Privacy Policy
AI Prompt Collector — Browser Extension
Enterprise / managed software notice
The Extension is a workplace governance tool. It is configured and force-installed by an organization (your "Organization") through managed device policy. The Organization — not Equanimo — decides whether to deploy the Extension, which AI tools it covers, and where the captured data is sent. Your Organization is the data controller for information collected through the Extension; Equanimo acts as a data processor providing the software and the receiving Gateway on the Organization's behalf. If you have questions about why the Extension is installed on your device or how your Organization uses the data, please contact your IT administrator.
This Privacy Policy describes how the AI Prompt Collector browser extension ("the Extension") collects, uses, and handles information. The Extension is published by Equanimo AI ("Equanimo", "we", "us") and is distributed to end users only by the organizations that deploy it (typically an employer's IT administrator via managed enterprise policy / MDM).
Single purpose
The Extension has one purpose: to capture prompts that a user submits to supported web-based AI assistants and route them to the Organization's Equanimo AI Gateway for governance, compliance, and auditing. Every permission and data flow described below exists solely to serve that purpose.
Information the Extension collects
The Extension activates only on the supported AI assistant websites listed in its manifest (e.g. Claude, ChatGPT, Gemini, Perplexity, Copilot, Mistral, Grok). It does not run on, monitor, or collect data from any other website.
On those sites, when you submit a prompt, the Extension collects:
The text of the prompt you submit to the AI assistant. This is read from the outgoing network request your browser sends to the AI service. Prompt text may contain whatever you choose to type, which could include personal or sensitive information.
- The URL of the AI assistant page where the prompt was submitted
- The page title
- The name of the AI tool (e.g. "ChatGPT")
- An approximate token count derived from the prompt length
Used to attribute the event to your Organization's tenant, not to build a profile:
- A tenant identifier provisioned by your Organization
- A user principal identifier associated with your Organization's account
- A one-way (SHA-256) hash derived from your browser and operating-system identifiers — not reversible, used only to distinguish devices
- Your browser type and version, operating system / user-agent string, and the installed Extension version
- A timestamp for each captured event
- A periodic heartbeat (~every 5 minutes) reporting that the Extension is running. Contains tenant identifier, user principal, browser/OS and Extension version, uptime, and recent error counts. The heartbeat does not contain prompt content.
- Best-effort error reports if the Extension encounters an internal failure
The Extension does NOT collect:
Your AI assistant responses, browsing history on non-AI sites, passwords, payment/financial information, your contacts, your location, keystrokes outside of submitted prompts, or analytics for advertising.
How information is used
Collected information is used solely to:
- Deliver captured prompts and associated context to your Organization's Equanimo AI Gateway for governance, compliance, audit, and policy-enforcement purposes defined by your Organization
- Confirm the Extension is installed, provisioned, and operating correctly (heartbeat and error telemetry)
We do not use the information for any unrelated purpose.
How information is stored and transmitted
Local storage
Configuration and a temporary offline buffer of up to 500 pending events are stored on your device using the browser's extension storage (chrome.storage). Buffered events are held only until they can be delivered to the Gateway, then removed. The buffer is capped and the oldest entries are dropped first.
Transmission
Captured events are transmitted over HTTPS to the Equanimo AI Gateway endpoint configured by your Organization (by default https://gateway.equanimo.ai; your Organization may configure a different endpoint). Requests are authenticated with a bearer token and a tenant identifier.
Code execution
The Extension executes only the code packaged within it. It does not download or execute remote code.
How information is shared
- Captured information is sent only to the Equanimo AI Gateway endpoint configured by your Organization. It is handled thereafter according to your Organization's policies and the agreement between your Organization and Equanimo.
- We do not sell your personal information.
- We do not transfer or use the information for any purpose unrelated to the Extension's single purpose, and we do not use it to determine creditworthiness or for lending purposes.
- We do not share captured information with advertisers or unrelated third parties.
Compliance with the Chrome Web Store Limited Use policy
Our collection and use of data through the Extension comply with the Chrome Web Store Limited Use requirements. Specifically, data collected by the Extension is:
- Used only to provide and improve its single purpose described above
- Not sold
- Not used or transferred for personalized advertising
- Not used or transferred to determine creditworthiness or for lending purposes
Any human access to the data is limited to the purposes described in this policy and as authorized by your Organization.
Data retention
The Extension itself retains data on your device only transiently (the offline buffer described in Section 4). Retention of data after it reaches the Equanimo AI Gateway is governed by your Organization's configuration and data-retention policies. Please contact your IT administrator for details specific to your Organization.
Your choices and rights
Because the Extension is deployed and managed by your Organization as a workplace tool, installation and configuration are controlled by your Organization rather than by individual end users. To exercise data rights, to request access to or deletion of data, or to opt out, please contact your Organization's IT administrator or privacy team. Depending on your jurisdiction and your Organization's policies, you may have rights to access, correct, or delete your personal information.
Children
The Extension is a workplace tool intended for use by employees and authorized users of deploying Organizations. It is not directed to children and does not knowingly collect information from children.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through your Organization. Continued use of the Extension after an update constitutes acceptance of the revised policy.
Contact
For questions about this Privacy Policy or Equanimo's handling of data as a processor:
Equanimo AI — Privacy enquiries
privacy@equanimo.aiFor questions about why the Extension is deployed on your device or how your Organization uses captured data, contact your Organization's IT administrator.