Agent EMP Extension — Privacy Notice

Version 2026-09-30.2 · Draft pending final legal review

This notice explains what information the Agent EMP Extension extension and its website ("the Extension") use, why, and your choices. "AgentEmp", "we" and "us" mean the business that operates AgentEmp.

Agent EMP Extension is an optional browser page-refresh tool. It does not request, collect, or store credentials for HealthSherpa, CMS, or other third-party platforms. Signing in verifies your AgentEmp extension access. Page refresh does not guarantee an active session or replace required sign-in or re-authentication.

1. What we never collect

  • Usernames, passwords, MFA or one-time codes, cookies or session tokens for HealthSherpa, CMS/FFM or any other third-party website.
  • What you type into web pages, form values, page text, screenshots, or consumer or applicant records.
  • Full web addresses (paths, query strings or # fragments), your browsing history, or the cookies of sites you visit.

The Extension doesn't include advertising pixels, analytics trackers or session recording, and we don't sell or share your information for advertising.

2. What we do process

InformationWhere it comes fromWhy
Your email address, when it was confirmed and when you last signed inYou, when you sign inTo run your Agent EMP Extension sign-in account and send sign-in emails you ask for
Agent EMP access list data: your email address (and a masked copy), the name listed, product (ACA or Medicare), how many states are listed for you, and your active/off status and when it changedAgentEmp's own agent access system (the same agent lists AgentEmp already uses), fetched by our server about once a minuteTo decide whether the Extension may work for you. This is stored for every agent on the Agent EMP access lists, even if they never sign in
Device record: a random installation ID, a device ID, a scrambled (hashed) device secret, extension version, when the device last checked in and the resulting statusThe Extension, when you connect it and each time it checks accessTo connect your browser, check access, and let you or an admin disconnect it
Connection codes (stored scrambled) and when they expire, were approved and usedThe Extension and you, when connectingTo connect your browser securely
Your acceptance of the Extension Terms and this notice: your account, the document versions and the server timeYouTo record that you agreed before activation
Security and activity records, such as device connected, device revoked, status changed, account deletedOur serviceSecurity, troubleshooting and accountability

Your browser sends our server only its installation ID, device ID and secret, and the extension version. It sends no page addresses, page content or browsing information.

3. What stays in your browser

These are kept only in the Extension's local browser storage or in the page itself, and are never sent to us:

  • Which tabs you started, the site (origin) and page title of those tabs, their intervals and timers.
  • Your remembered interval for each page (saved by site and page path, locally).
  • Your scroll position, saved in that page's own temporary tab storage just before a refresh and removed once restored.
  • Typing detection: inside the page, the Extension notes whether you've typed or changed a field and compares fields with their original state. Only a yes/no result is returned to the Extension. Field contents are never read out, stored or sent.

4. Service providers and network information

The website, server and database are hosted by our hosting and backend provider, Lovable, which includes a managed database and sign-in service that also sends sign-in emails. The Agent EMP access lists come from AgentEmp's own agent access system. Like any website, these providers' networks process your IP address and basic request details to deliver the service and protect it from abuse, and the sign-in service keeps its own security logs. Our application's own records listed above do not store your IP address.

5. How long we keep information

  • We have not yet set automatic deletion periods. Records are kept while needed for the purposes above, until you delete your account, or until an admin removes them.
  • When you delete your account on the Account page, we delete your sign-in account and your acceptance records and disconnect your devices. Disconnected device records, security and activity records, and Agent EMP access list data (which comes from AgentEmp's agent records, not from you) may be kept for security, accountability and legal reasons.
  • Information in your browser is removed when you disconnect or uninstall the Extension or clear its data.

6. Your choices and rights

  • See your status and devices, and disconnect devices, on the Account page.
  • Delete your Agent EMP Extension sign-in account on the same page.
  • Remove site access or uninstall the Extension from your browser at any time (see Permissions).
  • For access, correction or deletion requests, or questions, contact your AgentEmp admin or account manager. Depending on where you live, you may have additional rights under local law; we'll respond as the law requires. We may need to keep some information where the law requires or allows it.

7. Chrome Web Store User Data Policy

Agent EMP Extension's use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the information above only to provide and secure the Extension's single purpose — refreshing tabs you choose while your access is active. We don't use it for advertising, don't sell it, don't use it to determine creditworthiness or for lending, and don't let people read it except as needed for security, to comply with law, or with your permission.

8. Security

Connections use HTTPS. Device secrets and connection codes are stored only in scrambled (hashed) form, and device secrets are replaced periodically. Database tables are readable only by authorized admins, and changes go through checked server functions. No system is perfectly secure, and the Extension's code running in your browser can't be made tamper-proof; access decisions are made on our server.

9. Changes

If we change this notice materially, we'll update the version date and ask you to review it again before you continue using the Extension.