Security and privacy
Broadser is a free personal project by Ken Pan, part of Ken’s Toolbox. This page explains the controls and limits of the current version; the Privacy Policy and Terms of Use remain the governing disclosures.
Mac release status: Mac 1.0.23 is available as a signed and notarized download. Account export, dialog-safe screenshots and stricter update paths are included. The updated web sharing and account export controls are also available.
Where your data goes
Personal Mac boards are stored locally. Their files, backups and exports aren’t encrypted by Broadser. Protect your Mac account and disk, and treat exported files as private. Optional cloud accounts and collaboration use Supabase and HTTPS. Cloud boards aren’t end-to-end encrypted: the service and its infrastructure providers can process their contents.
Public snapshot links allow anyone with the link to read the published copy. Selected-content invitations also carry access credentials; recipients must sign in. A recipient may keep a copy after you stop sharing. Websites opened on Mac and connected AI tools have their own data practices.
Account and sharing controls
Cloud requests check account identity, active sessions and access permissions on the server. Creating, updating and joining selected-content views requires the current cloud agreement. Reading, exporting, stopping access and deleting an owned saved view remain available without renewing that agreement.
On Mac and the web, in Privacy settings, Download account information includes your owned selected-content snapshots and access records. The download may contain private notes and invitation links. Export boards separately for their external file bytes and complete live shared-board contents. In a saved view’s sharing panel, Delete saved view… removes that independent cloud copy and its access records; it doesn’t delete your source board or recipients’ copies.
Mac protection and connected tools
Website downloads are signed, notarized and use a hardened Electron runtime. Mac 1.0.23 automatic updates accept official release paths with archive size and SHA-256 metadata, and the native updater checks application signatures. These controls reduce tampering risk; they can’t make software impossible to reverse engineer or exploit.
Connected AI apps are off by default. Enabling them grants access to the open board, with separate controls for edits and page text. In Mac 1.0.23, their screenshot tool refuses captures while Home or a dialog is visible. Keep secrets out of boards you expose to a connected tool. API credentials stay in the Mac credential store when available; exported account information and ordinary board files don’t contain a protected vault.
Report a vulnerability
Use Support → Security concern. Describe the affected version, a minimal reproduction and the impact. Don’t send passwords, access tokens, API keys or other people’s data. Test only your own local copy, your own account and data you have permission to use; don’t disrupt production or access other accounts.
There is no paid bug bounty or guaranteed response time. Privacy requests, account deletion, copyright complaints and appeals use the same Support channel.