PII Shield

Browser extension

Privacy Policy

Last updated: 9 July 2026

PII Shield is a privacy tool. It exists to keep your personal data out of AI chat services, and to show your organisation what has already reached them. That second half means we do record what it finds - so the honest thing is to encrypt it, in your browser, with a key we do not have. This policy explains exactly what happens to your information, including the parts you might not like.

The one thing that matters: your personal data is redacted locally, inside your own browser, before any request leaves it. We do record what was found, so your workspace can see it - but it is encrypted in your browser to a key only your workspace holds, so we cannot read it, and it is never sold or shared. Your chat text and your files are never sent to us at all.

What the extension does

When you type into a supported AI chat site (such as Claude, ChatGPT, Gemini, and others listed in the extension), PII Shield scans the outgoing message inside your browser and replaces personal data with stable placeholder tokens (for example [email protected] becomes [EMAIL_1]) before the request is sent. The AI service only ever receives the tokens. When the reply comes back, the real values are restored so your experience is unchanged. All of this happens on your device.

Files you attach to a chat

PII Shield cannot read a file for you - a scanned PDF or an image cannot be inspected in the browser - so it does not pretend to. When you attach a file, the extension stops it before the AI site receives it and tells you plainly that it has not been scanned. You choose: redact it first, upload it anyway, or cancel. If you upload it anyway, we record the file's name (encrypted, as described below) so your workspace can see that an unscanned file was sent. The contents of your files are never uploaded to us, and the fingerprint the extension uses to recognise a file it has already redacted never leaves your machine.

Scanning your past conversations

The extension can look through the conversations already in your Claude account to find personal data you sent before you installed it. There are two ways this happens, and you should know about both:

Your conversations are read inside your browser and their text is never sent to us. Only the personal data found in them is recorded, encrypted, as described below.

What your workspace can see

This is the part to read twice. Personal data that PII Shield finds - whether it masked it as you typed, or found it in an old conversation, or the name of a file you uploaded - is recorded in a Leak Audit that the owner and administrators of your workspace can see. If your employer gave you the workspace key, your employer can see it.

That is what the product is for: it exists so an organisation can find out what personal data is reaching AI tools. We are telling you rather than burying it, because you should be able to decide whether to install it knowing that.

What is recorded is the value itself, encrypted in your browser to a key only your workspace holds, together with which site it happened on and when. We cannot read it - we hold no key that opens it. Your chat messages and your files are not sent to us.

Detection is not a guarantee

PII Shield's detection is automated. It is a heuristic, not a proof: it can miss personal data, and it can mask things that were not personal data at all. A clean result is not a certificate, and a passed quality review confirms only that the values we found are gone, not that we found them all.

Always review what you send to an AI. PII Shield reduces the risk of a leak; it does not remove it, and you use it at your own risk. This is also set out in our Terms.

What we store on your device

What we receive on our servers

A workspace key is required to use PII Shield, and with one entered the extension contacts piishield.ai for three things:

Your chat messages themselves are never sent to us, and neither are the contents of your files. With no workspace key the extension makes no network requests to us - but it also will not protect you: it fails closed and blocks messages carrying personal data rather than letting them through unprotected.

What we never do

A correction. An earlier version of this page said we "never transmit, log, or store the personal data the extension detects". That was wrong, and we are not going to quietly delete it. We do transmit and store it - that is what the Leak Audit is, and it is the reason the product exists. What is true, and what we should have said, is that it is encrypted in your browser before it reaches us and we cannot read it.

Permissions we request, and why

Data retention & your control

Settings live on your device until you remove the extension or clear them. Uninstalling the extension removes its local storage. If your organisation uses a workspace, any usage counts associated with your key are governed by your organisation's agreement with us; contact us to have them deleted.

Children

PII Shield is a workplace productivity tool and is not directed to children under 13.

Changes to this policy

If we change how the extension handles data, we will update this page and revise the date above. Material changes will be reflected in the extension's store listing.

Contact

Questions about this policy or your data? Email [email protected].