What we collect, and what we don't.
Effective 29 July 2026. Covers guerrillabots.com, the I² Recorder Chrome extension, and the Operative desktop app. Written to describe what actually happens in the system today, not a generic template.
Who we are
Guerrilla Bots Pvt. Ltd. (“Guerrilla Bots”, “we”), based in Bangalore, India, builds Guerrilla Process Automation (GPA) tools: I² Recorder (a Chrome extension that records browser actions), Operative (a Windows desktop app that runs and stores your automations locally), and Workbench (the web app at guerrillabots.com where recorded automations are reviewed and edited).
What we collect
Account information. Email address and authentication data, via Supabase Auth. If you sign up for the waitlist, also your name, company, and role if provided.
Workflow & automation data. When you record a workflow in Operative and push it to Workbench, we store: the sequence of actions (e.g. “click this element”, “type into this field”), element selectors, the Excel cell addresses/sheet names/column headers you choose to read or write during Excel Debrief, and the input/variable names in your workflow's data model. We do not ingest your Excel files or file contents wholesale. Only the specific cells, ranges, or table columns you explicitly select while recording.
Screenshots. Cropped images of the specific elements you interact with while recording (so you can visually confirm what a step does later), stored privately per account with access-controlled signed URLs.
Usage & diagnostic data. Which API endpoints were called, how long they took, and coarse token counts for AI calls, not the content of what you recorded or narrated. Used for rate limiting and debugging, not analytics on your business data.
Support & contact data. If you use the support form, whatever you choose to include: your message, an optional reply email, and an optional screenshot. This goes directly to our support inbox by email. It is not stored in our database.
Device information. A device identifier and app version for each machine running Operative, so we know which installs are active. No hardware fingerprinting beyond this.
What we deliberately don't collect
Credentials. Passwords and login credentials you use inside your automations (e.g. a portal login) are encrypted locally on your machine using Windows DPAPI (bound to your specific Windows user account) and are never transmitted to our servers. We have no cloud credential store today.
Your Excel/file contents. Operative reads and writes your files locally on your machine. Only the specific values you record (a cell, a column, a table) are sent to our AI calls for interpretation, and only those specific values are stored in your workflow. The underlying file itself never is.
Passive browsing. I² Recorder only captures DOM actions while you've explicitly started a recording session. It does not run in the background monitoring your browsing.
How we use it
To run the product: turning what you record into an editable, re-runnable automation, and letting you review/edit it in Workbench. To improve AI accuracy: cell context, narration text, and recorded actions are sent to our AI provider per-call to interpret what you meant (see below). To communicate: waitlist emails, support replies, and account-related notices. We do not sell your data, and we do not use your recorded workflow content to train AI models.
Third parties we use
Anthropic (Claude API): processes the specific cell context, file/folder descriptions, and narration text needed to interpret one recording step at a time. Subject to Anthropic's own data handling terms.
Supabase: our database, authentication, and private file storage provider (Postgres + object storage), hosted on Supabase's infrastructure.
Vercel: hosts guerrillabots.com and its API.
Resend: sends transactional email (waitlist confirmations, support form submissions).
Axiom: optional operational logging (endpoint, latency, error codes) for debugging. Not used for every deployment.
Data storage & security
Data in transit is encrypted (HTTPS/TLS). Screenshots are stored in a private object storage bucket, isolated per account, accessed only via time-limited signed URLs. Not publicly browsable. Credentials referenced by your automations stay on your machine, encrypted via Windows DPAPI; they are never bundled into a workflow file or uploaded.
We're a small, pre-revenue team. We follow reasonable security practices for a company at our stage, but we do not yet hold formal certifications (e.g. ISO 27001) or enterprise-grade secret storage, command signing, or audit-log system. Those are on our roadmap, not in place today. If your organisation needs a specific compliance posture before adopting Guerrilla Bots, contact us and we'll tell you honestly where we stand.
Data retention
Workflow data and screenshots are kept as long as your account is active. Support form submissions exist only as an email in our inbox. We don't retain a separate copy. You can request deletion of your account and associated data at any time (see Contact below).
Your rights
You can request access to, correction of, or deletion of your personal data by contacting us. If you're in India, this is handled consistent with the Digital Personal Data Protection Act, 2023; if you're elsewhere, we'll do our reasonable best to honor equivalent rights (e.g. GDPR-style access/erasure requests).
Children's privacy
Guerrilla Bots is a business automation tool, not directed at children. We don't knowingly collect data from anyone under 18.
Changes to this policy
If this changes materially, we'll update the effective date above. Significant changes will be called out, not buried in a diff.
Contact
Questions, data requests, or anything else: guerrillabots@gmail.com, or use the support form.