CORPILUS
Browser extension privacy

Corpilus Privacy Extension — Privacy Policy

Last updated: 2026-05-24

TL;DR — The Corpilus Privacy extension checks what you type, paste and attach before it reaches ChatGPT, Claude or Gemini, and masks or blocks personal and business identifiers. It is part of a Corpilus subscription and protects nothing until you sign in. The pattern check itself runs inside your browser, so the text you are about to send does not leave your device for it. Three things do use the Corpilus workspace you signed in to: files you ask it to check, the warning about hidden instructions in text you paste, and the optional deep check that additionally looks for names. Nothing is stored. If your company runs its own Corpilus — a dedicated server or an NVIDIA DGX Spark box — point the extension at it and even those never reach us.

1. What the extension does

Corpilus Privacy is a Manifest v3 browser extension that watches the prompt input field on ChatGPT, Claude.ai, and Gemini. When you start typing or paste content, it scans the text with a 9-language pattern corpus and replaces personal identifiers (names, emails, phone numbers, national IDs, IBANs, tax IDs) and business identifiers (contract numbers, internal project codes, customer IDs) with neutral placeholders such as [PERSON] or [TAX_ID]. The redacted version is shown inline before submit — you decide whether to send the redacted version, the original, or undo specific matches.

2. What data we collect

The extension does not store your prompts, and Corpilus does not keep them. Stays in your browser: • The pattern check on what you type and paste. The full pattern set runs locally, so this works with no network and the text does not leave your device. Goes to the Corpilus workspace you signed in to: • Files you ask it to check. • Text you paste, for the warning about hidden instructions aimed at the AI. • The optional deep check, which additionally looks for names. • A licence check (your tenant ID and subscription token). • Optional audit log entries — a SHA-256 hash of the masked prompt and per-pattern hit counts, never the original text. None of it is stored. If your company runs its own Corpilus (dedicated server or NVIDIA DGX Spark), set that address in Settings and these go to your own infrastructure instead. From your browser to the AI provider you chose: • Whatever you decide to submit — typically the masked prompt with placeholders. That submission is governed by the AI provider's own privacy policy (OpenAI, Anthropic, Google).

3. What data we do NOT collect

• Original prompt text — never • Personally identifying content of the prompts — never • Browsing history, URLs visited, search queries — never • Activity outside the three AI consoles — never (host permissions are limited to ChatGPT, Claude, Gemini, and our API) • Telemetry such as keystrokes, mouse movements, screenshots — never

4. Legal basis (GDPR Article 6)

Processing for the operation of the extension is based on: • Article 6(1)(b) — performance of your Privacy subscription contract • Article 6(1)(f) — legitimate interest in protecting our customers' confidential data when interacting with public AI services For audit log entries that include workspace-identifying metadata, the controller is your organization (your Corpilus tenant). We act as a processor on its instructions.

5. Data retention

• Licence tokens: stored in your browser; refresh on each session. • Pattern corpus: cached in your browser for up to 30 days. • Audit log entries (only if enabled): stored in your Corpilus workspace for the retention period you configure (default 12 months). You can export or delete them at any time via Settings → Audit Log. • Server logs of API calls: 30 days, then anonymised aggregates.

6. Third party data sharing

We do not sell, rent, or share your data with third parties for marketing. The extension transmits data to two categories of third parties only: • The AI provider (OpenAI / Anthropic / Google) — only what you submit. We do not control or proxy this; the data goes directly from your browser. • Technical service providers who help us operate the service — for API requests strictly related to the operation of the service. We never sell your data. We never use your data to train models.

7. Open-source patterns and audit

The pattern corpus and detection rules are documented in our public spec at github.com/corpilus/privacy-patterns. You can inspect every rule that will run against your prompts. The extension source code is reviewed before each Chrome Web Store release; release notes list every meaningful change.

8. Changes to this policy

If we change this policy in a way that materially affects what data is collected or how, we will notify subscribers by email at least 14 days in advance and bump the 'Last updated' date above. Continued use of the extension after the effective date constitutes acceptance.

Permissions we request and why

We follow Chrome's principle of least privilege. Every permission below has a single, documented purpose. We do not collect browsing history, do not track you across sites, and do not inject ads.

storage
Saves your local preferences (enabled / paused, language, redaction strictness) and a cached licence token. Never synced to our servers.
activeTab
Lets the popup interact only with the AI console tab you are looking at — never silently in the background.
host: chat.openai.com, chatgpt.com
Reads the prompt text from the ChatGPT input field before submit; never reads anything else on the page.
host: claude.ai
Same as above but for Claude.ai.
host: gemini.google.com
Same as above but for Gemini.
host: api.corpilus.com
Signs you in, checks files you attach, flags hidden instructions in pasted text and runs the optional deep check. The ordinary pattern check does not use it — that runs in your browser. Point this at your own Corpilus server in Settings if you self-host.

Contact

Data Protection inquiries: info@corpilus.com For GDPR data subject requests (export, deletion, objection) email the same address. We respond within 30 days as required by Article 12 of the GDPR.