Effective Date
August 17, 2026
Summary
GuardRail AI scans text you type into supported AI chat websites for sensitive data (like credit card numbers, API keys, or your own custom keywords) entirely on your device. The actual sensitive text it finds is never transmitted anywhere or stored by us — only a category label (e.g. "Credit Card Number") is recorded in your incident history, so you can review what was blocked without the sensitive value itself ever leaving your browser.
1. Information We Collect
GuardRail AI collects and processes the following information to provide its core functionality:
Account Information: Your email address and authentication credentials, handled via Firebase Authentication, to identify your account and sync your data across sessions.
Security Rules: Custom keyword lists and regex patterns you define, and which built-in detectors (credit card, SSN, API key, etc.) you've enabled or disabled, stored in Firebase Firestore and associated with your account.
Saved Prompts & Prompt Chains: Prompt templates, categories, and multi-step prompt chains you create, plus a limited version history of edits to your prompts (Pro), stored in Firestore.
Incident Log: When GuardRail AI blocks a potential data leak, it records the site, a category/severity label describing what was detected (e.g. "Credit Card Number", "Custom Keyword: Project Titan"), and a timestamp. It does not record the sensitive text itself.
Subscription Status: If you subscribe to Pro, your email is used to look up your subscription status with our payment processor, LemonSqueezy, and the resulting status (active/expired, renewal date, tier) is stored with your account.
Local Device Storage: Your active rules, prompts, incident log, and preferences are cached locally via the Chrome storage API for fast, offline-capable access.
2. What We Don't Collect
The full, unredacted content of the prompts and messages you type is never sent to our servers, stored in our database, or shared with any AI provider or third party by GuardRail AI. All sensitive-data detection happens locally, using on-device pattern matching — nothing about the content of your prompts is required to leave your browser for the extension to do its job.
We do not collect health information, precise location, general web browsing history outside the supported AI sites, or behavioral tracking data such as keystrokes, clicks, or mouse movement.
3. How Your Data is Used
Your data is used exclusively for the following purposes:
- Security Monitoring: Scanning text you type into supported AI chat sites, on-device, against built-in detectors and your configured rules, to prevent sensitive data from being sent.
- Prompt & Chain Management: Storing and syncing your saved prompts, categories, and prompt chains so they're available across your devices.
- Incident Tracking: Recording metadata about blocked attempts (not their content) so you can review your safety history and trends.
- Subscription Verification: Checking your subscription status to unlock Pro features, and periodically re-verifying it to keep your account state accurate.
- Notifications: If enabled, sending a local, on-device weekly summary notification of how many attempts were blocked. This can be turned off in Settings at any time.
We do not sell, rent, or share your personal data, security rules, or prompt content with any third party for marketing or advertising purposes. We do not use your data to determine creditworthiness or for lending purposes.
4. Permissions Explanation
| Permission | Why it's needed |
|---|---|
activeTab | To read the text you're actively typing into a supported AI chat site's input box, so it can be scanned on-device before submission. |
storage | To cache your security rules, prompts, incident log, and preferences locally for fast, offline-capable access. |
alarms | To periodically re-verify your subscription status in the background, and to schedule the optional weekly digest notification. |
notifications | To show the optional, user-toggleable weekly summary notification. Off by default behavior can be changed anytime in Settings. |
| Host permissions (chatgpt.com, claude.ai, gemini.google.com, perplexity.ai, copilot.microsoft.com, poe.com, chat.mistral.ai, chat.deepseek.com, grok.com) | To inject the scanning and prompt-management sidebar only on these specific, supported AI chat platforms. GuardRail AI does not run on, or read data from, any other website. |
5. Third-Party Services
GuardRail AI integrates with the following third-party service providers, who process a limited set of data strictly to provide the functionality described above:
- Firebase (Google): User authentication and data storage/sync (Firestore) for your account, rules, prompts, and incident log. Firebase's privacy policy
- LemonSqueezy: Subscription and payment processing. Your email is used to look up subscription status; GuardRail AI never handles or stores your card details — checkout happens entirely on LemonSqueezy's own hosted page. LemonSqueezy's privacy policy
These are service providers acting on our behalf, not independent third parties we sell or transfer your data to. We do not share your data with any other third party, and we do not send your prompt content to any AI model or service as part of GuardRail AI's own operation.
6. Your Rights & Data Deletion
You can review and delete your individual saved prompts, chains, and custom rules at any time from within the extension. To request deletion of your full account and associated data, email us at the address below — we will process deletion requests within 30 days.
7. Children's Privacy
GuardRail AI is not directed at children under 13, and we do not knowingly collect data from children under 13.
8. Security
The extension operates within Chrome's extension security model, including a strict content security policy that prevents loading or executing remote code. Data in transit to Firebase and LemonSqueezy is encrypted (HTTPS/TLS).
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date above and, where appropriate, noted on the Chrome Web Store listing. We encourage you to review this policy periodically.
10. Contact Us
If you have any questions, concerns, or data deletion requests regarding this Privacy Policy, please contact us at:
abdudevs@gmail.com