Privacy Policy
Last updated: 2 August 2026
Contents
- 1. Who we are
- 2. Scope of this policy
- 3. What we collect (Prompty for Web)
- 4. What we do not collect
- 5. Where processing happens
- 6. Legal bases (EU/UK GDPR)
- 7. Retention
- 8. Sharing, processors, and transfers
- 9. Your rights
- 10. United States (CCPA/CPRA)
- 11. Children
- 12. Browser permissions and local storage
- 13. This website
- 14. Security
- 15. Changes
- 16. Contact
- Annex A — PDC (Pro)
- Annex B — PEC (Enterprise)
1. Who we are
This policy is issued by Obex Labs (“we”, “us”, “our”). We are the controller of personal data processed in connection with personal (non-employer-managed) use of Prompty for Web and related free-tier APEX services described below.
Privacy requests: [email protected]. Security vulnerability reports: [email protected]. General enquiries: [email protected].
We have not appointed a Data Protection Officer. If that changes, we will update this policy.
2. Scope of this policy
This policy covers:
- Prompty for Web — the browser extension for personal and employer-managed use;
- APEX — Obex Labs’ policy, detector, model, and licence distribution service used by Prompty;
- PDC (Prompty Desktop Controller) — described in Annex A, for Pro / SME deployments;
- PEC (Policy Enforcement Controller) — described in Annex B, for Enterprise deployments.
Where an organisation deploys Prompty, PDC, or PEC for employees or contractors, that organisation is typically the controller of workplace audit and fleet data. Obex Labs acts as a software vendor and, where we process personal data on the organisation’s instructions, as a processor under a Data Processing Agreement (DPA). See Annex B.
3. What we collect (Prompty for Web)
- Country setting. On first install you select your country. The choice is stored locally and sent to APEX when Prompty refreshes detection rules so the correct jurisdiction policy can be served.
- Pseudonymous extension identifier and version. Policy-refresh requests include a stable pseudonymous extension identifier and the installed extension version. These values help us serve the correct policy and diagnose distribution issues. Together with standard server logs (which include IP address), they constitute pseudonymous personal data under EU/UK GDPR — they do not include your name or email, but they can relate to a device or installation.
- Server access logs. APEX records IP address, timestamp, requested path, extension identifier, and version for security, abuse prevention, and operational diagnosis. Retention: maximum 30 days.
- Optional usage telemetry (opt-in). On first install, Prompty asks whether you allow anonymous usage statistics. If you agree, we receive aggregate counts of how often each detector category was triggered (for example, that a “financial” or “health” category matched), plus extension version. These are counters only — never prompt text, never matched values, never browsing history. You can withdraw consent in extension settings at any time.
- Optional feedback and bug reports. If you submit feedback, we process what you write and any diagnostic bundle you include. Diagnostics are designed to be non-identifying (no prompt text or extracted values). Retention: deleted within 90 days of receipt.
4. What we do not collect
- The content of prompts you type or paste into an AI assistant. Obex Labs never receives prompt text in any deployment mode.
- Extracted sensitive values (for example, a specific account number or national ID that a detector matched).
- Your browsing history, or the full URLs of pages you visit (beyond the AI-assistant sites where the extension is active for scanning).
- Biometric identifiers, payment-card numbers, health records, or other special-category content. Optional telemetry may include aggregate category counters (for example, that a health-category detector fired) without any underlying content or values.
- We do not intentionally collect your civil identity (name, email, postal address) for personal installs, except if you choose to include it in feedback.
5. Where processing happens
Where Prompty runs in the browser
Prompty operates on the AI assistant websites it supports and, if you explicitly grant permission, on other sites you choose. On those pages it reads only the text you type into the prompt box and any files you attach, solely to scan them for sensitive data. It does not read, collect, or transmit other page content, and it takes no action on pages where you are not composing a prompt.
Personal installation (default — Free tier)
All prompt scanning and rule application happens locally on your device. Nothing you type is sent to Obex Labs’ servers. The only information that leaves your device toward Obex Labs is the policy-refresh data in Section 3, optional telemetry if you opted in, and any feedback you submit.
Files you attach to a prompt (documents, images, PDFs) are inspected on your device — including on-device OCR for text in images. File contents are never uploaded to Obex Labs.
Pro installation (with PDC)
When the Prompty Desktop Controller (PDC) is installed and healthy, Prompty may delegate detection to PDC on your device (typically via a local endpoint such as 127.0.0.1). Prompt content is processed on that device for detection; it is not sent to Obex Labs. See Annex A.
Employer-managed / Enterprise installation (with PEC and optionally PDC)
Your organisation may deploy Prompty through IT policy. In that configuration:
- Detection often still runs on the endpoint (in-browser and/or via local PDC).
- Metadata-only audit and usage events may be sent to your organisation’s PEC (or equivalent), not to Obex Labs as an independent controller.
- If your organisation enables network-layer enforcement (for example PEC ICAP), additional inspection may occur on infrastructure your organisation operates or controls, subject to your employer’s privacy notice and employment-law obligations.
Obex Labs does not receive prompt content in any deployment mode. Your employer’s privacy terms apply to workplace processing. Deploying organisations should provide employees with an Article 13 notice before activation.
6. Legal bases (EU/UK GDPR)
For personal (non-employer) use of Prompty for Web and APEX:
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver jurisdiction policy and detectors; keep the extension working | Country setting, extension ID, version | Article 6(1)(f) legitimate interests — providing and securing the free service; or Article 6(1)(b) where use is contractual |
| Security, abuse prevention, operational diagnosis | Server access logs (IP, ID, version, timestamp) | Article 6(1)(f) legitimate interests — protecting our services and users |
| Optional product improvement telemetry | Aggregate detector-category counts, version | Article 6(1)(a) consent — withdraw anytime in settings |
| Optional feedback / bug reports | Content you submit; diagnostic metadata | Article 6(1)(a) consent and/or Article 6(1)(f) legitimate interests — support and product quality |
You may object to legitimate-interests processing where applicable (see Section 9). Core policy refresh is required for Prompty to function; if you do not want that processing, uninstall the extension.
For employer-managed deployments, your organisation determines the legal basis for workplace processing (often legitimate interests or legal obligation). Obex Labs’ processor activities are governed by the DPA with that organisation.
7. Retention
- Server access logs: maximum 30 days, then deleted.
- Optional telemetry: maximum 12 months, then deleted.
- Feedback diagnostics: deleted within 90 days of receipt.
- Country setting and extension identifier on your device: until you clear extension data or uninstall.
8. Sharing, processors, and transfers
We do not sell your personal data. We do not share personal data with third parties for their own marketing.
We use service providers (processors) who process data on our instructions to operate APEX and related systems. Categories include:
- Cloud infrastructure / hosting (UK and/or EEA);
- Email and transactional messaging for support;
- Security and operational monitoring tools, where configured.
A current list of subprocessors is available on request at [email protected]. We require processors to protect data appropriately and to use it only for the contracted purpose.
Primary hosting for APEX telemetry and related free-tier services is in the United Kingdom and/or European Economic Area. If we transfer personal data outside the UK/EEA, we will use a lawful transfer mechanism (for example, an adequacy decision, the UK International Data Transfer Agreement, or EU Standard Contractual Clauses) and update this section.
Employer-managed deployments. Audit events and usage telemetry may be routed to your employer’s PEC or other infrastructure. Obex Labs does not control that data as an independent controller. Your employer’s policies apply.
9. Your rights
If UK or EU/EEA data protection law applies, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw consent at any time (without affecting prior lawful processing).
To exercise these rights, email [email protected]. We will respond within one month (extendable by up to two further months for complex requests, with notice).
You also have the right to lodge a complaint with a supervisory authority. For the UK, that is the Information Commissioner’s Office (ICO). In the EEA, you may contact your local data protection authority. We encourage you to contact us first so we can try to resolve your concern.
For workplace deployments, contact your employer’s privacy or DPO channel for data held in the organisation’s systems; Obex Labs can assist where we act as processor.
10. United States (CCPA/CPRA)
If you are a California resident, we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA, and we do not use personal information for cross-context behavioural advertising. You may request to know, delete, or correct personal information we hold about you by emailing [email protected]. We will not discriminate against you for exercising these rights. Categories of information we may collect are described in Section 3 (identifiers such as IP address and pseudonymous installation ID; internet / electronic activity limited to policy-service requests and optional aggregate telemetry).
11. Children
Prompty for Web is not directed at children under 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] and we will delete it.
12. Browser permissions and local storage
Prompty requests browser permissions only as needed to:
- Run on supported AI assistant sites (and any additional sites you explicitly allow) to read prompt-box text and attachments for local scanning;
- Store settings locally (country, consent flags, cached policy, extension identifier);
- Contact APEX (and, when configured, your organisation’s PEC or local PDC) for policy, licence, and optional telemetry.
Permission justifications in the Chrome Web Store / Firefox Add-ons listing match this description. Uninstalling the extension removes local extension storage managed by the browser.
13. This website
When you browse pages on this website (for example the home page, Help & FAQ, Privacy Policy, or Terms), your browser makes ordinary web requests to our hosting infrastructure. Those requests typically create server access logs (IP address, timestamp, requested URL, user agent) used for security and operations, retained on a short cycle consistent with Section 7 where applicable.
Typography and icons used on this website are self-hosted on our origin. We do not load fonts or icon libraries from Google Fonts, Cloudflare cdnjs, or other third-party CDNs. We do not run advertising or analytics cookies on this website.
If you email us, we process the content of your message and your email address to respond.
14. Security
Data in transit to Obex Labs services is encrypted with TLS 1.2 or higher. We implement technical and organisational measures designed to protect data against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is perfectly secure; please use the product accordingly.
15. Changes
We may update this policy periodically. We will post the revised version here with an updated “Last updated” date. Material changes will also be noted in extension update notes or an in-extension notice where practicable. For optional processing that relies on consent, we will seek renewed consent before applying material changes to that processing. Continued use after notice means you acknowledge the updated policy for processing that does not require fresh consent.
16. Contact
Privacy: [email protected]
Security: [email protected]
General: [email protected]
Annex A — PDC (Pro / SME)
This annex applies when the Prompty Desktop Controller (PDC) is installed under a Pro or Enterprise licence. PDC is software that runs on the end-user device.
A.1 Role
PDC is a local desktop control plane. It may: cache policy; run the detection pipeline when Prompty delegates to it (“zombie mode”); run on-device classification aids (for example an ONNX model) without sending prompt text to Obex Labs; aggregate metadata-only detection telemetry; and help produce local diagnostic bundles.
A.2 Prompt content
When Prompty delegates detection to PDC, prompt text (and attachment-derived text) is processed on the local device, typically over a loopback/local network interface to PDC. That content is used for detection and then discarded according to PDC’s design; it is not uploaded to Obex Labs.
A.3 Data that may leave the device
- Licence and registration metadata (for example entity identifier and ping token) to APEX or, in Enterprise deployments, via PEC;
- Metadata-only telemetry and health events (detector categories, counts, decisions, versions — not prompt text or extracted values);
- Optional product feedback you choose to send.
A.4 Optional folder pre-scan (if enabled)
If an administrator or user enables scoped folder pre-scan, PDC may inspect explicitly named folders on the device and cache per-file verdicts locally. By default, only metadata rollups (not filenames or full paths) are eligible to leave the device. More detailed path reporting, if offered, requires explicit employer configuration and appropriate notice/consent under applicable law.
A.5 Controllership
For personal Pro use where you licence PDC yourself, Obex Labs is controller for the limited licence and telemetry data sent to APEX, on the bases in Section 6. For employer-deployed PDC, your organisation is controller of workplace telemetry and audit; see Annex B.
Annex B — PEC (Enterprise)
This annex applies when an organisation deploys the Policy Enforcement Controller (PEC) under an Enterprise licence.
B.1 Roles
- Deploying organisation — controller of employee/endpoint audit, fleet, and policy-event personal data.
- Obex Labs — provider of the software; processor only to the extent Obex Labs systems process personal data on the organisation’s documented instructions (for example limited aggregate metrics or support). A written DPA (GDPR Article 28) must be in place before such processing.
B.2 What PEC processes
PEC is designed to collect metadata-only audit and metrics events (for example device/install identifiers, AI-tool hostname, policy version, matched category, decision, timestamps). Per product requirements, PEC must not receive prompt text or extracted sensitive values.
B.3 Network enforcement (ICAP)
If the organisation enables PEC’s ICAP / network policy engine, additional request inspection may occur on infrastructure the organisation operates or controls. That processing is determined by the organisation’s configuration and must be covered in the organisation’s employee privacy notice and, where required, works-council or labour consultations.
B.4 Employee notice
Before activating Prompty/PEC/PDC for staff, the organisation should provide an Article 13 / UK GDPR notice. Obex Labs supplies a template for that purpose; the organisation must complete and issue it.
B.5 Obex Labs’ free-tier claims still hold
Even in Enterprise deployments, Obex Labs does not receive prompt content. Data that remains entirely within the customer’s PEC/PDC estate is governed by the customer’s policies, not by Obex Labs as controller.
prompty