Twitch updated its terms so Amazon can train AI models on streamer content, and the opt-out is a toggle sitting in a settings page. Streamers noticed. Amazon’s position is that creators can turn it off whenever they like, which is true, and also the reason the design works.

An opt-out toggle is a fire exit at the back of a building nobody has ever walked to.

Opt-out means you do the work

The interesting part was never the collection. Everybody collects. The move is making collection the resting state, so that silence counts as a yes and the burden of objecting lands on the person with the least time to read policy documents.

You can trace the same shape across the last eighteen months of AI data stories. Anthropic settled for $1.5 billion over training material it shouldn’t have had. The Hugging Face breach put model artifacts and tokens somewhere they were never supposed to sit. Different failures, same precondition: the data had already left the place it started, and once it moves you’re negotiating with someone else’s retention policy instead of your own hard drive.

So the question worth asking about any AI tool isn’t whether the company is trustworthy. It’s how many machines your data touches before it reaches a model.

The part nobody checks about browser agents

This is where I think most people running a cloud AI browser agent have no idea what the architecture actually is, because the product surface looks identical to a local one: sidebar, chat box, “summarize this page,” done.

Underneath, a cloud agent works like this. You ask it something about the tab you’re in. The extension serializes the page, which in practice means the DOM, often a screenshot, and any text you highlighted. That payload goes to the vendor’s backend. The backend assembles a prompt and forwards it to whichever model provider they’re using. The response comes back through the same chain in reverse.

Every hop in that chain is a place where logging happens, and vendor logging is normal engineering practice rather than anything sinister — you need request logs to debug, you need traces to figure out why a task failed, and most privacy policies reserve the right to retain that material for some window measured in months. What’s on the page when this happens is the part people gloss over. It’s your Gmail thread. Your Salesforce opportunity. The internal wiki page with the incident postmortem on it. A half-filled form containing a client’s address. Whatever your logged-in session can see, the agent can see, and whatever the agent can see is what gets packaged up and shipped.

None of this is hidden. It’s in the docs. But it’s in the docs the way the Twitch toggle is in the settings, which is to say: technically available, practically invisible. We wrote more about the specific data flows in AI Browser Safety: What Gets Sent Where.

Two logs, one of them optional

Your tab, then the vendor’s server, then the model provider. The middle one is the hop you didn’t ask for and can’t inspect.

BYOK removes the middle machine

Bring-your-own-key isn’t really a privacy feature. It’s a routing change that happens to have privacy consequences.

With a local browser agent using your own API key, the page content never leaves the tab. The extension builds the prompt in your browser and posts it directly to Anthropic, or OpenAI, or Google, or DeepSeek — whichever provider’s key you pasted in. There’s no vendor backend in the middle, so there’s no vendor log to opt out of, no retention window to read about, and no third party whose terms can change next quarter. Your relationship is with the model provider, and that provider’s API terms already say they don’t train on API traffic by default.

Dassi runs this way. It lives in the Chrome side panel, reads the tab you’re already looking at with the sessions you’re already logged into, and sends prompts straight to your chosen provider. If you’d rather not deal with API keys, you can sign in with an existing ChatGPT subscription instead. It’s on the Chrome Web Store, free, and the whole design argument is basically the one in AI Data Mining Makes BYOK Essential.

Does that make you invulnerable? Hell no. Your provider still sees your prompts, and if you paste something dumb into a chat window the model still reads it. But there’s a real difference between one party seeing your data because you deliberately sent it there, and three parties seeing it because that was the setting when you installed the thing.

Amazon’s streamers get to hunt for a toggle. I’d rather use software where the toggle doesn’t need to exist, and where the boring default is the one I’d have picked anyway if anyone had bothered to ask.