AINCO Software Privacy Policies
Jump to: AI ChatGuard Privacy Policy · AI AgentGuard Privacy Policy
AI ChatGuard™ Privacy Policy
This policy explains what AI ChatGuard ("the extension," "we") collects. It explains how we use it, how long we keep it, and who we share it with. It describes how the extension works today. It works together with the disclosures inside the product: the bundled privacy page, the first run EULA, and the Settings screens.
At a glance
| Data category | Collected? | Purpose | Shared with | Retention |
|---|---|---|---|---|
| Prompts, chats, files, images, detected sensitive values | Never | Processed on device only | No one | Not collected |
| Account & identity (name, email, hashes, install/device IDs, session tokens; password hash for email sign-in) | Only if you create an account | Sign-in, licensing | AINCO backend | While account is active; deleted on request |
| Sign-in identity from Google or Facebook | Only if you choose that provider | Account creation, sign-in | The provider you choose; AINCO backend | While account is active |
| Payment data | Only if you subscribe | Subscription billing | ExtensionPay and Stripe (card details never reach AINCO) | Per processor policy |
| Device & technical data (OS, browser, device type) | Yes, with backend requests | Support, compatibility, licensing | AINCO backend | Up to 13 months |
| Usage telemetry (event counts and category labels, never content) | Opt-in; off by default | Product reliability and improvement | AINCO backend | Up to 13 months, then deleted or aggregated |
| AI-surface registry (hostname + structural fingerprint of AI tools) | Opt-in via telemetry toggle | Recognize new AI tools | AINCO backend | Up to 13 months |
| IP address & coarse location (server side) | With backend requests | Software support, licensing, security, and regional compliance (including EU privacy requirements) | Cloudflare (infrastructure) | Per infrastructure logs, up to 13 months |
1. Information we do NOT collect
The following never leaves your device and is never sent to our servers or any third party:
- The text of your prompts, your AI chat conversations, or AI responses.
- Files, documents, or images you scan, and the specific sensitive values detected within them (for example Social Security numbers, card numbers, passwords, API keys, names, emails, or addresses contained in your content).
- Full URLs, query strings, or page contents of the websites you visit.
- Your physical or GPS location. AI ChatGuard does not request, access, or collect device geolocation.
These values are filtered out before any network request is made, enforced in code by a blocklist that strips raw text, prompts, detected values, screenshots, conversation IDs, and full URLs.
2. Information we DO collect
(a) Account & identity — only if you choose to create an account or sign in
The free tier works without an account. If you sign up we collect: your name and email address; one-way SHA-256 hashes of them; a hashed password if you choose email sign-in (we never store the plain password); a randomly generated install ID and device ID (and their hashes) used to associate your settings and license with your installation; and authentication/session tokens issued when you sign in. A local EULA acceptance record (name, email, timestamp) is stored on your device at install.
(b) Sign-in through Google or Facebook — only the provider you choose
If you choose "Continue with Google" or "Continue with Facebook," that provider signs you in. It returns your email address, display name, and profile picture URL to us. We contact only the provider you pick, and only when you start a sign-in. No chat content or browsing data is ever shared with these providers.
(c) Device & technical data — for support, compatibility, and licensing
Operating system, browser and user-agent family, device type (for example Mac or PC), CPU architecture, and core count. We do not collect hardware model names or serial numbers.
(d) Usage telemetry — metadata only, never content, opt-in and off by default
Counts and types of protection events (for example "Detected," "Redacted," "Allowed"), the general category label of the data type detected (for example personal data, work data, credential, financial, medical — classifications, not your actual data), and the AI service an event occurred on (for example ChatGPT, Claude, Gemini). Telemetry transmits only if you enable the toggle in Settings → General → Telemetry. With it off, nothing is sent and queued events from a prior consenting period are dropped.
(e) AI-surface registry — to recognize new AI tools without an update
The hostname and a structural "shape" fingerprint of pages that appear to be AI chat tools. No URL paths, query strings, page content, browsing history, page titles, or visit timestamps are sent. Contribution is opt-in via the telemetry toggle.
(f) IP address & coarse location — received server side
When your browser contacts our servers, our hosting provider, Cloudflare, receives your IP address and may derive coarse location information such as country or region. We do not collect the exact location of your device, and we do not collect GPS coordinates. We use coarse location information to comply with regional legal requirements, including EU privacy laws, and for software support, licensing, security, and abuse protection. Location is never used for advertising.
3. How we use information
- Create, secure, and authenticate your account and sign-in.
- Validate licensing and subscription entitlements.
- Provide customer support and diagnose compatibility issues.
- Maintain and improve detection coverage of AI tools (the registry).
- Understand product usage in aggregate (event counts).
- Meet regional legal requirements, including EU privacy laws, and support software licensing and customer support using coarse location information such as country or region.
We do not use your data for advertising, ad targeting, profiling, creditworthiness, or lending decisions. We do not sell, rent, or trade user data.
4. Every party we share data with
We share only the limited data described above, only with the service providers that operate the product on our behalf:
- AINCO Software backend — limited account, authentication, licensing, registry, and opt-in telemetry data is processed by AINCO backend services. We use Cloudflare as our infrastructure provider.
- ExtensionPay and its payment processor Stripe — process subscription payments if you upgrade to a paid tier. Payment-card details are entered on the processor's secure page; AI ChatGuard never receives or stores your card number.
- Google or Facebook — only the sign-in provider you choose, and only when you initiate sign-in.
We may also disclose information if required by law, or to protect the rights, property, or safety of our users or the public. There are no other recipients of user data.
5. Google user data and Limited Use
AI ChatGuard's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Google sign-in data (email, display name, profile picture URL) is used only to create and authenticate your account, is never used for advertising, and is never sold or transferred to data brokers or other third parties.
6. On-device processing and local storage
All scanning, detection, redaction, rewriting, and on-device OCR run locally in your browser. The extension stores the following in browser storage on your device, none of which is automatically transmitted off-device: your settings and preferences; the local activity log (event metadata only, no content — you can clear it at any time or set it to auto-delete after 1 day, 1 week, 1 month, or 1 year in Settings); your EULA acceptance record; and, if you sign in, a cached account profile (email, display name, profile picture URL).
7. Data retention
- Account & identity: retained while your account is active; deleted on request (see Section 8).
- Authentication sessions: tokens expire automatically and are revoked when you sign out.
- Telemetry, registry, and device data: retained for up to 13 months from collection, then deleted or irreversibly aggregated.
- Server infrastructure logs (including IP): retained up to 13 months.
- On-device data: kept per your retention setting; removed by the browser when you uninstall.
8. Your choices and controls
- Use the free tier without an account.
- Leave telemetry off (the default), or turn it off at any time in Settings → General → Telemetry; this stops all outbound audit traffic.
- Pause or turn off protection at any time from the popup.
- Sign out at any time (Settings → Account) to revoke the active session token.
- Clear the local activity log and choose a retention period in Settings.
- Request access to, or deletion of, your account data by emailing support@aincosoftware.com. We respond within seven business days and remove your email, profile data, and audit rows on confirmation.
- Uninstall the extension at any time; local data is removed by the browser.
9. Children
AI ChatGuard is not directed to children under 13 (or the minimum age of consent in your jurisdiction), and we do not knowingly collect data from children.
10. Security
Data in transit is protected with HTTPS/TLS. Passwords are never stored in plain text; identifiers are hashed where feasible. Access to backend systems is restricted to authorized AINCO personnel. No method of transmission or storage is 100% secure.
11. Changes to this policy
We will post any changes on this page and update the effective date above. Material changes will also be flagged in-product.
12. Contact
AINCO Software · Portland, OR, USA · support@aincosoftware.com · https://aincosoftware.com
AI AgentGuard™ Privacy Policy
At a glance
| Data category | Collected? | Purpose | Shared with | Retention |
|---|---|---|---|---|
| Page content, prompts, form inputs, keystrokes, screenshots, browsing history | Never | Processed on device only | No one | Not collected |
| Device & operational data (random device UUID, heartbeat status, license/entitlement state, extension version) | Yes, to run the service | Operate, register, and license the extension | AINCO backend | While device is active, then limited period |
| AI-surface intelligence (hostnames of AI/bot/tracker endpoints + structural fingerprint shape) | Opt-in, only after you accept the EULA | Improve AI-surface detection lists | AINCO backend | Limited period, then deleted or aggregated |
| Account data (name, email, OAuth identifier, authentication tokens) | Required to use AI AgentGuard | Sign-in and licensing | AINCO backend; OAuth provider if you choose it | Until you delete your account |
| Billing data | Only if you purchase a license | Subscription billing | ExtensionPay and Stripe (full card number never reaches AINCO) | Per processor policy |
What we collect
Device & operational data (to run the service)
- A randomly generated device identifier (a UUID — not a hardware fingerprint).
- Heartbeat status: that the extension is installed and active, with timestamps.
- License/entitlement state (Free, Pro, MSP) and extension version.
AI-surface intelligence (to improve detection) — only after you accept the EULA
- Hostnames of AI/bot/tracker endpoints observed, plus a structural fingerprint shape.
- No URLs, no paths, no page content, no prompts, and no personal identifiers are included.
Account data (required to use AI AgentGuard)
- Your name and email address, and an OAuth identifier if you sign in with Google or Facebook.
- Authentication tokens, stored locally on your device and refreshed securely.
Billing data (only if you purchase a license)
- Handled by our payment processor (ExtensionPay / Stripe). We do not receive or store your full card number.
What we do NOT collect
Browsing history; page content; the text of your prompts or messages; form inputs; keystrokes; screenshots; precise location.
How we use data
To operate detection and enforcement; to register and license your device; to sync your settings and license across your devices; to improve our AI-surface detection lists; and to provide support. We do not sell your data and do not use it for advertising.
Consent & your controls
- Telemetry is gated on your acceptance of the EULA during first-run. No telemetry is sent before you accept.
- You can disable telemetry at any time in the extension's settings.
- An account is required to use AI AgentGuard, including the Free tier — much like a free web-email service. You register during first-run with Google, Facebook, or email.
- You can request access to, or deletion of, your account data (see Contact).
Optional privacy protections (off by default)
AI AgentGuard includes optional, user-enabled protections. Each is disabled unless you turn it on, and none of them collect or transmit anything:
- Block Fingerprints — injects a small script into the pages you visit that adds noise to common device-fingerprinting signals (canvas, WebGL, audio, and timing). It changes only what fingerprinting scripts can read; it reads no page content and transmits nothing.
- Block Recording — blocks known session-replay and heatmap (session-recording) trackers from loading.
- Block Location — blocks a site's access to the browser geolocation API. It blocks location access; it does not collect your location.
Enterprise / managed installations
Where AI AgentGuard is deployed by an organization via managed policy, the organization is the controller of its deployment. Administrators may enable or disable telemetry and route audit events to their own SIEM (audit_endpoint). Consult your organization's policy.
Service providers (processors)
- Cloudflare — hosting and edge delivery of our APIs.
- ExtensionPay / Stripe — subscription billing.
- Google / Meta — only if you choose OAuth sign-in.
Each processes data only to provide its service to us.
Data retention
Operational and registry metadata are retained while your device is active and for a limited period thereafter, then deleted or aggregated. Account data is retained until you delete your account.
Security
Data in transit is encrypted (HTTPS). Identifiers are random; access is least-privilege; we maintain audit logging. No method is perfectly secure, but we design to minimize what we hold.
Children
AI AgentGuard is not directed to children under 13 (or the applicable age in your region) and we do not knowingly collect their data.
International transfers
We operate in the U.S., Canada, and Europe. Where required, we rely on appropriate safeguards for cross-border transfers.
Your rights
Depending on your location (e.g., GDPR / CCPA), you may have rights to access, correct, delete, or port your data, and to object to or restrict processing. Contact us to exercise them.
Changes
We will post any changes here and update the effective date; material changes will be surfaced in the extension.