AINCO Software Privacy Policies

Privacy policies for AINCO Software's browser extensions. Each product's policy is provided in full below.

Jump to: AI ChatGuard Privacy Policy  ·  AI AgentGuard Privacy Policy

AI ChatGuard™ Privacy Policy

AI ChatGuard is a product of AINCO Software, based in Oregon, USA.
Effective date: June 4, 2026 · Policy version: 0.2.128
Contact: support@aincosoftware.com · https://aincosoftware.com

This policy explains what AI ChatGuard ("the extension," "we") collects. It explains how we use it, how long we keep it, and who we share it with. It describes how the extension works today. It works together with the disclosures inside the product: the bundled privacy page, the first run EULA, and the Settings screens.

Our privacy promise. AI ChatGuard checks your AI chats on your device, before you press send. Your prompts stay in your browser. So do your files, your images, and the sensitive things we detect. Nothing is sent to AINCO. Nothing is sent to anyone else. The only thing that leaves your browser is what you approve and send to the AI tool yourself.

At a glance

Data categoryCollected?PurposeShared withRetention
Prompts, chats, files, images, detected sensitive valuesNeverProcessed on device onlyNo oneNot collected
Account & identity (name, email, hashes, install/device IDs, session tokens; password hash for email sign-in)Only if you create an accountSign-in, licensingAINCO backendWhile account is active; deleted on request
Sign-in identity from Google or FacebookOnly if you choose that providerAccount creation, sign-inThe provider you choose; AINCO backendWhile account is active
Payment dataOnly if you subscribeSubscription billingExtensionPay and Stripe (card details never reach AINCO)Per processor policy
Device & technical data (OS, browser, device type)Yes, with backend requestsSupport, compatibility, licensingAINCO backendUp to 13 months
Usage telemetry (event counts and category labels, never content)Opt-in; off by defaultProduct reliability and improvementAINCO backendUp to 13 months, then deleted or aggregated
AI-surface registry (hostname + structural fingerprint of AI tools)Opt-in via telemetry toggleRecognize new AI toolsAINCO backendUp to 13 months
IP address & coarse location (server side)With backend requestsSoftware support, licensing, security, and regional compliance (including EU privacy requirements)Cloudflare (infrastructure)Per infrastructure logs, up to 13 months

1. Information we do NOT collect

The following never leaves your device and is never sent to our servers or any third party:

  • The text of your prompts, your AI chat conversations, or AI responses.
  • Files, documents, or images you scan, and the specific sensitive values detected within them (for example Social Security numbers, card numbers, passwords, API keys, names, emails, or addresses contained in your content).
  • Full URLs, query strings, or page contents of the websites you visit.
  • Your physical or GPS location. AI ChatGuard does not request, access, or collect device geolocation.

These values are filtered out before any network request is made, enforced in code by a blocklist that strips raw text, prompts, detected values, screenshots, conversation IDs, and full URLs.

2. Information we DO collect

(a) Account & identity — only if you choose to create an account or sign in

The free tier works without an account. If you sign up we collect: your name and email address; one-way SHA-256 hashes of them; a hashed password if you choose email sign-in (we never store the plain password); a randomly generated install ID and device ID (and their hashes) used to associate your settings and license with your installation; and authentication/session tokens issued when you sign in. A local EULA acceptance record (name, email, timestamp) is stored on your device at install.

(b) Sign-in through Google or Facebook — only the provider you choose

If you choose "Continue with Google" or "Continue with Facebook," that provider signs you in. It returns your email address, display name, and profile picture URL to us. We contact only the provider you pick, and only when you start a sign-in. No chat content or browsing data is ever shared with these providers.

(c) Device & technical data — for support, compatibility, and licensing

Operating system, browser and user-agent family, device type (for example Mac or PC), CPU architecture, and core count. We do not collect hardware model names or serial numbers.

(d) Usage telemetry — metadata only, never content, opt-in and off by default

Counts and types of protection events (for example "Detected," "Redacted," "Allowed"), the general category label of the data type detected (for example personal data, work data, credential, financial, medical — classifications, not your actual data), and the AI service an event occurred on (for example ChatGPT, Claude, Gemini). Telemetry transmits only if you enable the toggle in Settings → General → Telemetry. With it off, nothing is sent and queued events from a prior consenting period are dropped.

(e) AI-surface registry — to recognize new AI tools without an update

The hostname and a structural "shape" fingerprint of pages that appear to be AI chat tools. No URL paths, query strings, page content, browsing history, page titles, or visit timestamps are sent. Contribution is opt-in via the telemetry toggle.

(f) IP address & coarse location — received server side

When your browser contacts our servers, our hosting provider, Cloudflare, receives your IP address and may derive coarse location information such as country or region. We do not collect the exact location of your device, and we do not collect GPS coordinates. We use coarse location information to comply with regional legal requirements, including EU privacy laws, and for software support, licensing, security, and abuse protection. Location is never used for advertising.

3. How we use information

  • Create, secure, and authenticate your account and sign-in.
  • Validate licensing and subscription entitlements.
  • Provide customer support and diagnose compatibility issues.
  • Maintain and improve detection coverage of AI tools (the registry).
  • Understand product usage in aggregate (event counts).
  • Meet regional legal requirements, including EU privacy laws, and support software licensing and customer support using coarse location information such as country or region.

We do not use your data for advertising, ad targeting, profiling, creditworthiness, or lending decisions. We do not sell, rent, or trade user data.

4. Every party we share data with

We share only the limited data described above, only with the service providers that operate the product on our behalf:

  • AINCO Software backend — limited account, authentication, licensing, registry, and opt-in telemetry data is processed by AINCO backend services. We use Cloudflare as our infrastructure provider.
  • ExtensionPay and its payment processor Stripe — process subscription payments if you upgrade to a paid tier. Payment-card details are entered on the processor's secure page; AI ChatGuard never receives or stores your card number.
  • Google or Facebook — only the sign-in provider you choose, and only when you initiate sign-in.

We may also disclose information if required by law, or to protect the rights, property, or safety of our users or the public. There are no other recipients of user data.

5. Google user data and Limited Use

AI ChatGuard's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Google sign-in data (email, display name, profile picture URL) is used only to create and authenticate your account, is never used for advertising, and is never sold or transferred to data brokers or other third parties.

6. On-device processing and local storage

All scanning, detection, redaction, rewriting, and on-device OCR run locally in your browser. The extension stores the following in browser storage on your device, none of which is automatically transmitted off-device: your settings and preferences; the local activity log (event metadata only, no content — you can clear it at any time or set it to auto-delete after 1 day, 1 week, 1 month, or 1 year in Settings); your EULA acceptance record; and, if you sign in, a cached account profile (email, display name, profile picture URL).

7. Data retention

  • Account & identity: retained while your account is active; deleted on request (see Section 8).
  • Authentication sessions: tokens expire automatically and are revoked when you sign out.
  • Telemetry, registry, and device data: retained for up to 13 months from collection, then deleted or irreversibly aggregated.
  • Server infrastructure logs (including IP): retained up to 13 months.
  • On-device data: kept per your retention setting; removed by the browser when you uninstall.

8. Your choices and controls

  • Use the free tier without an account.
  • Leave telemetry off (the default), or turn it off at any time in Settings → General → Telemetry; this stops all outbound audit traffic.
  • Pause or turn off protection at any time from the popup.
  • Sign out at any time (Settings → Account) to revoke the active session token.
  • Clear the local activity log and choose a retention period in Settings.
  • Request access to, or deletion of, your account data by emailing support@aincosoftware.com. We respond within seven business days and remove your email, profile data, and audit rows on confirmation.
  • Uninstall the extension at any time; local data is removed by the browser.

9. Children

AI ChatGuard is not directed to children under 13 (or the minimum age of consent in your jurisdiction), and we do not knowingly collect data from children.

10. Security

Data in transit is protected with HTTPS/TLS. Passwords are never stored in plain text; identifiers are hashed where feasible. Access to backend systems is restricted to authorized AINCO personnel. No method of transmission or storage is 100% secure.

11. Changes to this policy

We will post any changes on this page and update the effective date above. Material changes will also be flagged in-product.

12. Contact

AINCO Software · Portland, OR, USA · support@aincosoftware.com · https://aincosoftware.com

AINCO SOFTWARE PRIVACY POLICY · v0.2.128 · 2026-06-04


AI AgentGuard™ Privacy Policy

AINCO Software, LLC, of the State of Oregon
Effective date: June 15, 2026 · Version: 1.0
Contact: privacy@aincosoftware.com · https://aincosoftware.com

Our privacy promise. AINCO is the data controller for AI AgentGuard. Our core principle is metadata-only: AI AgentGuard works from hostnames and timing signals. It never reads, stores, or transmits the content of the pages you view, the text you type, your form data, your prompts, or your browsing history.

At a glance

Data categoryCollected?PurposeShared withRetention
Page content, prompts, form inputs, keystrokes, screenshots, browsing historyNeverProcessed on device onlyNo oneNot collected
Device & operational data (random device UUID, heartbeat status, license/entitlement state, extension version)Yes, to run the serviceOperate, register, and license the extensionAINCO backendWhile device is active, then limited period
AI-surface intelligence (hostnames of AI/bot/tracker endpoints + structural fingerprint shape)Opt-in, only after you accept the EULAImprove AI-surface detection listsAINCO backendLimited period, then deleted or aggregated
Account data (name, email, OAuth identifier, authentication tokens)Required to use AI AgentGuardSign-in and licensingAINCO backend; OAuth provider if you choose itUntil you delete your account
Billing dataOnly if you purchase a licenseSubscription billingExtensionPay and Stripe (full card number never reaches AINCO)Per processor policy

What we collect

Device & operational data (to run the service)

  • A randomly generated device identifier (a UUID — not a hardware fingerprint).
  • Heartbeat status: that the extension is installed and active, with timestamps.
  • License/entitlement state (Free, Pro, MSP) and extension version.

AI-surface intelligence (to improve detection) — only after you accept the EULA

  • Hostnames of AI/bot/tracker endpoints observed, plus a structural fingerprint shape.
  • No URLs, no paths, no page content, no prompts, and no personal identifiers are included.

Account data (required to use AI AgentGuard)

  • Your name and email address, and an OAuth identifier if you sign in with Google or Facebook.
  • Authentication tokens, stored locally on your device and refreshed securely.

Billing data (only if you purchase a license)

  • Handled by our payment processor (ExtensionPay / Stripe). We do not receive or store your full card number.

What we do NOT collect

Browsing history; page content; the text of your prompts or messages; form inputs; keystrokes; screenshots; precise location.

How we use data

To operate detection and enforcement; to register and license your device; to sync your settings and license across your devices; to improve our AI-surface detection lists; and to provide support. We do not sell your data and do not use it for advertising.

Consent & your controls

  • Telemetry is gated on your acceptance of the EULA during first-run. No telemetry is sent before you accept.
  • You can disable telemetry at any time in the extension's settings.
  • An account is required to use AI AgentGuard, including the Free tier — much like a free web-email service. You register during first-run with Google, Facebook, or email.
  • You can request access to, or deletion of, your account data (see Contact).

Optional privacy protections (off by default)

AI AgentGuard includes optional, user-enabled protections. Each is disabled unless you turn it on, and none of them collect or transmit anything:

  • Block Fingerprints — injects a small script into the pages you visit that adds noise to common device-fingerprinting signals (canvas, WebGL, audio, and timing). It changes only what fingerprinting scripts can read; it reads no page content and transmits nothing.
  • Block Recording — blocks known session-replay and heatmap (session-recording) trackers from loading.
  • Block Location — blocks a site's access to the browser geolocation API. It blocks location access; it does not collect your location.

Enterprise / managed installations

Where AI AgentGuard is deployed by an organization via managed policy, the organization is the controller of its deployment. Administrators may enable or disable telemetry and route audit events to their own SIEM (audit_endpoint). Consult your organization's policy.

Service providers (processors)

  • Cloudflare — hosting and edge delivery of our APIs.
  • ExtensionPay / Stripe — subscription billing.
  • Google / Meta — only if you choose OAuth sign-in.

Each processes data only to provide its service to us.

Data retention

Operational and registry metadata are retained while your device is active and for a limited period thereafter, then deleted or aggregated. Account data is retained until you delete your account.

Security

Data in transit is encrypted (HTTPS). Identifiers are random; access is least-privilege; we maintain audit logging. No method is perfectly secure, but we design to minimize what we hold.

Children

AI AgentGuard is not directed to children under 13 (or the applicable age in your region) and we do not knowingly collect their data.

International transfers

We operate in the U.S., Canada, and Europe. Where required, we rely on appropriate safeguards for cross-border transfers.

Your rights

Depending on your location (e.g., GDPR / CCPA), you may have rights to access, correct, delete, or port your data, and to object to or restrict processing. Contact us to exercise them.

Changes

We will post any changes here and update the effective date; material changes will be surfaced in the extension.