Prism browser extension: privacy policy
DRAFT for legal review before it’s published as the Chrome Web Store privacy policy. Facts below match the code as of 2026-10-07. Bracketed items need a decision.
Who we are. Prism DLP is a product of Stabilise Ltd (company number 16244247, registered office 6-7 St Cross Street, London, EC1N 8UB, United Kingdom; ICO registration ZB938192), which provides it and is responsible for this policy. This policy covers the Prism DLP browser extension; the Stabilise privacy policy covers Stabilise’s other services. Contact: privacy@stabilise.io.
What the extension is for. Prism is a data loss prevention tool your employer deploys. The extension checks what you paste or upload into supported AI tools (ChatGPT, Claude and Gemini) against your organisation’s data policy, and may warn you or stop the action.
What it collects, and when. Only on the supported AI sites, and only when you paste or upload content:
- the pasted text, or the contents of a text file you upload (other files: name, type and size only)
- the site and page address (without query strings)
- your work email and, if configured, your name, from your organisation’s settings or your signed-in Chrome profile
- a justification you type when you choose to continue after a warning
Nothing is collected from other websites, and nothing at all until your organisation has configured the extension.
How it’s used. Solely to decide whether the action fits your organisation’s policy and to let your organisation’s security team review flagged events. Prism removes detected secrets and personal data (for example API keys, card numbers, email addresses and phone numbers) before storing anything; the original values are not stored.
Who it’s shared with. Your organisation (the Prism customer), through the Prism console. Our infrastructure providers (Railway, hosting; Supabase, database) process it on our behalf in the UK and EU. [If and when enabled: TypeSafe, which receives only redacted text to help assess risk, under a data processing agreement with zero data retention.] We don’t sell data, use it for advertising, or use it to train AI models.
Retention. Your organisation sets how long events are kept (90 days by default). Your organisation can ask us to delete all of its data at any time.
Your rights. Prism processes this data on behalf of your employer, who is the data controller. Contact your organisation’s privacy or IT team to exercise your rights; we’ll support them.
Security. Data is encrypted in transit (HTTPS/TLS). Each organisation’s data is isolated from every other’s. [Encryption at rest per provider; link to security overview / threat model summary.]
Changes. We’ll update this page and the “last updated” date when anything changes.
Last updated: [date of publication]