Scope And Contact
Updated 7 October 2026 for AI Prompt Leak Guard 0.1.0. The product brand is candidloom, operated by SUNIL KUMAR GURJALA. Contact loomcandid@gmail.com for privacy questions or a request concerning information you supplied to support or billing.
Local Prompt Protection
The extension reads the prompt editor on supported AI pages to detect sensitive text and offer warnings, redaction or blocking. This processing happens on your device. The extension does not send prompt text, detected values, file contents, page URLs or browsing history to candidloom or an analytics service. Submitting a prompt to your chosen AI provider is still governed by that provider's policy.
Prompts and matches are handled temporarily while the page is open. They are not saved as a prompt history by the extension. Local upload inspection is an evaluation feature in the separate sandbox build; the standard candidate provides free local prompt protection. No detector can guarantee that every sensitive value will be found.
Information Stored In Your Browser
- Protection rules, site switches, appearance choices, allowed site patterns and configuration timestamps.
- SHA-256 hashes of values you choose to trust. The entered value is not persisted as the allowlist entry. A hash of a predictable value can still be guessed; treat exported settings as private.
- The latest scan's finding count, severity counts and timestamp. A later scan replaces this summary; it contains no prompt text or matched values.
- For an activated evaluation build, license state, feature flags, validity timestamps and a masked activation hint. The full pasted entitlement is verified locally and is not stored by this activation flow.
- If your browser is managed, policy supplied by your administrator can also apply.
These records use local extension storage, not cloud synchronization. Settings and the latest summary do not have an automatic age-based deletion period. You can remove individual trusted values and activation information in Settings. Removing the extension removes its local storage. Exported configuration files and administrator-managed policies must be removed separately by you or your administrator.
Website Access
The current package declares content scripts for 31 specific HTTPS hosts serving 18 AI services. The browser can grant access to those listed pages when the extension is installed. Site switches control whether protection is active; switching one off does not revoke the browser's host permission. Use the browser's extension site-access controls to restrict access. There is no permission to read every website or the browser history database.
Separate Checkout And Activation Service
Public paid sales are not open. The hosted integration currently uses Razorpay Test Mode and a separately labelled sandbox extension. Ordinary local protection does not require a billing account. The following account and purchase flow is being prepared for paid launch and is not a claim that live checkout is available.
The planned customer page uses an emailed one-time sign-in code to verify your buyer email through Supabase Auth. Cloudflare Turnstile checks for automated abuse. These providers process the email or request/browser information needed for their respective services. Our billing service stores the verified email, account identifier, an internal customer reference and verification time. The page keeps its sign-in token in memory rather than browser storage; refreshing or signing out of that page requires signing in again. This sign-in code is separate from an activation code.
For a purchase, the server supplies the one-person monthly plan and records the accepted terms version and time. Razorpay processes checkout and payment-method information. Our service checks provider account, plan, subscription, payment, invoice and event information to verify payment. It records the account/plan/subscription/payment and event or request references needed for the purchase and activation history, plus status and the paid period; it does not store card numbers or CVVs. Payment-provider contact fields do not automatically change the verified email used for activation.
Activation redemption sends the activation ID and code to the billing service. In the planned account flow, a new-code request uses your signed-in account and its subscription reference; you do not need a previous activation ID. The existing invitation-based sandbox instead asks for the earlier activation ID and registered buyer email.
Supabase hosts authentication, the billing function and database; Google Cloud KMS signs entitlements and protects activation-code envelopes; Resend sends activation emails; and Cloudflare serves the customer pages and provides the planned sign-in abuse check. The dedicated activation sender is activation@notify.candidloom.com. Support is at loomcandid@gmail.com.
A successful redemption returns a signed entitlement for you to paste into the corresponding extension build. Sandbox entitlements work only in the labelled sandbox build; production activation must be accepted before paid sales open. A new-code request sends a replacement only to the registered buyer and invalidates earlier unused codes. Sign-in codes, activation codes and entitlements grant access: keep them private.
Activation codes expire after at most 24 hours, or at the paid-period boundary if sooner. Code expiry is not record deletion. The sandbox retention job uses a 365-day threshold for committed delivery records and redeemed activation records, and a 30-day threshold for delivered outbox records, subject to remaining database references. Checkout, unused activation and recovery-history records do not yet have an automatic deletion deadline. The planned account flow also records customer verification, terms acceptance, purchase and activation-issuance history; refund or access restrictions retain a decision reference. Automatic deletion deadlines for these additional records and authentication records are not yet established. Contact support to request review/removal; a production retention policy and recovery process must be established before public paid sales.
Website Hosting, Support And Sharing
Documentation is hosted on GitHub Pages and Cloudflare; customer pages use Cloudflare. We have not added analytics trackers or advertising code. Hosting, payment and email providers may process request metadata such as IP address, browser information and delivery events to operate their services. Their own privacy terms apply; this policy does not claim that providers keep no logs.
If you email support, your email address and message are received by our email provider. Send only made-up examples and browser/version information, or an order/subscription reference for a billing request. Do not send real prompts, credentials, payment details, private screenshots, sign-in codes, activation codes or signed entitlements. Support correspondence is retained while needed to address the request; contact us to request deletion.
We do not sell prompt data or use extension content for advertising, profiling, lending or data brokerage. Service providers process the data needed for the services described above. The sandbox database and KMS resources are in Sydney; other providers may process data in additional countries.
Changes
We will update this policy before introducing new collection, sharing or analytics. The Chrome Web Store privacy declarations must reflect the submitted build and this published policy.