Do NOT use Polar as your primary browser if you care about privacy.
— Sooraj (@iAnonymous3000) August 27, 2026
I read the policy, terms, roadmap, templates, and repo. The red flags:
1. Authenticated content can leave your device
Polar says cookies and passwords stay local. But its agent sends page context, screenshots,… https://t.co/wgEbIUmcY8 pic.twitter.com/3inR8bejND
After reviewing the policies, terms, roadmaps, etc of the Polar browser, a privacy researcher has publicly warned people against treating it as their primary browser.
In a detailed post on X, @iAnonymous3000 said that authenticated work data can actually leave the device. Retention is open-ended, and the company hasn’t made a product-wide promise that it won’t train models on customers’ data.
For those unaware, Polar is an AI-first browser that’s based on Chromium. It’s from Recursive Intelligence, and one of the founders previously worked on Perplexity’s Comet browser.
The main selling point (USP) is that an agent can click, type, and navigate the web while being logged in as the user. PiunikaWeb’s Dwayne Cubbins previously tried this browser, but it appears to target large work teams and doesn’t appear to be exactly tailored for basic individual browsing.
The breakdown of the privacy starts with the logged-in design. Polar says that cookies and passwords stay local. The post argues that the agent still sends page context, screenshots, recent pages, prompts, and more to Polar and its providers.
While providers are said to be banned from training on customer data, Polar’s roadmap describes a “users-and-data flywheel,” which asks whether it could train specialized models with enough data. This is an obvious logical gap. If customer data isn’t being provided for training, then how will Polar train specialized models, and on whose data?

Furthermore, the browser retains conversations, runs, screenshots, memory, analytics, and other relevant records with no stated maximum period cutoff. There’s no self-service account deletion.
The Polar browser itself is a closed-source project, so there’s no reproducible build. The terms clearly prohibit reverse engineering, and since the agents read untrusted pages and screenshots while acting, there are risks of indirect prompt injection. The guardrails from Polar are argued to be rather insufficient.
At the time of writing, the Polar browser team hasn’t publicly acknowledged the thread. However, if you’re a regular user of this browser, then the privacy analysis recommends holding back on making it your default until there’s further public clarification about the privacy gaps.
Disclaimer: This article is based on a third-party review of Polar’s public policies and documents, and its accuracy relies heavily on the original source. It is not a self-performed security audit.