Project T900 privacy policy

Effective: 1 October 2026 · Applies to: Project T900 (called Anubiss before 0.17.0), 0.16.0 and later: the web app, the browser extension and the desktop app; and its website, t900.si · Published by: WildOwlLab · Contact: [email protected]

In short

What Project T900 stores, and where

Project T900 stores your library on your device only:

Project T900 does not keep:

Project T900 does not add encryption of its own to what it stores: the data is protected by your device, your browser and your operating-system account. Anyone who can use your account can open it, so use a login and, where you can, disk encryption.

What Project T900 reads, and when

Project T900 works only on what you give it, when you give it:

Project T900 never captures your screen, never reads your browsing history, other tabs, your chats or your keystrokes, never watches the clipboard and never listens in the background.

What leaves your device

Nothing, by Project T900's doing. Project T900 makes no network requests except to load its own files:

Your text leaves your device only when you send it:

Other companies are involved only in getting Project T900 to you:

Sharing between the web app, the extension and the desktop app

Each part of Project T900 keeps its own library. You can let them share one, on the same computer, with no network involved. Sharing is off until you turn it on:

Browser extension permissions

The extension asks for as little as it can, and for no access to websites beyond those below:

PermissionWhy
activeTabTo see the address and title of the tab you opened the Project T900 popup on, so it knows whether it can help on that site, and to talk to that tab. Only that tab, only when you open the popup.
storageOnly its in-memory session area, never written to disk: to hand your prompt or selected text from the popup to the full review page when you choose Open full review (cleared as soon as that page reads it), and to remember when to try reconnecting to the desktop app.
alarmsOnly to reconnect to the desktop app while sharing with it is on.
nativeMessaging (optional)To share your library with the Project T900 desktop app. The browser asks you for it when you turn on Share with the desktop app, and not before.

Its script on web pages runs only on chatgpt.com, chat.openai.com, claude.ai and gemini.google.com, to read your prompt or selected text when you ask and to insert a context pack when you ask; and on localhost and 127.0.0.1, to connect to a copy of the web app on your own computer when you turn on sharing. It asks for no other site access and no permission to read your tabs, history, bookmarks, cookies, downloads or clipboard.

Sensitive content

Project T900 looks, on your device, for a few unmistakable kinds of secret: private keys, API keys and other labelled secrets, passwords, payment card numbers and identity numbers. It flags what it finds, leaves flagged source text out of packs by default, and keeps memories marked sensitive out unless you include them. It is not a complete check for secrets or personal information and can miss things: review what you share.

Your control

WildOwlLab holds no data about you, so there is nothing for us to access, correct, export or delete on your behalf. All of it is on your device, under your control.

Children

Project T900 is not directed at children and collects no data from anyone, including children.

Changes to this policy

If what Project T900 stores, reads or sends ever changes, this policy will change first, with a new effective date, and the release notes for that version will say so.

Contact

Email [email protected] with questions about this policy or about how Project T900 handles your data.