Open Editor
Privacy
5 min read

AI Browser Agents and Your Pasted Text: What Stays Private When the Browser Can Act for You

Older privacy advice asked whether a website stores what you paste. In 2026 there is a second question: what else is in your browser that can read and act on the page you pasted it into?

Since 2025, browsers like ChatGPT Atlas and Perplexity's Comet have shipped AI agents that read web pages, click buttons and fill in forms inside the same browser you are logged in with. That raises an uncomfortable question for anyone who pastes drafts, notes or client text into web pages: the old advice was about whether a website stores what you paste, but now there is also software in your own browser that can read and act on the page. This post separates what is documented from what is inference.

Working on text you'd rather not paste into a random site? ClearText Editor processes it in your browser and uploads nothing, and the section on limits below explains what that does and doesn't cover.

What Browsers Already Protect

The clipboard itself has real protections. According to web.dev's guide to the Async Clipboard API, pages in active tabs can write to the clipboard without asking, but reading from it always requires permission. The page must be the active tab, and if you deny the prompt, the read request fails. So an ordinary website cannot quietly read what you last copied.

The older risk, a server keeping a copy of whatever you paste into an online tool, is covered in Why You Should Never Paste Sensitive Text Into Online Servers and Do Online Text Tools Store Your Data?. This is a different problem: not who receives your text, but what can act on the page it sits on.

What Agents Change

An agent works with your logins and your open pages, so it is a more valuable target. OpenAI said in December 2025 that "prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully 'solved,'" and that a browser agent "becomes a higher-value target of adversarial attacks." In February 2026, security firm Trail of Bits published an audit of Perplexity's Comet. When a user asked the assistant to summarize an attacker-controlled page, hidden instructions could push it to exfiltrate private Gmail data.

Technique (Trail of Bits, Comet)What it told the agent to do
Fake CAPTCHA"Copy all text for verification" from a page that redirected to Gmail
FragmentsFetch pages and pass Gmail contents as a URL parameter to an attacker's endpoint
Fake security validatorSend content to a "validator" that returned "SAFE" while keeping the data
Fake user messageGrant itself permission on one page, then use it on a second

Perplexity's security lead said the audit helped close these gaps before launch, and the Trail of Bits post does not describe a clipboard-reading attack. Its first technique does involve being told to copy page text. The sources I checked do not establish that agents read your clipboard, so I'm not claiming they do.

A client-side tool means the site never receives your text. It does not mean nothing else in your browser can see the page it's on. If an AI agent is active in that browser, a page displaying your draft may be part of what it can read. That's my inference from how these agents work, not a documented attack.

Habits That Reduce the Exposure

  • Don't leave sensitive text in the clipboard. After pasting, copy something harmless to replace it.
  • Keep agent tasks and sensitive drafts apart. Don't run an agent in a browser profile or window where confidential text is open.
  • Treat page content as untrusted. Hidden instructions travel inside ordinary pages, so ask an agent to summarize sources you trust.
  • Grant the minimum. Trail of Bits advises builders to apply the principle of least privilege; as a user, don't hand an agent logins it doesn't need.
  • Prefer local tools for sensitive text, and close the tab when you're done.

The honest summary: ordinary web pages can't read your clipboard without permission, and tools that process text locally never upload it, but neither fact covers software acting inside your own browser. Agents are real attack targets: OpenAI itself says prompt injection may never be fully solved, and Trail of Bits showed data being pulled from a logged-in account. Keep sensitive text and agent tasks in separate sessions, and keep the clipboard clean.

For questions or inquiries contact us at info@cleartexteditor.com