Privacy Policy

Privacy Policy

Last updated: June 8, 2026

Introduction

ShadowWatch.ai ("we," "our," or "us") provides enterprise AI governance and monitoring services. This privacy policy describes how the ShadowWatch.ai browser extension ("Extension") collects, processes, and handles data when deployed by your organization.

Important: This Extension is deployed and controlled by your employer or organization. ShadowWatch.ai acts as a data processor on behalf of your organization. For questions about how your organization uses this data, please contact your IT or compliance department.

Data We Collect

The Extension monitors interactions with AI tools to help organizations manage AI usage risks. When you use supported AI platforms, the Extension may collect:

AI Tool Interactions

  • Prompts and messages sent to AI tools (ChatGPT, Claude, Gemini, Perplexity, etc.)
  • AI-generated responses
  • File upload metadata (filename, file type, file size)
  • Conversation context and threading information

Detection Signals

  • Risk scores (0-100+) based on content analysis
  • Detected sensitive data patterns (SSN, API keys, credentials, etc.)
  • Policy violations and enforcement actions taken
  • Warning messages displayed to the user

Metadata

  • Device identifier and browser information
  • Timestamp and duration of AI tool usage
  • AI platform domain and specific model used
  • User identifier (email or employee ID) when enrolled

How Data Is Used

Collected data is used by your organization to:

  • Monitor compliance with organizational AI usage policies
  • Detect and prevent data leaks or security incidents
  • Enforce content policies (e.g., blocking sensitive data from being sent to AI tools)
  • Generate compliance reports and audit trails
  • Provide real-time risk assessments and user warnings

Data Storage & Security

Storage Location

All data is stored within your organization's dedicated ShadowWatch.ai tenant. Your organization's administrators control access to the tenant, user permissions, and data management policies. ShadowWatch.ai hosts and operates the underlying infrastructure and accesses customer data only as necessary to provide, maintain, secure, support, or comply with legal obligations related to the Service.

Data Security

Data is transmitted securely using HTTPS/TLS encryption and is protected by industry-standard security controls. ShadowWatch.ai is responsible for securing the hosting infrastructure and platform, while your organization is responsible for managing user accounts, access permissions, security policies, and any integrations configured within your tenant.

Third-Party Access

ShadowWatch.ai does not sell customer data or provide access to customer data to third parties except as necessary to operate the Service, comply with legal obligations, or with your organization's authorization. Your organization may choose to integrate ShadowWatch.ai with third-party security, compliance, or productivity tools, and any data shared with those services is governed by your organization's configuration and the applicable third-party privacy policies.

Data Retention

Data retention is governed by the retention period selected at the time of purchase. ShadowWatch.ai retains data only for the duration associated with the purchased plan. Additionally, when you connect external systems as notification channels, any data transmitted to those systems is retained according to the independent retention policies of those platforms, which are administered and controlled by you or your organization. ShadowWatch.ai does not impose or extend retention periods beyond those established. For information regarding organization-specific retention requirements, contact your IT or compliance department.

Your Rights

Since ShadowWatch.ai acts as a data processor on behalf of your organization, your rights regarding personal data are exercised through your organization. You may have the right to:

  • Request access to personal data collected about you
  • Request deletion of your data (subject to legal/retention requirements)

Note: To exercise these rights, contact your organization's data protection officer or IT department. ShadowWatch.ai cannot directly process data subject requests without authorization from your organization.

Content Analysis Details

The Extension analyzes content locally in your browser to detect:

Sensitive Data Types

  • • Social Security Numbers
  • • Credit card numbers
  • • Email addresses
  • • Phone numbers
  • • IP addresses

Security Risks

  • • API keys and tokens
  • • Passwords and credentials
  • • Private keys and certificates
  • • Database connection strings
  • • Custom regex patterns

Analysis rules are configured by your organization. Detected sensitive data may trigger warnings, block actions, or generate alerts to administrators.

Contact & Support

For questions about this Extension or privacy practices:

Your Organization

Contact your IT department or data protection officer for questions about data collected by your organization, access requests, or policy concerns.

ShadowWatch.ai

For technical support or questions about the Extension software: support@shadowwatch.ai

Changes to This Policy

ShadowWatch.ai may update this privacy policy to reflect changes in our practices or services. Organizations deploying the Extension will be notified of significant changes. We encourage you to review this policy periodically.