Legal

Browser Extension Privacy Policy

The privacy policy for ThreatLens Shadow AI Monitor — what the extension collects, how the data is used, and your organisation’s role. Last updated 11 August 2026.

ThreatLens Shadow AI Monitor (‘the extension’) is an enterprise browser extension that helps organisations understand ‘shadow AI’ — use of third-party AI tools that bypasses their governed ThreatLens gateway. It is installed by employees of organisations that use ThreatLens and connects to that organisation’s ThreatLens console.

The extension’s single purpose

The extension has one purpose: shadow-AI discovery — helping your organisation see when AI tools are used in ways that bypass its governed ThreatLens gateway. It does nothing else, and it requests only the permissions that purpose requires.

What the extension collects

When you navigate to a recognised AI service (for example ChatGPT, Claude, Gemini, Perplexity, and similar tools on the product’s recognised host list), the extension records:

  • the URL of that AI-site navigation, and
  • the time it occurred.

It also stores, locally, the connection you configure: your organisation’s collect endpoint and the enrolment token issued to your ThreatLens account.

What the extension does NOT collect

  • No page contents, text you type, form data, or keystrokes.
  • No browsing history for any site outside the recognised AI-host list.
  • No cookies, passwords, or credentials.
  • No screenshots or clipboard data.

Permissions the extension uses

To do only what is described above, the extension requests:

  • Host access to the recognised AI-service hosts — so it can detect when you navigate to them. It does not read the contents of those pages.
  • Local storage (storage) — to keep your connection settings and a small queue of pending sightings on your device.

The extension requests no permissions beyond those needed for shadow-AI discovery.

How the data is used

Recorded AI-site visits are sent to your own organisation’s ThreatLens console (the endpoint you connect to) so your organisation can produce shadow-AI discovery reporting. The data is transmitted over HTTPS and authenticated with your per-user token. ThreatLens does not sell this data and does not use it for advertising, creditworthiness, or lending.

Who provides the extension, and who controls the data

ThreatLens, Inc. publishes the extension. The organisation whose ThreatLens console you connect to is the data controller of the reported sightings and governs their retention and access under its own policies. Reporting is per-user, and the connection is revocable at any time from the ThreatLens console (Governance → Shadow AI → Tokens) or by removing the extension.

  • Where your organisation uses ThreatLens as a hosted (SaaS) service, ThreatLens processes the reported sightings on your organisation’s behalf, as a processor, under the agreement between ThreatLens and your organisation.
  • Where your organisation self-hosts ThreatLens (private cloud or on-premises), the reported sightings are delivered directly to that environment and are not processed by ThreatLens.

Security

Reported sightings are transmitted over HTTPS/TLS and authenticated with your per-user token. Your token and the small queue of pending sightings are stored only in your browser’s local extension storage; they never leave your device except to reach your organisation’s configured endpoint.

Retention

Reported sightings are retained in your organisation’s ThreatLens tenant according to that organisation’s configured retention. Local extension storage (your token and a small pending-visit queue) lives only in your browser and is cleared when you disconnect or uninstall.

International data transfers

If your organisation’s ThreatLens environment is located in a different country from where you use the extension, the reported sightings are transferred to that environment. Those transfers are governed by your organisation as the data controller.

Who the extension is for

The extension is an enterprise tool, distributed to employees of organisations that use ThreatLens. It is not directed to children and is not intended for personal, consumer use.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date at the top of this page and, where appropriate, communicated through the extension or the ThreatLens console.

Contact

Questions about this extension: privacy@thethreatlens.com. Questions about how your employer uses the reported data: your organisation’s ThreatLens administrator.

This extension is published by ThreatLens, Inc.