Privacy
Last updated: October 4, 2026. This is a plain-language summary of what the product does; it is not a substitute for the terms of service you accept when you subscribe.
The short version
Prompt text does not leave your browser. The extension reads what is about to be sent to an AI site so it can check it against its rules, on the device. That text is not transmitted to our servers, not written to our database, and not put in any log, email or Slack message we send.
What the extension checks
- Text pasted into, dropped on, or typed in the message box of the AI sites it protects (ChatGPT, Claude, and the others listed in the extension).
- Names and the first 64 KB of the content of text files you attach, plus the file name (for example
.envor.pem). Images, PDFs and Office files are not scanned. - The outgoing request to the site's conversation endpoint, as a backstop in case the message box was missed. The text of that request is checked in the browser and is not retained.
The extension only has permission to run on those AI sites. It does not run on your email, banking, or any other site.
What we receive and store
For each event (a block, a warning, a "send anyway", or a "would have blocked" in monitor mode) the extension sends our servers:
- the category of data detected (for example "AWS access key" or "SSN"),
- the AI site hostname (for example
claude.ai), - the action taken (blocked, warned, sent anyway, would-have-blocked),
- the timestamp,
- a user label (a name or email your admin or the user entered, if any) and a random install ID created by the extension,
- the extension version.
We do not receive the matched value, a snippet, or any hash or fingerprint of the text. (The extension keeps a local activity log on the device that includes a keyed fingerprint so it can show "same attempt repeated"; that fingerprint uses a random secret that stays in the browser and is never transmitted.)
We also store your organization's account details (company name, admin email, subscription status), the keyword and allow-list entries your admin types into the dashboard, and the hashed (not plain) organization and admin keys. Billing is handled by Stripe; we do not see or store card numbers.
Retention: event records are deleted after 90 days. Ask us to delete your organization's data at any time by emailing support.
Who else touches data (subprocessors)
- Cloudflare: hosts the API, database and this website.
- Stripe: subscription billing and the customer portal.
- Resend: sends transactional email (welcome, digest, payment notices).
- Slack: only if your admin connects a webhook; digests contain counts, categories and user labels, never prompt text.
Limits of what we can say
- The extension's job is to read the text before it is sent, so anyone with admin control of the browser could read what the browser reads. We don't have that access; your IT admin may.
- User labels can be personal data (for example an email address). Use initials or a device name if you'd rather not report names.
- We do not sell data and do not use event data for advertising or to train models.
Contact
Questions or deletion requests: support.