The short version: Secure AI Prompt scans what you type entirely on your own device. It does not collect, transmit, sell, or share any of your data. There is no server. Nothing you type ever leaves your browser because of this extension.
What the extension does
Secure AI Prompt runs inside your browser on supported AI chat websites. As you type, it scans the text you enter for sensitive items — such as API keys, credentials, private IP addresses, and internal hostnames — and warns you before you submit them. All scanning happens locally, in the browser tab, using pattern matching built into the extension.
Data we collect
None. Specifically:
We do not collect, log, or transmit the content you type.
We do not send your text, detected items, or browsing activity to any server. The extension has no backend server to send anything to.
We do not use analytics, tracking, advertising, or third-party SDKs.
We do not sell or share any data, because we do not have any.
Data stored on your device
The extension saves a small amount of information locally, using your browser's built-in storage, so it can function and remember your preferences:
Settings — your chosen mode, enabled detectors, custom rules, and allowlist entries.
Local counters — how many times a warning was shown, a redaction was applied, or a warning was overridden. These are simple numeric counts and detector names (for example, "aws-access-key-id"). They never include the actual text you typed or the sensitive values themselves.
This information stays on your device (and, if you use Chrome sync, within your own Google account's synced browser storage). It is never sent to us or any third party.
Permissions
Storage — to save your settings and the local counters described above.
Access to specific AI websites (such as ChatGPT, Claude, Gemini, and Copilot) — so the extension can read the prompt editor on those sites and scan your text locally before you send it. This access is used only for scanning within the page; nothing read from the page is transmitted anywhere.
Enterprise deployments
When an organization deploys Secure AI Prompt to its employees through managed browser policy, the organization's IT administrators may configure settings such as detection rules and enforcement mode. Any such configuration is delivered through the browser's managed-policy mechanism and controlled by the organization, not by us. The extension still performs all scanning locally and still transmits no typed content.
Children
This extension is a workplace tool and is not directed at children.
Changes to this policy
If this policy changes, the updated version will be posted at this URL with a revised "last updated" date.