Legal

Privacy Policy

Effective August 11, 2026

AIControl ("we", "us") provides an AI security gateway and browser extension that organizations use to inspect and govern their employees' interactions with AI assistants. This policy describes what data we collect through our website, console, gateway, and browser extension, and how it's used.

Who this applies to

AIControl is a business-to-business product. If you're using AIControl because your employer or organization installed it, your organization is the "controller" of your data under most privacy frameworks — it configures the security policy, can see the security events that get flagged, and controls how long that data is retained. Questions about a specific block or policy should go to your own organization's IT/security team first.

What we collect

  • Account data: the email address and organization name used to register a workspace, and a securely hashed password (never stored or transmitted in plain text).
  • Prompt content, at the moment of submission: the browser extension and gateway inspect the text sent to a supported AI assistant or LLM provider, before it's sent, to check it against your organization's security policy.
  • Security events: the outcome of that inspection (allowed / warned / blocked, and why), stored as an audit record visible to your organization's own administrators.
  • Device and connection metadata: browser/extension version and a device identifier used to recognize a specific installation as belonging to your organization's account.

What we don't do

  • We do not persist the full text of your prompts or AI responses. By design, findings are stored as masked previews or one-way cryptographic hashes, not the raw content — this isn't a setting that can be toggled off, it's how the system is built.
  • We do not sell any data we collect.
  • We do not use prompt content for advertising, profiling, or training any model.
  • We do not share your organization's data with any other organization on the platform. Every workspace is isolated.

How prompt inspection works

When your organization has connected a real AI provider (OpenAI, Anthropic, Azure OpenAI, Google Gemini, AWS Bedrock, or a self-hosted model), AIControl's gateway sits between your request and that provider: it evaluates the request against your organization's policy, then forwards allowed requests on to the provider your organization configured. We don't operate our own AI models and don't retain a copy of provider responses beyond what your organization's security policy requires for audit purposes (masked previews / hashes, as above).

Cookies and local storage

The AIControl console stores your session token in your browser's local storage so you stay signed in — this is functional, not tracking, and isn't shared with any third party. We don't currently run third-party analytics or advertising trackers on the console or marketing site.

Where data is stored

AIControl's hosted service runs on cloud infrastructure. Organizations with data residency requirements can self-host AIControl entirely within their own infrastructure instead — in that deployment model, no data reaches AIControl's servers at all.

Data retention

Security events and audit records are retained according to your organization's own AIControl configuration, set by your organization's administrators. Account data is retained for as long as your organization's workspace is active.

Your rights

If you'd like a copy of your data, or to have it deleted, contact your organization's AIControl administrator first — they control the workspace. If you're an administrator and need help, contact us directly.

Changes to this policy

If we make a material change to this policy, we'll update the effective date above and, where required, notify workspace administrators directly.

Contact

Questions about this policy: support@aicontrol.co.in