After reviewing the policies, terms, roadmaps, etc of the Polar browser, a privacy researcher has publicly warned people against treating it as their primary browser.

In a detailed post on X, @iAnonymous3000 said that authenticated work data can actually leave the device. Retention is open-ended, and the company hasn’t made a product-wide promise that it won’t train models on customers’ data.

For those unaware, Polar is an AI-first browser that’s based on Chromium. It’s from Recursive Intelligence, and one of the founders previously worked on Perplexity’s Comet browser.

The main selling point (USP) is that an agent can click, type, and navigate the web while being logged in as the user. PiunikaWeb’s Dwayne Cubbins previously tried this browser, but it appears to target large work teams and doesn’t appear to be exactly tailored for basic individual browsing.

The breakdown of the privacy starts with the logged-in design. Polar says that cookies and passwords stay local. The post argues that the agent still sends page context, screenshots, recent pages, prompts, and more to Polar and its providers.

While providers are said to be banned from training on customer data, Polar’s roadmap describes a “users-and-data flywheel,” which asks whether it could train specialized models with enough data. This is an obvious logical gap. If customer data isn’t being provided for training, then how will Polar train specialized models, and on whose data?

Polar browser roadmap screenshot.

Furthermore, the browser retains conversations, runs, screenshots, memory, analytics, and other relevant records with no stated maximum period cutoff. There’s no self-service account deletion.

The Polar browser itself is a closed-source project, so there’s no reproducible build. The terms clearly prohibit reverse engineering, and since the agents read untrusted pages and screenshots while acting, there are risks of indirect prompt injection. The guardrails from Polar are argued to be rather insufficient.

At the time of writing, the Polar browser team hasn’t publicly acknowledged the thread. However, if you’re a regular user of this browser, then the privacy analysis recommends holding back on making it your default until there’s further public clarification about the privacy gaps.

Disclaimer: This article is based on a third-party review of Polar’s public policies and documents, and its accuracy relies heavily on the original source. It is not a self-performed security audit.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Sudhanshu K
244 Posts

I have been a consumer technology enthusiast for over 5 years. Thanks to my experience in software beta testing and product reviews, I've understood and learnt a lot about what bugs and issues bother people, and I spend time trying to simplify their solutions. I cover smartphones, software, social media, apps, AI, and most consumer tech gadgets. Actively pursuing a Computer Science bachelor’s degree. I'm mostly active on Twitter/X (@TechWhirlUlt), drop a DM or tag me if you want to share info or connect!