Privacy Policy
1. Who we are
NorthSyte is operated by Ethan Russett, its founder, in Ottawa, Ontario, Canada. NorthSyte is in the process of incorporating; when it does, this policy will be updated to name the company as the organization responsible for your data.
For privacy questions or requests, email privacy@northsyte.com.
This policy covers the NorthSyte browser extension ("NorthSyte — AI Privacy Guard"), the setup page it opens, and northsyte.com. If you use NorthSyte through your employer, see section 10.
2. How the extension works
On supported AI tools (such as ChatGPT, Claude and Gemini), NorthSyte checks what you have typed before it is sent, using pattern rules and an AI model that both run inside your browser. If it finds something sensitive, it warns you. You always decide whether to send.
The scan itself makes no network request. The extension only runs on the AI sites listed in its permissions; it does not read other sites you visit.
3. What we collect
3.1 Your installation record
When you install NorthSyte, our server creates a random installation ID and a secret access token for your copy of the extension. We store the ID, a one-way hash of the token (never the token itself), the extension version, when it was installed, and when it last contacted us.
3.2 Your email address
NorthSyte asks for your email address on a setup page at northsyte.com, and protection switches on once you provide it. We store the address and when you gave it. It identifies your installation and lets us send you service messages about it — for example, if a site we protect changes and your coverage is affected.
Separately, there is an optional box to receive product news. If you tick it, we record that you consented, when, and which version of this policy was in effect. If you don't, we will not send you marketing.
3.3 Detection events
Each time you submit a prompt on a supported AI tool, the extension sends a short record to our servers containing only:
| What | Example |
|---|---|
| The AI tool you used | chatgpt |
| When you submitted | a timestamp |
| Categories of sensitive data found, if any | pii.email, pii.credit_card |
| How confident the AI model was, for each category | 0.97 |
| Whether you were warned, and whether you sent anyway | yes / no |
| Whether only the AI model (not the pattern rules) caught it | yes / no |
| Your installation ID | a random ID |
A record is sent for every submitted prompt, including prompts where nothing was found and prompts where you have switched warnings off — so we can measure how often the product helps. From the categories, our server calculates a severity rating.
These records are not anonymous. They carry your installation ID, and your installation record holds your email address, so we can connect your detection events to you. We use them to understand whether NorthSyte works — how many people use it, whether warnings are useful, and where detection is too eager or misses things — and to find your data if you ask us to show or delete it.
3.4 Security logs
Our firewall records technical details of requests to our servers — such as IP address, time, the address requested and browser headers — to detect abuse. These logs are kept for 30 days.
3.5 On your device
The extension keeps its settings, detection rules, installation ID and access token in your browser's extension storage. Websites can't read it. Some of it (your installation ID and settings) syncs across your Chrome browsers if you use Chrome sync.
3.6 Problem reports
If you use Report a problem in the extension, we receive what you write in the description and, only if you choose to give one, an email address to reply to. The extension adds:
| What | Example |
|---|---|
| The AI tool you were on, if any, and whether NorthSyte could still find its message box | gemini, adapter-drift |
| The extension version, your browser and operating system | 0.2.0, Chrome 128, macOS |
| Whether the AI detection model is switched on | on / off |
| The categories found in your most recent detection, and when | pii.ssn |
| Your installation ID | a random ID |
It never adds your prompts, the page you were on, or the sensitive values that were detected. Please don't paste them into the description — the extension checks it for obvious sensitive data before sending and asks you to remove it. Reports are emailed to the NorthSyte team so we can look into them.
3.7 The website
If you use the waitlist or demo form on northsyte.com, we receive what you enter in it, and use it only to respond to you. The site has no analytics or advertising trackers.
4. What we never collect
- The text of your prompts. Not sent, not stored, not logged.
- The sensitive values we detect. We record that a card number was found — never the number.
- AI tools' responses, or any other page content.
- Your browsing history, or activity on sites outside the supported AI tools.
- Payment details.
5. Who else is involved
We use a small number of service providers. None of them receives your prompts.
- Amazon Web Services hosts our servers and database in Canada (Montréal region). Your installation record, email address, detection events and problem reports are stored there, and problem reports are emailed to our team through Amazon's email service in the same region.
- Hugging Face hosts the AI detection model. The first time the extension runs, your browser downloads the model from Hugging Face, which sees a normal download request (including your IP address). After that the model runs on your device.
- GitHub hosts northsyte.com, including the setup page, and receives standard web request information when you visit.
- Google provides the fonts on northsyte.com (your browser requests them from Google) and our email (Google Workspace), which handles messages you send us and any we send you.
- Web3Forms receives and forwards to us what you submit in the website's waitlist form.
We do not sell your personal information, and we do not share it with advertisers or data brokers. We may disclose information if required by law.
Some providers may process data outside Canada, including in the United States, where it may be accessible to authorities under local law.
6. Why we are allowed to use it
In Canada we rely on your consent, given when you install NorthSyte and provide your email on the setup page, for the purposes described here. Marketing emails are sent only with the express consent required by Canada's Anti-Spam Legislation (CASL).
If you are in the EU or UK, our legal bases under the GDPR are:
- Providing the extension (installation record, email for service messages): performance of our agreement with you.
- Detection events and security logs: our legitimate interest in running, securing and improving a privacy product. They contain no prompt text and no detected values.
- Problem reports: our legitimate interest in fixing the problem you asked us to look at.
- Product news: your consent, which you can withdraw at any time.
Canada is recognized by the European Commission as providing adequate protection for personal data transferred from the EU.
7. How long we keep it
- Detection events: 24 months, then deleted automatically.
- Installations that never provided an email: deleted automatically after 24 months without contacting us.
- Your email address and installation record: kept while you use NorthSyte, and deleted within 30 days of your request. Uninstalling the extension stops collection but does not by itself tell us to delete your data — email us for that.
- Proof of consent: if you consented to product news and later unsubscribe or ask us to delete your data, we may keep a minimal record that consent was given and withdrawn (dates and policy version) for as long as needed to show we followed anti-spam law.
- Problem reports, including any reply address you gave: 12 months in our database, then deleted automatically. A copy is emailed to our team; ask us and we'll delete both sooner.
- Security logs: 30 days.
8. Your rights and choices
Email privacy@northsyte.com to:
- see the data linked to your installation, including a portable copy
- correct your email address
- delete your data, including your detection events
- withdraw consent to product news (or use the unsubscribe link in any such email)
- object to or ask us to restrict how we use your data
We'll respond within 30 days, and may ask you to confirm you control the email address on the installation.
You can stop all collection at any time by removing the extension. You can also switch off warnings in the extension, but as described in 3.3, detection records are still sent while it is installed.
If you're unhappy with our response, you can complain to the Office of the Privacy Commissioner of Canada, or, in the EU or UK, to your data protection authority.
9. Security
Data is encrypted in transit and at rest. Access tokens are stored only as one-way hashes, and our database is not reachable from the internet. The strongest protection is the design itself: prompts are never sent to us, so there is no store of prompts to breach. No system is perfectly secure; if a breach creates a real risk of significant harm to you, we will notify you and the relevant regulator as the law requires.
10. If your employer provides NorthSyte
The business edition of NorthSyte is deployed by organizations for their employees. In that case your employer decides how it is used, and we process the data on their behalf under our agreement with them — questions should go to your employer first. The same core rule applies: prompt text never leaves your device.
11. Children
NorthSyte is not intended for anyone under 16, and we don't knowingly collect their data. If you believe a child has given us their information, email us and we'll delete it.
12. Changes to this policy
We'll post changes here and update the version and date above. If we make a material change — especially to how we use your email address — we'll tell you by email or in the extension before it takes effect and, where the law requires, ask for your consent again.
13. Contact
NorthSyte · Ottawa, Ontario, Canada
privacy@northsyte.com
