Privacy policy
Last updated: May 26, 2026
CITRO LABS PTE. LIMITED ("Citro," "we," "us," "our") is dedicated to safeguarding your privacy and personal data. This Privacy policy ("Privacy policy") outlines how we collect and process your personal data. This Privacy policy applies to the EGOBOT AI browser application (desktop and mobile), the EGOBOT browser extension, our website (https://www.ego.app/), our cloud-based AI agent service, and any integrations we offer with third-party messaging or communication platforms, and any associated subdomains or services, and its associated subdomains (collectively, our "Services").
If you are under 14 years old, do not meet the age requirements for using or accessing the Services in your jurisdiction, or if there are other legal restrictions applicable to your user status, please comply with local laws by either refraining from using the Services or reviewing this Privacy policy under the supervision of your legal guardian ("Guardian"). You should only access or use the Services after obtaining your Guardian's consent as required by applicable law. If you are a parent or Guardian and become aware that your child has provided us with personal data, please contact us immediately. Should we learn that personal data has been collected from anyone under 14 years old (or the applicable legal age) without verified Guardian consent, we will promptly take measures to delete such data from our servers.
Please read this Privacy policy carefully and in its entirety before using or continuing to use our Services. If necessary, make appropriate decisions based on the guidelines outlined herein. Failure to provide certain personal data may result in our inability to offer you the Services, restrictions on your use of the Services, or the Services not functioning as intended.
If you are located in the European Economic Area (EEA), the United Kingdom or Switzerland (collectively, the "EEA+" areas), the United States, please also read carefully and fully and consent to the EEA+ Addendum, the US Addendum to this Privacy policy respectively.
1. How We Collect and Use Your Personal Data
We collect data that you actively provide when using the Services, as well as data automatically generated during your use or interaction with the Services, through the following methods:
Account Registration. When you register an account with us, we will collect information associated with your account, including your username, email address, phone number, and account credentials. We may also collect verification codes to confirm your identity.
Citro Services. We offer interactive services powered by generative AI model technology combining a browser or desktop client running on your device with a cloud-based AI agent that operates on an all-day basis. You may provide input ("Content") to the Services, including prompts, uploaded materials such as files and images, or direct operational instructions by interacting with the buttons available in the operation interface. We will collect and process such Content for task execution. When you use the browser extension, we may also collect webpage structure and metadata.
Browser Activity Data. When you use the EGOBOT AI browser, we collect data necessary to deliver browsing and AI-assisted features. This includes but without limitation: (i) URLs and page titles of websites you visit; (ii) page content (text, structure, and metadata) of websites you access, to the extent necessary to deliver AI-powered assistance; (iii) your interactions with webpages, including clicks, scrolls, and form interactions (excluding passwords, payment information, and other sensitive credentials); (iv) search queries entered through the browser; (v) download history; and (vi) browser configuration and extension settings. Such data could include sensitive personal data. For your security, please do not input sensitive personal data into our Services.
AI Agent and Task Execution Data. When you instruct the cloud-based AI agent to perform tasks on your behalf (e.g., browsing webpages, filling forms you have authorized, sending messages through connected accounts, etc.), we collect and process: (i) the natural-language instructions you give the agent; (ii) the intermediate steps, tool calls, and webpage interactions the AI agent performs to complete the task; (iii) the contents of webpages or applications the agent accesses on your authorization; (iv) the result of each task. Task execution logs are retained on our cloud servers so that the AI agent can resume tasks across sessions.
Browser Session and Authentication Data. When you instruct the AI agent to perform tasks or applications where you are already logged in, the AI agent operates by accessing browser session associated with your authenticated state on those sites. This AI agent may utilize session identifiers (such as session cookies) that your browser established with third-party websites, solely to carry out the specific tasks you have authorized. We do not collect, store, or transmit your login credentials (such as usernames or passwords) in connection with this feature. The AI agent accesses only the active session already present in your browser at the time of task execution. Such session access may enable the AI agent to view, interact with, or retrieve content from websites and applications as if you were operating them directly, including content that is only accessible because you are logged in. You expressly authorize this session-based access each time you initiate a task that requires the AI agent to interact with an authenticated website or application. The data accessed through your existing browser session is processed solely for the purpose of completing the task you have instructed and is subject to the retention practices described in Section 4. You may revoke this access at any time.
Multi-Platform Integration Data. If you choose to connect third-party messaging or communication tools to the Services, we will, to the extent technically required and only with your explicit authorization, access contact identifiers, the messages or files involved in the specific tasks you have asked the AI agent to perform on the connected third party platforms. We do not export your message history beyond what is required to complete the authorized task and you may revoke any platform integration at any time.
Voice Input Data. The Services include a voice-input feature. When you invoke voice input, we collect the audio you provide and transcribe it to convert it into text instructions for the Services. You may disable voice input at any time, and you may request deletion of your voice recordings as described in Section 5.
Screenshots and Screen-Capture Data. When you activate the AI agent, the Services may automatically capture a screenshot of your current screen or active window to provide the AI agent with the visual context it needs to understand and complete your request. Screen recordings may also be captured when you explicitly invoke a screen-recording feature. Screenshots are processed solely for the purpose of fulfilling the immediate request, are not used for advertising, and are deleted or de-identified once the task is complete unless you have separately opted in to longer retention for product-improvement purposes. You may disable automatic screenshot capture at any time.
Sensitive Information Protection. We implement technical measures designed to exclude clearly sensitive locations from the Service's data-collection scope. Sensitive information including passwords, payment-card primary account numbers, and other credentials autofilled by your browser or operating system are not transmitted to the AI agent and are not stored by us in association with your AI inputs. Despite these measures, you should not deliberately place sensitive personal data into the working folder or paste credentials into AI prompts.
Our Services are powered by one or more third-party generative AI models. When you interact with AI features, your inputs (prompts, uploaded files, and browsing context shared with the AI) may be transmitted to these third-party AI providers for the purpose of generating responses. We take steps to contractually restrict those providers from using your data for their independent model training. Please refer to Section 3 for further details on our third-party service providers.
When you use our Services, according to the functional needs, we will request you authorize the camera, photo album (storage), microphone, screenshot and screen record, accessibility, file management, command line or other operating system-related permissions based on the type of information you input. If you refuse to authorize, you will not be able to use certain functions such as taking photos or inputting image and voice information, but this will not affect your use of other functions of the Services.
When you use the Services in health, financial, legal or other specialty-related scenarios, we may collect your health-related information, financial information or other information you voluntarily input to our Services. Based on the content you input, we will generate responses, answers and consultation summaries or reports (which do not constitute medical, financial, legal or other professional advice) for your reference.
When you issue a search request during a conversation with AI, we will automatically receive the information you actively input to provide you with real-time search results. For example, when you ask us about nearby locations, in order to answer your question, we may collect your precise geographical location. This geographical location may include precise location information obtained through GPS sensors, WLAN access points, Bluetooth, and base station sensors. We only collect your precise geographical location when you have a clear need to find nearby locations or provide other location based services. Precise geographical location information is sensitive personal data. If you refuse to provide it, we will not recommend the nearby location-related information or provide other location based services based on the geographical location obtained through GPS sensors, but this will not affect the normal use of other functions we provide. We will only display content or services that may be relevant to you based on the district-level geographical location obtained through network location information (such as base stations, IP addresses, and WLAN).
Profiling and Automated Processing. We may use automated means to analyze your browsing behavior, task history, AI agent execution logs, content preferences, and usage patterns to create a profile that enables personalized features such as AI recommendations, tailored search results, and relevant content suggestions. This profiling does not produce legal or similarly significant effects on you. Where such profiling is used in connection with targeted advertising, you have the right to opt out as described in Section 5 and the applicable regional Addenda.
If the Content you input or submit includes personal data relating to any other individual, you are responsible for ensuring that you have obtained all necessary legal authorizations or consents before providing such data. This is to prevent the unauthorized or inappropriate disclosure of others' personal information.
In order to maintain and enhance the performance and quality of the Services, we may utilize the Content you submit and the corresponding output to optimize our Services. Such use will be conducted only after the information has been securely encrypted, thoroughly de-identified, and rendered incapable of being re-associated with any specific individual. If you do not wish for your personal data to be processed in this manner, you may opt out by contacting us through the channels specified in Section 5 of this Privacy policy.
We will not collect sensitive information such as identification documents and numbers, data concerning health, bank accounts, passwords, etc. However, due to technical limitations and the way you use our Services, we may unwittingly collect other personal data that you voluntarily input into the Services, which may include the said sensitive information. We will immediately delete or anonymize such information once noticed by us. For your security, please do not input sensitive information into our Services.
Feedback. When you submit feedback to us, we will collect information such as your description of the issue, any attached supporting materials, your email address, and the name of the contact person, to understand the nature of your feedback and your specific needs. This information is necessary to provide the feedback-related services. We may use your email address or other contact details to verify your identity, clarify your concerns, provide relevant support, and help resolve any issues you encounter. To assist with feedback related to your use of the Services, we may access your usage data, including conversation history, content you have liked, and past feedback submissions.
Notification. You acknowledge and agree that we may use the contact information you provide (such as your email address) to send you various notifications related to the operation of the Services. These may include messages for identity or security verification, user updates, experience research, and dispute resolution. We may also send you promotional information about our services, features, or events via the contact details you've provided. If you prefer not to receive such promotional messages, you may unsubscribe using the method included in the message or contact us directly to opt out.
Payment Information. If you subscribe to paid features of our Services, we collect payment-related information necessary to process transactions, which may include your billing name, billing address, and payment method details. Full payment card details are processed directly by our third-party payment processors and are not stored on our servers.
Safeguarding. To protect your account security and improve our service quality, we will automatically collect certain information generated during your use of the Services.
Please find below the legal basis for our processing of your personal data:
| Purpose | Type of Data | Legal Basis |
|---|---|---|
| To provide, maintain and facilitate any products and services offered to you with respect to your EGOBOT account, which are governed by our Terms of Service | Identity and Contact Data; Payment Information; Feedback; Inputs and Outputs; Technical Information | Contract |
| To provide, maintain and facilitate optional services and features that enhance platform functionality and user experience | Identity and Contact Data; Feedback; Inputs and Outputs; Technical Information | Consent (for example for precise device location or for health app integrations); Legitimate interests. It is in our and our users' legitimate interests to expand our product features and deliver additional services that enhance platform functionality and user experience. |
| To communicate with you and to promote our Services | Identity and Contact Data; Communication Information; Technical Information | Where necessary to perform a contract with you, such as processing your contact information to send you a technical announcement about the Services; Your consent when we ask for it to process your personal data for a specific purpose that we communicate to you, such as processing your contact information to send you certain forms of marketing communications; Legitimate interests. It is in our legitimate interests to promote our Services and to send direct marketing. |
| To create and administer your EGOBOT account | Identity and Contact Data; Payment Information; Feedback | Contract |
| To facilitate payments for products and services provided by EGOBOT | Identity and Contact Data; Payment Information | Contract |
| To prevent and investigate fraud, abuse, and violations of our Terms of Service, unlawful or criminal activity, unauthorized access to or use of personal data or EGOBOT systems and networks, to protect our rights and the rights of others, and to meet legal, governmental and institutional policy obligations | Identity and Contact Data; Payment Information; Inputs and Outputs; Technical Information | Legitimate interests; Legal obligation. It is in our legitimate interests to protect our business, employees and users from illegal activities, inappropriate behavior or violations of terms that would be detrimental. We also have a duty to cooperate with authorities. |
| To investigate and resolve disputes | Identity and Contact Data; Inputs and Outputs; Feedback | Legitimate interests; Legal obligation. It is in our legitimate interests to fully understand and make reasonable efforts to resolve customer complaints in order to improve user satisfaction. We also have a legal obligation in some cases. |
| To investigate and resolve security issues | Identity and Contact Data; Feedback; Technical Information; Inputs and Outputs | Legal obligation; Legitimate interests. It is in our legitimate interests to protect user data and our systems from intrusion or compromise through monitoring and swift response. We also have a legal obligation to provide adequate security safeguards. |
| To debug and to identify and repair errors that impair existing functionality | Identity and Contact Data; Feedback; Technical Information | Legitimate interests. It is in our legitimate interests to maintain continuous functioning of our services and rapid correction of problems to ensure a positive user experience that encourages engagement. |
| To improve the Services and conduct research (excluding model training) | Identity and Contact Data; Feedback; Technical Information; Inputs and Outputs | Legitimate interests. It is in our legitimate interests and in the interest of EGOBOT users to evaluate the use of the Services and adoption of new features to inform the development of future features and improve direction and development of the Services. Our research also benefits the AI industry and society: it investigates the safety, inner workings, and societal impact of AI models so that artificial intelligence has a positive impact on society as it becomes increasingly advanced and capable. |
| To improve the Services and conduct research (including model training) | Feedback; Inputs and Outputs | Consent (when users submit Feedback); Legitimate interests. It is in our legitimate interests and in the interest of EGOBOT users to evaluate the use of the Services and adoption of new features to inform the development of future features and improve direction and development of the Services. Our research also benefits the AI industry and society: it investigates the safety, inner workings, and societal impact of AI models so that artificial intelligence has a positive impact on society as it becomes increasingly advanced and capable. |
| To enforce our Terms of Service and similar terms and agreements | Identity and Contact Data; Inputs and Outputs; Technical Information | Contract; Legitimate interests. In certain circumstances outside of the performance of our contract with you, we may rely on legitimate interests. It is in our legitimate interests to enforce the rules and policies governing use of our services, to maintain intended functionality and value for users. We aim to provide a safe, useful platform. |
2. How We Use Cookies and Other Similar Technologies
We use cookies to monitor which parts of our website you visit. Cookies are small data files stored by your browser on your device. While not essential for basic website use, cookies help improve performance and functionality. Without them, some features like videos might not work properly, and you may need to log in each time because your previous login won't be remembered. Most browsers let you disable cookies, but this may restrict or block certain website functions. Importantly, we never store personal data within cookies.
We categorize cookies as follows: (i) Strictly Necessary Cookies: required for the operation of our Services (no consent required); (ii) Functional Cookies: remember your preferences and settings; (iii) Analytics Cookies: help us understand how you use our Services; (iv) Advertising/Targeting Cookies: used to deliver relevant advertisements and to enable targeted advertising.
3. How We Share, Transfer, or Disclose Your Personal Data
AI Model Providers: Third-party providers of generative AI model APIs that process your inputs and browsing context on our behalf to generate AI-powered responses and features.
Connected Platform Providers: Where you have connected a third-party messaging or communication platform, the contents of the specific messages or files needed to complete your authorized task will pass through that platform's infrastructure under that platform's own terms.
Business Partners: In order to facilitate our business operations and deliver specific services, we may share personal data with our business partners, such as hosting, support, cloud infrastructure, security monitoring, analytics, and payment providers.
Business Transactions: In the event of a strategic transaction, restructuring, bankruptcy, acquisition, or transfer of services to another provider, your personal data may be disclosed to relevant counterparties for due diligence and continuity of services.
Government Agencies or Other Third Parties: We may disclose your personal data to comply with legal obligations, protect rights and security, prevent fraud, or mitigate legal risks.
Affiliates: We may share personal data with our affiliates, who are permitted to use such data in accordance with this Privacy policy.
4. How We Store and Protect Your Personal Data
We will retain your personal data solely for the duration necessary to deliver our Services to you or to fulfill other legitimate business purposes, including dispute resolution, ensuring safety and security, or meeting legal requirements.
The retention period for personal data will be determined based on factors including:
- The purpose for which we process the data;
- The amount, nature, and sensitivity of the data;
- The potential risk of harm from unauthorized use or disclosure; and
- Any legal requirements that we are subject to.
5. How You Can Exercise Your Personal Data Rights
You have the following legal rights concerning your personal data:
- Access your personal data and information relating to how it is processed;
- Delete your personal data from our records;
- Rectify or update your personal data;
- Transfer your personal data to a third party (right to data portability);
- Restrict how we process your personal data;
- Withdraw your consent where consent is the legal basis; and
- Lodge a complaint with your local data protection authority.
You can exercise these rights by submitting your request to privacy@citrolabs.ai.
6. How We Update the Privacy policy
To continually improve our Services, updates and changes may be made from time to time. We will update this Privacy policy accordingly, and any such updates will become an integral part of this Privacy policy.
7. How to Contact Us
If you have any complaints, suggestions, or inquiries regarding personal data protection, or if you have questions about this Privacy policy, please contact us at privacy@citrolabs.ai.
8. EEA+ Addendum
If you are located in the European Economic Area (EEA), the United Kingdom or Switzerland (collectively, the "EEA+" areas), please refer to this EEA+ Addendum. This addendum complements our Privacy policy and provides detailed information on how we handle your personal data in EEA+ regions.
A. Who is the data controller?
The data controller is CITRO LABS PTE. LIMITED, registered address at 67 AYER RAJAH CRESCENT, #02-10, SINGAPORE 139950, and its affiliates. To contact our GDPR representatives, please contact privacy@citrolabs.ai.
B. What types of personal data do we collect and how do we collect it?
Please see Section 1 above.
C. For what purposes do we process personal data?
Please see Section 1 above.
D. What lawful bases of processing and legitimate interests do we rely on?
Please see Section 1 above.
E. What categories of recipients receive personal data from us?
Please see Section 3 above.
F. Where is your personal data processed and on what basis do we transfer personal data across borders?
We may transfer and disclose personal data to third parties in jurisdictions including California. To ensure an adequate level of data protection, we implement appropriate safeguards and data transfer mechanisms with our processors as required.
G. How long do we process personal data?
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations.
H. What data protection rights do you have?
In the EEA, Switzerland and the UK you have rights including access, correction, deletion, restriction, portability, withdrawal of consent, and complaint to supervisory authorities.
- EEA: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- United Kingdom: https://ico.org.uk/global/contact-us/
- Switzerland: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html
I. Are you required to provide us with your personal data?
Providing personal data to us is voluntary; however, without certain personal data, we may be unable to deliver our Services to you.
J. Automated decision-making
We use automated processing to provide AI-powered features, including personalized recommendations and content suggestions. These processes do not produce decisions that have legal or similarly significant effects on you.
9. US Addendum
If you reside in Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island or California, please refer to this US Addendum.
Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island
Subject to applicable law, you may request confirmation, access, correction, deletion, and opt-out rights concerning targeted advertising, sale of personal data, and qualifying profiling activities.
California
Notice of Collection: Please see Section 1 above for the categories of personal information we collect.
CCPA Privacy policy
A. Right to Know About Personal Information Collected, Disclosed, or Sold
California residents may request details regarding personal information collected, used, disclosed, or sold.
B. Our Personal Information Handling Practices over the Preceding 12 Months
We may collect identifiers, network activity, audio/visual information, and inferences, and disclose or share relevant categories as permitted by law.
C. Right to Request Correction or Deletion of Personal Information
You may request correction or deletion by contacting privacy@citrolabs.ai.
D. Notice of Right to Opt-Out of Selling/Sharing of Personal Information
You have the right to opt out of sale or sharing where applicable.
E. Right to Non-Discrimination for the Exercise of a Consumer's Privacy Rights
You may not be discriminated against because you exercise your privacy rights under applicable law.
F. Right to Limit Use of Sensitive Personal Information
You have the right to request limits on use of sensitive personal information as permitted by law.
G. Verification Process and Authorized Agents
Only you, or a legally authorized person, may submit requests concerning your personal information, subject to verification requirements.
H. Contact Information
For privacy rights requests, contact privacy@citrolabs.ai.
10. Canada Addendum
These supplemental disclosures contain additional information relevant to residents of Canada and should be read together with the rest of this Privacy policy.
Consent. By expressly consenting to this Privacy policy, you confirm you have read, understand, and consent to the collection, use, processing, and disclosure of your personal data in accordance with this Privacy policy.
Cross-jurisdictional Transfers. By providing us with personal data, you acknowledge and agree that your personal data may be transferred or disclosed to other jurisdictions for processing and storage outside of Canada.
Quebec Residents. Residents of Quebec may have additional rights under Act 25, including data portability and de-indexation requests.