Zasady ochrony prywatności dodatku CipherPrompt DLP
CipherPrompt DLP Autor: Agata Ćwirko IT
CIPHERPROMPT DLP — PRIVACY POLICY (BROWSER EXTENSION)
Last updated: 4 August 2026
Full policy: https://cipher-prompt.pl/privacy/
IN SHORT
CipherPrompt DLP inspects what you paste, drop or attach on AI platforms entirely on
your own device. That content is never transmitted to us or to anyone else. There is
no telemetry, no analytics, no tracking and no user account. The only thing that ever
leaves your browser is your licence key, sent to our own licensing service so we can
check that it is valid.
WHO IS RESPONSIBLE
Agata Ćwirko IT (Poland) is the data controller.
Contact: support@cipher-prompt.pl
WHAT THE EXTENSION NEVER COLLECTS
The following never leaves your device and is never sent to us:
- The text you paste or type into AI platforms, and your prompts or their responses
- The contents of files you drop or attach, including documents and PDFs
- Your clipboard contents
- Any API key, credential, card number or personal data that a detection rule matches
- Your browsing history, the pages you visit, or which AI platforms you use
- Usage statistics, feature analytics, crash reports or advertising identifiers
The add-on contains no analytics or telemetry code of any kind. Detection runs against
regular-expression patterns held in memory on your device, and a match produces a local
warning only.
WHAT IS SENT OFF YOUR DEVICE
The extension makes exactly three kinds of network request:
1. Licence activation and validation — on activation and roughly once a day.
Sent: your licence key and a random installation identifier generated locally
(for example "mach_9f2c…"; it is a random UUID, not a hardware or personal
identifier).
Recipient: our licence proxy on Cloudflare Workers, which relays the request to
Creem, our licence provider. The proxy exists so the merchant API key is never
shipped inside the add-on.
Purpose: verifying your licence and counting how many installations it covers.
Legal basis: performance of our contract with you.
This is the "authentication information" declared in the add-on's data-collection
permissions.
2. Detection rule updates — about every 12 hours.
A plain download of https://cipher-prompt.pl/super-config.json. Nothing about you or
your activity is sent. As with any download, our host receives your IP address and
request headers.
3. Checkout links — only when you open the purchase page.
Asks our licence proxy which checkout page to open. No identifier is sent.
Purchases themselves happen on Creem's website, not in the add-on. Creem acts as
merchant of record; your payment details go to Creem and are never seen or stored by
us. We receive only your licence key and the email address tied to the purchase.
STORED ON YOUR OWN DEVICE
Held in extension storage, accessible only to the add-on, and never uploaded:
- Your licence key and activation state
- Your detection rules, allow/block lists and settings
- The optional settings PIN
- The random installation identifier
Removing the add-on deletes all of it.
HOW LONG WE KEEP DATA
- Licence and activation records: while your licence is active, then up to 12 months
- Purchase and invoice records: as required by Polish tax law (currently 5 years),
held by Creem
- Server logs (IP addresses and request paths): short-term, for security and abuse
prevention. Licence keys are never written to our logs.
We hold no record of your prompts, pastes, files or detected matches, because we never
receive them.
INTERNATIONAL TRANSFERS
Our providers (Creem, Cloudflare, our website host) may process data outside the
European Economic Area, under the safeguards required by the GDPR.
YOUR RIGHTS
Under the GDPR you may request access to, correction of, or erasure of your personal
data, restrict or object to processing, receive your data in a portable form, and lodge
a complaint with the Polish supervisory authority (UODO). Write to
support@cipher-prompt.pl. Because we hold almost nothing about you, most requests
concern your purchase record, which we retrieve from Creem.
ENTERPRISE DEPLOYMENTS
Where an organisation deploys CipherPrompt DLP by policy, that organisation is the
controller of its employees' data and sets its own rules; blocked-event logs are
written locally on the device and are never sent to us.
CHILDREN
The add-on is a business tool and is not directed at children.
CHANGES
Material changes will be published at https://cipher-prompt.pl/privacy/ with an updated
date, and where required we will notify you by email.