In short
Prompt Guard processes the content it inspects on your device, and that content is never sent to us. Some features do involve our servers — activating a licence, syncing your settings if you switch that on, or applying a policy your organisation set — and this policy sets out exactly which, and exactly what each one carries.
Accounts: Free needs no account. Pro and Team create one when you activate your licence.
01Scope
This policy applies to the Prompt Guard browser extension published by ExtHive, on every browser where it is distributed.
It does not cover the websites you use Prompt Guard on. Those sites have their own privacy policies, and using our extension does not change how they treat your data.
The general ExtHive Privacy Policy covers everything not specific to this extension, including your rights and how to exercise them.
02Permissions and why each one exists
Browsers ask you to approve permissions at install time. Here is every permission Prompt Guard requests and the feature that requires it. We do not request permissions for features we have not built.
| Permission | Why it is needed |
|---|---|
storage | Stores your detector settings, allowlist and local activity log on your device. |
Host access to supported AI sites | Lets the extension read and annotate the compose box on the AI platforms you enable. It is not granted for any other site. |
scripting | Injects the scanner and the inline warning UI into supported pages. |
Host access to api.exthive.com | Used by paid plans only, to activate your licence and — where you have enabled them — to sync settings or fetch your organisation's Team policy. The Free plan makes no requests to this host. |
03What happens to each kind of data
The table below lists every category of data Prompt Guard touches, how it is handled, and whether it ever leaves your device. Only if enabled means it stays local unless you turn on a feature that needs otherwise, or are on a plan that includes one.
| Data | Handling | Leaves device? |
|---|---|---|
| Prompt text and detector matches | Scanned in memory inside your browser and discarded immediately after the scan. Never transmitted to ExtHive or any third party, on any plan, including Team. | No |
| Settings, custom detectors and allowlists | Stored in local extension storage by default. If you enable Pro settings sync, they are encrypted and stored by ExtHive so your own devices stay in step. On Team plans, the administrator's policy and shared allowlist are fetched from ExtHive; your personal entries stay yours. | Only if enabled |
| Activity log | Records the detector name, timestamp and action taken — never the matched value or surrounding prompt. Stays on your device on Free and Pro. On Team plans this metadata is reported to your organisation's audit export. | Only if enabled |
| Account, licence and subscription data | Paid plans only. Your email, licence key, plan and subscription status are processed to operate the licence. Payments are handled by Paddle as Merchant of Record; ExtHive never sees your card details. The Free plan creates none of this. | Only if enabled |
04Accounts and features that use our servers
The Free plan has no sign-up at all: no email, no identifier, no network calls to us. Pro and Team need an ExtHive account because a paid licence has to belong to someone — pasting the licence key we email you creates it, keyed to the address you purchased under. That account holds the licence, enforces the device limit, and is what makes optional settings sync and Team policy possible. Cancelling drops you back to Free rather than locking you out, and you can delete the account afterwards.
These are the only parts of Prompt Guard that involve ExtHive servers. Everything else runs on your device.
| Feature | What it sends | Optional? |
|---|---|---|
| Licence activation | Paid plans check your licence key and subscription status against our servers so the paid features can unlock, and periodically thereafter. | No — included in the plan |
| Settings sync (Pro) | Off unless you turn it on. Copies your detector configuration, custom rules and allowlist between your own devices, encrypted in transit and at rest. | Yes — off by default |
| Team policy and seats (Team) | Your administrator's detector policy, shared allowlist and seat assignments are stored by us and distributed to the seats in your organisation. | No — included in the plan |
| Organisation audit export (Team) | Seats report which detector fired, when, and what the user did — never the matched value or the prompt around it — so administrators can report on the control. | No — included in the plan |
Deleting your account removes the data held for these features. Where a feature is optional, turning it off stops any further data being sent and deletes what was already stored, as set out under Retention below.
05What we never collect
To be explicit, Prompt Guard does not collect, transmit or store any of the following:
- your browsing history or the list of sites you visit;
- the content of pages you view, beyond the moment-in-time processing described above;
- keystroke logs or clipboard contents;
- device fingerprints, advertising identifiers or location data;
- anything used to build an advertising or behavioural profile.
We do not sell data, we do not share it with data brokers, and we do not use your content to train machine learning models.
06Local storage on your device
Prompt Guard uses your browser’s extension storage to keep your preferences. That storage is sandboxed to the extension: other websites and other extensions cannot read it.
You can clear it at any time from the extension’s settings, or by removing the extension. Uninstalling deletes all local extension data permanently.
If you have enabled a feature that stores data with us — settings sync, or a plan that applies an organisation policy — uninstalling does not by itself delete that copy. Turning the feature off or deleting your account does, on the timeline set out under Retention.
If you enable your browser’s built-in extension sync, your browser vendor — not ExtHive — may sync those preferences across your own devices under their privacy policy.
07Retention
Prompt text is held only in volatile memory for the duration of a scan and is never written to disk or to a network. Local settings and logs persist on your device until you clear them or uninstall. Synced settings are held for as long as sync is enabled and are deleted within 30 days of you turning it off or deleting your account. Team policy and audit metadata are retained for the life of the organisation's subscription, or a shorter period if the administrator sets one. Licence and billing records are retained for as long as your subscription is active, and afterwards only as long as tax and accounting law requires.
08Extension store disclosures
Extension stores require developers to declare their data handling. Our declarations for Prompt Guard state that we do not sell or transfer user data to third parties beyond the approved use cases, do notuse or transfer it for purposes unrelated to the extension’s single purpose, and do not use or transfer it to determine creditworthiness or for lending.
Those declarations match this policy. If you ever find a discrepancy between what a store listing says and what this page says, please tell us at privacy@exthive.com and we will correct it.
09Your rights and how to use them
Because Prompt Guardkeeps your data on your own device by default, you can exercise most privacy rights directly: view your data in the extension’s settings, export it where an export exists, and delete it by clearing storage or uninstalling.
For anything held in your account — a licence record, synced settings, an organisation policy or a support email — write to privacy@exthive.com. Your full set of rights, and the timeframes we work to, are set out in the general Privacy Policy.
10Changes to this policy
If Prompt Guard’s data handling changes, we will update this page and the date at the top before the change ships. A change that would send data off your device where it previously did not will always be announced in advance and, where the law requires, made subject to your consent.
Questions about this document?
Write to legal@exthive.com and a person will answer, usually within 1 business day.