Privacy

What we send, and what we never send.

Your message text never reaches us. There is no version of this product where we can see what you typed.

The short version

Guard4AI runs on your machine.

Four things happen when you use it: it reads your message, works out which parts are sensitive, swaps them for realistic fakes, and swaps your real values back into the reply. All four happen inside your browser. There is no step where your text is sent to us, or to anyone else, to be checked.

One thing does leave, and it is worth being exact about, because “your text never leaves your device” would be too strong. The message you send to ChatGPT, Claude or Gemini still goes to ChatGPT, Claude or Gemini. That is what sending it means, and no browser extension can change it. What Guard4AI changes is the version that arrives: the sensitive parts are replaced before it goes, so the AI company receives the masked text rather than the real values. Anything Guard4AI does not catch goes as you typed it. Their privacy policy governs it from there, not ours.

Three things ever leave while you work, all of them tally marks, and a fourth request carries nothing but your seat id. A note that something was caught, and what kind of thing it was, so an admin can see the system is working. Once a day, the name of an AI tool you used, so an admin can see which tools the company uses at all. And when you attach a file, its broad type and one of three outcomes. Not the value. Not the message. Not the file. Separately, and on a timer, your browser asks whether your seat is still valid and what scanning policy your admin has set; that request carries your seat id and nothing else. On a personal licence, none of them.

One thing leaves once, at the start. On a team plan, the first and last name you type when you redeem your employer’s invite code. It is stored against your seat and shown to the admin who issued the code, so the tally marks above have a person’s name on them rather than a serial number. A personal licence never asks for it.

That accounts for everything Guard4AI sends. Written out as requests rather than as topics, a team seat can make six and no others:

  1. Redeeming the invite code, once. Carries the code and the first and last name you type.
  2. Recording a catch. Carries your seat id, the category, and which AI tool it happened on. One request per category.
  3. Recording a tool as used, at most once per tool per day. Carries your seat id and the tool’s name.
  4. Recording an attachment. Carries the file’s broad type and one of three outcomes.
  5. Confirming the seat is still valid, roughly every fifteen minutes while you are using an AI tool. Carries your seat id, and brings back the scanning policy your admin has set.
  6. Handing the seat back when you deactivate. Carries your seat id.

A personal licence makes two: it checks the key is still paid, and it releases the device when you deactivate. None of the eight carry your message.

Everything on this page describes the extension unless it says otherwise. This website is a separate thing and it does use analytics, which is set out in a section of its own near the bottom. The two never meet.

What Guard4AI does

It watches the message box on twenty-eight supported AI chat sites, including ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, Meta AI, DeepSeek and Mistral. Before you send, it checks the text for phone numbers, emails, addresses, passwords, card numbers, Medicare and passport and TFN numbers, names, company names and confidential business detail.

It can warn you, or swap the real value for a realistic fake one so the AI never sees the real thing. When the reply comes back, it swaps your real values back in locally, so you read your own information and the AI never knew it.

Dollar amounts, dates and quantities are flagged but deliberately left alone, so sums you ask the AI to do still come out right. You can mask one by hand any time you want.

What leaves your device

When Guard4AI catches something sensitive, all that leaves your device is a tally mark.

It adds one to a number on your admin’s dashboard, and says what kind of thing it was: a phone number, an email address. That’s it. Not the number itself. Not the message. Not a single word of what was typed.

An admin can see
  • that something was caught
  • what category it was (“Phone number”)
  • which AI tool it happened on
  • which person, by the name they gave when they activated
  • when
  • which AI tools the company uses, as a share — with no seat attached
  • how many attachments were checked, stopped, or unreadable — also with no seat attached
An admin can never see
  • the actual value
  • the message it was in
  • any text around it
  • the page address
  • anything about the rest of your browsing
  • anything you typed, ever
  • the name, size or contents of any file you attach

“Which AI tool” means the name of the site, such as ChatGPT or Claude or Gemini, chosen from a fixed list of the twenty-eight sites Guard4AI supports. It is not a link and not a page address. Guard4AI has no access to any other site on the web and cannot see the rest of your browsing at all.

What happens to the files you attach

When Guard4AI checks an attachment it tells the company account two things: roughly what kind of file it was — PDF, Word document, text, image, or a format it does not read — and which of three things happened. It was read and nothing was found; it was stopped for you to look at; or it could not be read at all.

Never the filename. Never the size. Never a page of it, a word of it, or anything it found in it. And no seat id: that record has no column for one, the same as the AI tool counter.

This is new, and it is worth being plain about what changed. Until now the company account only ever heard about an attachment when something was stopped in it. An admin could see the catches and had no idea what they were a fraction of — and no way at all to see how much of what their team attaches Guard4AI cannot open. Spreadsheets, slide decks and scanned pages with no text layer are attached unchecked, and an admin who does not know that is being given a false picture of their own coverage.

Your admin sees it as three counts for the whole company, and a breakdown of the unreadable ones by file type. Never a filename, never a size, never anything from inside the file.

These counts are shown from the first connected browser. On a small team that means they can be about you specifically: with two or three people, a company total is close to an individual one. We would rather say that plainly than imply a crowd you are not hidden in.

Which AI tools get used

Guard4AI tells the company account when a browser uses one of the supported AI tools — at most once per tool per day, and only the tool’s name. An admin needs it because the catch counter cannot answer it: a catch is only recorded when something sensitive is found, so a tool the team uses constantly with nothing sensitive in it would otherwise be invisible.

That record has no seat id in it. There is no column for one, so there is nothing to join back to a person — unlike the catch counter, which does carry your seat, and now your name with it.

Your admin sees it as a list of tools with two percentages each: the share of use, and the share of catches. Never a count, because a count can be subtracted back into a number of messages.

The list is shown from the first connected browser. On a small team a share is close to an attribution: if there are two of you, "eighty per cent of use is ChatGPT" is nearly a fact about one person. It is still shares rather than counts, and still tool names rather than anything you typed, but we are not going to pretend that a small team is anonymous.

Your admin can turn checking on for everyone

There is one company-wide setting, and it has two positions. On Flexible, which is the default, you decide whether Guard4AI checks the files and images you attach, and you can switch Guard4AI off whenever you like. On Enforced, those three switches are held on: you will see them in the Guard4AI settings, greyed out, labelled with the name of the organisation that set them.

Enforced turns protection on. There is no setting that lets an admin turn your protection off, or make Guard4AI check more than it already does, or send anything it does not already send.

Your extension asks for that setting on the same request it already makes to confirm your seat is still valid, roughly every fifteen minutes while you are using an AI tool. That request carries your seat id and nothing else, exactly as it did before. The setting travels back on the answer. Nothing about your own switches, your files or your messages is sent in order to ask.

Two things follow from that which are worth saying plainly. Your admin sets one policy for the whole company — there is no per-person version of it. A seat now carries a name, so we could build one; we have not, and the setting genuinely does not exist rather than being hidden from you. And if you are on the Individual plan, none of this exists: you are the only seat, so there is no admin, and the setting is refused by our database rather than merely hidden from the page.

Your admin sees your name against your counts

This page used to say the seat was anonymous, and it was: the dashboard showed rows like 0A401498 · 12 catches and nothing in our database connected one to a person. That has changed, and we would rather replace the promise than quietly drop it.

When you redeem your employer’s invite code you are now asked for your first and last name, and the extension tells you at that moment who will see it. It is stored against your seat, and your admin’s dashboard shows rows like Sarah Chen · 0A401498 · 12 catches · active 2 hours ago. The seat id stays alongside the name, because two people with the same name still have to be tellable apart.

So an admin can see, for a named person: how many items were masked for them, what categories those were, which AI tools it happened on, when it happened, and when their browser was last active. That is a real change in what a team plan is, and it is deliberate. The person paying is the admin, and a dashboard of unreadable ids is not a thing anyone can act on.

What has not changed is the ceiling. An admin still cannot see a value, a message, a word you typed, a filename, or a page address. Adding a name to a tally does not turn a tally into a transcript, and there is still nothing on our side to turn into one.

The name is self-reported. You type it yourself and nothing verifies it: not an email, not a directory, not your employer. We show it as given, and nowhere in the product is it presented as a confirmed identity. Treat it as a label on a seat, which is what it is.

If you are on a personal licence none of this exists. There is no seat, no admin, and the field is ignored if you fill it in.

We could not show an admin the real data if they demanded it

Your text is never sent to us, so there is nothing on our side to hand over. What you sent to the AI company is between you and them, and their policy governs it.

That isn’t a policy we have chosen and could quietly revise later. The report is assembled one field at a time from three values: seat id, category, site name. Each is checked against a fixed list. If the code that builds it ever grows a fourth field, it refuses to send anything at all rather than ship whatever was added. The database checks the same three independently, and the table has no column that could hold your text even if something tried to put it there.

If a court ordered us to produce the contents of an employee’s messages, we would have nothing to produce.

Individual licences report nothing

If you bought Guard4AI for yourself, no counts leave your machine. None. No categories, no totals, no site names.

The only thing a personal copy ever sends is a check that your subscription is paid. That runs about once a day and carries a random activation token, nothing else. From that we can see that a licence was checked and roughly when. We cannot see who you are, what you use it on, or what it caught.

The counting code isn’t switched off for individuals. It never runs. It only fires when a company invite code has been redeemed, and a personal licence never writes that record.

What stays on your device, and only your device

Uninstalling removes all of it.

The permissions we ask for, and why

Who else is involved

None of them receive your message text, because we never have it.

What the AI company still sees

Whatever you actually send. If masking is on, they get the fake version. If it is off, they get what you typed. Their own privacy policy governs it from there. Guard4AI’s job is to stop you over-sharing by accident, not to change what happens to the message once you have decided to send it.

This website, which is not the extension

Everything above is about the Guard4AI extension: the thing installed in your browser that reads your messages and does not send them anywhere. This section is about guard4ai.com, the marketing and account website you are reading right now. They are two different pieces of software and they are governed differently, so we keep them apart rather than writing one paragraph that half-covers both.

This website uses two measurement tools, and they do different things. Google Analytics 4 counts visits. Microsoft Clarity records them, which is a bigger claim and gets a section of its own below.

When you load a page here, Google receives:

We see aggregate reports built from that: how many people read the pricing page, which pages they arrive on, roughly which countries they are in. We use it to decide what to write and what to fix.

None of it is joined to your Guard4AI account, and none of it is joined to a seat id. There is no mechanism that could: the analytics data sits in Google’s systems and the seat records sit in ours, and nothing carries a value that appears in both.

Both tools are on this website only. Neither is in the extension, and neither ever sees anything the extension handles.

The extension loads no analytics of any kind, contacts neither Google nor Microsoft, and has no measurement code in it at all. Nothing you type into an AI tool, nothing it catches, and nothing about a file you attach goes to either of them or to us. Visiting this website tells them you visited a website. It tells them nothing about your use of the product.

Microsoft Clarity records your visit, and we would rather say so first

Clarity is not a counter. It rebuilds your visit so we can watch it back: which pages you moved through, where you moved the pointer, what you clicked, how far you scrolled, and how the page changed as you went. It is a reconstruction of the page rather than a video of your screen, and it never reaches outside the browser tab. We use it to find the places where the site is confusing, which a page-view count cannot show us.

Three identifiers are stored in your browser for it: two cookies, _clck and _clsk, and one entry in session storage, _cltk. They tie the parts of one visit together, and tell a returning browser apart from a new one.

What is never recorded. Clarity masks the contents of every input box and every dropdown, in all of its modes, and that behaviour cannot be switched off by us or by anyone administering our account. So:

What we masked on purpose. Clarity does not mask ordinary page text by default, only what you type. Some of our pages print something that matters as text, so those carry an explicit instruction not to record them: the licence key on the page after checkout, the invite code on the dashboard and the account page, the list of seats and the names on it, and the address echoed back to you on the “check your email” screens.

If you would rather not be recorded at all, decline below and Clarity is never loaded. Declining leaves everything on this site working exactly as it did.

If you fill in the contact form

The form at guard4ai.com/contact asks for your name, your company, a work email, a phone number, a rough headcount, and anything you want to add. All of it goes two places and no further: a row in our database that only we can read, and an email to us so we see it without having to check the database. It is used to answer you and to work out a price. It is not added to a mailing list, it is not passed to anyone, and nothing in it reaches the extension or the dashboard.

Two things stop the form being used for spam, and one of them is worth naming. Cloudflare Turnstile checks that a person is sending it, which means Cloudflare sees that request. And the route limits how many enquiries can come from one connection in an hour, which it does by storing a one-way hash of your IP address rather than the address. There is no way back from what is stored to where you were: it can answer “have I seen this sender in the last hour” and nothing else.

Asking first, where asking is required

In the EEA, the UK and Switzerland, nothing is stored in your browser until you say it may be. Google’s tag starts with that storage switched off, and a bar appears asking; if you decline, or simply never answer, it stays off. Clarity is held to something stricter: it is not loaded at all until the answer is yes, so where consent is required there is no recording to discard, because none was ever started. Elsewhere, Australia included, the law does not require asking, so we do not put a box in front of you that has only one useful answer.

Either way, the advertising side of Google’s tag is switched off everywhere and never switched on. We run no advertising and this measurement account never will.

Your answer is remembered in your own browser and nowhere else. You can change it here at any time:

Two other ways out, if you would rather not be counted anywhere: Google publishes a browser add-on that opts you out of Analytics on every site, and any content blocker will stop the tag loading. Nothing here breaks if you use either — sign-in, checkout and the dashboard do not depend on it.

Two smaller things, stated rather than buried

Because we set the page address we report ourselves, the part of a link after a # is never sent to Google. That matters here because confirmation links from your email return to this site with a sign-in token in exactly that position, and we would rather it went nowhere near an analytics account.

The admin dashboard and the account page carry no tag at all: no Google Analytics, and no Clarity. They are account pages rather than pages anyone browses to, so measuring them would put the people running Guard4AI into the numbers meant to describe the people considering it. There is a second reason now, and it is the stronger one. Those two pages show a live invite code, and the dashboard shows your team’s names against their counts. A session recording of either would send that to Microsoft, so neither page has a recorder on it to send anything.

Your rights

If you are on a team plan, we hold your first and last name, a seat id, timestamps, and a tally of categories against it. Under the GDPR and the Australian Privacy Act you can ask us for a copy of it, ask us to correct it, or ask us to delete it. Email hello@guard4ai.com.

One practical note, and it is the opposite of what this page said before. Now that a seat carries a name, we can look you up — so we ask for the seat id as well, from the bottom of the Guard4AI settings page, because a name is not unique and we would rather act on the right row than a likely one. Your admin can correct a name from their dashboard, and can remove a seat, which deletes it and every count filed against it.

If you are an account holder or an individual licence holder, we hold your email and your billing record. Same rights, and we can look you up by email.

We will answer within 30 days. If you think we have got it wrong, you can complain to the Office of the Australian Information Commissioner, or to your local supervisory authority in the EU or UK.

Changes

If we change what leaves your device, we will change this page and move the date at the top.

Contact

hello@guard4ai.com

Privacy questions, access requests, deletion requests.

Last updated 10 September 2026 · Guard4AI · Built in Australia