal redaction layer or provider retention guarantee. Use a dedicated browser profile and public, synthetic inputs while evaluating. Keep keys out of prompts, committed files, and issue reports. Review the provider and host settings for the route you use.

Read the privacy notice, BYOK terms, and published security notes.