Privacy Policy
Last updated: January 2026
1. Overview
Cloak ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how the Cloak browser extension ("Extension") handles your data. Our fundamental principle is privacy by design—all processing happens locally in your browser, and we do not collect, store, or transmit any of your personal information.
2. Data Processing
2.1 Local Processing Only
All anonymization and restoration of personally identifiable information (PII) occurs entirely within your browser. No data is sent to external servers, including ours.
2.2 What We Process
The Extension processes text you type in ChatGPT to:
- Detect and anonymize PII (emails, phone numbers, credit cards, etc.)
- Replace PII with tokens before sending to ChatGPT
- Restore original PII in ChatGPT's responses
This processing happens in real-time and only on pages where the Extension is active (ChatGPT domains).
3. Data Storage
3.1 Browser Storage
The Extension uses your browser's local storage to:
- Store entity maps (token-to-PII mappings) for each conversation
- Remember your extension settings (enabled/disabled, PII type preferences)
- Track anonymization statistics (counts only, no actual data)
All storage is local to your browser and device. We do not have access to this data.
3.2 Data Retention
Entity maps are stored in memory and browser storage. They are automatically cleaned up when you:
- Close the browser tab
- Switch to a different conversation (old maps are cleared after 10 conversations)
- Uninstall the Extension
4. Data Collection
We do not collect any personal information. Specifically:
- No analytics or tracking
- No telemetry or usage data
- No network requests to external servers
- No cookies or tracking pixels
- No third-party services
5. Third-Party Services
The Extension does not integrate with any third-party services. It operates independently and only interacts with ChatGPT's website to anonymize and restore PII.
6. Your Rights
Since all data is stored locally in your browser, you have full control:
- Access: All data is accessible through your browser's developer tools
- Deletion: Uninstall the Extension or clear browser storage to delete all data
- Control: Enable or disable the Extension at any time through the popup
- Settings: Customize which PII types to anonymize
7. Children's Privacy
The Extension does not knowingly collect information from children under 13. Since we do not collect any information, this is not applicable. However, parents should supervise their children's use of browser extensions.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this page. You are advised to review this Privacy Policy periodically for any changes.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us through our website at getcloak.org.
10. Compliance
This Extension is designed to comply with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Other applicable privacy laws
Since we do not collect, store, or transmit personal data, the Extension inherently complies with these regulations.