# Privacy and Data

This page lists the categories of data Octet Browser processes, where each is collected, and how long it is held. Use it for your privacy notice, your records of processing, and your data processing agreement with Octet.

## Data collected in the browser

The collector reads these categories from the user's browser and sends them to your edge:

| Category | Examples |
|---|---|
| Device and browser configuration | Time zone, language and regional format settings, screen properties, hardware properties such as processor count |
| Device rendering characteristics | Hashes of how the device draws graphics and produces audio |
| Browser environment | Permission states the browser reports without prompting, whether automation is active, and the presence of some browser extensions |
| Network information | IP addresses the browser's WebRTC stack reports |
| Network timing measurements | How long network round trips take, in `full` and `lite` mode |
| A device identifier | A hash derived from the characteristics above. It is sent to Octet, not returned to you, and discarded with the rest of the session's data. |
| A device key | The public half of a key pair the collector keeps in the browser. Octet uses it to check the collection and to refuse copies of it. It is not returned to you. |

The collector never asks for permission to use location, camera, microphone or notifications. It reads no cookies, no local storage and no page content.

## Data stored in the browser

The collector stores one item in the browser: the device key pair, in the IndexedDB database `octet` on your origin (store `keys`, entry `device-v1`). The private key is non-extractable, so page scripts can use it but can't read it out. It stays until the browser or the user clears your site's data, and some browsers clear script-written storage sooner. If the browser blocks storage, the collector keeps a key in memory for that page load and stores nothing.

In `passive` mode the collector makes no network measurements and does no WebRTC. The other categories are still collected.

## Data added by your edge

Your edge adds data about the connection itself:

| Category | Examples |
|---|---|
| IP address | The user's public IP address, taken from the TCP connection |
| Request headers | User agent, accepted languages, and browser client hints |
| Connection measurements | Round-trip timings and other properties of the browser's TCP connection to the edge |

## Where the data goes

1. The collector encrypts the browser's data to Octet and sends it to your edge over HTTPS. Your edge can't read it. Scripts on your own page can read it before it is encrypted, because the collector runs in the page.
2. Your edge adds its own data about the connection, and forwards everything to the Octet API over mutual TLS.
3. Octet computes a verdict and returns only the verdict to your backend.

In `full` and `lite` mode the browser also sends requests to three Octet network hosts, which see the user's IP address. See [Network and CSP](/docs/browser/reference/network/).

## How long data is held

| Where | What | How long |
|---|---|---|
| The user's browser | The device key pair | Until the browser or the user clears your site's data |
| Your edge | Network timing for a session | In memory, up to 60 seconds, deleted when forwarded |
| Octet API | The session's data and its verdict | In memory, up to 2 minutes |
| Octet API | A hash of each accepted collection, to refuse copies of it | In memory, up to 1 hour |
| Octet API | The location and network type found for a network block (a /24 for IPv4, a /48 for IPv6), with no IP address | In memory, up to 1 hour |
| Your backend | The verdict you fetched | Your choice |

Octet keeps no per-user record and builds no profile across sessions. Each session stands alone.

By default your edge logs no end-user data. Its diagnostic setting, `EDGE_DEBUG`, logs end-user IP addresses, so keep it off in production. See [Edge Configuration](/docs/browser/reference/edge-config/).

## Roles

You decide to use Octet and what to do with each verdict. Describe Octet Browser in your privacy notice as a fraud and compliance check that determines the country a session operates from. The [Octet Browser terms](https://octetproof.com/terms/browser/) set out Octet's obligations. For questions about data processing, write to [privacy@octetproof.com](mailto:privacy@octetproof.com).
