Privacy policy

Local where it matters.

Effective and last updated: September 29, 2026

The important part: webpage and document text selected for detection is processed locally by the PII Detector Chrome extension. We do not upload that content to our servers to perform detection, and we do not sell personal information or use it for advertising.

This Privacy Policy explains what information PII Detector, operated by disco-very ("PII Detector," "we," "us," or "our"), handles when you use the extension, website, account features, organization features, support, and billing services. "Handle" includes accessing information locally on your device as well as collecting or storing information on our systems.

Information we handle

InformationWhen and why it is handledWhere it is processed or stored
Webpage and document content
Text, files, and detected sensitive values you choose to scan, redact, restore, or highlight.
Used only to provide detection and redaction features you request.Processed locally in Chrome. Local review state and reversible-redaction mappings may remain in extension storage until cleared. This content is not uploaded to our API for detection.
Account information
Google or Microsoft account ID, email address, display name, and profile image.
Collected only if you choose to sign in, so we can authenticate you and provide quotas, settings sync, subscriptions, and organization features.Profile details are stored locally; account ID and email may also be stored in our account database as needed to provide the signed-in service. Provider access tokens are used for verification; we do not retain provider refresh tokens on our backend.
Signed-in usage records
Hostname of the scanned site—not the full URL—finding count, finding-type totals, scan source (webpage or document), action type, and timestamp.
Collected only while signed in to enforce quotas, operate subscriptions, provide organization reporting, prevent abuse, and improve reliability. Raw page text and detected values are not included.Sent to and stored by our service. Organization administrators may see organization-level usage and audit information for authorized members.
Settings and custom lists
Extension preferences, disabled detection groups, user-created terms, list names, organization domain, and synchronization timestamps.
Stored locally. If you sign in and use synchronization, they are sent to our service so they are available across sessions or to authorized organization members.Personal custom-list contents are encrypted in the extension before upload. Organization lists are encrypted by our service at rest and shared with authorized members of that organization.
License, quota, and billing records
Plan, entitlement, scan quota, Stripe customer/subscription IDs, subscription status, and billing timestamps.
Used to provide free and paid features, manage subscriptions, and prevent abuse.Stored by our service. Stripe processes payment-card and transaction information; PII Detector does not store full card numbers.
Feedback and support
The issue category, optional message you type, finding type, scan source, extension version, timestamp, and limited technical diagnostic fields. If you affirmatively select the unchecked sharing option, the report also includes the detected value and nearby webpage or document text shown to you.
Collected only when you submit feedback or contact support. Sensitive detected content is excluded by default and is sent only after you choose to include it. Please share only content you are authorized to disclose.Sent to and stored by our service or support provider for troubleshooting and product improvement.
Service and security logs
IP address, user agent, request time, response status, and error/security metadata that may be generated by hosting providers.
Used to deliver and secure our website and API, diagnose failures, rate-limit abuse, and meet legal obligations.Processed by our hosting and infrastructure providers and retained only as reasonably necessary for these purposes.

How we use information

We do not sell personal or sensitive information, use it for targeted advertising, transfer it to data brokers, or use it to determine creditworthiness or for lending. We do not use browsing activity for advertising; the hostname records described above support the extension's signed-in quota, organization, security, and service features.

Chrome permissions

PII Detector requests permissions needed for its single purpose: detecting and redacting sensitive information at your direction. Page access and scripting allow scanning, highlighting, redaction, and restoration on supported pages. Storage keeps settings and local work state. Offscreen access runs local models and document processing. Alarms support license/session maintenance. Identity enables optional Google or Microsoft sign-in. Side Panel displays the extension interface. We do not use these permissions for advertising or unrelated tracking.

When information is shared

We disclose information only as needed to operate the service, when you direct us, or when legally required:

Service providers may process information only to perform services for us and are subject to contractual or legal safeguards appropriate to their role.

Google API Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Storage, retention, security, and deletion

Local settings, scan state, and reversible-redaction mappings remain on your device until you clear them, sign out where applicable, or uninstall the extension. Account, quota, subscription, settings-sync, organization, feedback, and security records are retained while needed to provide and secure the service, satisfy billing or legal obligations, resolve disputes, or enforce agreements. When information is no longer needed, we delete or anonymize it according to operational and legal requirements.

We use HTTPS in transit, access controls, and encryption appropriate to the information. Personal custom lists are encrypted in the extension before synchronization, and organization lists are encrypted at rest. No security method is perfect, but we work to protect information against unauthorized access, alteration, disclosure, or destruction.

Your choices and rights

Children's privacy

PII Detector is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided account information so we can investigate and delete it where appropriate.

Changes to this policy

We may update this policy as the product or legal requirements change. We will post the updated policy here and revise the effective date. If a change materially affects how previously collected information is used, we will provide additional notice or obtain consent where required.

Contact

Questions or privacy requests: support@disco-very.ai.