Privacy Policy
Effective: September 8, 2026
Last updated: September 8, 2026
Operated by: PiiBlock (sole proprietorship)
Location: Sri Lanka
Data Controller: Available upon request at [email protected]
Contact: [email protected]
The PiiBlocker extension processes all data locally in your browser. In free mode it makes zero outbound network requests. This website is a separate thing, and it does collect data when you use a contact form. This policy answers for each separately.
1. The Three Scopes In This Policy
PiiBlock operates three things. They handle data differently. Every section below names the scope it answers for.
- The extension - the PiiBlocker browser extension you install from the Chrome Web Store.
- This website - piiblock.com, including the three contact forms on it.
- The enterprise service - managed deployments for organisations that buy Enterprise seats.
A claim about one scope is not a claim about the others. Where a section says "the extension", it does not describe this website.
2. The Extension: Data We Collect
Scope: the extension. We collect NO personal data through the extension. Specifically:
- The extension does not collect your prompts or AI conversations
- The extension does not collect the PII it detects
- The extension does not collect your browsing history
- The extension does not collect usage analytics
- In free mode, the extension sends no data to us. No server of ours receives anything from the extension.
- The extension does not set cookies
- The extension does not fingerprint your browser
3. The Extension: Local Data Storage
Scope: the extension. The following data is stored LOCALLY on your device only and never transmitted anywhere:
- Extension settings - on/off toggle, detection preferences
- Encrypted PII mappings - AES-256-GCM encrypted, auto-expiring after 4 hours, purged on browser close
- Personal PII dictionary entries - detection hints you have manually saved
- Anonymous aggregate statistics - e.g., "12 items detected today" - no PII values stored
This data never leaves your browser. It is stored in Chrome's local storage and IndexedDB.
4. The Extension: Encryption
Scope: the extension. All PII mappings are encrypted using AES-256-GCM via the Web Crypto API. Encryption keys are ephemeral - generated in memory, marked non-extractable, and permanently lost when the browser closes. No keys are ever written to disk or sent anywhere.
5. This Website
Scope: this website. This section describes piiblock.com. It does not describe the extension.
Hosting
This website is hosted by Cloudflare. Every request to this site passes through Cloudflare's edge network. Cloudflare processes your IP address to serve the page and to protect the site from abuse. This happens for every visit, including visits where you fill in nothing.
Web Analytics
Our website uses Cloudflare Web Analytics, a privacy-focused analytics service that collects anonymised, aggregated page view data. Cloudflare Web Analytics does not use cookies, does not track individual users, does not collect IP addresses, and does not fingerprint browsers. No personally identifiable information is collected through our website analytics.
Contact Forms
This website has three forms. Each one collects different fields:
- Enterprise inquiry - name, work email, organisation, seat count, and your message.
- Feedback - your message, and your email address if you choose to give one.
- Uninstall feedback - a reason for uninstalling, which is required, and depending on that reason: the site it happened on, what happened, categories of data it missed or wrongly flagged (never the data itself), the tool you switched to, or what concerned you. A free-text comment. An email address, only if you tick the box asking us to follow up. We also record your browser family and major version, and, when the extension passes them in the link, its version and your browser locale. Nothing else.
Nothing is sent until you press the submit button. Loading a page that carries a form sends us nothing. Closing the tab without submitting sends us nothing.
When you submit a form, we receive the fields listed above. The submission is emailed to our team and stored. See section 8 for how long we keep it.
Spam Protection
Pages carrying a form use Cloudflare Turnstile to block automated submissions. Turnstile processes your IP address and sets a cookie in your browser. This happens on the pages that carry a form. It does not happen on the rest of the site.
6. The Enterprise Service
Scope: the enterprise service. Managed deployments report masking events to an admin dashboard. Those reports contain only metadata. The detected text itself never leaves the browser. This applies only to organisations that have bought Enterprise seats and deployed the extension centrally. It does not apply to free mode.
7. Processors We Use
Scope: this website and the enterprise service. The extension uses no processors. Two companies handle data on our behalf:
- Cloudflare - hosts this website and runs the edge network it is served from. Cloudflare receives the IP address of every visitor. Cloudflare also provides Turnstile spam protection on form pages, Web Analytics, and the storage where form submissions are kept.
- Resend - sends us an email notification when someone submits a form. Resend receives the contents of that submission in order to deliver the notification to us.
We do not sell data to anyone. We do not share submissions with anyone beyond the two processors named above.
8. Retention and Deletion
Scope: this website. We keep inquiry submissions for 6 months. After that, we remove all identifying details (name, email address, organisation, and message content), retaining only the submission type, the reason selected, and the date, which cannot be linked back to you.
You can ask us to delete your submission at any time before then. Email [email protected] and we will remove it.
Scope: the extension. Extension data is stored on your device. Delete it yourself at any time from the extension popup, or by uninstalling the extension. We hold no copy of it.
9. Cookies
Scope: the extension. The extension sets no cookies.
Scope: this website. Cloudflare Turnstile sets a cookie on pages that carry a form. It is used to tell real visitors from bots. We set no advertising cookies and no tracking cookies. Cloudflare Web Analytics uses no cookies.
10. Data Sharing
Scope: the extension. There is nothing to share. The extension transmits no data to us in free mode.
Scope: this website. Form submissions go to the processors named in section 7 and to our own team. Nowhere else. We do not sell, rent, or trade any of it.
11. Your Rights Under GDPR (EU/EEA and UK Users)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:
- Right of Access - For the extension, we hold nothing about you. For this website, if you have submitted a form, we hold that submission and will send you a copy on request.
- Right to Erasure - Delete extension data yourself from the extension popup or by uninstalling. For a form submission, email us and we will delete it.
- Right to Data Portability - For the extension, we hold nothing to transfer. For a form submission, we will provide it in a machine readable format on request.
- Right to Object - You can object to our processing of a form submission. Email us and we will stop and delete it.
- Right to Lodge a Complaint - You have the right to lodge a complaint with your local Data Protection Authority (DPA).
Legal basis: For the extension, all processing happens locally on your device and we receive nothing, so no server-side processing occurs. For this website, our legal basis for handling a form submission is legitimate interest in answering the person who contacted us. Our legal basis for Turnstile is legitimate interest in keeping the forms free of spam.
UK Users
If you are located in the United Kingdom, you have equivalent rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The rights described above apply equally to UK residents. You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Your Rights Under CCPA (California Users)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know - For the extension, we collect nothing, so there are no categories to disclose. For this website, the categories we collect are the form fields listed in section 5 and the IP address processed by Cloudflare.
- Right to Delete - Extension data is stored on your device and you can delete it at any time from the extension popup or by uninstalling. For a form submission, email us and we will delete it.
- Right to Opt-Out of Sale - We do not sell, rent, or trade your personal information to any third party.
- Non-Discrimination - We will not discriminate against you for exercising any of your CCPA rights.
13. Chrome Web Store Compliance
Scope: the extension. PiiBlocker adheres to the Chrome Web Store User Data Policy and its Limited Use requirements. Our use of data obtained through Chrome APIs is limited to providing and improving the extension's core functionality.
14. Permissions We Request
Scope: the extension. Below are the browser permissions PiiBlocker requests, and why each is necessary:
- storage - Stores settings and encrypted mappings locally on your device
- contextMenus - Adds the right-click "Mask with PiiBlocker" option
- activeTab - Reads the current tab to detect PII (only on supported AI sites)
- Host permissions - Injects the content script on the 7 supported AI chatbot sites only: ChatGPT (chatgpt.com), Claude (claude.ai), Gemini (gemini.google.com), Grok (grok.com), DeepSeek (chat.deepseek.com), Kimi (kimi.com), Perplexity (perplexity.ai). The extension cannot read any other site.
15. Children's Privacy
Scope: the extension. The extension collects no personal data from any user, regardless of age. No age verification is required to use it.
Scope: this website. The contact forms are meant for adults getting in touch about the product. They are not directed at children. We do not knowingly collect personal data from anyone under 16 through them. If you believe a child has submitted a form, email us and we will delete it.
16. International Data Transfers
Scope: the extension. The extension performs all processing locally on your device. Nothing is transmitted, so no cross-border transfer happens.
Scope: this website and the enterprise service. Form submissions are stored in the Oceania region. Enterprise reporting metadata is stored in the Oceania region. Our team operates from Sri Lanka and reads submissions from there.
If you submit a form from anywhere else, including the United States or the EEA, your submission is transferred to and stored in the Oceania region, and is read by our team in Sri Lanka. Submitting a form is your choice. If you would rather not have your data transferred, do not use the forms and contact us by email instead.
17. Data Breach Notification
Scope: the extension. The extension stores no user data on servers, so a server-side breach cannot expose it. Extension data stays encrypted and local to your device.
Scope: this website and the enterprise service. Form submissions and enterprise reporting metadata are stored on servers, so a breach is possible. If one happens and affects your data, we will notify affected people by email within 72 hours of becoming aware of it, and we will notify the relevant supervisory authority where the law requires it.
In the unlikely event of a security vulnerability in the extension itself, we will notify users through the Chrome Web Store update mechanism and on our website.
18. Changes to This Policy
If we make material changes to this policy, we will post the updated version at this URL and update the "Last updated" date at the top. We encourage you to review this page periodically.
19. Policy History
We maintain a record of material changes to this privacy policy.
- March 3, 2026 - Initial publication
- April 1, 2026 - Added Cloudflare Web Analytics disclosure, added Gemini host permission, added UK GDPR reference, updated legal entity details, updated children's privacy section
- September 8, 2026 - Restructured the policy around three scopes: the extension, this website, and the enterprise service. Added contact forms to the website, covering what each form collects, that nothing is sent before you submit, and Cloudflare Turnstile spam protection. Disclosed Cloudflare hosting and the IP address processing that comes with it. Added a processor section naming Cloudflare and Resend. Added retention periods and how to request deletion. Corrected the international transfers section to state where data is stored. Corrected the host permissions list, which named 3 sites when the extension requests 7. Removed the Formspree disclosure, which is no longer in use.
Previous versions of this policy are available upon request at [email protected].
20. Contact
Questions or concerns about this privacy policy? Reach us at:
- Privacy enquiries: [email protected]
- General support: [email protected]
- Security issues: [email protected]
Operated by: PiiBlock (sole proprietorship)
Location: Sri Lanka