Privacy Policy
Last updated: June 2026
1. Overview
InvestigAItor (“we”, “us”, or “our”) provides enterprise AI activity monitoring software. This Privacy Policy describes how we collect, use, and protect information in connection with our browser extension, admin dashboard, training portal, and related services (collectively, the “Service”).
2. Information We Collect
Account information: When you create an account, we collect your name, work email address, organization name, and role within the organization.
Activity data: The browser extension collects AI platform interaction events on behalf of your organization, including URLs visited on AI platforms, platform identifiers, event timestamps, policy enforcement outcomes (allowed, warned, blocked, approval requested), and prompts entered into AI tools (for PII detection).
Sensitive data detections: When the extension detects potential PII (credit cards, SSNs, email addresses, phone numbers, IP addresses, API keys, or organization-defined custom patterns) in a prompt, it records a redacted match. Raw PII values are always redacted on-device before transmission - the raw value never leaves the employee's browser. A screenshot of the prompt is captured only when no PII is detected.
File upload and speech events: The extension detects when files are uploaded to or voice/speech input is used with AI platforms, and logs these events. File contents are not captured. Audio is not recorded; however, if the AI platform transcribes speech input into text and treats it as a prompt, that transcription may be captured as part of normal prompt monitoring.
Device and user information: Device names, browser type, extension version, and user identifiers (typically the operating system username provided via managed configuration) are collected to support deployment management and per-user billing. Each device supports multiple users; each user may appear on multiple devices.
Training data: When employees use the training portal (training.investigaitor.org), we collect course progress, quiz answers, scores, and completion status. This data is associated with the employee's user identity and accessible to organization administrators.
Approval requests: When an employee requests access to a restricted platform, we collect their stated reason for access and the administrator's response (approval or denial with optional notes).
3. Information We Do Not Collect
- Browsing activity on non-AI websites
- AI model responses or outputs (only prompts/inputs are captured)
- Keystroke logging or clipboard contents
- Screenshots on prompts where PII was detected, or outside of prompt events
- Microphone audio, camera video, or screen recordings
- Employee passwords or login credentials for any site
- Personal device activity (only organization-managed browser profiles are monitored)
4. How We Use Information
- To deliver and operate the InvestigAItor platform
- To authenticate users and enforce organization-level access policies
- To execute automated governance rules (automations) configured by administrators
- To generate activity reports, analytics, and compliance exports for authorized administrators
- To deliver scheduled reports via email to designated recipients
- To send transactional emails (account verification, billing notices, alert notifications)
- To display in-browser training reminders and policy enforcement banners
- To forward events to organization-configured SIEM endpoints or webhooks
- To improve and develop our services
5. Data Ownership and Control
Activity data collected by the browser extension belongs to your organization. As the account administrator, you control who can access this data through role-based permissions and custom roles. We process this data solely to provide the Service and do not sell or share it with third parties for advertising purposes.
Administrators may configure device groups and user groups with distinct policy overrides, alert thresholds, and training requirements. Access to specific features can be scoped through custom roles with granular permissions.
6. Data Security
We use industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest (AES-256), row-level security, and role-based access controls. All data is stored in enterprise-grade hosted database infrastructure.
Organizations may additionally enforce MFA requirements for dashboard access, restrict member invitations to approved email domains, configure session inactivity timeouts, and limit dashboard access to specific IP addresses.
7. Data Retention
We retain account data for the duration of your subscription plus 30 days after cancellation. Activity event logs are retained for 365 days by default. Organizations may configure a custom retention period in their dashboard settings.
Organizations may enable automatic cleanup of inactive devices after 30, 60, or 90 days of inactivity. You may also request earlier deletion of all data by contacting us.
8. Automated Decision-Making
The Service supports automated actions configured by organization administrators, including automatic device blocking when PII detection thresholds are exceeded, automatic training assignment based on governance events, and automatic alert dispatch. These automations execute rules set by your organization's administrators, not by InvestigAItor. Administrators can review, modify, or disable any automation at any time.
9. Third-Party Services
We use the following third-party services to operate the platform:
- Stripe - payment processing and subscription management
- Managed cloud database - database hosting and storage
- Vercel - application hosting and CDN
- SMTP provider - transactional email delivery
Activity data is not shared with AI providers or any other third party beyond what is listed above.
10. Employee Monitoring Disclosure
InvestigAItor is intended for use in accordance with applicable employment law. Organizations deploying the extension are responsible for providing appropriate notice to employees as required by their jurisdiction (e.g., GDPR, CCPA, state electronic monitoring laws). We provide a built-in training module (“Understanding AI Monitoring at Your Organization”) that organizations may assign to employees as part of their transparency efforts. We recommend consulting legal counsel before deployment.
11. HIPAA and Healthcare
For organizations subject to HIPAA, we offer a Business Associate Agreement (BAA). The BAA covers the handling of Protected Health Information (PHI) that may be incidentally captured during AI activity monitoring. Organizations must execute a BAA before using the Service in connection with PHI.
12. Your Rights
Depending on your location, you may have rights to access, correct, or delete personal data we hold about you. To exercise these rights, contact us at [email protected]. We will respond within 30 days.
13. Changes to This Policy
We may update this policy from time to time. We will notify account administrators of material changes by email at least 14 days before they take effect.
14. Contact
Questions about this policy? Email us at [email protected].