Privacy Policy

Version 2026-09-15 · Last updated September 15, 2026

The short version Your prompts never leave your device. NorthSyte scans what you type into AI tools inside your browser. We never receive the text you type or the sensitive values we detect — only a short record that a detection happened and what kind of data it was. To activate the extension we ask for your email address. We don't sell your data.

1. Who we are

NorthSyte is operated by Ethan Russett, its founder, in Ottawa, Ontario, Canada. NorthSyte is in the process of incorporating; when it does, this policy will be updated to name the company as the organization responsible for your data.

For privacy questions or requests, email privacy@northsyte.com.

This policy covers the NorthSyte browser extension ("NorthSyte — AI Privacy Guard"), the setup page it opens, and northsyte.com. If you use NorthSyte through your employer, see section 10.

2. How the extension works

On supported AI tools (such as ChatGPT, Claude and Gemini), NorthSyte checks what you have typed before it is sent, using pattern rules and an AI model that both run inside your browser. If it finds something sensitive, it warns you. You always decide whether to send.

The scan itself makes no network request. The extension only runs on the AI sites listed in its permissions; it does not read other sites you visit.

3. What we collect

3.1 Your installation record

When you install NorthSyte, our server creates a random installation ID and a secret access token for your copy of the extension. We store the ID, a one-way hash of the token (never the token itself), the extension version, when it was installed, and when it last contacted us.

3.2 Your email address

NorthSyte asks for your email address on a setup page at northsyte.com, and protection switches on once you provide it. We store the address and when you gave it. It identifies your installation and lets us send you service messages about it — for example, if a site we protect changes and your coverage is affected.

Separately, there is an optional box to receive product news. If you tick it, we record that you consented, when, and which version of this policy was in effect. If you don't, we will not send you marketing.

3.3 Detection events

Each time you submit a prompt on a supported AI tool, the extension sends a short record to our servers containing only:

WhatExample
The AI tool you usedchatgpt
When you submitteda timestamp
Categories of sensitive data found, if anypii.email, pii.credit_card
How confident the AI model was, for each category0.97
Whether you were warned, and whether you sent anywayyes / no
Whether only the AI model (not the pattern rules) caught ityes / no
Your installation IDa random ID

A record is sent for every submitted prompt, including prompts where nothing was found and prompts where you have switched warnings off — so we can measure how often the product helps. From the categories, our server calculates a severity rating.

These records are not anonymous. They carry your installation ID, and your installation record holds your email address, so we can connect your detection events to you. We use them to understand whether NorthSyte works — how many people use it, whether warnings are useful, and where detection is too eager or misses things — and to find your data if you ask us to show or delete it.

3.4 Security logs

Our firewall records technical details of requests to our servers — such as IP address, time, the address requested and browser headers — to detect abuse. These logs are kept for 30 days.

3.5 On your device

The extension keeps its settings, detection rules, installation ID and access token in your browser's extension storage. Websites can't read it. Some of it (your installation ID and settings) syncs across your Chrome browsers if you use Chrome sync.

3.6 Problem reports

If you use Report a problem in the extension, we receive what you write in the description and, only if you choose to give one, an email address to reply to. The extension adds:

WhatExample
The AI tool you were on, if any, and whether NorthSyte could still find its message boxgemini, adapter-drift
The extension version, your browser and operating system0.2.0, Chrome 128, macOS
Whether the AI detection model is switched onon / off
The categories found in your most recent detection, and whenpii.ssn
Your installation IDa random ID

It never adds your prompts, the page you were on, or the sensitive values that were detected. Please don't paste them into the description — the extension checks it for obvious sensitive data before sending and asks you to remove it. Reports are emailed to the NorthSyte team so we can look into them.

3.7 The website

If you use the waitlist or demo form on northsyte.com, we receive what you enter in it, and use it only to respond to you. The site has no analytics or advertising trackers.

4. What we never collect

5. Who else is involved

We use a small number of service providers. None of them receives your prompts.

We do not sell your personal information, and we do not share it with advertisers or data brokers. We may disclose information if required by law.

Some providers may process data outside Canada, including in the United States, where it may be accessible to authorities under local law.

6. Why we are allowed to use it

In Canada we rely on your consent, given when you install NorthSyte and provide your email on the setup page, for the purposes described here. Marketing emails are sent only with the express consent required by Canada's Anti-Spam Legislation (CASL).

If you are in the EU or UK, our legal bases under the GDPR are:

Canada is recognized by the European Commission as providing adequate protection for personal data transferred from the EU.

7. How long we keep it

8. Your rights and choices

Email privacy@northsyte.com to:

We'll respond within 30 days, and may ask you to confirm you control the email address on the installation.

You can stop all collection at any time by removing the extension. You can also switch off warnings in the extension, but as described in 3.3, detection records are still sent while it is installed.

If you're unhappy with our response, you can complain to the Office of the Privacy Commissioner of Canada, or, in the EU or UK, to your data protection authority.

9. Security

Data is encrypted in transit and at rest. Access tokens are stored only as one-way hashes, and our database is not reachable from the internet. The strongest protection is the design itself: prompts are never sent to us, so there is no store of prompts to breach. No system is perfectly secure; if a breach creates a real risk of significant harm to you, we will notify you and the relevant regulator as the law requires.

10. If your employer provides NorthSyte

The business edition of NorthSyte is deployed by organizations for their employees. In that case your employer decides how it is used, and we process the data on their behalf under our agreement with them — questions should go to your employer first. The same core rule applies: prompt text never leaves your device.

11. Children

NorthSyte is not intended for anyone under 16, and we don't knowingly collect their data. If you believe a child has given us their information, email us and we'll delete it.

12. Changes to this policy

We'll post changes here and update the version and date above. If we make a material change — especially to how we use your email address — we'll tell you by email or in the extension before it takes effect and, where the law requires, ask for your consent again.

13. Contact

NorthSyte · Ottawa, Ontario, Canada
privacy@northsyte.com