Agent EMP Extension — Privacy Notice
Version 2026-09-30.2 · Draft pending final legal review
This notice explains what information the Agent EMP Extension extension and its website ("the Extension") use, why, and your choices. "AgentEmp", "we" and "us" mean the business that operates AgentEmp.
Agent EMP Extension is an optional browser page-refresh tool. It does not request, collect, or store credentials for HealthSherpa, CMS, or other third-party platforms. Signing in verifies your AgentEmp extension access. Page refresh does not guarantee an active session or replace required sign-in or re-authentication.
1. What we never collect
- Usernames, passwords, MFA or one-time codes, cookies or session tokens for HealthSherpa, CMS/FFM or any other third-party website.
- What you type into web pages, form values, page text, screenshots, or consumer or applicant records.
- Full web addresses (paths, query strings or # fragments), your browsing history, or the cookies of sites you visit.
The Extension doesn't include advertising pixels, analytics trackers or session recording, and we don't sell or share your information for advertising.
2. What we do process
| Information | Where it comes from | Why |
|---|---|---|
| Your email address, when it was confirmed and when you last signed in | You, when you sign in | To run your Agent EMP Extension sign-in account and send sign-in emails you ask for |
| Agent EMP access list data: your email address (and a masked copy), the name listed, product (ACA or Medicare), how many states are listed for you, and your active/off status and when it changed | AgentEmp's own agent access system (the same agent lists AgentEmp already uses), fetched by our server about once a minute | To decide whether the Extension may work for you. This is stored for every agent on the Agent EMP access lists, even if they never sign in |
| Device record: a random installation ID, a device ID, a scrambled (hashed) device secret, extension version, when the device last checked in and the resulting status | The Extension, when you connect it and each time it checks access | To connect your browser, check access, and let you or an admin disconnect it |
| Connection codes (stored scrambled) and when they expire, were approved and used | The Extension and you, when connecting | To connect your browser securely |
| Your acceptance of the Extension Terms and this notice: your account, the document versions and the server time | You | To record that you agreed before activation |
| Security and activity records, such as device connected, device revoked, status changed, account deleted | Our service | Security, troubleshooting and accountability |
Your browser sends our server only its installation ID, device ID and secret, and the extension version. It sends no page addresses, page content or browsing information.
3. What stays in your browser
These are kept only in the Extension's local browser storage or in the page itself, and are never sent to us:
- Which tabs you started, the site (origin) and page title of those tabs, their intervals and timers.
- Your remembered interval for each page (saved by site and page path, locally).
- Your scroll position, saved in that page's own temporary tab storage just before a refresh and removed once restored.
- Typing detection: inside the page, the Extension notes whether you've typed or changed a field and compares fields with their original state. Only a yes/no result is returned to the Extension. Field contents are never read out, stored or sent.
4. Service providers and network information
The website, server and database are hosted by our hosting and backend provider, Lovable, which includes a managed database and sign-in service that also sends sign-in emails. The Agent EMP access lists come from AgentEmp's own agent access system. Like any website, these providers' networks process your IP address and basic request details to deliver the service and protect it from abuse, and the sign-in service keeps its own security logs. Our application's own records listed above do not store your IP address.
5. How long we keep information
- We have not yet set automatic deletion periods. Records are kept while needed for the purposes above, until you delete your account, or until an admin removes them.
- When you delete your account on the Account page, we delete your sign-in account and your acceptance records and disconnect your devices. Disconnected device records, security and activity records, and Agent EMP access list data (which comes from AgentEmp's agent records, not from you) may be kept for security, accountability and legal reasons.
- Information in your browser is removed when you disconnect or uninstall the Extension or clear its data.
6. Your choices and rights
- See your status and devices, and disconnect devices, on the Account page.
- Delete your Agent EMP Extension sign-in account on the same page.
- Remove site access or uninstall the Extension from your browser at any time (see Permissions).
- For access, correction or deletion requests, or questions, contact your AgentEmp admin or account manager. Depending on where you live, you may have additional rights under local law; we'll respond as the law requires. We may need to keep some information where the law requires or allows it.
7. Chrome Web Store User Data Policy
Agent EMP Extension's use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the information above only to provide and secure the Extension's single purpose — refreshing tabs you choose while your access is active. We don't use it for advertising, don't sell it, don't use it to determine creditworthiness or for lending, and don't let people read it except as needed for security, to comply with law, or with your permission.
8. Security
Connections use HTTPS. Device secrets and connection codes are stored only in scrambled (hashed) form, and device secrets are replaced periodically. Database tables are readable only by authorized admins, and changes go through checked server functions. No system is perfectly secure, and the Extension's code running in your browser can't be made tamper-proof; access decisions are made on our server.
9. Changes
If we change this notice materially, we'll update the version date and ask you to review it again before you continue using the Extension.