PromptShield
Privacy Policy
Last updated 26 September 2026
This policy explains what data the PromptShield platform (enterprise.promptshield.live) and the PromptShield Endpoint Guard browser extension collect, why, and who can see it. PromptShield is used by organizations to enforce their policy on AI tools. If your employer asked you to install the extension, your employer is the organization that controls your data, and PromptShield processes it on their behalf.
What the extension does
The extension blocks AI websites that your organization has not approved (for example ChatGPT, Claude, Gemini and Copilot) and shows a warning page instead. The list of blocked sites is built into the extension. It does not read the content of any web page, what you type, or your browsing on sites that aren't blocked.
What the extension collects
Nothing is sent until you sign in to PromptShield and choose “I agree, link this browser”. After that:
- When you open a blocked AI site: your name, email address, department and device name (from your PromptShield account), your IP address, your browser and operating system, the blocked site and page address, the number of attempts, and the time. Search terms, prompt text and anything else in the address after the page path (query strings and fragments) are removed before anything is sent.
- Every 15 minutes: a check-in with your browser, operating system, extension version and IP address, so your security team can see the extension is active.
- If you remove the extension: a random device identifier is sent so your security team can see it was uninstalled.
The extension stores a random device identifier, your link to your PromptShield account, and a count of blocked attempts in your browser. Attempts made before you link the extension are counted in your browser only and are never sent.
What the PromptShield platform collects
When your organization gives you a PromptShield account, we store your name, email address, role and department. When you use the AI gateway, excerpts of the prompts you send through it and the responses, along with any data loss prevention findings, are recorded for your organization's security and compliance team.
How the data is used
Only to enforce your organization's AI policy and to show your organization's administrators and security team where unapproved AI tools are being used. We do not sell data, use it for advertising, use it to decide on credit or lending, or share it with anyone other than the service providers that host PromptShield.
Who can see it
Administrators and security staff in your organization, and PromptShield staff when it is needed to run and support the service. Other organizations using PromptShield cannot see your data.
Where it is stored and how long it is kept
Data is sent over encrypted connections (HTTPS) and stored on servers run by our hosting providers. It is kept for as long as your organization uses PromptShield. Your organization's administrators can delete records, and your organization can ask us to delete all of its data at any time.
Your choices
- Your organization requires the extension to be installed and linked to use PromptShield. If you don't agree to link it, you won't be able to use the platform. The extension still blocks sites, but nothing is reported until it is linked.
- You can remove the extension at any time from
chrome://extensions. Your organization may require it in order to use PromptShield. - To see, correct or delete your data, contact your organization's administrator, or email us and we will work with your organization on the request.
Changes and contact
If we change what is collected, we will update this page and ask for your agreement again before sending anything new. Questions: isaiahsamuel342@gmail.com.