Back home

    Legal

    Privacy Policy

    Effective date: May 29, 2026

    Entity: KorGuard Inc.

    Contact: privacy@korguard.org

    The short version

    • Your prompts never leave your device. All detection runs locally in your browser. KorGuard never transmits, stores, or sees the text or files you type into AI chat interfaces.
    • No personal or health information is collected. We do not collect names, emails, device identifiers, IP-based identity, or any PHI/PII.
    • We collect only anonymous detection metadata — enough to give your organization a compliance dashboard, and nothing that can identify you.
    • We do not sell data or use it for advertising.

    What KorGuard is

    KorGuard is an enterprise browser extension that helps organizations stay compliant with regulations such as HIPAA and GLBA. It scans text and file attachments locally, in your browser, before they are submitted to third-party AI chat interfaces (e.g., ChatGPT, Claude, Gemini, Copilot, and Google's AI Overview follow-up chat and AI Mode on google.com), and warns or blocks when it detects sensitive identifiers or health/financial information. Ordinary Google web searches are not scanned or logged — only the AI conversation surfaces.

    KorGuard is deployed by your organization's IT administrators (typically via managed device policy such as Microsoft Intune). Your organization is the controller of the limited metadata described below; KorGuard Inc. acts as its service provider/processor.

    How detection works (and why your content stays private)

    Detection is performed by an on-device machine-learning model running entirely within your browser (ONNX Runtime in WebAssembly). The text and files you enter are analyzed on your own machine. They are never sent to KorGuard's servers, never written to disk by KorGuard, and never logged.

    Information we do NOT collect

    • The content of your prompts, messages, or uploaded files.
    • Names, email addresses, phone numbers, or other personal identifiers.
    • Any protected health information (PHI) or personal financial data.
    • Device identifiers, hardware fingerprints, or persistent user IDs.
    • Your browsing history on sites other than the supported AI interfaces.

    Information we DO collect (anonymous detection signals)

    When the extension detects a potential compliance issue (a "signal"), it sends metadata only to KorGuard's backend so your organization's administrators can see aggregate compliance activity. A signal contains:

    FieldExampleNotes
    Severityhigh / med / lowRisk level of the detection
    Actionblocked / overridden / warnedWhat the extension did
    RegulationHIPAA / GLBAWhich rule was implicated
    Confidence0.9Model confidence score
    LLM hostchatgpt.comWhich AI site it occurred on
    Input typeprompt_submissionText vs. attachment, etc.
    Per-session IDrandom UUIDNewly generated per signal; not linked to you
    Timestampserver-assignedWhen the signal was received

    There is no prompt text and no device or user identity in a signal. The per-session identifier is a random value that is not tied to your name, account, or device, and cannot be used to re-identify you.

    Authentication

    The extension authenticates to KorGuard's backend with a per-organization API key provisioned to your organization by its IT administrators. The key identifies the organization, not the individual user.

    How we use the information

    Solely to provide the service: to populate your organization's compliance dashboard and aggregate reporting, and to operate, secure, and improve the product. We do not use it for advertising and we do not sell it.

    Sharing and sub-processors

    We do not sell or rent data. We use the following sub-processors to operate the service:

    • Amazon Web Services (AWS) — backend hosting (US region).
    • Supabase — database storage of anonymous signals.

    We may disclose information if required by law.

    Data retention

    Anonymous signals are retained for as long as your organization maintains its KorGuard subscription, or as configured with your organization, and then deleted or aggregated. Because signals contain no personal data, they cannot be used to identify or contact you.

    Security

    Data in transit is protected with TLS/HTTPS. Backend infrastructure runs in private networks with encryption at rest and audit logging. API keys are stored only as salted hashes (argon2id), never in plaintext.

    Permissions the extension requests

    • Host access to supported AI sites + KorGuard's API host — to read your draft input locally for scanning and to send anonymous signals. On Google, the extension runs only on results/AI Mode pages and scans only the AI conversation boxes — never your ordinary searches, and never Maps, Drive, Docs, or other Google services.
    • Storage — to cache your organization's policy configuration and read the managed API key/organization ID.
    • Offscreen / Alarms — to run the local model and periodically refresh configuration.

    The extension does not request access to your general browsing.

    Children

    KorGuard is a workplace tool not directed to children and does not knowingly collect data from anyone under 16.

    Changes to this policy

    We will post any changes here and update the effective date.

    Contact