Privacy policy
Local where it matters.
Effective and last updated: September 29, 2026
This Privacy Policy explains what information PII Detector, operated by disco-very ("PII Detector," "we," "us," or "our"), handles when you use the extension, website, account features, organization features, support, and billing services. "Handle" includes accessing information locally on your device as well as collecting or storing information on our systems.
Information we handle
| Information | When and why it is handled | Where it is processed or stored |
|---|---|---|
| Webpage and document content Text, files, and detected sensitive values you choose to scan, redact, restore, or highlight. | Used only to provide detection and redaction features you request. | Processed locally in Chrome. Local review state and reversible-redaction mappings may remain in extension storage until cleared. This content is not uploaded to our API for detection. |
| Account information Google or Microsoft account ID, email address, display name, and profile image. | Collected only if you choose to sign in, so we can authenticate you and provide quotas, settings sync, subscriptions, and organization features. | Profile details are stored locally; account ID and email may also be stored in our account database as needed to provide the signed-in service. Provider access tokens are used for verification; we do not retain provider refresh tokens on our backend. |
| Signed-in usage records Hostname of the scanned site—not the full URL—finding count, finding-type totals, scan source (webpage or document), action type, and timestamp. | Collected only while signed in to enforce quotas, operate subscriptions, provide organization reporting, prevent abuse, and improve reliability. Raw page text and detected values are not included. | Sent to and stored by our service. Organization administrators may see organization-level usage and audit information for authorized members. |
| Settings and custom lists Extension preferences, disabled detection groups, user-created terms, list names, organization domain, and synchronization timestamps. | Stored locally. If you sign in and use synchronization, they are sent to our service so they are available across sessions or to authorized organization members. | Personal custom-list contents are encrypted in the extension before upload. Organization lists are encrypted by our service at rest and shared with authorized members of that organization. |
| License, quota, and billing records Plan, entitlement, scan quota, Stripe customer/subscription IDs, subscription status, and billing timestamps. | Used to provide free and paid features, manage subscriptions, and prevent abuse. | Stored by our service. Stripe processes payment-card and transaction information; PII Detector does not store full card numbers. |
| Feedback and support The issue category, optional message you type, finding type, scan source, extension version, timestamp, and limited technical diagnostic fields. If you affirmatively select the unchecked sharing option, the report also includes the detected value and nearby webpage or document text shown to you. | Collected only when you submit feedback or contact support. Sensitive detected content is excluded by default and is sent only after you choose to include it. Please share only content you are authorized to disclose. | Sent to and stored by our service or support provider for troubleshooting and product improvement. |
| Service and security logs IP address, user agent, request time, response status, and error/security metadata that may be generated by hosting providers. | Used to deliver and secure our website and API, diagnose failures, rate-limit abuse, and meet legal obligations. | Processed by our hosting and infrastructure providers and retained only as reasonably necessary for these purposes. |
How we use information
- Provide local detection, highlighting, redaction, restoration, and document features.
- Authenticate users and deliver optional synchronization, quota, subscription, and organization features.
- Process billing, maintain entitlements, and provide the customer portal.
- Secure the service, prevent fraud or abuse, diagnose errors, and maintain reliability.
- Respond to support requests and use optional feedback to improve detection quality.
- Comply with law and enforce our terms.
We do not sell personal or sensitive information, use it for targeted advertising, transfer it to data brokers, or use it to determine creditworthiness or for lending. We do not use browsing activity for advertising; the hostname records described above support the extension's signed-in quota, organization, security, and service features.
Chrome permissions
PII Detector requests permissions needed for its single purpose: detecting and redacting sensitive information at your direction. Page access and scripting allow scanning, highlighting, redaction, and restoration on supported pages. Storage keeps settings and local work state. Offscreen access runs local models and document processing. Alarms support license/session maintenance. Identity enables optional Google or Microsoft sign-in. Side Panel displays the extension interface. We do not use these permissions for advertising or unrelated tracking.
When information is shared
We disclose information only as needed to operate the service, when you direct us, or when legally required:
- Google and Microsoft provide optional authentication. Their services return the account information described above.
- Stripe processes subscriptions, payments, invoices, and the customer portal.
- Vercel hosts the website and API; Neon provides database infrastructure; and Upstash provides rate-limiting or caching infrastructure.
- Hugging Face or the configured model host may receive a normal model-file download request. The text you scan is not included in that request.
- Organization administrators and authorized members may access organization lists, policies, membership, and organization-level usage or audit information.
- Authorities or transaction parties may receive information if required by law, to protect rights and safety, or as part of a merger, financing, acquisition, or sale, subject to appropriate confidentiality protections.
Service providers may process information only to perform services for us and are subject to contractual or legal safeguards appropriate to their role.
Google API Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Storage, retention, security, and deletion
Local settings, scan state, and reversible-redaction mappings remain on your device until you clear them, sign out where applicable, or uninstall the extension. Account, quota, subscription, settings-sync, organization, feedback, and security records are retained while needed to provide and secure the service, satisfy billing or legal obligations, resolve disputes, or enforce agreements. When information is no longer needed, we delete or anonymize it according to operational and legal requirements.
We use HTTPS in transit, access controls, and encryption appropriate to the information. Personal custom lists are encrypted in the extension before synchronization, and organization lists are encrypted at rest. No security method is perfect, but we work to protect information against unauthorized access, alteration, disclosure, or destruction.
Your choices and rights
- You can use core local scanning without signing in.
- You can decline optional feedback, sign out, clear extension storage, or uninstall the extension.
- You can manage or cancel a paid subscription through the customer portal.
- You may request access, correction, export, or deletion of account information by emailing us. We may need to verify your identity before completing a request.
- Organization-controlled information may also be governed by your organization's administrator and policies.
Children's privacy
PII Detector is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided account information so we can investigate and delete it where appropriate.
Changes to this policy
We may update this policy as the product or legal requirements change. We will post the updated policy here and revise the effective date. If a change materially affects how previously collected information is used, we will provide additional notice or obtain consent where required.
Contact
Questions or privacy requests: support@disco-very.ai.
