Privacy Policy

Last updated: 2 August 2026

Contents

1. Who we are

This policy is issued by Obex Labs (“we”, “us”, “our”). We are the controller of personal data processed in connection with personal (non-employer-managed) use of Prompty for Web and related free-tier APEX services described below.

Privacy requests: [email protected]. Security vulnerability reports: [email protected]. General enquiries: [email protected].

We have not appointed a Data Protection Officer. If that changes, we will update this policy.

2. Scope of this policy

This policy covers:

Where an organisation deploys Prompty, PDC, or PEC for employees or contractors, that organisation is typically the controller of workplace audit and fleet data. Obex Labs acts as a software vendor and, where we process personal data on the organisation’s instructions, as a processor under a Data Processing Agreement (DPA). See Annex B.

3. What we collect (Prompty for Web)

4. What we do not collect

5. Where processing happens

Where Prompty runs in the browser

Prompty operates on the AI assistant websites it supports and, if you explicitly grant permission, on other sites you choose. On those pages it reads only the text you type into the prompt box and any files you attach, solely to scan them for sensitive data. It does not read, collect, or transmit other page content, and it takes no action on pages where you are not composing a prompt.

Personal installation (default — Free tier)

All prompt scanning and rule application happens locally on your device. Nothing you type is sent to Obex Labs’ servers. The only information that leaves your device toward Obex Labs is the policy-refresh data in Section 3, optional telemetry if you opted in, and any feedback you submit.

Files you attach to a prompt (documents, images, PDFs) are inspected on your device — including on-device OCR for text in images. File contents are never uploaded to Obex Labs.

Pro installation (with PDC)

When the Prompty Desktop Controller (PDC) is installed and healthy, Prompty may delegate detection to PDC on your device (typically via a local endpoint such as 127.0.0.1). Prompt content is processed on that device for detection; it is not sent to Obex Labs. See Annex A.

Employer-managed / Enterprise installation (with PEC and optionally PDC)

Your organisation may deploy Prompty through IT policy. In that configuration:

Obex Labs does not receive prompt content in any deployment mode. Your employer’s privacy terms apply to workplace processing. Deploying organisations should provide employees with an Article 13 notice before activation.

6. Legal bases (EU/UK GDPR)

For personal (non-employer) use of Prompty for Web and APEX:

Purpose Data Legal basis
Deliver jurisdiction policy and detectors; keep the extension working Country setting, extension ID, version Article 6(1)(f) legitimate interests — providing and securing the free service; or Article 6(1)(b) where use is contractual
Security, abuse prevention, operational diagnosis Server access logs (IP, ID, version, timestamp) Article 6(1)(f) legitimate interests — protecting our services and users
Optional product improvement telemetry Aggregate detector-category counts, version Article 6(1)(a) consent — withdraw anytime in settings
Optional feedback / bug reports Content you submit; diagnostic metadata Article 6(1)(a) consent and/or Article 6(1)(f) legitimate interests — support and product quality

You may object to legitimate-interests processing where applicable (see Section 9). Core policy refresh is required for Prompty to function; if you do not want that processing, uninstall the extension.

For employer-managed deployments, your organisation determines the legal basis for workplace processing (often legitimate interests or legal obligation). Obex Labs’ processor activities are governed by the DPA with that organisation.

7. Retention

8. Sharing, processors, and transfers

We do not sell your personal data. We do not share personal data with third parties for their own marketing.

We use service providers (processors) who process data on our instructions to operate APEX and related systems. Categories include:

A current list of subprocessors is available on request at [email protected]. We require processors to protect data appropriately and to use it only for the contracted purpose.

Primary hosting for APEX telemetry and related free-tier services is in the United Kingdom and/or European Economic Area. If we transfer personal data outside the UK/EEA, we will use a lawful transfer mechanism (for example, an adequacy decision, the UK International Data Transfer Agreement, or EU Standard Contractual Clauses) and update this section.

Employer-managed deployments. Audit events and usage telemetry may be routed to your employer’s PEC or other infrastructure. Obex Labs does not control that data as an independent controller. Your employer’s policies apply.

9. Your rights

If UK or EU/EEA data protection law applies, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw consent at any time (without affecting prior lawful processing).

To exercise these rights, email [email protected]. We will respond within one month (extendable by up to two further months for complex requests, with notice).

You also have the right to lodge a complaint with a supervisory authority. For the UK, that is the Information Commissioner’s Office (ICO). In the EEA, you may contact your local data protection authority. We encourage you to contact us first so we can try to resolve your concern.

For workplace deployments, contact your employer’s privacy or DPO channel for data held in the organisation’s systems; Obex Labs can assist where we act as processor.

10. United States (CCPA/CPRA)

If you are a California resident, we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA, and we do not use personal information for cross-context behavioural advertising. You may request to know, delete, or correct personal information we hold about you by emailing [email protected]. We will not discriminate against you for exercising these rights. Categories of information we may collect are described in Section 3 (identifiers such as IP address and pseudonymous installation ID; internet / electronic activity limited to policy-service requests and optional aggregate telemetry).

11. Children

Prompty for Web is not directed at children under 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] and we will delete it.

12. Browser permissions and local storage

Prompty requests browser permissions only as needed to:

Permission justifications in the Chrome Web Store / Firefox Add-ons listing match this description. Uninstalling the extension removes local extension storage managed by the browser.

13. This website

When you browse pages on this website (for example the home page, Help & FAQ, Privacy Policy, or Terms), your browser makes ordinary web requests to our hosting infrastructure. Those requests typically create server access logs (IP address, timestamp, requested URL, user agent) used for security and operations, retained on a short cycle consistent with Section 7 where applicable.

Typography and icons used on this website are self-hosted on our origin. We do not load fonts or icon libraries from Google Fonts, Cloudflare cdnjs, or other third-party CDNs. We do not run advertising or analytics cookies on this website.

If you email us, we process the content of your message and your email address to respond.

14. Security

Data in transit to Obex Labs services is encrypted with TLS 1.2 or higher. We implement technical and organisational measures designed to protect data against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is perfectly secure; please use the product accordingly.

15. Changes

We may update this policy periodically. We will post the revised version here with an updated “Last updated” date. Material changes will also be noted in extension update notes or an in-extension notice where practicable. For optional processing that relies on consent, we will seek renewed consent before applying material changes to that processing. Continued use after notice means you acknowledge the updated policy for processing that does not require fresh consent.

16. Contact

Privacy: [email protected]
Security: [email protected]
General: [email protected]

Annex A — PDC (Pro / SME)

This annex applies when the Prompty Desktop Controller (PDC) is installed under a Pro or Enterprise licence. PDC is software that runs on the end-user device.

A.1 Role

PDC is a local desktop control plane. It may: cache policy; run the detection pipeline when Prompty delegates to it (“zombie mode”); run on-device classification aids (for example an ONNX model) without sending prompt text to Obex Labs; aggregate metadata-only detection telemetry; and help produce local diagnostic bundles.

A.2 Prompt content

When Prompty delegates detection to PDC, prompt text (and attachment-derived text) is processed on the local device, typically over a loopback/local network interface to PDC. That content is used for detection and then discarded according to PDC’s design; it is not uploaded to Obex Labs.

A.3 Data that may leave the device

A.4 Optional folder pre-scan (if enabled)

If an administrator or user enables scoped folder pre-scan, PDC may inspect explicitly named folders on the device and cache per-file verdicts locally. By default, only metadata rollups (not filenames or full paths) are eligible to leave the device. More detailed path reporting, if offered, requires explicit employer configuration and appropriate notice/consent under applicable law.

A.5 Controllership

For personal Pro use where you licence PDC yourself, Obex Labs is controller for the limited licence and telemetry data sent to APEX, on the bases in Section 6. For employer-deployed PDC, your organisation is controller of workplace telemetry and audit; see Annex B.

Annex B — PEC (Enterprise)

This annex applies when an organisation deploys the Policy Enforcement Controller (PEC) under an Enterprise licence.

B.1 Roles

B.2 What PEC processes

PEC is designed to collect metadata-only audit and metrics events (for example device/install identifiers, AI-tool hostname, policy version, matched category, decision, timestamps). Per product requirements, PEC must not receive prompt text or extracted sensitive values.

B.3 Network enforcement (ICAP)

If the organisation enables PEC’s ICAP / network policy engine, additional request inspection may occur on infrastructure the organisation operates or controls. That processing is determined by the organisation’s configuration and must be covered in the organisation’s employee privacy notice and, where required, works-council or labour consultations.

B.4 Employee notice

Before activating Prompty/PEC/PDC for staff, the organisation should provide an Article 13 / UK GDPR notice. Obex Labs supplies a template for that purpose; the organisation must complete and issue it.

B.5 Obex Labs’ free-tier claims still hold

Even in Enterprise deployments, Obex Labs does not receive prompt content. Data that remains entirely within the customer’s PEC/PDC estate is governed by the customer’s policies, not by Obex Labs as controller.