Legal
Effective date: May 29, 2026
Entity: KorGuard Inc.
Contact: privacy@korguard.org
KorGuard is an enterprise browser extension that helps organizations stay compliant with regulations such as HIPAA and GLBA. It scans text and file attachments locally, in your browser, before they are submitted to third-party AI chat interfaces (e.g., ChatGPT, Claude, Gemini, Copilot, and Google's AI Overview follow-up chat and AI Mode on google.com), and warns or blocks when it detects sensitive identifiers or health/financial information. Ordinary Google web searches are not scanned or logged — only the AI conversation surfaces.
KorGuard is deployed by your organization's IT administrators (typically via managed device policy such as Microsoft Intune). Your organization is the controller of the limited metadata described below; KorGuard Inc. acts as its service provider/processor.
Detection is performed by an on-device machine-learning model running entirely within your browser (ONNX Runtime in WebAssembly). The text and files you enter are analyzed on your own machine. They are never sent to KorGuard's servers, never written to disk by KorGuard, and never logged.
When the extension detects a potential compliance issue (a "signal"), it sends metadata only to KorGuard's backend so your organization's administrators can see aggregate compliance activity. A signal contains:
| Field | Example | Notes |
|---|---|---|
| Severity | high / med / low | Risk level of the detection |
| Action | blocked / overridden / warned | What the extension did |
| Regulation | HIPAA / GLBA | Which rule was implicated |
| Confidence | 0.9 | Model confidence score |
| LLM host | chatgpt.com | Which AI site it occurred on |
| Input type | prompt_submission | Text vs. attachment, etc. |
| Per-session ID | random UUID | Newly generated per signal; not linked to you |
| Timestamp | server-assigned | When the signal was received |
There is no prompt text and no device or user identity in a signal. The per-session identifier is a random value that is not tied to your name, account, or device, and cannot be used to re-identify you.
The extension authenticates to KorGuard's backend with a per-organization API key provisioned to your organization by its IT administrators. The key identifies the organization, not the individual user.
Solely to provide the service: to populate your organization's compliance dashboard and aggregate reporting, and to operate, secure, and improve the product. We do not use it for advertising and we do not sell it.
We do not sell or rent data. We use the following sub-processors to operate the service:
We may disclose information if required by law.
Anonymous signals are retained for as long as your organization maintains its KorGuard subscription, or as configured with your organization, and then deleted or aggregated. Because signals contain no personal data, they cannot be used to identify or contact you.
Data in transit is protected with TLS/HTTPS. Backend infrastructure runs in private networks with encryption at rest and audit logging. API keys are stored only as salted hashes (argon2id), never in plaintext.
The extension does not request access to your general browsing.
KorGuard is a workplace tool not directed to children and does not knowingly collect data from anyone under 16.
We will post any changes here and update the effective date.
Questions: privacy@korguard.org