Privacy

Last updated October 7, 2026. Version 2026-10-07.

What we store

Your account: your email address and your password, which our account provider (Supabase) keeps only as a one-way hash. If you sign in with Google, or signed in with LinkedIn before, we also keep the name and profile picture it shares. Accounts are shared with Ken's Toolbox.

Your board: everything on it — notes, pictures, the web addresses of the pages you pin, frames, and connections. We store it with your account so you can open it on any device, and your browser keeps a copy. Pictures are stored once each, separately from the rest of the board; a picture you remove from your board is deleted from our storage at a later save, a day or more after you remove it.

Pages you add or open

Automatic website previews start off. If you enable them, the source web address — including meaningful query parameters and search words — is sent to Broadser's preview service. The server fetches that page once to read its title, description, image, and whether it may be shown inside another site. The response is not stored in a shared CDN cache. Preview caches belong to the current account; public snapshot viewers do not use the device’s private preview cache. Signing out clears that account’s derivative preview and image caches; unsuccessful cleanup is reported. Current clients send the address in a POST request body, without its fragment, to reduce exposure in access-log URLs. Older clients may send it in a query string. Our hosting provider still processes these requests and may retain service logs. Avoid adding private links containing access tokens. External thumbnails, remote screenshots and profile photos start off. Enabling them permits requests to their image hosts. Embedded and local images remain available. Automatically embedded websites start off; opting in or explicitly opening or playing a website contacts its publishing site, which can use its own cookies and privacy practices. Broadser suppresses the originating board’s Referer header. The browser workspace displays saved screenshots or source links; opening the original source contacts that site. Uploaded and saved screenshots become board content and may be included in copies you share. Mac web searches go to Bing.

What we don't do

We do not show ads, sell personal information, or run advertising analytics or tracking scripts. We use the service providers described here to operate Broadser, and share board content with the people you authorize. Your board is private to your account unless you share a link to it (see Shared links).

Where it's kept

We store accounts and boards with Supabase, and Netlify serves the site. Current hosted clients use system fonts and serve the pinned sign-in library from Broadser’s own origin. Older clients may still contact Google Fonts and jsDelivr, which receive the request’s IP address. Your browser keeps your sign-in session and a copy of your board in local storage; signing out removes that copy once everything has reached your account.

Shared links

You can share a board as a read-only link: Share ▸ Read-only link on the web, or the Shared links page, where Broadser for Mac's web page of a board goes. A link holds a copy of the board as it was when you shared it — its cards, notes, and pictures, and the titles, addresses, and pictures of its pages — stored with Supabase under a random address, with a list of your links kept with your account. Anyone who has the link can see that copy, without an account; links aren't listed anywhere, and we ask search engines not to index them. Changes you make to the board later aren't shown.

New published snapshots and exported webpages omit your top-level profile unless you explicitly include it; this does not change existing links, copies or comment authors. To stop sharing, open Shared links and choose Turn off. Broadser removes stored files before their ownership records and shows failed cleanup so it can be retried. Downloaded copies cannot be recalled, and public caches may continue to show a previously fetched copy until they expire. Delete my board data turns off all your public links too.

A board you save as a web page (Share ▸ Web page) is a file you keep and send yourself; we never receive it unless you bring it to Shared links.

Broadser for Mac

Broadser for Mac works locally without an account. Personal boards, folders, templates, settings, backups, page pictures, imported PDFs, and website data (cookies and sign-ins) stay on your Mac, in Broadser's own folder and any backup folder you choose. Signing in does not upload personal boards. An optional account enables shared boards: when you create or join one, its content and edits are stored with Supabase and downloaded to participating devices.

Pages load directly from the sites that publish them, under each site's own terms and privacy policy; searches you type in Broadser go to Bing. Ordinary browsing and personal boards are not sent to Broadser. Shared boards are sent to Supabase when you use collaboration. Broadser has no advertising analytics or tracking. Diagnostic logging and native crash dumps start off. A minimal local clean/phase marker supports interrupted-session recovery. Enabled diagnostic logs are bounded and pruned to seven days at startup and hourly. Turning collection off retains old reports until you clear them or later enable pruning; starting or stopping already initialized native crash collection requires restarting Broadser. Standard diagnostic exports filter historical records through an allowlist. Explicitly included crash dumps may contain private memory data. OS-owned crash reports have a separate lifecycle. No report is uploaded automatically; review an export before sending it.

The version of Broadser for Mac from this website checks once a day for a newer version: it downloads a small file from this site that names the newest one, and then that version itself if it's newer. Nothing about you, your Mac, or your boards goes with those requests; like any download, they show our hosts (Netlify, and GitHub for the app itself) your IP address. Settings ▸ About turns the daily check off. The App Store version is updated by the App Store.

Ask AI uses Apple Intelligence on your Mac where your Mac has it, or the AI service you choose in Broadser ▸ AI & Connected Apps, with your own key for it — Anthropic, OpenAI, Google, or another listed there — or another model running on your Mac (LocalAI, Ollama, LM Studio). With Apple Intelligence or another model on your Mac, model inference runs locally; web searches and page-opening tools still contact external sites. With a service, your message and the board content the assistant reads — cards, pictures on them, the text of pages and PDFs it opens, and web searches it runs, which open in Side Peek and go to Bing — are sent from your Mac straight to that service, under your own agreement with it. Your API keys and Mac account sessions are encrypted on disk using a key protected by macOS Keychain. Personal board files, PDFs, exports, backups and diagnostic files are not encrypted by Broadser; use FileVault and protect any backup destination. Nothing is sent to a service before you turn it on, and none of it comes to us. Reading PDFs and finding related cards in search happen on your Mac, whichever model you use.

Connected apps (MCP) are off until you turn them on in the same place. Then AI apps on your Mac that have the key shown there — such as Claude Desktop, Claude Code, or Cursor — can read the board you have open. New settings do not grant board changes or signed-in page reading; you must allow those separately. Existing explicit grants are retained. Broadser accepts them only from your Mac. What those apps do with what they read is up to them and the services they use.

PDFs you add to a board are copied into Broadser's folder on your Mac. Pages and passages you send to Broadser from your browser (the Save to Broadser bookmark, or the Share menu) go from that app straight to Broadser on your Mac, and nowhere else. Share ▸ Read-only link saves the board as a web page and opens our Shared links page in your browser; nothing is sent to us unless you put that file there (see Shared links).

When a web page asks for your camera, microphone, or location, Broadser asks you first for that site, then macOS asks once for Broadser. Your answers are kept on your Mac; Page ▸ Reset Site Permissions clears them.

To delete local boards, use Home (Trash ▸ Empty Trash); clear website data and page pictures in Settings. Emptying Trash does not remove older backups, exports, or imported PDF copies. Delete those separately when erasing sensitive material; Settings ▸ Boards and storage ▸ Show in Finder opens the folder that holds the rest.

Shared boards and collaboration

Shared boards are separate from personal web and Mac boards. Supabase stores their snapshots, edit history, room membership, display names, session tools and invitation links. Authorized members can view the board; editors can change it; owners manage access. Outgoing online presence, cursor, selection, viewport and raised-hand information start off. Enabling presence shares those signals with connected members; turning it off withdraws them while edits continue to synchronize through the private collaboration channel. Membership names and comment authors remain part of collaboration. Invitation links normally expire after seven days. Revoking an invitation prevents new joins but does not remove existing members; remove those members separately.

Recipient-specific invitations store the invited email and display name and check the confirmed account email. A one-use email sign-in link authenticates its holder, so keep it private. Its expiry is separate from the board invitation. Organizers may supply a display photo from the LinkedIn profile submitted for an event. It can initialize your first verified Broadser identity after you review the cloud agreement; explicit identity choices are preserved. Supabase stores these photos at public object URLs: anyone with a photo URL can view it, and recipients may keep copies. You can change the displayed avatar in the identity editor or contact Support to request removal of a stored source photo.

Configured event workspaces also store verified participant bindings, current group assignments, section copies, revisions and access preferences to control event access. Own-group collaboration remains governed by room membership. Outside-group sections are closed by default and read-only; viewing requires both participants to choose reciprocal event access. You can change this choice later. Each new section read checks current membership, assignment and access settings. Foreign views are temporary and are not added to your local home-board cache; content already seen or copied cannot be recalled.

Selected-content sharing creates a separate, authenticated, read-only snapshot with its own invitations and access settings. Owners choose which frames and nested canvases are shared, hidden or shown as generic restricted placeholders. A private parent restricts all descendants. Hidden content, titles and related references are excluded from the recipient response. A shared snapshot does not automatically receive later source-board edits, and its invitation does not grant access to the source board or live editing. Stopping sharing removes viewer grants and invalidates invitations while retaining the owner’s saved snapshot; previously downloaded or captured content cannot be recalled.

Participating devices keep local shared-board copies for recovery and offline work. Signing out through Broadser clears this account's shared-board caches on the current device after its pending edits have synced. Access revocation cannot erase copies already downloaded, exported, backed up or captured by someone else. Boards are not end-to-end encrypted: Supabase and authorized service administrators can access stored content. Do not use Broadser for secrets requiring end-to-end encryption.

Deleting personal web board data does not delete shared boards or your Ken's Toolbox account. To delete a shared board you own, open Share & collaborate and choose Delete shared board; a member can choose Leave shared board. Deleting personal web board data removes the personal cloud board, its owned media and old public snapshot links after file cleanup. Shared rooms and selected-content snapshots are managed separately. It does not erase your shared Toolbox identity or other products’ data automatically. Failed cleanup remains visible and retryable. Use Support for a shared Toolbox account-deletion request and identify the scope; that request can affect other products. Public profile-avatar files in the shared project are outside automatic Broadser-only deletion. Provider backups and hosting logs have separate retention; deletion from the active service does not guarantee immediate erasure from those systems.

Who operates Broadser and your choices

Broadser is a free personal project operated by the creator of Ken's Toolbox. For privacy questions, a copy of your account information, or an account deletion request, contact the operator through Support. Describe whether your request concerns only Broadser or your shared Ken's Toolbox account; do not send passwords or API keys.

You can download account information in the account controls. This includes your profile, personal cloud-board record, owned public-share and shared-room metadata, own membership, invitation and section records, legal receipts and their archived documents, and scoped Storage metadata. Selected-content snapshots and their access records are not included in this account-information download; contact Support to request an export or erasure of those records. Complete shared-board exports and file-byte backups remain separate; downloads can contain private content and invitation links. You can also export boards, edit your profile, turn off public links, remove shared-board members, leave shared boards, or delete shared boards you own. Remote AI and connected apps are optional and can be turned off. Your privacy rights depend on where you live; requests for access, correction, deletion or a portable copy can be sent through Support. We may need to verify that you control the account before acting on a request.

Writing to us

If you write to us from the Support page, we receive your message, the Broadser you picked, and your email address if you give one, so that we can answer. Netlify, which serves this site, keeps the messages for us. We use them to handle your request and necessary privacy, security or legal follow-up. You can request deletion; a limited record may be retained when needed to document the action or meet legal obligations.

Deleting your data

On your board, open the account menu — the first button at the top of the sidebar — and choose Delete my board data. If the sidebar is hidden, open it with the sidebar button at the top left. This removes your board and its pictures from your account and from this browser — including cached page information and any backup copy — turns off the links you shared, and signs you out. Another browser you're signed in to keeps its own copy until it next opens your board; it then sees that the board was deleted and doesn't upload it again. To delete your account itself, write to us from the Support page.

Operator, purposes and your choices

Broadser is maintained by Ken Pan as a free personal project, part of Ken's Toolbox. Contact the operator through Support for privacy questions, access, correction, export, account deletion or complaints. We use account and cloud data to provide the features you request, support you and protect the service. We do not use your board content to train our own AI models. External AI providers apply their own policies to material you send them.

Where applicable data-protection law requires a legal basis, we process data needed to provide requested cloud features for performance of the service agreement, proportionate security and abuse-prevention data for legitimate interests, and data required by law for legal obligations. Optional device permissions and optional external integrations remain your choice; withdrawing a permission stops future access through that permission. Acknowledging this policy is not blanket consent to unrelated processing. To document the cloud agreement, we store your account ID, server-recorded acceptance time, terms and privacy versions and document hashes, and affirmative age/terms/privacy declarations. We do not collect a birth date, IP address or device fingerprint for this record. The record is retained with the account and deleted when the account is deleted from the active service; provider backups have separate lifecycles. It is not used for advertising.

Retention and international processing

Active account and cloud-board records are retained while you use those features, until deleted or no longer needed to provide the service, subject to necessary security and legal retention. Local data remains under your control until removed. Provider backups and logs follow the provider's configured lifecycle and are not immediately erased by an app deletion. Contact Support for the scope of a deletion request or information about applicable provider retention; we do not promise a fixed backup or log erasure period here. A narrowly scoped record of a complaint or deletion action may be retained where needed to establish its handling or meet legal obligations.

Supabase, Netlify and the other providers named above may process data outside your country. Cross-border access and legal protections can differ. We do not claim that data stays in your country. Applicable transfer arrangements and your rights depend on the service configuration and applicable law; contact Support with questions before uploading sensitive information.

Privacy rights, age limits and policy changes

Depending on applicable law, you may have rights to access, correct, delete or export personal information, restrict or object to processing, withdraw applicable consent, and complain to your local data-protection authority. Contact Support with your account email and requested scope. We may request proportionate verification; never send passwords or API keys. We will handle requests within applicable legal deadlines. Other people's downloaded copies and data they independently control may be outside our ability to erase.

Cloud accounts, collaboration and hosted sharing are intended for adults aged 18 or older. We do not knowingly offer those services to children. If you believe a child has supplied personal data, contact Support so we can investigate and remove it as appropriate. We do not collect a birth date or identity document for the age self-declaration.

Broadser does not use advertising tracking and does not change its behavior in response to browser Do Not Track signals. Sites loaded in cards or Side Peek, remote image hosts, older clients’ font/CDN providers and external integrations can receive IP addresses and use their own cookies or tracking under their own policies. This policy does not control those sites. Session and board storage support app operation.

The date above identifies the current policy. Material changes will be announced on the website or in the account experience where practicable; new consent will be requested if required. See the Terms of Use for use and sharing responsibilities.