Aegis AI Guard
Privacy Policy
Last updated August 7, 2026
This policy explains how Aegis AI Guard collects, handles, stores, and shares user data in the Chrome extension, dashboard, and supporting services.
1. Who we are
This Privacy Policy describes how Aegis AI Guard ("Aegis," "we," "us," or "our") collects, uses, stores, and shares information when you use the Aegis AI Guard Chrome extension, web dashboard, marketing site, and related APIs (together, the "Service").
For business and family deployments, the organization or parent/guardian account that deploys Aegis is typically the controller of member or household data. Aegis processes that data as a service provider to operate the Service. For individual account holders and marketing-site visitors, Aegis is the controller of the data described below.
Privacy contact: aegisaiguard@gmail.com. Website: https://aegisaiguard.com.
2. User data collection
Depending on how you configure and use the Service, Aegis may collect:
- Prompt content. The extension reads prompt text typed into supported AI sites (ChatGPT, Claude, Gemini, and Microsoft Copilot) so it can analyze risk before submission. Analysis runs locally by default. Cloud analysis requires both explicit user consent and an organization policy that enables it; then the prompt is transmitted over HTTPS for transient analysis.
- Prompt metadata and findings. SHA-256 prompt hash, prompt length, risk score, severity, matched categories, enforcement action taken, analysis mode, platform name, timestamps, and truncated browser user-agent.
- Account and authentication data. Email address, name, role, organization membership, password (processed for authentication; not stored by Aegis in plaintext), and session tokens.
- Network and request metadata. IP address associated with authenticated API requests that sync events, used for security and audit context.
- Local extension settings and state. Preferences, policy cache, encrypted session credentials, event retry queue, usage counters, family controls (including PIN hash/salt, child profile display name, schedules, and category settings), override/approval request records, and local behavior counters.
- Billing information. Plan selection and Stripe customer/subscription identifiers. Payment card details are collected and processed by Stripe, not stored on Aegis servers.
- Marketing and support leads. Name, email, company, form selections, and message content submitted through demo or contact forms. When enabled, Cloudflare Turnstile receives the verification token and request metadata needed to prevent automated abuse.
- Website analytics. Aggregated site analytics and performance metrics on the Aegis website/dashboard (for example via Vercel Analytics and Speed Insights) only after the visitor opts in through Privacy choices. The preference is stored in the browser and can be changed at any time.
Aegis collects this information through the Chrome extension (content scripts and background service worker), the dashboard and account APIs, and voluntary form submissions on the website. We do not sell user data.
3. How we handle and use user data
We use collected data only to operate and improve the Service's disclosed purpose:
- Analyze prompts for policy, safety, and data-loss risks before they are submitted to AI platforms.
- Enforce organization or family policies (allow, warn, block, require approval).
- Provide audit logs, security alerts, and administrative reporting to authorized org admins/managers or family account holders.
- Authenticate users, maintain sessions, and manage roles and memberships.
- Process subscriptions and billing.
- Respond to support, demo, and contact requests.
- Maintain security, prevent abuse, diagnose failures, and measure site reliability.
Limited Use. User data obtained through the Chrome extension is used only to provide and improve Aegis AI Guard's single purpose: AI prompt policy enforcement and safety controls. We do not use that data to determine creditworthiness or for unrelated advertising. We do not sell or transfer user data to third parties for purposes unrelated to the Service's core functionality, except as required by law or with user consent.
Prompt plaintext sent for cloud analysis is used transiently to return risk scores and findings and is not logged or persisted. Event sync is hash-and-metadata only; client risk fields are labeled as client-reported rather than server-verified.
4. Storage and security
On-device storage. The extension stores settings, a wrapped refresh credential, policy cache, event outbox/retry state, usage stats, and family-control configuration in Chrome local storage (chrome.storage.local). Access tokens use chrome.storage.sessionand expire with the browser session. Refresh-token wrapping is defense-in-depth, not a secret against software that can read extension storage.
Server storage. Account profiles, organization policies, prompt-event metadata (including prompt hash, scores, categories, actions, platform, IP address, and email/name snapshots), security alerts, audit logs, and billing identifiers are stored in our database hosted by Supabase. Dashboard and API hosting is provided by Vercel.
Transmission. Data transmitted between the extension, dashboard, and Aegis APIs uses HTTPS. Optional custom backend host access is requested only when an administrator connects a non-default backend origin.
Retention. Default retention is 90 days for prompt events and security alerts, and one year for audit logs. Organization administrators can preview and apply retention cleanup from the dashboard privacy controls. Provider backups may persist for a limited backup window and are not used as active product data.
Uninstall. Removing the extension stops further collection by the extension. Local extension storage is cleared according to Chrome's uninstall behavior. Server-side account and organization data remain until deleted through dashboard privacy controls or a privacy request.
5. Sharing of user data
We share user data only with service providers and authorized parties needed to operate the Service:
- Supabase — authentication and database hosting.
- Vercel — application hosting, plus optional, consent-gated Vercel Analytics and Speed Insights for aggregated website/dashboard usage and performance.
- Stripe — payment processing and subscription management.
- Resend or FormSubmit — configured delivery of demo and contact-form lead emails. FormSubmit is the repository fallback when a Resend API key is not configured.
- Cloudflare Turnstile — optional CAPTCHA verification for signup and lead forms when configured.
- Organization administrators and managers (or family account holders) — access to event metadata, alerts, member account details, and related reports for their tenant, consistent with assigned roles.
We may also disclose information if required by law, legal process, or to protect the rights, safety, and security of users or the Service. We do not sell personal information and do not share extension user data with AI platforms beyond what the user themselves submits on those sites.
6. Extension permissions
Aegis requests storage (settings, encrypted credentials, policy data, and a bounded event retry queue), alarms (policy refresh and reliable event delivery), scripting, and host access to supported AI sites so it can inspect a prompt before submission and show the policy panel. Optional broader host access may be requested when an administrator connects a custom backend URL. Permissions are used only for these disclosed functions.
7. Children and family accounts
Family mode is intended for use by a parent or guardian who configures controls for household members. Parents/guardians are responsible for obtaining any consent required for children's use. Family settings may store a child profile display name, schedule, category restrictions, PIN hash/salt, and approval/override request reasons. Children should not create standalone Aegis accounts without parental involvement.
8. Your choices and rights
You can:
- Choose local-only analysis versus cloud (or both) analysis in extension settings.
- Sign out, change settings, or uninstall the extension at any time.
- Allow or decline optional Vercel telemetry through the persistent Privacy choices control; telemetry components remain unloaded when declined.
- Use dashboard privacy controls (where available to your role) to export tenant data, apply retention cleanup, anonymize deleted-member snapshots, or request organization deletion.
Depending on your location, you may also request access, correction, export, deletion, restriction, or objection regarding personal data we control. Contact aegisaiguard@gmail.com, or your organization administrator if your data is processed under an organization account.
Member dashboard actions anonymize historical event snapshots; they do not erase the Supabase authentication identity. Organization deletion requests require review and may retain narrowly required security/audit records for legal holds, fraud prevention, or statutory obligations. Contact us for a full lawful erasure request.
9. Changes to this policy
We may update this Privacy Policy to reflect product or legal changes. The "Last updated" date at the top will change when we do. Material changes to data handling practices will be disclosed prominently, including through the Service or Chrome Web Store listing where required. Continued use of the Service after an update means you acknowledge the revised policy.