Legal
Privacy Policy
Last updated: August 11, 2026 · Effective date: August 11, 2026
This Privacy Policy explains how Feldr (“Feldr,” “we,” “us,” or “our”) — a product of Magynta Technologies Private Limited — collects, uses, and protects information in connection with the Feldr browser extension and the associated Feldr admin dashboard and API (together, the “Service”).
Feldr is a privacy extension. Its entire purpose is to help you avoid sharing sensitive information with third-party AI assistants. We built it to collect as little as possible.
1. Privacy at a glance
- Detection happens on your device. When you type a prompt or attach a file on a supported AI site, Feldr scans that content locally in your browser for personal data (PII), health data (PHI), financial data, and secrets/credentials.
- Your prompt content and files are never uploaded to us for scanning. They do not leave your browser for detection.
- We record only lightweight detection metadata — enough for you and your organization to see that a detection occurred and what type it was, never the sensitive value itself.
- We do not sell your data and we do not use it for advertising.
2. Information we collect
a) Account information
When you sign in with Google, Feldr receives your email address (via the userinfo.email scope). We use it to identify you and to associate your activity with the correct organization/workspace on the dashboard.
b) Detection metadata (“incidents”)
When Feldr detects sensitive data in content you are about to send, it records an incident to the Feldr API. Each incident may include:
- the type(s) detected (e.g. "Email Address," "Credit Card") as category labels;
- a severity/risk level;
- the action taken (e.g. redacted, ignored, sent anyway);
- the AI platform where it occurred (e.g. ChatGPT, Gemini) and your browser;
- a timestamp; and
- a redacted preview — a short snippet of the surrounding text with the sensitive values masked/removed so it can be reviewed safely.
We use this to power your personal counters and, for organizational deployments, the admin dashboard.
c) Local settings (stored on your device only)
Your configuration — which detection categories are enabled, per-site toggles, sensitivity thresholds, and UI preferences — is stored locally using the browser’s storage. This data stays on your device and is not transmitted to us. On managed/enterprise devices, an administrator may pre-configure these settings via enterprise policy.
d) What we do NOT collect
- The raw sensitive values we detect (they are redacted before anything leaves your browser).
- The full content of your prompts, messages, files, images, or documents.
- Your general browsing history or activity on non-supported sites.
- Your location, contacts, or the contents of your mailbox.
3. How detection works
Feldr runs a detection engine — pattern matching plus on-device machine-learning models and optical character recognition (OCR) — entirely within your browser (including a hidden “offscreen” document used to run WebAssembly for image/PDF/document analysis). To perform this local analysis, Feldr downloads its machine-learning model and runtime files from public content-delivery networks (Cloudflare-backed cdn.jsdelivr.net and GitHub). These files are static model weights and inference runtime only; they do not transmit your content and do not control the extension’s behavior remotely.
4. How we use information
We use the information above to:
- run local detection and let you redact sensitive data before you send it;
- show you and your organization's administrators detection activity and trends;
- authenticate you and route your activity to the correct organization;
- send team-invitation emails on your behalf when you explicitly choose to (see Section 5);
- maintain the security, integrity, and reliability of the Service.
We do not use your information for advertising, profiling for ads, or to determine creditworthiness or for lending purposes.
5. Google API Services — Limited Use disclosure
Feldr’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- The gmail.send scope is used only to send an email (such as a team invitation) that you initiate from within Feldr. Feldr cannot read, search, delete, or modify your mailbox, and does not access your existing messages.
- The userinfo.email scope is used only to obtain your email address for sign-in and organization mapping.
We do not transfer this Google user data to third parties except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger/acquisition.
We do not use this data for advertising, and we do not allow humans to read it, except (a) with your affirmative consent, (b) as necessary for security or to comply with law, or (c) where the data is aggregated and anonymized.
6. Service providers and sub-processors
We share information only with vendors that help us operate the Service, under contractual confidentiality and data-protection obligations. These currently include:
- Google LLC — authentication (OAuth) and Gmail send, as described above;
- MongoDB — storage of incident metadata and account records;
- AWS SES — transactional and alert emails;
- Microsoft Azure — hosting of the Feldr API and dashboards.
We do not sell or rent your personal information to third parties.
7. Data retention
We retain account information for as long as your account is active, and detection metadata for 12 months or until the subscription is active (whichever is longer), after which it is deleted or anonymized. Local settings remain on your device until you clear them or uninstall the extension. You may request deletion of your data as described in Section 9.
8. Security
We use industry-standard measures — encryption in transit (HTTPS/TLS), access controls, and tenant isolation — to protect your information. No method of transmission or storage is 100% secure, but minimizing what we collect is our first line of defense: sensitive content is redacted on your device before any metadata is sent.
9. Your rights and choices
Depending on your location, you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, and to withdraw consent.
- Access / deletion: contact us at the address below and we will respond as required by applicable law (e.g. GDPR, UK GDPR, CCPA/CPRA).
- Uninstalling: removing the extension stops all local detection and revokes its access to the current tab. You can also revoke Feldr’s Google access at myaccount.google.com/permissions.
We do not “sell” or “share” personal information as those terms are defined under California law.
If you are in the EEA/UK, our lawful bases for processing are performance of a contract, legitimate interests (securing your data and providing our privacy extension), consent (for Google email sending), and legal obligation.
10. Enterprise / managed deployments
If you use Feldr through your employer or organization, that organization is the controller of your detection metadata and may configure the extension and view incident activity through the admin dashboard. Please refer to your organization’s own privacy notice for details on how it uses that information.
11. International data transfers
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
12. Children
Feldr is not directed to children under 16 (or the age of digital consent in your jurisdiction) and we do not knowingly collect their personal information.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated “Last updated” date and, where appropriate, additional notice. Continued use of the Service after changes take effect constitutes acceptance.
14. Contact us
Magynta Technologies Private Limited
Privacy inquiries: dpo@magynta.com
Postal address: B2 Golden Orchid, Plot No. 136, Sector 11, PCNTDA, Chikhali Pradhikaran, Pune - 411019
If you have unresolved concerns, you may have the right to lodge a complaint with your local data protection authority.