AI Workspace legal
Privacy Policy
Effective August 24, 2026
AI Workspace is a Chrome extension for saving, organizing, searching, syncing, and reusing prompts, snippets, files, and AI chat context across supported AI tools. This policy explains what information AI Workspace processes, how it is used, and when it is shared with service providers.
1. Information we process
Account information
If you sign in, we process your email address, Supabase user ID, and authentication session information. Sign-in may use Google OAuth or an email one-time password.
Saved workspace content
AI Workspace lets you save prompts, templates, snippets, folders, tags, notes, selected text, context files, and AI chat content. This content is stored locally in your browser by default.
Content you choose to use
When you explicitly save selected text, save a chat, import content, attach a context file, refine or create a prompt, or export content, AI Workspace processes the text, file, title, URL, and related metadata needed to complete that action. AI Workspace does not continuously monitor all browsing activity and does not log keystrokes.
Source information
When you save or import content, AI Workspace may store the source URL, page title, platform name, and timestamps so you can find or reopen it later.
Usage, account, and purchase activity
We may process account status, credit balances and reservations, action types, timestamps, and limited usage metadata to manage credits, feature access, sync, billing, abuse prevention, and troubleshooting.
Payments are handled by Dodo Payments. We do not collect or store full payment-card numbers. We may receive purchaser email, product, payment and checkout identifiers, amount, currency, status, refund or dispute status, and entitlement or credit-fulfilment status.
Affiliate applications
If you apply to the affiliate program, we process the name, email, main channel or profile URL, audience and promotion information, and terms acceptance you submit. We also use a one-way, secret-derived network fingerprint for application rate limiting; we do not store the raw network address with your application.
Website analytics
On this public website, we use Google Analytics 4 to understand page views, referral sources, approximate geography, browser and device information, scrolling, outbound link clicks, and clicks that open our Chrome Web Store listing. Analytics cookies are optional and remain disabled unless you choose “Allow analytics.” You can change that choice at any time using the “Privacy choices” button.
Website analytics does not receive saved prompts, chats, snippets, context files, extension account identifiers, or payment details. Learn more about how Google uses information from sites that use its services.
2. Local storage and sync boundaries
Eligible prompt-library data can sync when you enable account-based sync. Saved conversations, snippets, and context files stay on your device unless you explicitly export or send them.
Prompts and templates
Prompts, templates, blocks, folders, and related prompt-library information are stored locally and may participate in account-based sync through our Supabase backend when sync is available and enabled.
Saved chats and snippets
Saved conversation and snippet content is stored locally by the extension and is not included in prompt sync. Saved Markdown and structured conversation bodies—including locally derived Markdown and plain text—are encrypted at rest using Web Crypto AES-GCM before they are persisted. Structured image records contain metadata and source links only; the extension does not download or retain image bytes during this foundation phase. Conversation content leaves the device only when you explicitly insert, copy, download, or export it.
When you explicitly save or export a current conversation, or hydrate a reference-only imported chat, AI Workspace may request that conversation from the provider’s signed-in website interface inside a matching ChatGPT, Claude, Gemini, or Grok tab. The response is validated and converted locally; it is not sent to AI Workspace telemetry or an external conversion service. Perplexity and failed structured requests use page extraction and display a warning that the captured content may be incomplete.
Context files
Original context-file bytes are stored in extension-owned IndexedDB and encrypted at rest. File metadata—including the original file name, display name, note, and tags—is stored locally and is not encrypted. Context files and their metadata are not included in Supabase or Chrome sync.
When you choose to attach a context file to an AI site, AI Workspace asks for confirmation before sending the file to that provider. The provider’s own privacy policy and terms apply after the file is sent.
Local preferences and operational data
Chrome extension storage and IndexedDB may also contain settings, cached account status, sync metadata, and local-only usage events. Local usage events are limited to operational fields such as event name, timestamp, platform, counts, and action source; private text fields are rejected or removed.
3. How we use information
We use information only to operate and improve AI Workspace’s requested functionality, including:
- Saving, organizing, searching, and reopening workspace content.
- Inserting content into supported AI tools.
- Syncing eligible prompt-library data when enabled.
- Authenticating accounts and maintaining sessions.
- Managing credits, Lifetime Workspace entitlements, billing, and purchase fulfilment.
- Reviewing and operating the approval-based affiliate program.
- Running AI features that you explicitly request.
- Completing optional Notion, Gemini Notebook, Obsidian, Markdown, and JSON workflows.
- Preventing abuse, diagnosing errors, and maintaining service reliability.
4. AI processing
When you use AI-powered features such as prompt refinement, prompt creation, or question generation, the relevant prompt text and request metadata may be sent to our backend and Google Gemini to generate the requested result.
We do not send saved workspace content to an AI service unless you trigger a feature that requires that content or explicitly place it into an AI provider’s input.
5. Service providers
We do not sell user data. Information is transferred to service providers only as needed for features you use:
- Supabase: authentication, backend APIs, account status, credits, eligible prompt sync, and database storage.
- Google OAuth: optional Google sign-in.
- Google Gemini: AI generation actions that you explicitly request.
- Google Analytics: consent-based measurement of visits and interactions on this public website.
- Dodo Payments: checkout, payments, webhooks, refunds, and purchase fulfilment.
- Notion: optional exports after you connect and choose a destination.
- Gemini Notebook: optional export and organization actions you initiate.
- Supported AI sites: content or files you explicitly insert or attach to that provider.
We do not use or transfer user data for advertising, creditworthiness, lending, or unrelated purposes. AI Workspace’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
6. Sharing and legal disclosure
We do not sell, rent, or trade user information. We may disclose limited information when required by law, to protect users or the service from fraud or abuse, or to comply with legal obligations.
7. Retention and deletion
Local information remains on your device until you delete it, clear extension storage, or uninstall the extension. Removing the extension may delete locally stored information.
Account, billing, credit, and synced prompt-library records may be retained as needed to operate the service, preserve purchase history, prevent abuse, meet financial or legal obligations, and support account recovery.
Affiliate applications and program records may be retained while an application is under review, while a creator participates in the program, and afterward as reasonably needed for fraud prevention, payment records, disputes, and legal obligations.
To request account or server-side data deletion, email support@aiworkspaceextension.com.
8. Security
We use reasonable technical and organizational measures to protect user information. Sensitive backend secrets are stored in managed server-side environments and are not included in the extension package. Local saved-chat, snippet, and context-file contents use encryption at rest as described above.
No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.
9. Children’s privacy
AI Workspace is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
10. Changes and contact
We may update this policy as AI Workspace changes. Material updates will be reflected in the effective date above and may be announced through the extension or website where practical.
For privacy questions or deletion requests, contact support@aiworkspaceextension.com.