Privacy Policy
Last updated: June 8, 2026
Introduction
ShadowWatch.ai ("we," "our," or "us") provides enterprise AI governance and monitoring services. This privacy policy describes how the ShadowWatch.ai browser extension ("Extension") collects, processes, and handles data when deployed by your organization.
Important: This Extension is deployed and controlled by your employer or organization. ShadowWatch.ai acts as a data processor on behalf of your organization. For questions about how your organization uses this data, please contact your IT or compliance department.
Data We Collect
The Extension monitors interactions with AI tools to help organizations manage AI usage risks. When you use supported AI platforms, the Extension may collect:
AI Tool Interactions
- • Prompts and messages sent to AI tools (ChatGPT, Claude, Gemini, Perplexity, etc.)
- • AI-generated responses
- • File upload metadata (filename, file type, file size)
- • Conversation context and threading information
Detection Signals
- • Risk scores (0-100+) based on content analysis
- • Detected sensitive data patterns (SSN, API keys, credentials, etc.)
- • Policy violations and enforcement actions taken
- • Warning messages displayed to the user
Metadata
- • Device identifier and browser information
- • Timestamp and duration of AI tool usage
- • AI platform domain and specific model used
- • User identifier (email or employee ID) when enrolled
How Data Is Used
Collected data is used by your organization to:
- • Monitor compliance with organizational AI usage policies
- • Detect and prevent data leaks or security incidents
- • Enforce content policies (e.g., blocking sensitive data from being sent to AI tools)
- • Generate compliance reports and audit trails
- • Provide real-time risk assessments and user warnings
Data Storage & Security
Storage Location
All data is stored within your organization's dedicated ShadowWatch.ai tenant. Your organization's administrators control access to the tenant, user permissions, and data management policies. ShadowWatch.ai hosts and operates the underlying infrastructure and accesses customer data only as necessary to provide, maintain, secure, support, or comply with legal obligations related to the Service.
Data Security
Data is transmitted securely using HTTPS/TLS encryption and is protected by industry-standard security controls. ShadowWatch.ai is responsible for securing the hosting infrastructure and platform, while your organization is responsible for managing user accounts, access permissions, security policies, and any integrations configured within your tenant.
Third-Party Access
ShadowWatch.ai does not sell customer data or provide access to customer data to third parties except as necessary to operate the Service, comply with legal obligations, or with your organization's authorization. Your organization may choose to integrate ShadowWatch.ai with third-party security, compliance, or productivity tools, and any data shared with those services is governed by your organization's configuration and the applicable third-party privacy policies.
Data Retention
Data retention is governed by the retention period selected at the time of purchase. ShadowWatch.ai retains data only for the duration associated with the purchased plan. Additionally, when you connect external systems as notification channels, any data transmitted to those systems is retained according to the independent retention policies of those platforms, which are administered and controlled by you or your organization. ShadowWatch.ai does not impose or extend retention periods beyond those established. For information regarding organization-specific retention requirements, contact your IT or compliance department.
Your Rights
Since ShadowWatch.ai acts as a data processor on behalf of your organization, your rights regarding personal data are exercised through your organization. You may have the right to:
- • Request access to personal data collected about you
- • Request deletion of your data (subject to legal/retention requirements)
Note: To exercise these rights, contact your organization's data protection officer or IT department. ShadowWatch.ai cannot directly process data subject requests without authorization from your organization.
Content Analysis Details
The Extension analyzes content locally in your browser to detect:
Sensitive Data Types
- • Social Security Numbers
- • Credit card numbers
- • Email addresses
- • Phone numbers
- • IP addresses
Security Risks
- • API keys and tokens
- • Passwords and credentials
- • Private keys and certificates
- • Database connection strings
- • Custom regex patterns
Analysis rules are configured by your organization. Detected sensitive data may trigger warnings, block actions, or generate alerts to administrators.
Contact & Support
For questions about this Extension or privacy practices:
Your Organization
Contact your IT department or data protection officer for questions about data collected by your organization, access requests, or policy concerns.
ShadowWatch.ai
For technical support or questions about the Extension software: support@shadowwatch.ai
Changes to This Policy
ShadowWatch.ai may update this privacy policy to reflect changes in our practices or services. Organizations deploying the Extension will be notified of significant changes. We encourage you to review this policy periodically.