中文
1概述
CSI 是一个开源项目(github.com/ximing/csi),由一个 Chrome 扩展和一个运行在你自己电脑上的本地 daemon 组成,让本机运行的 AI 客户端(如 Claude Code)默认通过回环连接操控你真实的 Chrome 浏览器。
2我们不收集什么
CSI 没有遥测、没有分析统计、没有崩溃上报、没有账号系统,也不运营任何远端服务器。浏览器工具结果发送到用户配置的 daemon,并返回给调用客户端;CSI 不把浏览器数据作为遥测发送给项目维护者。更新检查与软件下载会访问发布服务。
3数据如何流动(默认使用本机连接)
- Chrome 扩展通过 WebSocket 连接你配置的 daemon(默认
ws://127.0.0.1:10088/ws)。 - daemon 默认监听
127.0.0.1(回环地址);用户可通过 bind_host / CSI_HOST 配置非回环监听,让网络客户端访问。 - 所有浏览器操作(导航、点击、输入、读取页面、截图、导出 PDF、标签页与标签组管理)都发生在你本机的 Chrome 里,使用你自己已登录的会话。
- 截图与 PDF 由 daemon 写入本机磁盘(默认为系统临时目录,或指令中指定的路径),不会上传。
- 扩展使用
chrome.storage.local保存连接与窗口设置(daemon 地址、重连周期等),这些数据留在你的浏览器本地配置中。 - daemon 在本机
~/.csi/下写配置、PID 文件和运行日志;日志按天滚动,默认保留 3 天(可配置)。
用户配置非本机 daemon 地址或开放非回环监听后,工具结果可能通过网络传输给获准访问的客户端。
4第三方 AI 客户端
向 daemon 发出指令的是你自己在本机运行的 AI 客户端(例如 Claude Code)。页面内容、截图路径等工具结果会返回给该客户端;该客户端可能会按其自身隐私政策把内容发送到它自己的云端服务。这属于 AI 客户端的行为,不在 CSI 的控制范围内——请同时阅读你所用 AI 客户端的隐私政策。
5扩展权限说明
debugger:通过 Chrome DevTools Protocol 在页面内执行工具(读取、点击、截图等)。tabs/activeTab/tabGroups/windows:标签页、标签组与窗口管理。storage:保存扩展的本地连接设置。alarms:断线重连的看门狗定时器。host_permissions: <all_urls>:只有在收到你的指令时才会操作对应页面;扩展不会主动访问任何网站。
6安全边界
daemon 默认回环监听、鉴权关闭。本机可访问该端口的进程能驱动浏览器;配置非回环监听会扩大访问范围。auth_enabled 开启且 api_key 非空时,请求须通过 key 鉴权(探活与管理页静态入口除外)。
7数据留存与删除
我们不持有你的任何数据,因此无从删除。本机产物(截图、PDF、日志、配置)都在你自己的磁盘上,删除对应文件即可;卸载扩展会清除其 chrome.storage.local 中的设置。
8政策变更与联系
本政策随仓库更新,变更以 git 历史为准。问题与反馈请提交 GitHub Issue。
English
1Overview
CSI is an open-source project (github.com/ximing/csi) consisting of a Chrome extension and a local daemon running on your own machine. It lets AI clients running locally on your computer (such as Claude Code) drive your real Chrome browser over a loopback connection by default.
2What we do not collect
CSI has no telemetry, no analytics, no crash reporting, no accounts, and no remote servers. Browser tool results are sent to the configured daemon and returned to the calling client. CSI does not send browser data to project maintainers as telemetry. Update checks and software downloads contact release services.
3How data flows (local connection by default)
- The Chrome extension connects to the configured daemon over WebSocket (default
ws://127.0.0.1:10088/ws). - The daemon defaults to
127.0.0.1(loopback). Users can configure bind_host / CSI_HOST to accept network clients. - All browser actions (navigate, click, type, read pages, screenshots, save-as-PDF, tab and tab-group management) happen inside your own Chrome, using your own logged-in sessions.
- Screenshots and PDFs are written to your local disk by the daemon (the system temp directory by default, or a path given in the command). They are never uploaded.
- The extension stores connection and window settings (daemon URL, reconnect interval, etc.) in
chrome.storage.local, which stays inside your browser profile. - The daemon writes its config, PID file, and runtime logs under
~/.csi/on your machine; logs rotate daily and are kept for 3 days by default (configurable).
If users configure a non-local daemon address or non-loopback listening, tool results may travel over the network to authorized clients.
4Third-party AI clients
Commands are sent to the daemon by AI clients that you run locally (e.g., Claude Code). Tool results such as page content or screenshot file paths are returned to that client; the client may transmit this content to its own cloud service under its own privacy policy. That is the AI client's behavior and is outside CSI's control — please also read the privacy policy of the AI client you use.
5Extension permissions
debugger: executes tools inside pages via the Chrome DevTools Protocol (read, click, screenshot, etc.).tabs/activeTab/tabGroups/windows: tab, tab-group, and window management.storage: stores the extension's local connection settings.alarms: watchdog timer for reconnecting to the daemon.host_permissions: <all_urls>: pages are only ever acted upon when you (via your AI client) command it; the extension never visits any site on its own.
6Security boundary
The daemon defaults to loopback with authentication disabled. Local processes that can reach the port can drive the browser; a non-loopback bind expands access. When auth_enabled is true and api_key is nonempty, requests require the key, except health checks and the static admin entry points.
7Retention and deletion
We hold none of your data, so there is nothing for us to delete. Local artifacts (screenshots, PDFs, logs, config) live on your own disk — delete the files to remove them. Uninstalling the extension clears its settings from chrome.storage.local.
8Changes and contact
This policy is maintained in the repository; see git history for changes. Questions and feedback: GitHub Issues.