Prompt Firewall — Privacy Policy
Last updated: 2026-04-28
Prompt Firewall is a local-first privacy guard for AI tools. We do not operate any backend, do not run analytics, and never receive your data.
What the extension stores
All data is stored locally in your browser via chrome.storage.local:
- Your enable / disable toggle and Privacy Mode flag
- Statistics counters (for example, “warnings shown”)
- Your watchlist entries (terms you choose to flag)
- Your custom detection rules and document-mode toggles
- Your selected policy template
- Your bring-your-own-key API credentials (provider, key, model, endpoint)
- Your audit log of warning events — metadata only (timestamp, site, action taken, risk score, finding categories). No prompt content is ever stored.
- Your license key or trial start timestamp
What the extension transmits
In its default configuration, Prompt Firewall transmits nothing. All detection and redaction happen inside your browser.
The optional Sanitise Prompt feature sends the current prompt directly from your browser to the LLM provider you configured (OpenAI, Anthropic, Google Gemini, or your local Ollama endpoint), authenticated with your own API key. The extension does not proxy, log, or store these requests.
Privacy Mode
When Privacy Mode is on, the extension refuses to make any outbound request, including Sanitise calls to remote providers. Local Ollama remains available.
Third parties
The extension does not embed third-party analytics, advertising, or tracking SDKs.
Data subject rights
Because nothing is stored on a server, there is no remote data to access, export, or delete. To wipe local data, remove the extension or use the “Clear log” / “Reset statistics” buttons in the UI.
Contact
For privacy questions or bug reports, use the support contact on this extension’s Chrome Web Store listing once it is published, or your project’s public issue tracker if one is linked from the listing.