Last updated: 26 May 2026
Privacy-first commitment: AI Shield does NOT read, store, or transmit the content of your AI conversations. We log only detection events (e.g., "credit card detected at 14:30") for compliance reporting. Full details below.
AI Shield (operated by Koller Group, "we", "our", or "us") provides a Chrome extension and web platform that helps companies prevent accidental data leaks when employees use AI chat tools.
This Privacy Policy explains how we collect, process, store, and share information when you use:
We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and applicable data protection laws.
We collect the following categories of information:
When you sign up for AI Shield, we collect:
For paid plans:
When the AI Shield Chrome extension detects sensitive data patterns in your AI tool inputs, we log:
What we DO NOT collect: The content of your AI conversations, the specific text of detected items, your full browsing history, or any data outside the AI platforms listed in our extension manifest.
Automatically collected when you use our services:
If you contact us:
We use your information for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain the AI Shield service | Contract performance (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Contract performance (Art. 6(1)(b)) |
| Send compliance reports and product updates | Contract performance (Art. 6(1)(b)) |
| Detect and prevent fraud or abuse | Legitimate interest (Art. 6(1)(f)) |
| Improve our services and develop new features | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications | Consent (Art. 6(1)(a)) — opt-in only |
Our data processing follows these principles:
The AI Shield Chrome extension performs all sensitive data detection locally in your browser. This means:
Our backend processes:
AI Shield uses automated pattern matching to detect sensitive data, but does NOT make automated decisions that produce legal effects or similarly significant effects on you (GDPR Article 22). The detection alerts allow YOU to decide whether to remove data, proceed, or ignore the warning.
All data is stored on servers located in the European Union (specifically Railway infrastructure in the EU region) and in the United States (Stripe payment processing). We have implemented Standard Contractual Clauses (SCCs) for any data transfers outside the EU.
| Data Type | Retention Period |
|---|---|
| Account information | Active account + 30 days after deletion |
| Detection events | 2 years (for GDPR audit compliance) |
| Payment records | 7 years (legal/tax requirements) |
| Email logs | 1 year |
| Server logs | 90 days |
| Marketing data | Until consent withdrawn |
You can request deletion of your account and associated data at any time by emailing privacy@getaishield.co. We will process deletion requests within 30 days.
We do NOT sell your personal data. We share data only with the following categories of third parties, all under data processing agreements (DPAs) compliant with GDPR Article 28:
| Provider | Purpose | Location |
|---|---|---|
| Railway | Backend hosting and database | EU / US |
| Stripe | Payment processing | US (SCC + DPA in place) |
| Resend | Transactional email delivery | EU |
| Cloudflare | CDN, DNS, security | Global |
| Google Workspace | Business email and support | EU / US (SCC in place) |
We may disclose your data if required by law, court order, or government authority. We will notify you of such requests when legally permitted.
If AI Shield is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you and provide options regarding your data.
We implement appropriate technical and organizational measures to protect your data, including:
Data breach notification: In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:
To exercise any of these rights, email us at privacy@getaishield.co. We will respond within 30 days (extendable to 60 days for complex requests).
You can lodge complaints with your national data protection authority. For UK users: ICO (Information Commissioner's Office). For EU users: find your national authority.
The AI Shield Chrome extension requires the following permissions and has the following data practices:
| Permission | Purpose |
|---|---|
storage |
Store your authentication token and company code locally in the browser |
| Host permissions (AI platforms) | Inject content scripts to detect sensitive data patterns on supported AI chat platforms |
The extension activates ONLY on the following platforms:
The extension stores the following locally in your browser (Chrome's chrome.storage.local):
This data is NOT shared with any server unless required for authentication.
AI Shield is a business-to-business product intended for use by adults (18 years or older) in professional settings. We do NOT knowingly collect data from children under 16 years of age. If you believe we have collected such data, please contact us immediately at privacy@getaishield.co and we will delete it.
We may update this Privacy Policy from time to time. When we do:
You can review the version history of this policy by contacting us.
For any privacy-related questions, requests, or concerns:
Company: AI Shield is a product of Koller Group. Company registration details will be updated once formal incorporation is complete.