Privacy Policy
Last updated: 10 July 2026
Summary
Thrace Security is an AI-governance tool: a Chrome extension plus a backend and admin portal, available as a managed cloud service or open-source and self-hosted. When you self-host, your data never reaches the Thrace authors — it stays entirely within your own systems.
Who this covers
This policy describes the data handling of the Thrace Security browser extension and the open-source self-hosted platform. In a self-hosted deployment, your employer (the organization that deploys Thrace) is the data controller; Thrace Security is the software provider and does not receive your data. The managed Thrace Cloud service is governed by the customer agreement in addition to this policy.
What the extension processes
To enforce your organization's policy, the extension inspects content you send to AI tools (ChatGPT, Claude, Gemini, Copilot and similar) before it leaves your browser:
- Prompt text, uploaded file contents, and AI responses — inspected in real time and sent to your organization's backend for scanning against its policy. This text is used only to make an allow / warn / redact / block decision.
- Your Google Workspace email — used solely to attribute activity to you for your organization's security team.
- The site (domain/app) you are using an AI tool on.
What is stored
The backend stores metadata only:
- which categories of sensitive data were detected (e.g. “credit card”, “API key”), never the values themselves;
- the action taken (allowed, warned, redacted, or blocked);
- the app/domain, a timestamp, and your Workspace email;
- a short snippet that has already had sensitive values redacted.
Raw prompt text is never persisted.
Google user data — Limited Use
The extension's use of information received from Google APIs (your Workspace account email) adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. That data is used only to provide the governance features described above, is not sold, is not transferred to third parties except as needed to operate your deployment, and is not used for advertising.
Sharing & third parties
Thrace includes no third-party analytics, advertising, or telemetry. Data flows only from the extension to your organization's backend. Your organization may configure an alert integration (e.g. Slack) — in that case only alert metadata is sent to the destination it configures.
Data retention & your rights
Retention is controlled by your organization. Because your employer administers the system, requests to access, correct, or delete your data should be directed to your employer's IT/security team.
Security
Data is transmitted over HTTPS; the backend uses scoped API keys and parameterized database queries, and does not store raw prompt content. The full source is open for inspection under the Apache-2.0 license.
Changes
We may update this policy; the “last updated” date above will change accordingly.
Contact
Questions about the software or this policy: support@getthrace.com. Questions about your own data in a deployed instance: contact the organization that deployed Thrace for you.