Docs/Octet Browser/Concepts/Privacy and Data

Privacy and Data

This page lists the categories of data Octet Browser processes, where each is collected, and how long it is held. Use it for your privacy notice, your records of processing, and your data processing agreement with Octet.

Data collected in the browser

The collector reads these categories from the user's browser and sends them to your edge:

Category Examples
Device and browser configuration Time zone, language and regional format settings, screen properties, hardware properties such as processor count
Device rendering characteristics Hashes of how the device draws graphics and produces audio
Browser environment Permission states the browser reports without prompting, whether automation is active, and the presence of some browser extensions
Network information IP addresses the browser's WebRTC stack reports
Network timing measurements How long network round trips take, in full and lite mode
A device identifier A hash derived from the characteristics above. It is sent to Octet and not returned to you.

The collector never asks for permission to use location, camera, microphone or notifications. It reads no cookies, no local storage and no page content.

In passive mode the collector makes no network measurements and does no WebRTC. The other categories are still collected.

Data added by your edge

Your edge adds data about the connection itself:

Category Examples
IP address The user's public IP address, taken from the TCP connection
Request headers User agent, accepted languages, and browser client hints
Connection measurements Round-trip timings and other properties of the browser's TCP connection to the edge

Where the data goes

  1. The browser sends its data to your edge over HTTPS.
  2. Your edge forwards it to the Octet API over HTTPS.
  3. Octet computes a verdict and returns only the verdict to your backend.

In full and lite mode the browser also sends requests to three Octet network hosts, which see the user's IP address. See Network and CSP.

How long data is held

Where What How long
Your edge Network timing for a session In memory, up to 60 seconds, deleted when forwarded
Octet API The session's data and its verdict In memory, up to 2 minutes
Octet API The location and network type found for a network block (a /24 for IPv4, a /48 for IPv6), with no IP address In memory, up to 1 hour
Your backend The verdict you fetched Your choice

Octet keeps no per-user record and builds no profile across sessions. Each session stands alone.

By default your edge logs no end-user data. Its diagnostic setting, EDGE_DEBUG, logs end-user IP addresses, so keep it off in production. See Edge Configuration.

Roles

You decide to use Octet and what to do with each verdict. Describe Octet Browser in your privacy notice as a fraud and compliance check that estimates the country a session operates from. The Octet Browser terms set out Octet's obligations. For questions about data processing, write to privacy@octetproof.com.