Privacy Policy

GuardRail AI

Effective Date

August 17, 2026

Summary

GuardRail AI scans text you type into supported AI chat websites for sensitive data (like credit card numbers, API keys, or your own custom keywords) entirely on your device. The actual sensitive text it finds is never transmitted anywhere or stored by us — only a category label (e.g. "Credit Card Number") is recorded in your incident history, so you can review what was blocked without the sensitive value itself ever leaving your browser.

1. Information We Collect

GuardRail AI collects and processes the following information to provide its core functionality:

Account Information: Your email address and authentication credentials, handled via Firebase Authentication, to identify your account and sync your data across sessions.

Security Rules: Custom keyword lists and regex patterns you define, and which built-in detectors (credit card, SSN, API key, etc.) you've enabled or disabled, stored in Firebase Firestore and associated with your account.

Saved Prompts & Prompt Chains: Prompt templates, categories, and multi-step prompt chains you create, plus a limited version history of edits to your prompts (Pro), stored in Firestore.

Incident Log: When GuardRail AI blocks a potential data leak, it records the site, a category/severity label describing what was detected (e.g. "Credit Card Number", "Custom Keyword: Project Titan"), and a timestamp. It does not record the sensitive text itself.

Subscription Status: If you subscribe to Pro, your email is used to look up your subscription status with our payment processor, LemonSqueezy, and the resulting status (active/expired, renewal date, tier) is stored with your account.

Local Device Storage: Your active rules, prompts, incident log, and preferences are cached locally via the Chrome storage API for fast, offline-capable access.

2. What We Don't Collect

The full, unredacted content of the prompts and messages you type is never sent to our servers, stored in our database, or shared with any AI provider or third party by GuardRail AI. All sensitive-data detection happens locally, using on-device pattern matching — nothing about the content of your prompts is required to leave your browser for the extension to do its job.

We do not collect health information, precise location, general web browsing history outside the supported AI sites, or behavioral tracking data such as keystrokes, clicks, or mouse movement.

3. How Your Data is Used

Your data is used exclusively for the following purposes:

We do not sell, rent, or share your personal data, security rules, or prompt content with any third party for marketing or advertising purposes. We do not use your data to determine creditworthiness or for lending purposes.

4. Permissions Explanation

PermissionWhy it's needed
activeTabTo read the text you're actively typing into a supported AI chat site's input box, so it can be scanned on-device before submission.
storageTo cache your security rules, prompts, incident log, and preferences locally for fast, offline-capable access.
alarmsTo periodically re-verify your subscription status in the background, and to schedule the optional weekly digest notification.
notificationsTo show the optional, user-toggleable weekly summary notification. Off by default behavior can be changed anytime in Settings.
Host permissions (chatgpt.com, claude.ai, gemini.google.com, perplexity.ai, copilot.microsoft.com, poe.com, chat.mistral.ai, chat.deepseek.com, grok.com)To inject the scanning and prompt-management sidebar only on these specific, supported AI chat platforms. GuardRail AI does not run on, or read data from, any other website.

5. Third-Party Services

GuardRail AI integrates with the following third-party service providers, who process a limited set of data strictly to provide the functionality described above:

These are service providers acting on our behalf, not independent third parties we sell or transfer your data to. We do not share your data with any other third party, and we do not send your prompt content to any AI model or service as part of GuardRail AI's own operation.

6. Your Rights & Data Deletion

You can review and delete your individual saved prompts, chains, and custom rules at any time from within the extension. To request deletion of your full account and associated data, email us at the address below — we will process deletion requests within 30 days.

7. Children's Privacy

GuardRail AI is not directed at children under 13, and we do not knowingly collect data from children under 13.

8. Security

The extension operates within Chrome's extension security model, including a strict content security policy that prevents loading or executing remote code. Data in transit to Firebase and LemonSqueezy is encrypted (HTTPS/TLS).

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date above and, where appropriate, noted on the Chrome Web Store listing. We encourage you to review this policy periodically.

10. Contact Us

If you have any questions, concerns, or data deletion requests regarding this Privacy Policy, please contact us at:

abdudevs@gmail.com