Pastebreak

Privacy

Last updated: October 4, 2026. This is a plain-language summary of what the product does; it is not a substitute for the terms of service you accept when you subscribe.

The short version

Prompt text does not leave your browser. The extension reads what is about to be sent to an AI site so it can check it against its rules, on the device. That text is not transmitted to our servers, not written to our database, and not put in any log, email or Slack message we send.

What the extension checks

The extension only has permission to run on those AI sites. It does not run on your email, banking, or any other site.

What we receive and store

For each event (a block, a warning, a "send anyway", or a "would have blocked" in monitor mode) the extension sends our servers:

We do not receive the matched value, a snippet, or any hash or fingerprint of the text. (The extension keeps a local activity log on the device that includes a keyed fingerprint so it can show "same attempt repeated"; that fingerprint uses a random secret that stays in the browser and is never transmitted.)

We also store your organization's account details (company name, admin email, subscription status), the keyword and allow-list entries your admin types into the dashboard, and the hashed (not plain) organization and admin keys. Billing is handled by Stripe; we do not see or store card numbers.

Retention: event records are deleted after 90 days. Ask us to delete your organization's data at any time by emailing support.

Who else touches data (subprocessors)

Limits of what we can say

Contact

Questions or deletion requests: support.