Privacy Policy — version 1.12
In effect from 2026-09-25. Supersedes version 1.11. Previous versions remain available at/legal/privacy/versions/.
Privacy Policy
Aporta Systems, LLC — aportasystems.com/legal/privacy
This page describes what Aporta does with personal data as the Service actually works on the date above. Where something is not yet in place, we say so.
Aporta has not completed a SOC 2 examination and is not certified to ISO/IEC 27001.
1. Who we are and what this page covers
Aporta Systems, LLC is a Tennessee limited liability company. We make a browser extension and a hosted service that detect sensitive data in text before an employee sends it to a generative-AI tool, replace that data with tokens, and record what was sent.
This page covers:
- the Aporta browser extension;
- our website, aportasystems.com; and
- the accounts our customers’ administrators and users hold with us.
Where a customer has signed a Data Processing Agreement (DPA), the DPA governs data processed through the Service, and it wins if it and this page disagree.
2. Our two roles
For data processed through the Service, we are a processor. Our customer — the company that bought Aporta — is the controller. They decide who uses the Service, what it detects, and what their people may send to AI tools. We act only on their instructions and for no purpose of our own. If you are one of their employees, or someone whose information appeared in what an employee typed, your relationship is with them, and we will refer any request you send us to them.
For our website and account administration, we are a controller. That covers people who visit our website, contact us, or hold a login.
3. What the extension reads and sends
What it reads
The extension reads what you type into the message box of the five AI tools listed at aportasystems.com/legal/supported-tools. It reads nothing on any other site, and nothing outside those message boxes — not other tabs or your browsing history. On other AI sites, your employer’s policy decides whether you are blocked or redirected to a supported tool.
If your employer turns on attachment scanning (it is off by default), the extension also reads spreadsheets, Word documents and presentations you attach to one of those tools. It reads them in your browser; the file is never uploaded to us. Values found in a file are then handled like typed text, so they reach our detection service as described below. PDFs and scanned images are not scanned. A file containing a part we cannot read is refused rather than partly scanned.
What it sends — including text you never send
Some detection runs on your device, and that text does not leave it. Other detection runs on our servers, and for that the text in the message box is sent to us.
This happens when you pause typing, not only when you press send. So text you type and then delete — and never submit to any AI tool — has still reached our detection service. We process it in memory and do not keep it, but it did leave your device.
Our customers must tell their people this. It is also stated in our customer agreement and in the extension’s side panel whenever you are signed in (which is whenever server-side detection runs). It is not yet shown on the screen a browser sees before it is enrolled.
What happens to what we find
Detected values are replaced with tokens before your text goes to the AI tool. The link between each token and its original value (the “mapping”) is encrypted and stored so the tool’s answer can be made readable for you; who can open it is explained in section 9. We keep an encrypted, tamper-evident record of what was detected and what was sent.
We do not record the AI tool’s responses.
A credential we hold if your employer connects an export destination
If your employer connects Google Drive or OneDrive, we hold a credential that lets us write their sealed export there on a schedule. It can create files, and reaches only files it created (Google) or one app folder (Microsoft). It is encrypted under a key specific to your employer’s organization, which is itself protected by a managed key service.
We delete the credential when the connection is removed, and destroy the key that opens it when the organization leaves. Neither step revokes the permission at Google or Microsoft. When an administrator disconnects Google, we also ask Google to revoke it. Microsoft offers no way to do that, so at Microsoft an administrator must always remove it.
This is built and not yet switched on for any customer.
What the extension does not do
- On a device your employer does not centrally manage, it cannot stop you disabling it, switching browsers, or using a personal device. It records gaps in coverage rather than preventing them.
- It protects identifiers it recognizes. It does not protect confidential subject matter that contains no recognizable identifier.
- Server-side detection of names, places and organizations is English-only. A name written in Japanese, Chinese, Korean, Arabic, Hebrew, Greek, Cyrillic or Thai is not detected at all. Fixed-format patterns — identification and account numbers, and terms a customer adds — match in any script.
4. How we use data
These commitments match obligations in our contracts.
- We do not sell personal data or share it for cross-context behavioral advertising. We run no advertising, and no one can pay us to influence what the Service does.
- We do not train models on your content. We do not use prompt text, token mappings, or a customer’s custom detection terms to train, fine-tune or evaluate any machine-learning model, ours or anyone else’s.
- The only thing we derive from use is counts: which detection categories fired and how often, to improve detection. We do not derive, keep, disclose or export the underlying values, prompt text or detection terms, and the counts do not identify the customer. If you see a broader phrase such as “anonymized data” used about Aporta, it does not describe a wider right; we have none.
- We share personal data only with the sub-processors listed at aportasystems.com/legal/subprocessors, except where law or valid legal process requires it.
The AI tools are not ours. ChatGPT, Claude, Gemini, Microsoft Copilot (the Microsoft 365 Copilot chat site in Chrome and Edge, and the consumer site in Chrome only) and Perplexity are not engaged by us and are not our sub-processors. Your text goes to them directly from your browser, under their terms and your account with them. We reduce what is sent and record what was. We report the account tier and training opt-out status we can observe, so your employer can manage that relationship.
One exception, switched off: answers through Google Gemini
When our support for one of the five tools breaks and the extension has blocked that tool rather than let it run unprotected, we have built a way to answer a question through Google’s Gemini model on Google Cloud, on our account. On that path Google is our sub-processor and is listed as one. It is the only place we would send your text from the Service to an AI provider ourselves. The demo on our website, which also uses Gemini, is described in section 5.
It is off. It has never been on in the service our customers use, and nothing from any customer has been sent to Google this way. We have turned it on in our own test environment, which holds no customer content.
It needs two switches. We must turn it on for the Service as a whole. Then each customer has its own setting, off unless a Super User turns it on; they can turn it off at any time, and every change is recorded in the organization’s audit record with who and when. Even then, it is offered to a person only while one of the five tools is blocked for them because our protection cannot run there — meaning a browser they are signed in on reported, within the last 24 hours, that the extension lost its hold on that tool and sent them to the Aporta portal. It is not offered while their tools work, or because an AI provider’s own service is down. A monthly spending cap we set limits each customer’s use; reaching it stops these answers and nothing else. Existing customers get at least thirty days’ notice before we turn it on, and the right to object in section 6.
What goes to Google: the text of that one question, with detected values replaced by placeholders.
- You type the question into the Aporta console. Before anything is sent to us, the console replaces values in your browser: the fixed-format patterns the extension matches on your device, and your employer’s added terms. It does not detect names, places or organizations, so those are sent as typed. The console shows you the text before sending it.
- The replaced values stay in your browser, and the console puts them back into the answer there. Neither the values nor the list of which placeholder stands for which value is sent to us or to Google.
- We check the text again on our own infrastructure for the same patterns and terms, and send nothing if we find a value. This check also does not detect names, places or organizations.
- We send the text twice per answer — once to measure it against the spending cap, once to get the answer — with a fixed instruction of ours that contains nothing of yours.
- We do not send attachments, earlier messages, token mappings, audit records, or your name, your employer or any account identifier. The request uses our key.
- The answer comes back with placeholders still in it. We record the text we sent, with its placeholders, in your employer’s audit record. We do not record the answer.
We are not telling you the text contains no personal data — only that our detectors found none. Detection is not perfect: this dramatically reduces inadvertent exposure rather than preventing it, and that difference matters most here.
What Google keeps. This path runs on Google Cloud, under the Google Cloud terms and Google’s Cloud Data Processing Addendum. Those terms say that, unless we instruct otherwise, Google will not keep the text outside our account for longer than it needs to produce the answer, will not keep the answer there at all, and will not use either to train its models. Two exceptions are Google’s own. If Google’s automated safety checks flag a request, Google may keep that text for up to 90 days to check it against its usage rules, and its staff may read it; Google lets a customer ask to be excluded from this, and we have not yet asked. Google also holds recent requests in memory for up to 24 hours to answer faster; a customer can switch that off, and we have not yet decided whether to. Our sub-processor list sets out these terms.
5. Data we handle as a controller
| What | Why | How long |
|---|---|---|
| Name, work email, employer, role — for administrators and users | To create and secure accounts, sign you in, and provide support | For the account’s life, then up to 24 months |
| Details you send us through the website or by email | To answer you and keep a record of what was discussed | Up to 24 months from last contact |
| The beta sign-up form on our website: full name, work email, business name, role, and what you write about how your team uses AI | To answer your request to join the beta | Up to 24 months from last contact. Formspree also keeps the submission in our account with it; its terms state no period for that |
| Text you send from the demo on our website, after the demo has replaced the values it detected | To show you the demo’s answer | Our code stores neither the text nor the answer. Google keeps it under its own terms, described below |
| Device and coverage telemetry: extension version, health, coverage tier, detection counts | To show an administrator whether protection is working on each device | As stated in the Order Form |
| Server logs: IP address, user agent, timestamps, request paths | Security, abuse prevention, and fixing faults | Up to 12 months |
| Aggregate usage analytics for the website and dashboard: page path, referrer, coarse device and country | To see which pages are used and where visitors come from | Aggregate only, held by the analytics service; not linked to an account |
| Billing contact name and email, subscription and invoice records | To bill for the Service and keep financial records | For the account’s life, then as tax and accounting law requires |
Where a lawful basis is required, we rely on performing our contract with our customers and on our legitimate interest in operating and securing the Service.
The beta sign-up form
The form on our home page sends what you enter to Formspree, Inc., a form-handling service we use: your full name, work email, business name and role, and what you write about how your team uses AI. If you arrive from our risk calculator, that last box starts with a summary of your result, which you can change before sending. Your browser sends the form to Formspree directly, so Formspree also receives your network address and browser details, as any website you contact does. Formspree keeps the submission in our account with it and makes it available to us. Its terms state no retention period for submissions.
The demo on our website
The demo at aportasystems.com/demo detects values in your browser and replaces them with placeholders. When you send the protected prompt, that text, with the placeholders in it, goes to our website’s server and from there to Google’s Gemini model, under Aporta’s own Google account. The answer comes back to your browser, which puts the values back when you copy it.
- What goes to Google: the text as your browser sent it, cut to 2,000 characters, with a fixed instruction of ours that contains nothing of yours. The values the demo replaced, and the words you added to protect, stay in your browser. We add no name, email address, network address or other identifier of yours.
- What the demo does not catch is sent as typed. Its detection is simpler than the Service’s, and our server does not check the text again before sending it. The page asks you to use made-up details.
- What we keep: our code stores neither the text nor Google’s answer. To limit repeated requests, our server holds your network address for about six seconds in our infrastructure provider’s cache.
- What Google keeps: Google’s published terms for this service describe keeping prompts and answers for a period to check them against its usage rules, during which its staff may read one that is flagged. We have not established what retention applies to our account.
For the demo, we are the controller and Google is our processor. This is our website, not the Service.
Cookies. Our website and dashboard set no advertising or cross-site tracking cookies — only the cookies needed to keep you signed in and your session secure. We count page views and referrers with a cookieless analytics service from the infrastructure provider already on our sub-processor list. It sets no cookie, stores nothing on your device, and does not identify individual visitors; in the dashboard we can see that a page was used, not which of your people used it. There is no consent banner because there is nothing to consent to.
6. Who else handles it
Our providers are listed, with what each does, the data it touches and where, at aportasystems.com/legal/subprocessors. Most run the Service itself. Four do not:
- Microsoft 365 runs our email, document storage and support correspondence, so it holds personal data whenever a customer writes to us or signs something.
- Stripe runs our billing and holds the billing contact and invoice history. Card details go to Stripe directly and never reach us. Like every payment processor, Stripe also uses payment data on its own account for fraud prevention and regulatory compliance, under its own terms.
- Twilio sends our operational alerts by text message. It holds the mobile numbers of the Aporta staff who receive them, and its own record of who was messaged and when.
- Formspree receives our website’s beta sign-up form (section 5).
Google also answers the demo on our website (section 5), separately from its role in the Service.
The list is versioned and past versions stay available, so the list in force on any date can be shown. Customers get at least thirty days’ notice before we add or replace a provider, and may object on reasonable data protection grounds.
Each provider is under a written data processing agreement with us, and we remain responsible to you for what they do, with three qualifications:
- Google Gemini answers (section 4, switched off for every customer): these run under the Google Cloud terms, which include Google’s Cloud Data Processing Addendum. Google also offers an explicit acceptance of that addendum in its console, and we have not yet confirmed it is recorded on our account.
- The demo on our website (section 5): it uses a different Google service, whose terms describe an agreement that takes effect when accepted or written into a contract, not simply by using the service. We have not yet confirmed that either has happened on our account.
- Export delivery to your Google Drive or OneDrive (section 3, switched off for every customer): we have not yet confirmed which of either provider’s terms govern it.
- Formspree (section 5): we have not found a data processing agreement that Formspree offers. Its terms of service describe its customers as independent controllers of the personal data they collect through it.
Six of our own providers give us less notice than we give you: one gives fourteen days by updating a web page we must monitor; one gives fourteen days’ written notice and treats fourteen days’ silence as agreement; one gives ten days by email and treats ten days’ silence as agreement; one may replace a provider urgently and tell us afterwards; one commits to no fixed period, only to telling us as soon as reasonably practicable; and one says only that it updates a published list from time to time. For a change that starts with one of them, we cannot give you thirty days; we will pass on what notice we have as soon as we have it.
Our providers also use their own vendors. Our detection compute provider runs no physical infrastructure of its own; it schedules work across a published pool of cloud providers. Our configuration fixes the country that work runs in, not which provider runs it.
7. Where processing happens
The Service’s own stores are in the United States: the token vault, the per-customer databases and the audit record. Providers that hold data for us keep it where their entries on our sub-processor page say. For the audit record this is enforced by a jurisdiction restriction on the storage itself, not a location preference that could drift.
Processing can happen elsewhere in transit. Our detection compute is in the United States, but requests are authenticated and routed through a global edge network at the location nearest the person making them. If you use the Service outside the United States, your text is processed in transit outside the United States. It is not stored there or kept after the request ends.
Google Gemini answers (section 4, switched off): configured for the United States. We send them to Google’s United States endpoint, where Google’s terms commit it to carry out the processing in the United States only. We will confirm by test that it works there before we switch it on.
Our website (section 5). Text sent from the demo goes to Google under the terms of a different Google service, which let it process that text in any country where it or its providers have facilities, so it may be processed outside the United States. Formspree says it hosts its service in the United States; its privacy policy also says it may use information in any country where it operates, and one provider on its own published list is in Germany.
We do not offer a way to confine processing to a chosen region. Where a transfer out of the European Economic Area, the United Kingdom or Switzerland is in scope, we sign the applicable Standard Contractual Clauses with the customer.
8. Security
Our security measures are set out in Schedule 3 to the Data Processing Agreement. The points most often misread:
- Not end-to-end encryption. Connections use TLS, which protects text on the wire. TLS ends at our edge, so your text is unencrypted on our infrastructure while detection runs, and detected values are unencrypted when the product restores them for you. Our strong encryption applies to stored data — the token vault, the audit record, and any storage credential we hold for you.
- Separated keys. Reading the audit record gives no ability to unmask a token. Support roles have no access to prompt text.
- Approval to send tokenized values. Sending something already tokenized needs approval. For the most sensitive categories — social security and government ID numbers, payment card and financial account numbers, and credentials — two people must approve, and no customer setting can lower that. The one exception: a customer with a single operator may choose sole-operator status at setup. That person then approves alone after a typed confirmation, the record says “self-approved”, and no report shows it as approved by two people.
- No certification. We hold no third-party security certification today. Our roadmap is in Exhibit B to our Standard Terms.
9. Retention, deletion, and what survives
When a customer asks us to delete their data, we do — with these exceptions.
Audit records. They are hash-chained, so removing one would break verification, and they are held under a seven-year retention setting. That setting does not make them undeletable — we tested it, and an account credential can remove them — so it lets tampering be detected, not prevented. Instead of deleting them, we destroy their encryption key. They then remain stored but are permanently unreadable by anyone, including us. We confirm the key destruction in writing.
What outlives deletion, which is why we will not tell a customer their data has been deleted:
- tokenized conversation history in each user’s account with the AI vendor, which is under that vendor’s terms and which we cannot reach;
- the key-destroyed audit records above, which still exist but cannot be read; and
- a storage permission your organization granted us at Microsoft, which we can stop using but cannot revoke — and the same at Google if the organization leaves without disconnecting first, because destroying our key does not revoke it there.
Who can open your mappings and exports. It depends on who holds your organization’s vault key. Every organization starts with Aporta holding it, and while we hold it we can open your token mappings and your exports. Once your organization takes its own key, we hold only an encrypted copy of it and cannot open an export.
A customer can get a sealed, encrypted export of their own token mappings, opened with their recovery code. Each export states who held the key when it was sealed. It opens with a single page the customer saves alongside it, which runs on their own computer, sends and fetches nothing, and needs no extension, account or service of ours — so it works whether or not we still exist.
Scheduled delivery of exports into the customer’s own Drive or OneDrive is built and not switched on for any customer. During a delivery, we first build the sealed copy in our own storage in the United States and keep it until delivery finishes — never more than seven days, after which it is deleted automatically.
Every departing customer gets a written statement of exactly what survives and where.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete or port your personal data; to object to or restrict certain processing; to opt out of sale or sharing (we do neither); and not to be discriminated against for using these rights.
- Data we hold as a controller: write to privacy@aportasystems.com. We will respond within the time the applicable law allows.
- Data processed through the Service: contact the customer who deployed Aporta, as they are the controller. If you contact us instead, we will pass your request to them and help them answer it; we cannot act on it ourselves without their instruction.
If you are in the European Economic Area or the United Kingdom, you may complain to your supervisory authority.
11. Children
The Service is sold to businesses for their employees and contractors. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. Information about a child could appear in text an employee types — in a family law matter, for example. That content is controlled by our customer and governed by their AI-use policy.
12. Changes to this page
This page shows a version number and date. A published version is never edited in place: any correction, even a typo, creates a new version. Every past version stays available at a permanent address, so the text in force on any date can be produced.
If a change is material and adverse to a customer, we notify the contact on each active Order Form. Posting a change here is not by itself that notice.
13. Contact
Aporta Systems, LLC, 116 Agnes Road, Suite 200, Knoxville, Tennessee 37919, United States
We have not appointed an EU or UK representative under Article 27, because we do not currently offer the Service to individuals in those territories or monitor their behavior. If that changes, we will appoint one and say so here.