Privacy Policy
Effective Date: July 2026 • Version 2.0
LoricaPrompt is a browser extension designed to help you detect and prevent accidental pasting of sensitive data (such as API keys, passwords, and personal information) into AI tools and web-based applications.
Our Core Principle: We never transmit your sensitive content (clipboard, prompts, files) or usage data to any server. All detection statistics and activity logs are stored locally on your device only.
1. Data We Process (Locally Only)
Clipboard Content
- LoricaPrompt reads your clipboard only when you press Ctrl+V (or Cmd+V) on a supported AI tool.
- It uses two methods to ensure protection works on all platforms:
- Paste event — The standard method. The browser delivers clipboard text with the paste event.
- Clipboard API — A backup method. Some AI tools (like ChatGPT) intercept paste and don't fire the standard event. This backup ensures your data is still protected.
- Both methods require you to press a key. The extension never reads your clipboard on its own.
- All processing happens locally — clipboard text is scanned and immediately discarded.
- We never transmit, store, or share your clipboard data with any server.
Detection Patterns
- The extension uses regex patterns to detect sensitive data (API keys, SSNs, credit cards, etc.)
- Pattern matching occurs entirely on your device.
Activity Log (Local Only)
- LoricaPrompt stores a local activity log of blocked paste events.
- This log is stored in Chrome's local storage and never leaves your device.
Usage Statistics (Local Only)
- LoricaPrompt stores basic usage statistics locally to power the stats display in the popup and settings.
- This includes: browser type, operating system, number of scans performed, number of patterns detected, and which features are used (clipboard protection, File Shield, Name Vault, etc.).
- All statistics are stored locally on your device and never transmitted to any server.
2. Data Collection
| Data Type | Collected? |
|---|---|
| Clipboard contents | Read locally on paste only, never transmitted |
| Usage statistics (browser, OS, scan counts, feature usage) | Stored locally only, never transmitted |
| Browsing history | ❌ No |
| Personal information | ❌ No |
3. Services
Account Registration
Account creation is handled on browsercraftstudio.com, not inside the extension. When you register, the website collects your email address, username, and password. This data is stored on BrowserCraft Studio's servers and is governed by their own privacy practices. The extension does not have access to your password — it only receives an authentication token after you log in.
Authentication & Subscription
LoricaPrompt uses BrowserCraft Studio for optional account features. The extension connects to browsercraftstudio.com for the following purposes only:
- Login — To verify your account credentials and sign you in.
- Pro subscription check — To check whether your account has an active Pro subscription and unlock premium features accordingly.
The extension never sends clipboard content, personal data, browsing history, or file contents to BrowserCraft Studio. Only authentication tokens and subscription status are exchanged. This connection is restricted to browsercraftstudio.com only — no other websites are contacted.
4. Permissions Explained
| Permission | Why We Need It |
|---|---|
| storage | To save your settings and local activity log |
| activeTab | To access the current tab for clipboard protection and custom site injection |
| scripting | To inject content scripts on AI tools and read login tokens from our website after authentication |
| clipboardRead | To read clipboard content as a backup when the standard paste event is intercepted by the AI tool |
| alarms | To reset daily statistics and restore protection after a temporary pause |
| contextMenus | To allow scanning selected text on any page via right-click |
| notifications | To show alerts when sensitive data is detected (Optional) |
About "optional_host_permissions" (Access to all websites)
LoricaPrompt allows you to add custom websites for clipboard protection (e.g., your company's internal AI tool). Chrome requires us to declare access to all websites in order to request permission for any single website. This does NOT mean the extension has access to all websites. Here is how it actually works:
- The extension never accesses a website unless you explicitly add it as a custom site.
- When you add a custom site, the browser asks your permission for that specific domain only.
- Permission is granted only for the domains you choose. All other websites remain unaffected.
- You can review and revoke granted permissions at any time in Chrome settings.
5. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
- Right to access — You can request a copy of any data the extension holds about you.
- Right to deletion — You can request that all your data be deleted. Since all data is stored locally on your device, you can also delete it yourself by removing the extension or clearing its storage in Chrome settings.
- Right to rectification — You can request correction of any inaccurate data.
- Right to object — You can opt out of usage statistics collection in the extension settings.
To exercise any of these rights, contact us at support@browsercraftstudio.com.