← Back to Home
Privacy Policy for ChatDataMask
Last Updated: August 2026
This Privacy Policy explains how Andrii Kozak, a Poland-based individual owner and tax resident ("ChatDataMask", "we", "us", the "Data Controller"), handles data in connection with the ChatDataMask Chrome extension and the chatdatamask.com website (together, the "Service"). We designed the Service around data minimization required by the EU General Data Protection Regulation (GDPR) and the EU AI Act. The Service is used by people located in the EU, the United States, and other countries; where a right or obligation described below applies specifically to one region, we say so.
This policy has two distinct parts: (1) the core text-masking feature, which processes 100% locally and involves no data transmission of any kind, and (2) the optional Pro purchase, which necessarily involves limited data sharing with payment and email delivery providers so that we can process your purchase. We describe both accurately below, rather than making a blanket "we never transmit anything" claim that would not hold for paying customers.
1. THE CORE SERVICE: LOCAL-ONLY TEXT MASKING
The text-masking functionality of ChatDataMask operates under a strict local-processing model:
- Local Processing Only: All data masking, text anonymization, tagging, and text restoration happen locally on your device inside the Chrome Extension Side Panel.
- No Server Storage of Your Text: We do not own, operate, or maintain any external database or server that stores the text you mask, your prompts, or your AI conversation history.
- No Transmission of Masked Content: The Personally Identifiable Information (PII), confidential documents, financial data, and credentials you process through the masking feature never leave your browser.
All such data is cleared from session memory when you clear the screen, start a new session, or close the browser tab, as described in the extension's interface.
2. TYPES OF DATA PROCESSED LOCALLY (MASKING FEATURE)
To provide local masking, the extension temporarily handles the following data types strictly in your browser's local memory (RAM) during your active session — none of it is transmitted anywhere by this feature:
- Personal Identifiers: Names, locations, national ID numbers (e.g., PESEL, NIP, passport numbers, depending on the country settings you enable).
- Contact Information: Email addresses, usernames, and telephone numbers (validated locally via 'libphonenumber-js').
- Financial Data: Credit card numbers, IBAN, and SWIFT/BIC bank codes.
- Technical Identifiers: IP addresses, MAC addresses, and URLs found within the text you mask.
- AI Prompt Text: Any text you prepare for generative AI platforms (such as ChatGPT, Claude, Google Gemini, or Microsoft Copilot) that you choose to run through the masking feature.
3. DATA PROCESSED FOR THE PRO PLAN (PURCHASE & LICENSE ACTIVATION)
If you purchase the Pro Plan, we necessarily process a limited amount of data — separate from your masked text, which we never see — to deliver your purchase. This data is handled by the following processors on our behalf:
- Creem (payment processing): At checkout, Creem collects your first name, last name, email address, payment details, and — if you purchase as a business — a VAT number. We do not receive or store your card details ourselves; Creem processes payment directly. Creem may also use your email address to send you payment-related notices (such as receipts or renewal reminders). See Creem's own privacy policy for details: https://www.creem.io/privacy.
- Resend (license email delivery): When Creem confirms your payment, it sends a one-time webhook to our server. Our server then either activates your Pro license automatically within the extension (if your browser permissions allow this at the moment of purchase), or, if not, uses Resend to send a single email containing your Pro license key to the email address you provided at checkout, which you then paste into the extension yourself. Resend processes only that email address and the license email content, and only for this one-time purpose. See Resend's privacy policy: https://resend.com/legal/privacy-policy.
- Cloudflare Workers (license issuance): Your Pro license is issued as a signed token by a Cloudflare Worker we operate, triggered once by the Creem payment webhook described above. After that single moment of issuance, your Pro status is tracked locally inside the extension via a 31-day countdown — the extension does not make any further network calls to verify or renew your license until that period ends and you choose to purchase again.
We do not sell, rent, or lease your data to any third party for their own marketing purposes. The processors above act strictly on our instructions to deliver the Service you purchased.
4. LEGAL BASIS FOR PROCESSING
- Purchase & license data (Section 4) is processed on the basis of contract performance (Art. 6(1)(b) GDPR) — we need it to deliver the Pro Plan you purchased.
- Locally-processed masking data (Sections 1–2) never reaches us, so GDPR's controller obligations for that data are minimal by design — it is processed on your own device, under your own control.
5. DATA RETENTION
- Masked text and AI prompt content: cleared from memory on tab close or session reset, as described in Section 1 — we never receive a copy.
- Purchase and billing records: retained by us and by Creem for as long as required by applicable tax and accounting law (typically several years), after which they are deleted or anonymized.
- License validation data: retained only as long as needed to keep your license active, plus a reasonable period for support and fraud-prevention purposes.
6. THIRD-PARTY SERVICES AND AI TRAINING
- No Data Brokerage: We do not sell, rent, or share your data with third parties for their own advertising or marketing purposes.
- No AI Training Use: Because your original PII is replaced with placeholder tags before you send your prompts to AI providers (such as OpenAI or Anthropic), those providers never receive your real sensitive data through this substitution — so it cannot be exposed through their model training pipelines via this channel. This does not affect whatever the AI provider does with the masked/placeholder text itself under their own terms.
7. INTERNATIONAL DATA TRANSFERS
Our processors (Creem, Resend, and Cloudflare) may store or process data in countries other than your own, including the United States. Where this involves a transfer of EEA/UK residents' data outside the EEA/UK, such transfers are made subject to appropriate safeguards required by GDPR, such as Standard Contractual Clauses or an equivalent adequacy mechanism implemented by each processor. For more details on the specific transfer mechanisms and compliance measures used by our partners, you can review the Creem Data Processing Agreement and the Resend GDPR Compliance Statement.
8. YOUR RIGHTS UNDER GDPR AND OTHER LAWS
If you are located in the EEA/UK, you have the right to: access the personal data we hold about you; request correction or erasure of that data; restrict or object to certain processing; request data portability; and withdraw consent where processing is based on consent. Because masked text never reaches us, most of these rights apply to your purchase/billing data held via Creem and Resend. To exercise any of these rights, contact us at support@chatdatamask.com. You also have the right to lodge a complaint with your local supervisory authority — in Poland, this is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych – UODO).
If you are a California resident, you may have similar rights under the California Consumer Privacy Act (CCPA), including the right to know what personal data we hold and to request its deletion. If you are located elsewhere outside the EEA/UK, contact us at the same address and we will do our best to honor equivalent requests regardless of where local law makes them mandatory.
9. COMPLIANCE INDICATION (GDPR, RGPD, AVG, CCPA)
The Service is designed to help you exercise data-minimization practices consistent with:
- EU GDPR / Regulation (EU) 2016/679
- Ley Orgánica de Protección de Datos y Garantía de Derechos Digitales (LOPDGDD — Spain)
- Loi Informatique et Libertés (France)
- Algemene Verordening Gegevensbescherming (AVG — Netherlands)
- The EU AI Act
- The California Consumer Privacy Act (CCPA — United States)
Using the Service supports, but does not by itself guarantee, compliance with these frameworks — see Section 5 of our Terms of Use.
10. CHILDREN'S PRIVACY
The Service is not directed at children under 16. We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data, contact us so we can delete it.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above. We encourage you to review this page periodically.
12. CONTACT INFORMATION
For any questions regarding this Privacy Policy or the Service's data practices, contact us at support@chatdatamask.com, or via the contact information provided in the Chrome Web Store Developer Dashboard.