Zero Data Retention

Our Privacy Promise

We don't ask for your trust; we build architecture that makes data leakage impossible.

Effective Date: Launch Day · Version 1.0

GDPR & KVKK Compliant
Bank-Grade Encryption
Available in Chrome Web Store

100% Local Processing

All PII detection runs inside your browser on your own device. Your prompts never travel to a remote server — there's nothing to intercept.

Zero Data Retention

We log nothing. No prompts, no original text, no masked tokens. Close the tab and every key is gone — by design, not by policy.

Zero-Setup Required

Just install the extension and start working securely in seconds. No complex configurations or IT support needed.

The Charter

The 10 Articles

Each clause is a binding architectural guarantee — not a marketing claim.

  • 1.1. On-Device Inference: All PII detection happens within your browser's sandbox using local CPU/RAM.
  • 1.2. Zero Server Connectivity: Your prompts are never sent to our servers for processing.
  • 1.3. In-Transit Security: By eliminating the hop to a security server, Man-in-the-Middle risks are mathematically eliminated.

Chrome Web Store Privacy Compliance

Privacy Policy for MaskPrompt Extension

This Privacy Policy explains how MaskPrompt ("we", "our", or "the extension") collects, handles, stores, and shares data when you use our Local-First AI Privacy Gateway.

1. User Data Collection (Data We Collect)

We collect only the absolute minimum data required for authentication and licensing purposes.

  • Authentication Data: When you log in, we collect your email address and encrypted password credentials to verify your active subscription.
  • Device Identification: We generate and collect a secure device fingerprint. This ensures your license is cryptographically locked to your authorized hardware and prevents unauthorized access.
  • Zero Telemetry & Zero Prompt Collection: We do not collect, track, or log any of your text inputs, original prompts, masked tokens, or document contents (such as .docx files). We do not use third-party error tracking systems (e.g., Sentry), Google Analytics, or any other telemetry tools.

2. User Data Handling (How Data is Processed)

MaskPrompt operates entirely on a Local-First architecture.

  • On-Device Inference: All Personally Identifiable Information (PII) detection and masking operations happen entirely within your browser's sandbox utilizing local CPU and RAM.
  • Zero Server Connectivity for Processing: Your text prompts and documents are never transmitted to our servers or any external API for processing. The masking happens strictly client-side.
  • Blind LLM Principle: Masked text is forwarded programmatically to the target AI platform (e.g., ChatGPT) without exposing the original sensitive data, mathematically eliminating Man-in-the-Middle and model training risks.

3. User Data Storage (Data Retention)

We utilize standard browser storage APIs (chrome.storage.local and localStorage) strictly for operational requirements and user experience, not for storing sensitive PII or prompts.

  • Operational Storage: We store JSON Web Tokens (JWT) for session management, cached subscription plan names, and login states to maintain your session securely.
  • Configuration & UI Storage: We cache DOM configurations, background update flags, saved emails (for "remember me" functionality), and User Interface sizing preferences (e.g., side panel width, modal split height).
  • Transient Memory for Prompts (Auto-Wipe): The mapping dictionaries containing the relation between your original PII and masked tokens are never written to disk. They exist solely in temporary RAM (Volatile Memory). Closing the target AI tab or your browser session instantly and permanently purges this data.

4. User Data Sharing (Data Disclosure)

We have a strict zero-sharing policy regarding user prompts and sensitive information.

  • We do not sell, trade, or otherwise transfer your personally identifiable information, account details, or device fingerprints to outside parties.
  • No textual data, prompts, or mapping keys are ever shared with AI providers (like OpenAI or Google), advertising networks, or third-party trackers.
  • Data is only communicated with our secure backend strictly for the initial authentication and periodic subscription verification process.

Technical Transparency

In-Browser Inference vs. Cloud Processing

Every other "privacy AI" tool has the same architectural flaw: your text travels to their servers before reaching the LLM. We removed that hop entirely.

MaskPrompt — In-Browser Inference

Your prompt → local ONNX model in your tab → masked tokens → ChatGPT. We never see your original text—and neither does ChatGPT. There is nothing to log, subpoena, or breach.

Others — Cloud Processing

Your prompt → vendor's "privacy server" → masked text → ChatGPT. The vendor sees everything, plaintext, in transit and often at rest. Trust is required.

Ready to secure your AI workflows without changing your habits?

100% Free during launch. Zero configuration required.

Compliance Aligned

Built for the world's strictest regimes

GDPR
KVKK
HIPAA

Human-in-the-Loop, Always.

Architecture protects you from systems. Judgment protects you from edge cases. Every masked prompt passes under your eyes before it leaves your machine — because the last line of defense for your data should always be you.