Privacy
SourceSecure exists to stop client details reaching an AI tool. Collecting those details ourselves would make it a poor product, so we do not.
Last updated 26 September 2026
The short version
SourceSecure exists to stop client details reaching an AI tool. It would be a poor product if it collected those details itself, so it does not.
What you type into ChatGPT, Claude, Copilot, Gemini, Perplexity, Grok, DeepSeek, Meta AI, Mistral or Gemini Notebook is read in your own browser, on your own computer, and stays there. The documents you attach are read there too. None of it is sent to us.
What does reach us is a short list of facts about your firm's account, and counts. Numbers, never words. The exceptions are prompt coaching, which comes with Guard Pro and Guard 360 seats, and reply marks, which come with Guard 360 seats. Both are described in full below, and both can be switched off by each person.
What stays on your computer
Every message you type on a supported chat site is checked in the browser. The model that recognises names, addresses and company names runs on your machine, inside the extension. It is a file on your disk, not a service we operate.
Attachments are read the same way. A PDF, Word file, spreadsheet, PowerPoint or scan is opened, read and redacted in the browser. The file never leaves your computer, and neither does the redacted copy.
Your own words, your own documents, and the list of things you have personally chosen to ignore are held in your browser's storage. We cannot read them.
On a Guard 360 seat, your vault is held there too: short facts about your work and your firm, learned from your messages or saved by you, which AI replies are checked against, and facts about your own life too if you switch on Remember personal details. It never reaches us unless you choose to suggest one of its facts to your firm, as described below. You can see, change and delete every fact on its own page, reached from the SourceSecure icon.
What we hold about your account
Your email address, which is how you sign in and how we know which firm you belong to.
Your firm's name, how many seats of each kind it has bought, which kind of seat each person has, and whether the subscription is in good standing.
Whether your firm chose the two weeks of Guard 360 at checkout, and when each person's two weeks end. A one way key for the buyer's address is kept so the trial is only given once.
If somebody asks their admin for a better seat (to keep Guard 360 after their two weeks, or for Guard Pro or Guard 360 from the extension’s setup), their email address, which seat, and when they asked, which their admin sees. They are told so before they ask. It is removed when the admin gives them the seat, says not now, or removes them.
For a firm with Guard 360 seats, how many replies its people have had checked this month, as one number for the whole firm, so the firm's monthly allowance can be kept.
Which browsers you have connected, when each one was connected, and when it last checked in. Each browser holds a secret; we hold only a one way hash of it, never the secret itself.
Identifiers from Stripe for your firm's customer and subscription records. We never see or hold card details.
What the daily counts contain
Once a day each browser sends a small report so your admin's dashboard can show whether the firm is using SourceSecure. It contains a date and a set of counts, and nothing else. The counts are: how many items were caught, and of which kinds; how many times a message was held for review, and how many times it was then sent redacted or sent as typed; how many attached files were checked, flagged, and replaced with a redacted copy; how often Set up this chat, Help me and Sharpen my prompt were opened and used; how many tips were shown; how many prompts were scored and the scores added together, before and after; how many weekly notes were written and read, and plans kept; and, on Guard 360 seats, how many replies were checked, how many marks were shown, opened, asked about and dismissed, and how many replies drew each kind of mark, by its name from a fixed list such as “assumed” or “decided for you”. A file is counted, never described: its name and its contents stay on your computer.
With coaching, on Guard Pro and Guard 360 seats, the report also names the habit the person is working on, from a fixed list, as a count of one.
The report also says, for each supported site, how many times SourceSecure started there and how many times it could not find the message box. This is the one thing in the report that names anything outside your own browser, and what it names is one of the site names already printed on this page, never a web address, a page title or anything you were looking at. It is there because a chat site that redesigns its page stops SourceSecure working without any sign that anything is wrong, and these two numbers are the only way we would ever know.
There is no field in that report through which a sentence could travel. The code that reads it accepts a date and numbers, and discards everything else; a test walks every field and fails if any of them could carry text.
Each browser's counts are stored under your firm, with the browser's id and a one way key for the person it belongs to, never their email address. The key is there only so that somebody with several browsers counts as one person where people are counted. Your admin sees firm totals. The only thing shown per person is which kind of seat they have, whether their extension is connected and when it last checked in. The monthly report says which kinds of mark came up across the firm only once at least three people have Guard 360 seats, so that it never describes one or two people.
The word lists your firm sets
An admin can add words that SourceSecure should always redact, such as the firm's own name, a client company, a fund or a project codename. They can also add words it should stop flagging, such as an internal reference that looks like an account number.
These lists are typed by your admin and stored by us, because every browser in the firm has to receive them. If your admin types a client's name into the always redact list, we hold that name. That is the only place a client's name can reach us, and it gets there because somebody at your firm deliberately put it there.
They travel to each browser with the daily licence check. An admin can remove any entry at any time, and the removal travels the same way.
Your firm's profile, on Guard 360 seats
An admin of a firm with Guard 360 seats can keep a profile of the firm: short facts about it, such as which software it uses, and rules for how AI is used there. Like the word lists, these are typed by your admin and stored by us, because every Guard 360 seat in the firm receives them with the daily licence check. They are included, redacted, when a reply is checked.
A person on a Guard 360 seat can suggest a fact from their own vault for the profile. Only when they press Suggest to your firm beside it, and only the words of that one fact, are sent to us. Our server refuses a suggestion that looks like an email address, a phone number or a long number.
A suggestion is held for the admin, who sees its words and how many people suggested it, never who. With it we keep a one way key for each person who suggested it, only so that one person is not counted twice. It stays until the admin approves or dismisses it, or until the list of suggestions is full and it is the oldest that only one person made. When somebody is removed from the team, their key comes off every suggestion, and a suggestion nobody else made goes with it.
Prompt coaching, on Guard Pro and Guard 360 seats
Guard Pro and Guard 360 seats can suggest how to ask a better question. Doing that needs a model to read the conversation, and that model is not on your machine.
Before anything is sent, the same redaction that protects a message protects this: names, account numbers, SINs, addresses and the rest are replaced with stand ins such as [PERSON_1]. The redacted text is then sent to OpenAI, which returns a suggestion.
Our server checks the text again before it goes out. If it still finds something that looks like an email address, a phone number or a long number, it refuses to send rather than cleaning it quietly, because a leak getting through means the extension has a fault worth knowing about.
Nothing from a coaching request is stored. The text is sent, a suggestion comes back, and the text is gone. OpenAI does not train on data sent through their business API.
Tips look at the messages of the conversation you are having now, a few at a time, both your messages and the AI's replies. Help me, Sharpen my prompt and Set up this chat look further. Help me and Sharpen my prompt read the whole conversation on the page, including messages from before you opened it and anything typed in the message box but not yet sent, and any answers you give to their follow up questions. Set up this chat sends the answers to its six questions. All of it is redacted the same way before it leaves.
So that Help me is ready the moment you click it, it starts reading as soon as a tip appears on screen, before you have clicked anything. That means the redacted conversation is sent whenever a tip is shown, whether or not you go on to use Help me. It is limited to 60 a person a day. What comes back is placed in the message box for you to read and edit; it is never sent on your behalf.
Once a week coaching also writes each person a short note about how their week with AI went. For that, a summary of their week is sent: how many chats, how many messages each took, how that compares with their own earlier weeks, which of a fixed list of habits the coach noticed, and how many messages chats of each kind of work took, from a fixed list (client emails, summaries, research, analysis, drafting) the coach tags as it reads, never the subject. It contains no text anyone wrote, no names of sites and no clock times. On a Guard 360 seat it also carries up to eight short facts from the person's vault about their work, such as “Most of your clients are retirees”, learned from their redacted messages and checked again for client details, so the note's example can be set in their line of work. It does say how many chats fell in the morning, the afternoon and the evening, on how many days, and how long one notable chat lasted, and it carries the short headlines of the person's last few notes, which the coaching model wrote, so a new note does not repeat them. The note comes back and is kept on their computer only. Their employer never sees it.
Each person's browser also tells us which habit, from that fixed list, they are working on, so their firm can see which habits its people are building. The firm sees only totals: nothing at all until at least five people have picked a habit, and a habit fewer than three people share is counted under other habits. Nobody's note, plan or week is shown to the firm.
While an AI chat site is open and in view, a browser with coaching on also sends a short wake-up call to the coaching service every few minutes, so that a tip or Help me does not have to wait for it to start. The call carries nothing: no text, no id for the browser or the person, and not which site is open. Like any request, it does tell the service that some browser was using an AI site at that moment, from the network address it came from.
Coaching can be switched off by any person for their own browser, at any time, from the SourceSecure icon in Chrome. With it off, nothing you type leaves your computer for any reason, and the wake-up call stops too.
Reply marks, on Guard 360 seats
Everything here also applies during a two-week Guard 360 trial, if your firm chose one: for those two weeks your seat works as Guard 360, then goes back to your own.
A Guard 360 seat checks each AI reply for the places worth a second look, such as a decision made for you, an assumption, or something that contradicts what your firm has told it, and underlines them faintly. That also needs a model that is not on your machine.
When a reply finishes, your message and the reply are redacted in your browser in the same way as coaching, with the last few messages of the chat before them (at most four, cut short), so the check can tell what you already said from what the reply assumed. All of it is sent through our server to OpenAI, together with the facts from your vault and your firm's profile, redacted the same way. Our server checks all of it again before it goes, as it does for coaching. What comes back is where to underline and a short note for each, which are shown only on your screen.
When your message says something about your work or your firm, the same redacted message is sent once more to read short facts from it, together with the facts already in your vault, redacted the same way, so that a fact which has changed can replace the old one. The facts come back and are kept in your browser's vault and nowhere else, with the old wording kept there as history. The model is told never to keep anything about your private life, your health, your family, your own money or your job search, and never anything about a client or another named person. Save to vault does the same with text you select and choose to save.
Remember personal details is off unless you switch it on in the popup. While it is on, lasting facts about your own life, such as an allergy, your family or what you like, may be kept in your vault as well. They stay in your browser and are never offered to your firm, but like your other vault facts they are sent, redacted, with each reply check. Nothing about another person or a client is kept either way. Switching it off stops them being learned and sent; those already kept stay in your vault until you delete them.
Nothing from a reply check or a fact read is stored by us. Our logs record how many marks or facts came back and how long it took, never any words.
A firm's Guard 360 seats share an allowance of checked replies each month. Past it, every reply is still checked, but only the most important marks are shown until the 1st, and a person can have up to 20 replies a day checked in full. The monthly total is kept for the firm as one number, as described above.
Reply marks have their own switch, Mark AI replies, under the SourceSecure icon, and switching prompting tips off stops them too. With both off, nothing you type leaves your computer for any reason.
Where it is held
Your firm's records and the daily counts are held in Google Cloud Firestore in the northamerica-northeast1 region, which is Montreal, Canada. The functions that serve this site and the API run in the same region.
Some things are held elsewhere, by the companies named below. Sign in is run by Google's Firebase Authentication, which keeps each person's email address and sign in history in its own systems rather than in Montreal. Stripe holds billing details and the firm's name and contact address. Resend handles the email addresses we send to. Prompt coaching and reply marks send redacted text to OpenAI, in the United States. Our own server logs record what happened, never what anybody wrote, and are kept by Google Cloud.
Who else holds something
Google Cloud and Firebase, who host this site, the database and the sign in.
Stripe, who take the payment. They hold your billing details. We never see a card number.
Resend, who deliver our email. They handle sign in links and invitations, so they see the email addresses we send to.
OpenAI, who run the model behind prompt coaching and reply marks, and only for people on Guard Pro or Guard 360 seats. They receive redacted text and no account details.
That is the whole list. We do not use advertising networks, analytics services or trackers, and this site sets no cookies of its own. It loads its own fonts from its own servers rather than from Google, because a page selling the promise that nothing calls out should not quietly call out.
How long we keep it
Account records are kept while the firm has an account with us. When an admin removes somebody from the team, their membership, their connected browsers, their sign in account and the counters that limit how much they can use are deleted, the firm's daily counts stop pointing at them, and their key comes off any suggestion for the firm's profile. The counts themselves stay, as the firm's.
The firm's profile and the suggestions for it are kept until the admin removes them, or until the account is closed.
Daily counts are kept so a dashboard can show a trend. They contain no text and are not tied to a person.
To close an account entirely and have its records removed, email support@sourcesecure.ca from the address that manages the team. We do not yet have a self serve delete, and we would rather say so than imply one exists.
What you can ask for
Under Canadian privacy law, and under the equivalent rules in other places, you can ask what we hold about you, ask for it to be corrected, and ask for it to be deleted.
Write to support@sourcesecure.ca. We will answer within thirty days. If you are unhappy with the answer, you can raise it with the Office of the Privacy Commissioner of Canada.
Children
SourceSecure is sold to firms for use at work. It is not intended for anyone under 18 and we do not knowingly hold information about children.
Changes to this policy
If this changes in a way that affects what we collect or who receives it, we will email the admin of every firm before it takes effect. The date at the top of this page always says when it last changed.
Getting in touch
Email support@sourcesecure.ca. SourceSecure is operated by JOLIVE Labs Inc.