Privacy policy for PureCipher Prompt Defender
PureCipher Prompt Defender by PureCipher Inc
Privacy policy for PureCipher Prompt Defender
PureCipher Prompt Firewall Privacy Policy
Last updated: September 15, 2026
- Overview
PureCipher Prompt Firewall helps protect users from prompt injection and unsafe browser-to-AI handoffs. Core protection runs locally in Firefox. The extension does not include advertising, data sales, or default-on remote analytics or telemetry.
- Data processed locally
To provide its security features, the extension may process webpage content, selected or page-derived text, clipboard-related text in protected copy and paste flows, hostnames, extension settings, and minimal intervention metadata. This processing is used to detect hidden prompt-like instructions, identify likely AI-bound controls and destinations, sanitize suspicious text, show recent interventions, and provide Safe Handoff and Safe Summary review flows.
- Local storage and retention
Settings are stored in Firefox extension storage. Recent intervention metadata and pending Safe Handoff or Safe Summary payloads use session storage when available. Handoff payloads are short-lived, one-time-use records and expire after approximately ten minutes. Optional structured learning signals are stored locally for up to 30 days unless the user clears them sooner. A local salt is used to hash host indicators in learning exports.
- Data not transmitted by default
By default, the extension does not transmit raw page text, raw prompt text, clipboard contents, full URLs, page titles, structured learning signals, analytics, or advertising telemetry to PureCipher. Privacy-preserving reports and structured learning batches are generated locally and leave the device only when the user deliberately copies and shares them.
- Optional remote features
Secure federated learning and SecureMCP policy delivery are optional, disabled by default, and require explicit user action. The user must configure a valid HTTPS endpoint and trusted signing key. Firefox also requires the user to grant the declared data-transmission permissions before either feature can send data.
If enabled, these features may transmit aggregate data to the user-configured endpoint, including a pseudonymous locally generated client identifier; browser and extension version information; count-style intervention and feedback summaries; AI-provider and interaction-surface categories; model, feature-schema, and policy version identifiers; delivery timestamps; decision classes; and severity totals.
Optional remote payloads are designed to exclude raw page text, raw prompt text, raw URLs, page titles, clipboard contents, cookies, advertising identifiers, and example-level event records. Core local protection remains available if the user does not grant permission or enable these features. Transport uses HTTPS, and received coordinator documents or acknowledgements must pass configured signature verification.
- Clipboard and exports
Clipboard write capability is used only for user-facing actions such as copying sanitized selections, local privacy reports, learning batches, and Safe Handoff or Safe Summary output. The extension does not automatically upload clipboard contents.
- Third-party AI services
When a user chooses to send content to an AI service or another website, that destination's privacy practices apply. PureCipher can detect, pause, sanitize, or help review the handoff but does not control third-party services.
- Security and user control
Optional learning and remote-delivery features are off by default. Users can disable them or clear local learning data from the extension interface. No software can guarantee perfect security, so users should review sanitized output and share exports only with recipients they trust.
- Children's privacy
The extension is not designed specifically for children.
- Changes
PureCipher may update this policy as the extension evolves. Material changes to data handling will be disclosed before release.
- Contact
Privacy and support email: support@purecipher.com
Security contact: vamsi@purecipher.com
Support: https://purecipher.com/prompt-firewall/support/
Privacy policy: https://purecipher.com/prompt-firewall/privacy/