Privacy Policy — AI Sentinel
Privacy Policy — AI Sentinel
Last updated: August 5, 2026
Contact: sammat1683@gmail.com
AI Sentinel is a Chrome extension that (1) checks whether a website you're
visiting has a known public data breach history, (2) warns you before you
type or paste sensitive information like a credit card number, Social
Security Number, or API key into a web page, and (3) watches AI chat
responses (on services like ChatGPT, Claude, and Gemini) for the same kinds
of sensitive information appearing in the AI's reply.
This policy explains exactly what the extension does and does not do with
your data.
WHAT WE DO NOT COLLECT
AI Sentinel does not collect, transmit, or store the actual content of
anything you type, paste, or read. Specifically:
- We never store the text of a credit card number, Social Security Number,
API key, password, or any other sensitive value you type.
- We never send the content of your messages, chats, or web pages to any
server we control. We do not operate a server at all — there is no
backend collecting your activity.
- We do not track your browsing history.
- We do not use analytics, advertising, or tracking scripts of any kind.
- We do not sell, rent, or share any information with third parties.
WHAT THE EXTENSION DOES STORE, AND WHERE
When the extension detects something that looks sensitive (for example, "a
credit card number appeared in a text field"), it stores only:
- The category of what was detected (e.g. "credit card number")
- The website's domain name (e.g. "example.com")
- The date and time
- Whether it appeared in something you typed, or in an AI's reply
This information is stored using Chrome's built-in local storage
(chrome.storage.local), directly on your own device. It is never uploaded,
synced to any server, or accessible to anyone but you. You can clear this
history at any time from the extension's popup ("Clear history" button), or
by uninstalling the extension.
WHAT DATA LEAVES YOUR DEVICE, AND WHY
The only outbound network request the extension makes is to
haveibeenpwned.com, a free, independent, public breach-notification
service, to check whether the domain of the site you're currently visiting
has a known data breach on record.
- Only the domain name is sent (e.g. "example.com") — never your personal
information, your email address, your browsing history, or anything you
typed.
- This request happens automatically when you visit a site, so the
extension can show you the breach information without you having to ask.
- Have I Been Pwned's own privacy practices govern how they handle this
request; you can review their policy at haveibeenpwned.com/Privacy.
No other network requests are made by this extension.
PERMISSIONS THIS EXTENSION USES, AND WHY
- Read and change data on websites you visit: needed to scan page content
for breach-relevant context and to watch text fields and AI replies for
sensitive-looking data, entirely on your device.
- Storage: needed to remember your settings and the alert history described
above, locally on your device.
- Notifications: used only to show you in-page warning banners; no
notifications are sent from any server.
CHILDREN'S PRIVACY
This extension is a general-purpose privacy and security tool and is not
directed at children. It does not knowingly collect information from
children, in part because it does not collect personal information from
anyone.
CHANGES TO THIS POLICY
If this policy changes, the "Last updated" date at the top of this page
will be revised. Continued use of the extension after a change means you
accept the updated policy.
CONTACT
Questions about this policy or how the extension works can be sent to:
sammat1683@gmail.com