Privacy Policy
Last updated: July 2, 2026
Effective date: July 2, 2026
Applies to: ShieldWays Chrome extension version 3.1.x
Privacy-First Approach: ShieldWays does one thing: it scans the prompts you type into supported AI tools (ChatGPT, Claude, Gemini, Copilot, Perplexity) on your device, and warns, redacts, or blocks before sensitive data leaves your browser. Detection runs locally. While you are signed out, the extension sends nothing to our servers — no prompts, no events, no telemetry.
1. What the Extension Does On Your Device
To provide protection, the extension reads the text you type into the prompt fields of the supported AI sites and scans it locally in your browser for personal data (PII), financial data, secrets/API keys, and health data (PHI). This on-device scanning happens even though the content itself is never transmitted to us — we disclose it because the extension does read what you type on those sites, solely to protect it.
- Local processing only: the scan, and any warning, redaction, or block, happens entirely in your browser.
- Local counters: daily totals (prompts scanned, items protected, redactions, blocks) are stored locally so the popup can show today's activity. They contain no prompt content.
- Settings: your preferences (protection on/off, per-site toggles, custom keywords and patterns) are stored in Chrome's extension storage.
2. Information We Collect
2.1 While Signed Out: Nothing
If you never sign in, nothing ever leaves your device. The extension makes no network requests to our servers, sends no detection events, no analytics, and no logs. All scanning, settings, and counters stay local.
2.2 After You Sign In
If you choose to sign in to a ShieldWays account, the extension transmits the following to our servers:
- Settings sync: your protection settings (master on/off, per-site toggles, detection categories and actions, custom keywords and patterns) so they follow you across devices and appear in your dashboard.
- Content-free detection (audit) events: when the extension detects sensitive data in a prompt, it sends a record containing only these fields: event type, AI tool name, action taken (warn / redact / block), site domain, detection category, the types of items detected (e.g. "email", "credit card" — never the values), a count of items, and a timestamp. Your prompt text is never included.
- Authentication tokens: the extension holds your session tokens (issued by our authentication provider, Supabase) to make authenticated requests on your behalf, and refreshes them when they expire.
- Subscription status: the extension verifies your plan/tier with our servers to enable paid features.
- Security and diagnostic logs: content-free records of security-relevant events (e.g. sign-in failures, API errors) to protect your account and debug problems. These are transmitted only while you are signed in.
2.3 Opt-In Analytics
Usage analytics are off by default. If — and only if — you explicitly turn analytics on and you are signed in, we receive anonymized usage events (feature usage, performance metrics, sanitized error reports) together with an extension version and a device identifier (deviceId). Analytics events never include prompt content or detected values. You can turn analytics off at any time.
What We DO NOT Collect:
- Your AI prompts or conversation text — the content is scanned locally and never transmitted
- The values of detected PII, secrets, financial, or health data
- Meeting audio, video, recordings, or transcripts — this version of the extension contains no meeting features and requests no capture permissions
- Your browsing history — the extension only runs on the supported AI sites and shieldways.com
- Keystrokes outside the supported AI sites' prompt fields
- Anything at all while you are signed out
3. How We Use Your Information
3.1 Core Functionality
- Provide on-device prompt protection for supported AI tools
- Sync your preferences and settings across devices (signed-in users)
- Show your content-free detection history in your dashboard (signed-in users)
- Verify subscription status and enable paid features
3.2 Service Improvement (opt-in analytics only)
- Analyze aggregated usage patterns to improve reliability and detection quality
- Identify and fix bugs or performance issues
3.3 Security, Legal and Safety
- Protect accounts against fraud or abuse
- Comply with applicable laws and regulations
- Enforce our Terms of Service
4. Chrome Web Store Limited Use Disclosure
Limited Use: ShieldWays' use of information received from Google APIs, and its use and transfer of Chrome user data, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the data described in this policy only to provide and improve the extension's single, user-facing purpose — preventing sensitive data from leaking into AI tools — and we do not sell it, use it for advertising, or allow humans to read it except with your consent, for security purposes, or as required by law.
5. Data Processing and Storage
5.1 Data Storage Locations
- Local storage: settings, custom rules, daily counters, and session tokens are stored in Chrome's extension storage on your device
- Our servers: account data, subscription status, synced settings, and content-free detection events — for signed-in users only
- Third-party services: authentication (Supabase), payment processing, and hosting required to operate the service. Payment checkout happens on the payment provider's own pages, not inside the extension
5.2 Data Retention
- Local data: retained until you uninstall the extension or clear browser data
- Detection events and analytics: retained for up to 24 months
- Account data: retained while your account is active, plus 6 months for business records
- Support communications: retained for up to 3 years for quality assurance
6. Data Sharing and Disclosure
6.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing or any other purposes.
6.2 Limited Sharing
We may share limited, non-sensitive information only in these circumstances:
- Service providers: trusted partners who help us operate our service (authentication, payment processing, hosting)
- Legal requirements: when required by law, court order, or to protect rights and safety
- Business transfers: in the event of a merger, acquisition, or sale of assets (users will be notified)
- Consent: with your explicit consent for specific purposes
7. Your Privacy Rights
7.1 Access and Control
- Data access: view all data we have about you
- Data correction: update or correct your information
- Data deletion: request deletion of your account and data
- Data portability: export your data in a portable format
- Opt-out: analytics is opt-in and can be turned off at any time; signing out stops all transmission entirely
7.2 How to Exercise Your Rights
- Extension: protection and per-site controls in the popup; sign out to stop all data transmission
- Chrome settings: clear extension data through browser settings
- Account dashboard: manage settings, detection history, account, and billing
- Contact us: email privacy@shieldways.com for data requests
8. Security Measures
8.1 Technical Safeguards
- Encryption: all data transmission uses TLS encryption
- Local processing: prompt content is scanned on-device and never transmitted
- Access controls: strict employee access to user data
- Security audits: regular security assessments and vulnerability testing
8.2 Chrome Extension Security
- Manifest V3: uses the latest Chrome security standards
- Minimal permissions: only storage, alarms, and notifications — no tab capture, no screen access, no broad host access beyond the supported AI sites and shieldways.com
- Content Security Policy: restricts network connections to our API and authentication provider
- Signed distribution: only distributed through the official Chrome Web Store
9. Features Not In This Version
Earlier ShieldWays materials described meeting-protection features (screen-share redaction, meeting notetaking, transcription). The current extension does not include any meeting features. It does not run on meeting sites, does not request audio, video, or tab-capture permissions, and never processes meeting audio or recordings. If such features ship in a future version, this policy will be updated first and any new permissions will be requested explicitly.
10. International Data Transfers
Your information may be processed and stored in countries other than your own. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) for EU data
- Local data processing requirements compliance
- GDPR compliance for EU users
11. Children's Privacy
ShieldWays is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on our website
- Showing a notification in the extension
- Sending an email to registered users (for major changes)
- Requiring re-acceptance for significant changes
13. Compliance and Certifications
13.1 Regulatory Compliance
- GDPR: EU General Data Protection Regulation compliance
- CCPA: California Consumer Privacy Act compliance
- COPPA: Children's Online Privacy Protection Act compliance
- Chrome Web Store Policies: full compliance with Google's developer program policies, including the User Data Policy and Limited Use requirements
13.2 Enterprise Compliance
Enterprise tier users benefit from additional compliance features:
- Content-free audit logs
- Policy and device-management controls
- Custom Data Processing Agreements (DPAs), where applicable
Questions or Concerns? Your privacy is important to us. If you have any questions about how we handle your data, or if you believe your privacy rights have been violated, please reach out to us at privacy@shieldways.com.