Privacy & Transparency

Data Protection
you can trust

Your organization controls your data. NeuroShield is designed with privacy as a core principle, not an afterthought.

Last updated: August 2026
Product: NeuroShield for Browser
Questions? Contact us at support@neurosec.ai

What NeuroShield for Browser is

NeuroShield for Browser is a workplace security tool. An organization's administrator installs it so the organization can see, and where necessary prevent, sensitive information being sent to AI chat services such as ChatGPT, Microsoft 365 Copilot, Google Gemini, Anthropic Claude and Grok.

It is not a consumer product. It is deployed by an employer onto managed browsers, and it is configured entirely by that employer.

Who is responsible for your data

The organization that deployed the extension is the data controller. They decide which AI services are watched, whether messages are recorded or blocked, and how long the resulting records are kept.

NeuroSec supplies the software. Where the organization runs NeuroShield on their own infrastructure, NeuroSec does not receive any of the data described below. Where NeuroSec hosts NeuroShield on the organization's behalf, it acts as a data processor under that organization's instructions.

If you are an employee with questions about what is collected about you, your employer is the right place to ask.

What the extension reads

Only on the AI services your administrator has configured. On every other website it reads nothing.

Text you send to an AI service

The message typed into the chat box is read before it is sent, so it can be checked against your organization's policy.

Text inside files you attach to an AI service

Supported file types are plain text, CSV, Word (`.docx`) and PowerPoint (`.pptx`). The file is opened on your own device and only the text inside it is used. The file itself is never uploaded to NeuroShield.

Usage records

Which AI service was used, and when. Recorded so administrators can see AI usage across the organization.

Your identity and device

Your account identifier, so that usage can be attributed to a person, and a randomly generated identifier for the browser installation.

What the extension does not read

  • Any website other than the AI services your administrator configured
  • Passwords, sign-in forms, one-time codes and other authentication fields, which are explicitly excluded
  • Browsing history, bookmarks, cookies or saved credentials
  • Files you open, download or work with anywhere other than an attachment to a watched AI service

Where the data goes

Text and usage records are sent only to the NeuroShield server operated by or for your organization, at an address your administrator configures.

Data is not sold. It is not shared with advertisers. It is not used to train any model. It is not sent to any third party beyond the organization's own NeuroShield deployment.

What is stored in your browser

  • The NeuroShield server address and an enrollment credential
  • A randomly generated identifier for this browser installation
  • The current policy, so the extension works while offline
  • A short queue of usage records not yet delivered

This is held in the browser's extension storage and removed when the extension is uninstalled.

How long data is kept

Retention is set by the organization that deployed the extension, within its own NeuroShield deployment. NeuroSec does not determine it.

Where NeuroSec hosts NeuroShield, the default retention period is configurable by your organization's administrator (commonly 90 days or longer).

Diagnostics

Administrators can temporarily enable a diagnostics mode used to adapt the extension when an AI service changes its interface. While enabled, additional detail — including message content — is written to the browser's own developer console on the device. This information stays on the device and is not transmitted. It is intended for short troubleshooting sessions and is off by default.

Your data rights

Depending on where you live, you may have rights to access, correct, delete or restrict the processing of information about you, and to object to it. Because your employer controls this data, please direct such requests to them. NeuroSec will support them in responding.

Permissions explained

Below are the browser permissions NeuroShield requests and why each one is necessary:

Permission Why it's needed
Access to websites The list of AI services to watch is set by your administrator and can change, so it is not known when the extension is built. The extension only activates on the services actually configured.
storage Holds the server address, the current policy, and undelivered usage records.
alarms Refreshes the policy and delivers queued records on a schedule.
scripting Loads the extension's own code on the configured AI services. No code is downloaded from anywhere.

Changes to this policy

Material changes will be reflected here with a revised date, and where NeuroSec hosts NeuroShield, notified to the administrator.

Questions?

If you have questions about this policy or how your data is handled, please contact us at support@neurosec.ai or reach out to your organization's administrator.

Ready to secure your AI?

Learn how NeuroShield
protects your organization

Contact our team to discuss how NeuroShield can secure your enterprise's AI deployments.

Schedule a Call → View the Platform