ProtectedAI ("we", "us", "our") operates the ProtectedAI Chrome extension and associated services at protectedai.io. Our product anonymizes sensitive information before it is submitted to AI platforms such as ChatGPT, Claude, and Gemini.
This Privacy Policy explains what personal data we collect, how we use it, and what rights you have in relation to it. By using our service, you agree to the practices described in this policy.
When you create an account, we collect:
encrypted hash. We never store your password in plain text and cannot recover it.chatgpt, claude, gemini) — used at request time to validate access. Not stored per request.We explicitly do not collect or store:
We use the data we collect solely for the following purposes:
| Data | Purpose |
|---|---|
| Email address | Account identification; sending service notifications |
| Name | Personalizing your account and communications |
| Password hash | Authenticating your login |
| Company name & role | Managing team access and permissions |
| Language preference | Delivering anonymization labels in your preferred language |
| Last login | Account security monitoring |
| Notification log | Ensuring each lifecycle notification is sent only once |
| Error logs | Debugging and maintaining service reliability |
We do not sell, rent, or trade your personal data. We do not use your data for advertising or profiling.
We share your data with third parties only when strictly necessary to operate the service.
We use Resend as our transactional email provider. When we send you a service notification (account verification, team invitation, trial expiration), your email address is transmitted to Resend for delivery. Resend does not receive any text content processed through our service.
Our backend runs on a cloud hosting provider that processes your requests in transit but does not retain any user content. This section will be updated with the provider's name before publishing.
The ProtectedAI extension runs within the Google Chrome browser, subject to Google's own privacy policies. The JWT token is stored in chrome.storage.local, isolated to the ProtectedAI extension.
We do not share your data with AI platforms. Our service exists precisely to prevent your sensitive information from reaching those platforms.
bcrypt. We cannot recover your password.| Data Type | Retention Period |
|---|---|
| Text submitted for anonymization | Not retained — discarded immediately after processing |
| Active account data | Retained while your account is active |
| Expired or cancelled account data | Up to 90 days after expiration to allow reactivation |
| Server error logs | 30 days; no user content included |
| Service notification log | Life of the account |
You may request deletion of your account and all associated data at any time by emailing support@protectedai.io. Requests are processed within 30 days. Self-service account deletion from within the app is not yet available.
To exercise any of these rights, contact us at support@protectedai.io. We will respond within 30 days.
For users located in Colombia, the processing of personal data described in this policy is governed by Ley 1581 de 2012 (Ley de Protección de Datos Personales) and Decreto 1377 de 2013.
The rights of access, correction, and deletion described in Section 8 are consistent with the rights recognized to data subjects (titulares) under Colombian law. ProtectedAI acts as the Responsable del Tratamiento (data controller) for all personal data collected through the service.
For data protection inquiries: support@protectedai.io.
ProtectedAI is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us at support@protectedai.io and we will delete that data promptly.
In the event of a security breach that compromises personal data, ProtectedAI will notify affected users within the timeframes required by applicable law and take all necessary corrective measures. Notifications will be sent to the email address associated with the affected account.
We may update this Privacy Policy from time to time. We will revise the "Last updated" date and notify you by email at least 30 days before material changes take effect. Continued use of the service after that period constitutes acceptance.