Privacy · Browser extension
BiVelio Shield — Privacy Policy
BiVelio Shield (“the extension”) is published by BiVelio, Inc., a Delaware (United States) company operating from Andorra. This policy describes exactly what the extension does and does not do with your data. It is written to match the software’s actual behavior — if the two ever disagree, that is a bug; report it to privacy@bivelio.com.
At a glance
- Runs in your browserDetection and redaction happen on your device. With a names gateway — included with the Team plan, or configured by your organization on any paid plan, Pro or Team — the text of each message also goes to that gateway, to find names, answered as positions, stored nowhere.
- No account, no analyticsNo sign-up, no trackers, no cookies, no advertising SDK. Nothing to opt out of.
- Nothing you type is sent to BiVelio — with one exception you can seeOn the free tier the extension makes no request to us at all. Pro and Team send a seat check-in and value-free counts — how many values of each kind were kept out — and never a word of what you wrote. The exception: a names gateway. On the Team plan that is the one BiVelio operates for your organization under a data-processing agreement, included with the plan; on any paid plan your administrator can point the extension at one of their own instead. Message text goes there, is answered as positions and is kept nowhere.
- The vault key never touches diskThe value ↔ token map is AES-GCM encrypted; its key lives in memory and is discarded when you close the browser.
The short version
- The extension’s whole job is to keep your data on your machine. On the free tier it sends nothing to BiVelio or to any third party.
- Your prompts are inspected and redacted locally, in your browser, before they reach the AI provider you chose (ChatGPT / Claude). The provider receives placeholder tokens instead of your sensitive values — that is the point.
- No account, no sign-up, no analytics, no advertising. We do not collect, sell, rent, or share your personal data.
- One exception, on any paid plan — Pro or Team alike: if your organization has a names gateway — included with the Team plan, or configured by your administrator in the central policy — the text of each message you send — and any text of 1,000 characters or more that you paste into the chat composer, at the moment you paste it — goes to that gateway, which answers with the positions of the personal data it detects — names and places, and also contact details, identifiers, financial data, network addresses, secrets and GDPR Art. 9 special-category terms — and stores nothing.
Scope: which document you are reading
- This policy covers the BiVelio Shield browser extension and nothing else. It is the document the Chrome Web Store listing points at.
- The website you may have downloaded it from, the account, the team plan and the Sandbox are covered by the separate website & account privacy policy.
- The legal documents on bivelio.com are company-level and describe other BiVelio products. They do not describe the extension.
What data the extension handles, and where it stays
| Data | What it is | Where it lives | Leaves your device? |
|---|---|---|---|
| Prompt text | What you type into ChatGPT / Claude | Processed in your browser’s memory | Only the tokenized version reaches the AI provider — and BiVelio sees none of it, unless your organization is on the names route against a gateway BiVelio operates for it, by the Team plan or because an administrator pointed the extension there (next row) |
| Message text sent to your organization’s names gateway (with the Team plan, or by central policy on Pro and Team) | The text of each message you send, exactly as you typed it and before the local redaction runs — so the identifiers, secrets and Art. 9 terms the deterministic layer would have removed before the AI provider reach the gateway intact — up to 4,000 characters, whenever your organization is on the names route: the Team plan carries that gateway’s address signed inside its own licence, and on any paid plan an administrator can set one in the central managed policy, which takes precedence over the licence’s; and any text of 1,000 characters or more you paste into the chat composer, at the moment you paste it. Attachments are never sent to it. | Sent over TLS from your browser to that gateway — your organization’s own BiVelio Privacy Gateway or, under a data-processing agreement with your organization, a service BiVelio operates in Germany. It answers with the positions — and the matching text — of the personal data it detects: names and places, and also contact details, identifiers, financial data, network addresses, secrets and GDPR Art. 9 special-category terms. It keeps nothing: no storage, no log of the text. The substitution and the vault stay in your browser. | Yes, to that gateway only, and only while your organization is on that route. If the gateway does not answer within the time budget, or the text is longer than 4,000 characters, the message is sent with the deterministic layer only and a notice tells you so every time. With no gateway from either source nothing is sent and this row does not apply. |
| Value ↔ token map (the “vault”) | e.g. an email ↔ [BV:EMAIL:…] | chrome.storage.local, AES-GCM encrypted; the key is held only in in-memory session storage and is never written to disk | No — raw values are never recoverable from disk alone, and are never transmitted |
| Settings | The on/off toggle and the optional “Redact on shape” switch, and whether your organization has locked protection on (`locked`, a yes/no mirror of its managed policy) | chrome.storage.local | No |
| “Items protected” counter | A number of redactions performed | chrome.storage.local | The number itself stays on your device. On Pro and Team its BREAKDOWN leaves as counts: how many values of each family were kept out. No prompt text, no values, no tokens — and nothing that says who, when to the minute, or in which conversation. |
| “Protection interrupted” timestamp | The clock reading of the most recent fail-closed block (`lastBlock`); the popup uses it to warn you that a send was stopped | chrome.storage.local | No — a time only; it contains no prompt text, values, or tokens |
| Diagnostic markers | The storage-schema version, and when the extension last noticed a site had changed shape | chrome.storage.local | No — a version number and a timestamp; no text and no values |
| Pro licence token | The BVLIC1… entitlement you paste from Dashboard → Billing (plan and expiry only — no personal data) | chrome.storage.local, verified offline against BiVelio's public key | On Pro, the token and a random device id are sent to BiVelio in a periodic seat check-in (the token is a public entitlement, not a secret; the id names a seat, not a person). The free tier sends neither — and neither ever carries prompt text, values, or vault tokens. And if a check-in answers that the licence was revoked — after a plan change, for instance — the token alone goes once to privacy.bivelio.com, which answers with the licence your organization holds now: at most one such request per revoked licence per day, and never any content. |
| Aggregate privacy report (Pro and Team) | Counts only: how many values of each family were kept out, how many sends were blocked, and how many left unprotected because you chose to, and how many went out with names unchecked because the names gateway did not answer in time or the text was longer than 4,000 characters | chrome.storage.local (a bounded queue), sent to BiVelio about once an hour | Yes, on Pro and Team — and counts are all it is. There is no prompt text, no values, no tokens, no name, no email, no user id; times are kept to the HOUR, and nothing records which chat, tool or thread. The free tier sends none of it. |
When you fully close your browser, the in-memory encryption key is discarded, the stored vault becomes undecryptable, and older conversations de-identify themselves back to opaque tokens. This is intentional.
What the free tier redacts locally
Before your prompt leaves the browser, the deterministic engine detects and replaces:
- Emails and phone numbers
- Credit-card numbers (Luhn-validated)
- IBANs and bank details (mod-97-validated)
- National IDs — Spanish DNI / NIE / CIF, US SSN, and more
- API keys & secrets — OpenAI, AWS, GitHub, Stripe, Slack, and others
- IP addresses
- Health, religious, biometric and genetic terms — a curated multilingual lexicon (GDPR Art. 9 special categories)
Honest scope: to keep precision high, structured identifiers are validated by their checksum, so a well-formed but checksum-invalid value can pass unless you enable “Redact on shape” (below). The free tier redacts the Art. 9 terms in its curated lexicon, but it does NOT remove people’s names, addresses or general free-form text — there is no fixed pattern to match, and an Art. 9 phrase written in wording the lexicon does not list will also pass. Names and context are looked for on one route only: when your organization has a names gateway — included with the Team plan, or set by your administrator in the central policy on any paid plan, Pro or Team — the text of each message is sent to that gateway, which answers with the positions of the personal data it detects — a layer that reduces the leak of names and, measured, does not eliminate it (see “Names via your organization’s gateway” below). With no gateway from either source the extension does not look for names on any tier. The opposite failure is not gated on that switch: an identifier is validated after its separators are stripped, so a checksum-valid match can swallow the words beside it — measured, “BTW NL123456789B01 on file” takes six characters of your own sentence into the placeholder. Nothing extra reaches the provider (it sees less than you typed), but the prompt is silently altered.
The optional “Redact on shape” setting
You can turn on “Redact on shape” in the popup to also hide identifiers that look like an IBAN, card, or ID but fail their checksum (for example a mistyped number). It is off by default, still runs entirely locally, and we tell you plainly that it may over-redact things like order numbers, timestamps, or tracking codes. Your choice.
What the extension does NOT do
- It does not send your prompts, the values it redacts, or the tokens that replace them to BiVelio — with one declared exception: when your organization is on the names route against a gateway BiVelio operates for it under a data-processing agreement — included with the Team plan, or because an administrator pointed the extension there — the text of each message reaches that service as you typed it, before the local redaction runs, and it answers with the positions and the matching text of the personal data it detects — GDPR Art. 9 special-category terms included — and stores nothing. The values and the tokens stay in your browser on every route.
- It does not use trackers, cookies, analytics SDKs, or advertising.
- It does not read or act on any website other than the supported AI chat sites (see Permissions). Only three addresses can ever receive anything from it: the licensing endpoint where the Pro and Team seat check-in and the hourly aggregate report go — licensing.bivelio.com, unless your licence carries its own control-plane address, in which case they go there instead; privacy.bivelio.com, and only after a check-in has come back revoked, to trade that revoked token for the licence your organization holds now — the revoked token is the whole of what is sent, and it is asked at most once a day; and your organization’s names gateway — the address its Team licence carries, or the one an administrator set in the central policy — and only to send message text and receive positions. It does not access your browsing history, other tabs, or your files.
- It does not sell or share personal data, and it never uses your data to determine creditworthiness or for lending.
- It does not protect voice or realtime mode. It redacts the text you type; a spoken turn in ChatGPT Advanced Voice or Claude voice travels over a separate live-audio connection the extension never sees — and a text tool cannot redact audio. Type, don't speak, when a turn carries sensitive data.
- It does not cover Claude's “Cowork” composer. The extension redacts Claude's normal chat send; Cowork writes to a different endpoint (`PUT /v1/code/sessions/…`) that the extension deliberately leaves untouched, because that payload is code and session configuration rather than prose. Treat anything typed into Cowork as unprotected.
- It does not inspect files, images or attachments on the Free or Pro plans: an uploaded document, PDF, or a photographed passport is sent to the provider as-is, and a notice tells you when that happens. The Team plan redacts text files and PDF / Word / Excel / PowerPoint documents in your browser before they upload; scans, images and other unreadable files always ask you first before leaving unprotected.
Permissions, and why the extension needs them
- storage
- to keep the on/off toggle, the “Redact on shape” setting, the value-free counter, and the encrypted vault (key kept in memory, never on disk) described above.
- scripting
- to re-inject the local redaction script into an AI chat tab that was already open when the extension was installed or updated. Without it those tabs stay unprotected until you reload them by hand. It can only ever run on the host-permitted sites listed below.
- Host access to chatgpt.com, chat.openai.com, claude.ai
- to run the local redaction only on those AI chat sites.
- alarms
- (Pro) to schedule the periodic seat check-in below, about twice a day. Unused on the free tier.
- Host access to licensing.bivelio.com
- (Pro and Team) where the seat check-in and the hourly aggregate report go: licensing.bivelio.com, unless your licence carries its own control-plane address, in which case they go to that address instead. The extension asks for no other site permission — not even for the names gateway: its background worker calls the address your organization is on — the one its Team licence carries, or the one an administrator set — and only a gateway that explicitly accepts the extension answers. The same goes for privacy.bivelio.com, which needs no site permission either: when a check-in comes back revoked, the background worker asks it once for the licence your organization holds now, sending only the revoked token — so an upgrade or a plan change does not have to be re-activated by hand on every machine.
The AI providers you use
When you send a message, the extension forwards the redacted prompt to the AI provider you chose (OpenAI for ChatGPT, Anthropic for Claude). Your use of those services is governed by their privacy policies and terms — the extension does not change your relationship with them; it only reduces the sensitive data they receive.
Names via your organization’s gateway (Pro and Team)
The free tier is fully local as described above and never looks for people’s names. On the Team plan the gateway comes with the plan: the address of the names service BiVelio operates arrives signed inside your organization’s own licence, so there is nothing to install and no URL to type. On any paid plan — Pro or Team alike — your organization’s administrator can instead set a gateway address in the central managed policy, and that address takes precedence: what the extension checks before it calls the gateway is that you hold a paid licence, not which paid plan it is. Your dashboard generates that policy on the Team plan; on Pro an administrator can still write the same address into Chrome’s managed policy by hand. From then on, the text of each message you send — never attachments — goes from your browser to that gateway exactly as you typed it, before the local redaction runs — so the identifiers, secrets and Art. 9 terms the deterministic layer would have removed before the AI provider reach the gateway intact — and the gateway answers with the positions and the matching text of the personal data it detects: names and places, and also contact details, identifiers, financial data, network addresses, secrets and GDPR Art. 9 special-category terms; the substitution and the vault stay in your browser, and the gateway stores nothing. Pasting 1,000 characters or more into the chat composer sends that pasted text to the same gateway at the moment you paste it — before you send the message, and even if you edit it afterwards or never send it at all. Above 4,000 characters the gateway is not called at all. That gateway is your organization’s own BiVelio Privacy Gateway, or the service BiVelio operates in Germany under the data-processing agreement that forms part of the Team plan’s terms; nothing is sent to BiVelio otherwise. If the gateway does not answer within the time budget — unreachable, too slow, or its names layer not running — or the text is longer than 4,000 characters, the message is sent with the deterministic layer only and a notice is shown every time; those sends are counted in your organization’s aggregate report as “sent with names unchecked”. This layer reduces the leak of names, and we do not promise it eliminates them. Read the 4.875% in docs/BENCHMARKS.md for what it is: that figure measures the stack WITHOUT this layer (the deterministic detectors plus Presidio). Measured on the same corpus with the model the gateway actually runs, none of the 800 values leaked. That corpus is synthetic and scores only names and places — it says nothing about street addresses or health terms — so a zero there is not a promise of zero here. There is no per-user switch. Where the address comes with the Team plan, an owner or an administrator turns the layer off for the whole organization from the dashboard, and that takes up to an hour to reach a browser; where it comes from the central managed policy — always on Pro, and on Team wherever an administrator set one — that address takes precedence, as above, and the layer goes off by removing it from that policy. With no gateway from either source, nothing on this route happens at all.
Legal basis
The extension processes your prompt on your own device, on your instruction, to do the one thing you installed it for. Where the GDPR applies, that is performance of the contract you accepted when installing it (Art. 6(1)(b)). BiVelio itself does not process that data: on the free tier no personal data reaches us, so there is no processing by BiVelio to justify. On Pro, the seat check-in — your licence token and a random device identifier — is processed to enforce the seats you bought, also under Art. 6(1)(b). Where your organization is on the names route — because its Team licence carries the gateway’s address, or because an administrator configured a gateway in the central managed policy — the text sent there is processed on your organization’s instruction: your organization is the controller, and the gateway operator — your organization itself, or BiVelio under a data-processing agreement with it (Art. 28) — acts as its processor.
How long data is kept
On your device: the encrypted vault, the settings and the value-free counters stay in your browser's extension storage until you close the browser (the encryption key is discarded and the vault becomes undecryptable) or uninstall the extension (everything is removed). On BiVelio's servers: nothing at all on the free tier. On Pro, the seat check-in record — device identifier and last-seen day — is kept while the seat is active and flagged as deactivated when you retire the device; there is no automated purge today, as the website & account policy also states. On a names gateway, whether your organization’s own or the service BiVelio operates: the text of a message exists in memory for the length of the request and is never written to disk or to a log.
International transfers
The tokenised prompt goes to the AI provider you chose, under that provider's own policy; OpenAI and Anthropic process data in the United States. BiVelio is not a party to that transfer and does not change it — the extension only reduces what the request contains. On Pro, the seat check-in reaches BiVelio's licensing server in Germany (Hetzner Online GmbH) and stays in the EU. Where your organization is on the names route — because its Team licence carries the gateway’s address, or because an administrator configured a gateway in the central managed policy — message text goes to that gateway: wherever your organization runs it, or, for the service BiVelio operates, to Hetzner Online GmbH in Germany, inside the EU.
Automated decisions
The extension makes no decision about you within the meaning of Art. 22 and builds no profile. Every redaction decision in your browser is a deterministic rule — pattern, checksum, action — that you can inspect in the Playground on this site. The names a gateway finds come from a statistical model, best-effort rather than exhaustive; they too decide only what is replaced in your text, never anything about you.
Your rights
Because the extension stores no personal data on our servers — a names service BiVelio operates, where your organization chose one, holds the text of a message in memory only for the length of the request — there is generally nothing for us to access, export, or delete on your behalf. The local data (vault, settings, counter) is entirely under your control: the on/off switch and counter can be changed or reset from the popup, the vault de-identifies itself when you close your browser (its encryption key never leaves memory), and uninstalling the extension removes everything. Under the GDPR and similar laws you may still contact us with any question or request.
Complaints and the supervisory authority
If you believe the extension or BiVelio has processed your data unlawfully, you may lodge a complaint with a supervisory authority — in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement (Art. 77). The European Data Protection Board keeps the list of every authority and its contact details. We would rather you write to us first, but you do not have to. edpb.europa.eu ↗
Data protection officer
BiVelio has not designated a data protection officer: the extension keeps its processing on your device or, with a names gateway, on your organization’s instruction, and the small amount of value-free data Pro sends does not amount to the large-scale or systematic monitoring that Art. 37 requires one for. All privacy matters are handled directly at privacy@bivelio.com, and this section will change the day that changes.
Children
BiVelio Shield is not directed at children under 16 and does not knowingly process their data.
Changes to this policy
We will update this page and its “Last updated” date when the extension’s data behavior changes. Material changes will be reflected here before they take effect in a released version.
Contact
Privacy questions or requests: privacy@bivelio.com
BiVelio, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States · operating from Andorra 🇦🇩 · +1 302 208 5841
Version history
Every change to what this document declares is listed here with its date. Earlier wording is kept in the public repository history.
- v1.10
A correction to 1.9, and it is about the declaration rather than the off switch: the Art. 6 basis and the Art. 44 transfer each described only the organization that configures a gateway, so a Team organization — whose licence carries that address signed, with nobody configuring anything — read neither its own legal basis nor its own transfer to Germany. Both sections now name the two roads inside the sentence that qualifies them: the address a Team licence carries signed, and the one an administrator sets in the central managed policy on any paid plan, Pro or Team. What travels, what comes back and what is kept are unchanged from 1.9; no new recipient and no new category of data.
- v1.9
A same-day correction to 1.8, and it is about the off switch rather than about what travels: wherever this document described one road to switching the names layer off, it now names both in the same sentence. On Team an owner or an administrator switches the layer off from the dashboard; on Pro, and on any install whose gateway comes from a managed policy, that policy takes precedence and the layer goes off by removing the address from it. What travels, what comes back and what is kept are unchanged from 1.8; no new recipient and no new category of data.
- v1.8
The names route now comes with the Team plan. Until today it existed only where an administrator had written a gateway address into the central policy; on Team the address of the service BiVelio operates travels signed inside your organization’s own licence, so nothing is installed and no URL is typed, and an owner or an administrator switches the layer off for the whole organization from the dashboard — a switch that takes up to an hour to reach a browser; on Pro, and on any install whose gateway comes from a managed policy, that policy takes precedence and the layer goes off by removing the address from it. What travels, what comes back and what is kept are unchanged from 1.7. This version also catches the header up with the body: the post-revocation licence refresh to privacy.bivelio.com was written into this notice on 2026-09-19 and the version was left at 1.7, so the page named three addresses while calling itself the document that named two.
- v1.7
Names via the organization’s gateway declared: when the administrator sets a gateway address in the central policy (any paid plan — Pro or Team), the text of each message — up to 4,000 characters, never attachments — and any paste of 1,000 characters or more go to that gateway, the organization’s own or a service BiVelio operates in Germany under a data-processing agreement, and come back as positions; nothing is stored. Sends with names unchecked (the gateway not answering in time, the text too long) are notified every time and counted in the aggregate report. The published 4.875% measures the stack WITHOUT that layer; with it, none of the 800 corpus values leaked. The corpus is synthetic, so no promise of zero is made.
- v1.6
Attachment redaction moved to the Team plan: on the Free and Pro plans an attachment is uploaded uninspected, with a notice, exactly as before.
- v1.5
Layered layout with an index and an at-a-glance summary. Legal basis, retention, international transfers, automated decisions, complaints and the DPO statement added so the notice covers every Art. 13 item on its own.
- v1.4
Pro seat check-in declared: the licence token and a random device identifier are sent periodically; the free tier still sends nothing.
- v1.3
Pro attachment redaction declared: text files and PDF, Word, Excel and PowerPoint documents are rewritten in the browser before upload; scans and images ask first.
- v1.2
Storage table completed with the block timestamp and the diagnostic markers. Three coverage limits declared: voice and realtime modes, uninspected attachments on the free tier, and Claude's Cowork composer. Over-redaction next to a checksum-valid identifier declared.
- v1.1
Controller identified in full with the postal address and phone the Chrome Web Store trader declaration carries. GDPR Art. 9 special-category lexicon declared as part of what the free tier redacts.
- v1.0
First publication.