TRANSPARENCY · PROMPTGUARD

Privacy.

What stays in the browser, which minimized metadata reaches a company workspace, and how that data is used.

01

Controller and contact

David Hein
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
Email: info@fragenta.com

When PromptGuard is deployed by a company, that company defines the policies and purposes of use. Employees should first contact the organization responsible for their workspace with questions.

02

Local checks in the browser

PromptGuard reads text from the input field of a supported AI website immediately before submission and checks it locally against the active company policy. This check is used solely to detect sensitive content and to warn, redact, or block transmission.

Prompt text, detected values such as passwords or IBANs, match positions, and DOM snapshots are not transmitted to Fragenta or the company workspace and are not stored in the audit log.

03

Workspace, policies, and audit metadata

In a connected company workspace, the extension stores a device token, service address, most recently valid policy, and its last update time locally. The token is used only to authenticate that device and is not shared with the visited AI website.

If auditing is enabled, only the following data is transmitted over HTTPS:

  • the supported AI service hostname, without URL paths or query parameters;
  • the action, such as warned, blocked, or anonymized;
  • the detected data category and number of matches;
  • the policy version and event and receipt timestamps;
  • a freely chosen device name and pseudonymous device assignment within the workspace.

Business email address, organization, role, invitation status, and session status are also processed for workspace accounts. One-time enrollment, invitation, and reset secrets are stored only as hashes; the plain text is shown only when the secret is created.

04

Purpose, recipients, and retention

Data is used only to provide local protection, distribute policies securely, manage devices, and maintain a content-minimized security audit. It is not sold, used for personalized advertising, or used to evaluate individual employee performance.

Workspace data is accessible only to authorized administrators of the relevant organization and technically necessary operator access. Audit metadata is deleted according to the retention period set in the workspace. Local extension data remains until the device is disconnected, reset, or the extension is uninstalled.

The workspace is technically delivered through Cloudflare Workers, Durable Objects, and the operational monitoring enabled there. Cloudflare processes necessary connection, delivery, and error data as a technical service provider. For abuse prevention, PromptGuard creates a hash from the route and client IP; the raw IP address is not stored in the PromptGuard application database. Expired rate-limit entries, sessions, and one-time codes are cleaned up automatically.

Sessions normally expire after eight hours. One-time enrollment codes normally remain valid for 30 minutes and, solely for Chrome Web Store review, optionally for up to seven days. Workspace account and organization data remains until the pilot or contractual relationship ends, subject to statutory retention obligations.

05

Chrome Web Store Limited Use

PromptGuard's use of information received from Chrome extension APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. This information is used only for the clearly described purpose of protecting sensitive input.

No information is transferred to advertising networks or data brokers. People do not read prompt text or detected values because this content does not leave the browser during the check.

06

Website, support, and data subject rights

When this website is accessed, the hosting provider processes the connection data technically required to deliver and secure the site. The PromptGuard product page does not use proprietary advertising or analytics trackers.

When you email info@fragenta.com, the sender address, message content, and technical email metadata are processed to handle the request. Where the statutory requirements are met, data subjects may request access, correction, deletion, restriction, and objection. Fragenta has no access to content stored exclusively in the local browser.

PromptGuard is an independent product and is not affiliated with OpenAI, Google, Anthropic, or Microsoft. All trademarks belong to their respective owners.

Last updated: August 30, 2026 · Transparency information for the controlled B2B pilot. Specific contractual roles and data processing terms are reviewed for each customer before broader deployment.