Last Updated: 17 September 2026
Applies to: Promptrix version 7.0 and later
Promptrix ("Promptrix", "the Extension", "we", "us", or "our") is a Chrome extension designed to provide local GenAI data-loss prevention (DLP), prompt protection, AI interaction capture, and security auditing.
This Privacy Policy explains what information Promptrix accesses, how that information is processed, where it is stored, and under what circumstances information may leave the user's device.
Promptrix is designed with a local-first privacy architecture.
By default:
Promptrix processes supported AI interactions locally in the browser.
Promptrix does not operate a central server for user prompts or responses.
Promptrix does not sell, rent, or monetize user data.
Promptrix does not use captured prompts or responses for advertising or model training.
Promptrix does not use third-party analytics or advertising SDKs.
Promptrix does not collect general browsing history.
Promptrix does not require a Promptrix account.
Promptrix does not require access to the user's identity or email address.
DLP inspection is performed locally on the device.
Promptrix has optional integrations that can transmit information outside the device. These integrations are disabled by default and require the user to explicitly configure the destination.
Promptrix operates only on explicitly supported AI platforms.
Supported platforms may include:
ChatGPT
Google Gemini
Google AI Studio
Anthropic Claude
Perplexity
Microsoft Copilot
Microsoft Bing AI experiences
The exact supported domains may change as platforms evolve.
Promptrix does not intentionally operate on unrelated websites or collect general browsing activity.
On supported AI pages, Promptrix may access information necessary to provide its functionality, including:
Promptrix may read text entered or pasted into supported AI prompt fields.
This information is processed to:
perform DLP inspection;
detect potentially sensitive information;
warn the user;
block submission when configured;
mask detected sensitive information when configured; and
optionally save the interaction to the user's local prompt library.
Promptrix may read AI-generated response text on supported platforms.
Response content is used to provide the prompt-library and conversation-capture functionality.
When a user attaches a file to a supported AI interaction, Promptrix may inspect the file locally before the file is submitted.
Depending on the file type, Promptrix may inspect:
file bytes;
file type;
filename;
file size;
document text;
PDF content;
Office document content;
archive contents; and
other locally extractable content required for DLP inspection.
Attachment contents are processed locally for DLP inspection.
Promptrix does not transmit attachment contents to Promptrix-operated servers for DLP analysis.
Where technically applicable, extracted attachment content is processed in memory and is not retained as a separate stored copy after inspection.
Promptrix may capture:
AI platform name;
supported chat/session URL;
timestamp; and
locally generated identifiers required to organize captured activity.
The session URL is used to allow the user to associate a saved interaction with its original AI conversation.
Promptrix is not designed to collect:
passwords;
authentication credentials;
authentication cookies;
session tokens;
API keys outside the content voluntarily entered into an AI interaction;
payment card information as a separate data source;
device files unrelated to an attachment voluntarily submitted to a supported AI interaction;
general browser history;
browsing activity on unrelated websites;
keystrokes outside supported AI interaction fields;
precise location information;
contacts;
microphone or camera data;
Google account identity information;
Microsoft account identity information; or
email addresses through Chrome's identity APIs.
Promptrix does not request the Chrome identity or identity.email permission unless a future version explicitly introduces a feature requiring such access and the corresponding privacy disclosures are updated.
Prompts and AI responses may contain sensitive or personal information because users may voluntarily enter such information into an AI service.
Promptrix may inspect this content because detecting sensitive information is a core function of its DLP functionality.
Examples of information that may be detected include:
passwords and credentials;
API keys;
access tokens;
private keys;
financial information;
personally identifiable information;
cloud credentials;
source code secrets;
database connection strings;
internal company information; and
other security-sensitive content supported by the DLP detection rules.
Promptrix processes this information to provide DLP protection.
Promptrix does not intentionally use detected sensitive information for advertising, profiling, sale, or AI model training.
Before a supported AI prompt is submitted, Promptrix may inspect the prompt locally against the configured DLP policy.
Depending on the user's configuration, Promptrix may:
allow the prompt;
display a warning;
mask detected sensitive values;
block the prompt; or
record a security event in the local audit log.
The DLP engine is designed to perform detection locally.
Promptrix does not send prompt content to a Promptrix-operated cloud service for DLP analysis.
When DLP or security activity occurs, Promptrix may create a local audit event.
An audit event may contain:
generated event identifier;
timestamp;
AI platform;
chat/session URL;
action performed;
detector name;
data classification;
severity;
number of detected matches;
file name;
detected file type;
file size; and
content hash where applicable.
Promptrix is designed not to store the detected secret value itself in the audit event.
For example, a detected credential may be represented by a redacted value or placeholder rather than the original credential.
The audit log is intended to contain security metadata and redacted evidence, rather than the raw sensitive value.
The local audit history is limited to the most recent 1,000 events, unless a future version specifies a different limit.
Promptrix stores its locally retained data using Chrome extension storage mechanisms, including chrome.storage.local where applicable.
Chrome's Storage API provides extension-specific storage accessible to the extension's contexts.
Locally stored information may include:
captured prompts;
captured AI responses;
session URLs;
timestamps;
AI platform information;
DLP configuration;
detector configuration;
local audit events;
application settings; and
other information required to operate the Extension.
Promptrix does not maintain a central database containing users' captured prompts or responses.
Promptrix provides optional integrations that can transmit information outside the browser.
These integrations are disabled by default.
Information is transmitted only after the user explicitly enables and configures the relevant integration.
Users may configure a Cloudflare Worker endpoint for synchronization.
When enabled, the configured synchronization process may transmit captured prompt-library information, including prompts and AI responses, to the endpoint selected by the user.
The Cloudflare Worker is deployed and controlled by the user or their organization.
Promptrix does not operate that Worker or control the data stored there.
Users may configure a GitHub Gist backup.
When enabled, Promptrix may create or update a private GitHub Gist selected by the user.
The backup may contain a JSON representation of the user's locally stored prompt library.
The JSON backup is not encrypted by Promptrix.
Users are responsible for the security and access controls of their GitHub account and Gist.
Users may configure a SIEM or HTTP collector to receive Promptrix security events.
By default, forwarded events contain security metadata such as:
event type;
timestamp;
action;
detector;
classification;
severity;
AI platform; and
redacted evidence.
Sending raw prompt content is an explicit user-controlled option.
If the user enables transmission of prompt content, that content may leave the device and will be sent to the endpoint configured by the user.
Users should only configure SIEM or webhook destinations that they trust and are authorized to use.
When an optional integration is enabled, information may leave the user's device.
Promptrix does not control the privacy practices, retention policies, security controls, or processing performed by a destination configured by the user.
Examples include:
a user's Cloudflare Worker;
a user's GitHub account or Gist;
an organization's SIEM;
an organization's security webhook; or
another endpoint explicitly configured by the user.
Users are responsible for reviewing the privacy and security practices of those services.
Promptrix does not:
sell user data;
rent user data;
trade user data;
sell prompts or AI responses;
use prompts for advertising;
use prompts for behavioral advertising;
build advertising profiles;
provide captured content to data brokers; or
use captured prompts or responses to train AI models.
Promptrix does not include third-party advertising SDKs or analytics SDKs for tracking user behavior.
Promptrix's core DLP processing is designed to operate locally.
Promptrix does not require a Promptrix-operated server to analyze prompts or attachments.
Network communication may occur when the user explicitly enables an external integration, such as:
Cloudflare synchronization;
GitHub backup; or
SIEM/webhook forwarding.
The destination is determined by the integration configured by the user.
Where supported by the configured integration, Promptrix uses HTTPS for external communications.
Promptrix may require credentials or authentication material when a user configures an external integration.
Examples include:
GitHub access credentials or tokens;
Cloudflare credentials or tokens; and
SIEM authentication credentials.
These credentials are used only to authenticate the configured integration.
Where Promptrix stores integration credentials locally, it uses the security mechanisms implemented by the Extension and Chrome's extension storage environment.
Promptrix does not transmit these credentials to a Promptrix-operated server.
Users should revoke credentials from the corresponding third-party service when an integration is no longer required.
Promptrix requests permissions necessary to provide its functionality.
Host access is used to operate on supported AI platforms and to perform the Extension's prompt capture and DLP functions.
Optional permissions may be requested at runtime when required for optional functionality.
Chrome provides an optional-permission mechanism that allows extensions to request certain permissions when the related feature is enabled rather than requesting all permissions during installation.
Promptrix does not intentionally use permissions to monitor unrelated browsing activity.
The actual permissions requested by each published version are defined by that version's Chrome extension manifest.
Captured data remains locally stored until the user deletes it or removes the Extension.
Audit history is subject to the local audit-log limit described above.
Data transmitted to an external integration is subject to the retention policies of the destination selected by the user.
Promptrix does not control or automatically delete data already transmitted to a user's:
Cloudflare Worker;
GitHub Gist;
SIEM; or
webhook endpoint.
Users must manage deletion in those systems.
Promptrix provides users with controls to manage locally stored information.
Depending on the Extension version, users may:
delete individual captured interactions;
clear capture history;
clear the DLP activity log;
export locally stored information;
disable individual DLP detectors;
disable DLP functionality;
disable external integrations; and
remove the Extension.
Uninstalling Promptrix removes data stored by the Extension in its local extension storage, subject to Chrome's extension-storage behavior.
Data already transmitted to external services must be deleted from those services separately.
Promptrix uses a local-first architecture to reduce unnecessary transmission of sensitive information.
Security measures include:
local DLP processing;
minimal host access;
no Promptrix central prompt database;
redaction of sensitive evidence in local audit records;
HTTPS for configured external transmissions; and
user-controlled external integrations.
No electronic storage or transmission method can be guaranteed to be completely secure.
Users are responsible for securing their browser profile, operating system, device, and any external services they configure.
Promptrix is not directed toward children under 13.
Promptrix does not knowingly design its service to collect personal information from children.
This Privacy Policy may be updated when Promptrix's functionality, data handling, permissions, or integrations change.
The "Last Updated" date will be updated when material changes are made.
If a change materially affects what information Promptrix accesses, stores, or transmits, the relevant disclosure will be updated accordingly.
For privacy questions, security concerns, or requests relating to Promptrix, users may contact the developer through the official support channel provided on the Promptrix Chrome Web Store listing or through the official Promptrix project repository.
This Privacy Policy describes the intended data handling of Promptrix 7.0 and later.
The Extension's actual Chrome permissions, host permissions, optional permissions, network destinations, and data-handling behavior must remain consistent with these disclosures.
If a future version introduces a new category of data collection, new external service, new permission, or materially different data use, this Privacy Policy will be updated before or alongside that functionality.
Promptrix Privacy Model
Local by default → DLP processing on-device → Local storage → User-controlled integrations only when explicitly enabled.
Promptrix is designed so that sensitive AI interaction data does not need to pass through a Promptrix-operated server to perform its core DLP functionality.