Privacy and Data
This page lists the categories of data Octet Browser processes, where each is collected, and how long it is held. Use it for your privacy notice, your records of processing, and your data processing agreement with Octet.
Data collected in the browser
The collector reads these categories from the user's browser and sends them to your edge:
| Category | Examples |
|---|---|
| Device and browser configuration | Time zone, language and regional format settings, screen properties, hardware properties such as processor count |
| Device rendering characteristics | Hashes of how the device draws graphics and produces audio |
| Browser environment | Permission states the browser reports without prompting, whether automation is active, and the presence of some browser extensions |
| Network information | IP addresses the browser's WebRTC stack reports |
| Network timing measurements | How long network round trips take, in full and lite mode |
| A device identifier | A hash derived from the characteristics above. It is sent to Octet and not returned to you. |
The collector never asks for permission to use location, camera, microphone or notifications. It reads no cookies, no local storage and no page content.
In passive mode the collector makes no network measurements and does no WebRTC. The other categories are still collected.
Data added by your edge
Your edge adds data about the connection itself:
| Category | Examples |
|---|---|
| IP address | The user's public IP address, taken from the TCP connection |
| Request headers | User agent, accepted languages, and browser client hints |
| Connection measurements | Round-trip timings and other properties of the browser's TCP connection to the edge |
Where the data goes
- The browser sends its data to your edge over HTTPS.
- Your edge forwards it to the Octet API over HTTPS.
- Octet computes a verdict and returns only the verdict to your backend.
In full and lite mode the browser also sends requests to three Octet network hosts, which see the user's IP address. See Network and CSP.
How long data is held
| Where | What | How long |
|---|---|---|
| Your edge | Network timing for a session | In memory, up to 60 seconds, deleted when forwarded |
| Octet API | The session's data and its verdict | In memory, up to 2 minutes |
| Octet API | The location and network type found for a network block (a /24 for IPv4, a /48 for IPv6), with no IP address | In memory, up to 1 hour |
| Your backend | The verdict you fetched | Your choice |
Octet keeps no per-user record and builds no profile across sessions. Each session stands alone.
By default your edge logs no end-user data. Its diagnostic setting, EDGE_DEBUG, logs end-user IP addresses, so keep it off in production. See Edge Configuration.
Roles
You decide to use Octet and what to do with each verdict. Describe Octet Browser in your privacy notice as a fraud and compliance check that estimates the country a session operates from. The Octet Browser terms set out Octet's obligations. For questions about data processing, write to privacy@octetproof.com.