Privacy Policy
Last updated: 17 July 2026
Core principle: Redactr's Tier-1 detection (keyword
and pattern matching) runs entirely on your device — your prompts are never
sent to our servers. Enterprise plan subscribers who enable AI-powered NER detection have the
text they are typing transmitted to Redactr's secure server solely to perform that analysis;
no results or raw text are stored after the scan completes.
1. Who we are
Redactr ("we", "us", "our") is a data-loss prevention tool for businesses and individuals.
Our registered contact email is
support@redactr.io.
2. What the Chrome extension does
The Redactr Chrome extension monitors text you type into AI tools (ChatGPT, Claude, Gemini)
and — for Enterprise plan subscribers — file upload fields and email compose areas on those
same sites. When sensitive data is detected, the extension warns you or blocks the action.
Tier-1 (all plans): Pattern and keyword matching runs locally inside your
browser. No text leaves your device for this tier.
Tier-2 / AI detection (Enterprise only, opt-in): When you enable the AI
detection toggle, the text you are typing is sent over an encrypted HTTPS connection to
Redactr's API server to perform Named Entity Recognition (NER) using the GLiNER model.
The server returns detected entity types and immediately discards the input text — it is
not logged, stored, or used for training.
3. Data we collect
We collect only what is necessary to operate the service:
-
Account email address — collected via Google Sign-In when you authenticate
in the extension. Used to link you to your company account and verify your subscription plan.
-
Google display name — used for personalisation inside the extension popup.
-
Text submitted for Enterprise AI scanning (Tier-2, opt-in) — when the AI
detection feature is enabled by an Enterprise subscriber, the text being typed is transmitted
to Redactr's API server for NER analysis. It is processed in memory and immediately discarded;
it is never written to disk or any database.
-
Blocked-prompt alert metadata — when the extension blocks a prompt, a
lightweight record (finding types, risk score, website domain, timestamp) is sent to your
company's alert log in Firestore so the admin can review it. The blocked text itself is
never stored.
-
Blocked-file event metadata — for Enterprise subscribers, when a file is
blocked, a lightweight alert record (filename, file type, website domain, timestamp) is
written to your company's Firestore alerts collection. File contents are never stored.
-
Leak-prevention event count — a running integer stored locally in your
browser (chrome.storage.local). This number is never sent to our servers.
-
Billing email and company name — collected at checkout on the website when
a business purchases a plan. Used to provision your company account.
4. Data we do NOT collect
- Tier-1 scanned prompt text (detection is local; text never leaves your device for Tier-1)
- The contents of files you upload or attempt to upload
- The contents of emails you compose
- Browsing history or URLs visited
- Tier-2 scanned text after the NER response is returned (immediately discarded server-side)
- Any sensitive values that trigger a detection (we detect and block them — we never store them)
5. How we use your data
- To authenticate you and determine your subscription plan
- To allow your company admin to invite and manage team members
- To send transactional emails (trial activation, subscription confirmation)
- To display blocked-prompt and blocked-file alerts to your company admin
- To perform AI-powered NER analysis on text you submit while Tier-2 is enabled (Enterprise only)
6. Third-party services
-
Google Firebase / Firestore — stores user accounts, company records,
invite links, and alert metadata. Data stored in the US.
Firebase Privacy.
-
Google Sign-In (OAuth 2.0) — used for authentication. We receive your
email and display name only.
Google Privacy Policy.
-
Render (render.com) — hosts Redactr's API server, which performs
Enterprise Tier-2 NER analysis. Text submitted for AI scanning is processed on Render's
infrastructure and immediately discarded after the response is returned. No text is
persisted on Render.
Render Privacy Policy.
-
Resend — used to send transactional emails. Your email address is passed
to Resend only when sending a welcome or confirmation email.
Resend Privacy Policy.
-
PayPal — payment processing on the checkout page. Redactr does not store
card details; PayPal handles all payment data.
PayPal Privacy Policy.
7. Permissions used by the extension
-
storage — stores your local settings (enabled/disabled toggle, leak count,
authentication token) in your browser only.
-
identity — used to initiate Google Sign-In via chrome.identity.launchWebAuthFlow.
-
offscreen — runs image analysis for Enterprise file scanning in a background
document without blocking your browser tab.
-
Host permissions — chatgpt.com, claude.ai, gemini.google.com, mail.google.com,
outlook.live.com, outlook.office.com, outlook.office365.com — the extension only
runs on these specific sites. It does not have access to any other websites you visit.
8. Data retention
Your account data in Firestore is retained for as long as your subscription is active. You may
request deletion at any time by emailing support@redactr.io.
Local browser storage (chrome.storage.local) is cleared when you uninstall the extension.
9. Children's privacy
Redactr is a business tool not directed at children under 13. We do not knowingly collect data
from anyone under 13.
10. Changes to this policy
We may update this policy. The "Last updated" date at the top reflects the most recent revision.
Continued use of the extension after an update constitutes acceptance.
11. Contact
Questions or data requests: support@redactr.io