Last updated: [DATE — set on publish] · Publisher: Nehlos · Contact: [privacy@nehlos.com — confirm address]
AI Privacy Guardian ("the Extension") is built to prevent sensitive data from leaving your browser. Protecting your privacy isn't a side concern for us — it's the product. This policy explains, plainly, what the Extension does and does not do with your data.
To detect sensitive data, the Extension reads the text you enter into supported AI platforms (e.g., ChatGPT, Claude, Gemini, Copilot) and compares it against detection patterns. This analysis happens entirely within your browser. The text is held only in memory for the moment it takes to analyze it and is not stored or transmitted by this process.
The Extension stores the following locally on your device (via the browser's storage API), and this data never leaves your device unless your organization has enabled cloud logging:
Some organizations deploy the Extension centrally to monitor coverage and policy compliance. This is off by default and only active when an organization configures an API endpoint and key. When active, the Extension transmits event metadata only to the endpoint your organization controls:
chatgpt.com)What is never transmitted, under any configuration: your prompt text, the actual sensitive values detected (SSNs, card numbers, addresses, etc.), your keystrokes, your browsing history, or page content beyond the metadata above. The matched text never leaves your device.
When cloud logging is active, the Extension's on-screen notice reflects this honestly ("your organization logs event metadata — never your prompt text"). When it is not active, the notice states that all processing is on-device.
storage — to keep your settings and local activity log on your device.activeTab — to show the current page's protection status in the popup.alarms — to schedule periodic coverage check-ins (only used when an organization has enabled logging).The Extension does not request broad ("all sites") access, and does not read or transmit content from non-AI websites.
Our use of information received from the Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We collect only the limited event metadata described above (and only when an organization enables it), use it solely to provide the security-monitoring functionality, and do not transfer it except as necessary to provide that functionality to the deploying organization.
We will update this policy as the product evolves and revise the "Last updated" date. Material changes will be reflected in the Extension's store listing.
Drafting note for Romeo: confirm the contact email, set the publish date, and host this at a stable public URL (e.g., nehlos.com/privacy). The Chrome Web Store listing requires a link to a live privacy policy, and the data-use answers in the developer dashboard must match this document exactly.