AI Workspace legal
Privacy Policy
Effective October 8, 2026
AI Workspace is a Chrome extension for saving, organizing, searching, syncing, and reusing prompts, snippets, files, and AI chat context across supported AI tools. This policy explains what information AI Workspace processes, how it is used, and when it is shared with service providers.
1. Information we process
Account information
If you sign in, we process your email address, Supabase user ID, and authentication session information. Sign-in may use Google OAuth or an email one-time password.
Saved workspace content
AI Workspace lets you save prompts, templates, snippets, folders, tags, notes, selected text, context files, and AI chat content. This content is stored locally in your browser by default.
Content you choose to use
When you explicitly save selected text, save a chat, import content, attach a context file, refine or create a prompt, or export content, AI Workspace processes the text, file, title, URL, and related metadata needed to complete that action. AI Workspace does not continuously monitor all browsing activity and does not log keystrokes.
Source information
When you save or import content, AI Workspace may store the source URL, page title, platform name, and timestamps so you can find or reopen it later.
Usage, account, and purchase activity
We may process account status, credit balances and reservations, action types, timestamps, and limited usage metadata to manage credits, feature access, sync, billing, abuse prevention, and troubleshooting.
Payments are handled by Dodo Payments. We do not collect or store full payment-card numbers. We may receive purchaser email, product, payment and checkout identifiers, amount, currency, status, refund or dispute status, and entitlement or credit-fulfilment status.
Affiliate applications
If you apply to the affiliate program, we process the name, email, main channel or profile URL, audience and promotion information, and terms acceptance you submit. We also use a one-way, secret-derived network fingerprint for application rate limiting; we do not store the raw network address with your application.
Website analytics
On this public website, we use Google Analytics 4 to understand page views, referral sources, approximate geography, browser and device information, scrolling, outbound link clicks, and clicks that open our Chrome Web Store listing. Analytics cookies are optional and remain disabled unless you choose “Allow analytics.” You can change that choice at any time using the “Privacy choices” button.
Website analytics does not receive saved prompts, chats, snippets, context files, extension account identifiers, or payment details. Learn more about how Google uses information from sites that use its services.
2. Local storage and sync boundaries
Eligible prompt-library data can sync when you enable account-based sync. Saved conversations, snippets, and context files stay on your device unless you explicitly export or send them. A prompt becomes public only if you choose to share it as a link.
Prompts and templates
Prompts, templates, blocks, folders, and related prompt-library information are stored locally and may participate in account-based sync through our Supabase backend when sync is available and enabled.
Saved chats and snippets
Saved conversation and snippet content is stored locally by the extension and is not included in prompt sync. Saved Markdown and structured conversation bodies—including locally derived Markdown and plain text—are encrypted at rest using Web Crypto AES-GCM before they are persisted. Structured image records contain metadata and source links only; the extension does not download or retain image bytes during this foundation phase. Conversation content leaves the device only when you explicitly insert, copy, download, or export it.
When you explicitly save or export a current conversation, or hydrate a reference-only imported chat, AI Workspace may request that conversation from the provider’s signed-in website interface inside a matching ChatGPT, Claude, Gemini, or Grok tab. The response is validated and converted locally; it is not sent to AI Workspace telemetry or an external conversion service. Perplexity and failed structured requests use page extraction and display a warning that the captured content may be incomplete.
Context files
Original context-file bytes are stored in extension-owned IndexedDB and encrypted at rest. File metadata—including the original file name, display name, note, and tags—is stored locally and is not encrypted. Context files and their metadata are not included in Supabase or Chrome sync.
When you choose to attach a context file to an AI site, AI Workspace asks for confirmation before sending the file to that provider. The provider’s own privacy policy and terms apply after the file is sent.
Shared prompts
Sharing is optional and happens only when you choose Share, for a single prompt or for a folder shared as a pack of prompts you select. Creating a share link requires a signed-in account. When you share, AI Workspace sends the chosen prompts’ titles, text, and tags—and, for a pack, its name and the names of the subfolders they are in—to our Supabase backend and publishes them on a page at aiworkspaceextension.com that anyone with the link can view, copy, and add to their own library. Prompts you leave out, your other folders, saved chats, snippets, and context files are never included.
A share link is a snapshot. Later edits stay private until you choose to update the link, unless you turn on “Keep this link updated”, in which case your edits—and, for a pack, new prompts added to that folder—are published automatically about a minute after you make them. Before publishing, AI Workspace checks for content that looks like an API key or other credential and asks you to confirm. We ask search engines not to index share pages, but anyone who has a link can open it and pass it on.
For each share link we store the published content, your account ID as its owner, when it was created and updated, and aggregate view and import counts. So you can manage a link from your other signed-in devices, we also store which prompt or folder it was shared from (internal library IDs, not content) and its sharing settings; this is visible only to you and is removed when you stop sharing. If you choose to credit yourself, the display name and link you enter are shown on the share page. AI Workspace does not record who viewed or imported a shared prompt; optional website analytics on share pages works only as described in Website analytics. Our hosting providers may keep short-lived technical request logs.
You can stop sharing at any time. Stopping sharing, deleting a prompt you shared on its own, or deleting a folder you shared as a pack removes that link’s published content from our servers straight away, and the link stops working. A prompt you delete from inside a shared pack stays in the pack’s published copy until you update the pack or stop sharing it; packs set to update automatically drop it within about a minute. Copies that other people already added to their own libraries are theirs and are not affected.
Local preferences and operational data
Chrome extension storage and IndexedDB may also contain settings, cached account status, sync metadata, and local-only usage events. Local usage events are limited to operational fields such as event name, timestamp, platform, counts, and action source; private text fields are rejected or removed.
3. How we use information
We use information only to operate and improve AI Workspace’s requested functionality, including:
- Saving, organizing, searching, and reopening workspace content.
- Inserting content into supported AI tools.
- Syncing eligible prompt-library data when enabled.
- Publishing prompts you choose to share as links, and showing them on share pages.
- Authenticating accounts and maintaining sessions.
- Managing credits, Lifetime Workspace entitlements, billing, and purchase fulfilment.
- Reviewing and operating the approval-based affiliate program.
- Running AI features that you explicitly request.
- Completing optional Notion, Gemini Notebook, Obsidian, Markdown, and JSON workflows.
- Preventing abuse, diagnosing errors, and maintaining service reliability.
4. AI processing
When you use AI-powered features such as prompt refinement, prompt creation, or question generation, the relevant prompt text and request metadata may be sent to our backend and Google Gemini to generate the requested result.
We do not send saved workspace content to an AI service unless you trigger a feature that requires that content or explicitly place it into an AI provider’s input.
5. Service providers
We do not sell user data. Information is transferred to service providers only as needed for features you use:
- Supabase: authentication, backend APIs, account status, credits, eligible prompt sync, shared prompt links, and database storage.
- Google OAuth: optional Google sign-in.
- Google Gemini: AI generation actions that you explicitly request.
- Google Analytics: consent-based measurement of visits and interactions on this public website.
- Dodo Payments: checkout, payments, webhooks, refunds, and purchase fulfilment.
- Notion: optional exports after you connect and choose a destination.
- Gemini Notebook: optional export and organization actions you initiate.
- Supported AI sites: content or files you explicitly insert or attach to that provider.
We do not use or transfer user data for advertising, creditworthiness, lending, or unrelated purposes. AI Workspace’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
6. Sharing and legal disclosure
We do not sell, rent, or trade user information. We may disclose limited information when required by law, to protect users or the service from fraud or abuse, or to comply with legal obligations.
7. Retention and deletion
Local information remains on your device until you delete it, clear extension storage, or uninstall the extension. Removing the extension may delete locally stored information.
Shared prompt links keep their published content until you stop sharing, delete the prompt or folder you shared in AI Workspace, or delete your account. Deleting your account deletes all of your share links. After a link is stopped, we keep only a record that it existed so the same link is never reused.
Account, billing, credit, and synced prompt-library records may be retained as needed to operate the service, preserve purchase history, prevent abuse, meet financial or legal obligations, and support account recovery.
Affiliate applications and program records may be retained while an application is under review, while a creator participates in the program, and afterward as reasonably needed for fraud prevention, payment records, disputes, and legal obligations.
To request account or server-side data deletion, email support@aiworkspaceextension.com.
8. Security
We use reasonable technical and organizational measures to protect user information. Sensitive backend secrets are stored in managed server-side environments and are not included in the extension package. Local saved-chat, snippet, and context-file contents use encryption at rest as described above.
No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.
9. Children’s privacy
AI Workspace is intended for users who are 18 or older. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, contact support@aiworkspaceextension.com and we will delete it.
10. Changes and contact
We may update this policy as AI Workspace changes. Material updates will be reflected in the effective date above and may be announced through the extension or website where practical.
For privacy questions or deletion requests, contact support@aiworkspaceextension.com.