Privacy Policy — version 1.7
In effect from 2026-09-10. Supersedes version 1.6. Previous versions remain available at/legal/privacy/versions/.
Privacy Policy
Aporta Systems, LLC — aportasystems.com/legal/privacy
About this version
This page describes what Aporta Systems does with personal data, checked line by line against how the system is actually built rather than against how it is intended to work. Where a protection is not yet in place, this page says so.
Aporta has not completed a SOC 2 examination and is not certified to ISO/IEC 27001. Neither claim is made anywhere on this page or elsewhere.
0. How to read this page
Statements here describe the Service as it operates on the version date above. Where something is designed and not yet built, this page says so at the point it arises rather than describing the intended state. That is a deliberate rule: this page is read by people deciding whether to trust the product, and a capability described in the present tense before it exists is the failure this document is most likely to commit.
1. Who we are and what this page covers
Aporta Systems, LLC is a Tennessee limited liability company. We make a browser extension and a hosted service that detect sensitive data in text before an employee sends it to a generative-AI tool, replace that data with tokens, and record what was transmitted.
This page explains what we do with personal data. It covers three things:
- the Aporta browser extension, including what it reads and what it sends;
- our website at aportasystems.com; and
- the accounts our customers’ administrators and users hold with us.
It does not replace the Data Processing Agreement. Where a customer has signed one, that agreement governs our handling of data processed through the Service, and it controls if this page and the DPA ever disagree.
2. Our two different roles
This distinction determines who is accountable for what, so it comes first.
For data processed through the Service, we are a processor. Our customer — the firm or company that bought Aporta — is the controller. They decide who uses the Service, what it is configured to detect, and what their people are permitted to send to AI tools. We process that data on their documented instructions and for no independent purpose of our own. If you are an employee of one of our customers, or a person whose information appeared in something an employee typed, your relationship is with them and not with us. We will refer any request you send us to them.
For our website and for account administration, we are a controller. That covers people who visit aportasystems.com, contact us, or hold a login. That data is ours to account for and this page is where we do it.
3. What the extension reads and sends
This section is the one that matters most, and it is written plainly because a summary would be misleading.
What it reads
The extension reads text you type into the message box of the AI tools listed at aportasystems.com/legal/supported-tools. It runs only on those sites. It does not read other tabs, other websites, your browsing history, or anything you type outside those message boxes.
If your employer has turned on attachment scanning, the extension also reads files you attach to one of those tools — spreadsheets, Word documents and presentations, in the formats we support. That reading happens in your browser and the file itself is never uploaded to us. Values found inside it are then treated exactly as typed text is, which means they reach our detection service in the way described below. PDFs and scanned images are not scanned at all, and a file containing a part we cannot read is refused rather than partly scanned. Attachment scanning is off until an administrator turns it on.
What it sends, including text you never send
Detection runs in two places. Some patterns are matched on your own device and never leave it. More complex detection runs on our servers, and for that, the text in the message box is transmitted to us.
That transmission is triggered when you pause typing, not only when you press send. Partial, in-progress text is therefore sent to our detection service — including text you subsequently delete and never submit to any AI tool.
We say this plainly because it is the single least obvious thing about how the product works. If you type a client name, think better of it, and delete it, that text has already reached our detection service. It is processed in memory to find sensitive values and is not retained afterward, but it did leave your device. Our customers are required to disclose this to their people. As of this version the disclosure appears here and in the customer agreement; surfacing it inside the extension itself is specified and not yet built.
What happens to what we find
Values we detect are replaced with tokens before your text goes to the AI tool. The mapping between a token and its original value is encrypted and stored so the tool’s answer can be made readable again for you. We write an encrypted, tamper-evident record of what was detected and what was transmitted, which is what gives your employer an account of what left their control.
We do not record the AI tool’s responses.
What the extension does not do
It does not block you from using AI tools, and on a device your employer has not centrally managed it cannot prevent you from disabling it, switching browsers, or using a personal device. It records the absence of coverage rather than preventing it. It protects identifiers it recognizes; it does not protect confidential subject matter that contains no recognizable identifier. Server-side detection of names, places and organizations runs an English-language model only: a name written in Japanese, Chinese, Korean, Arabic, Hebrew, Greek, Cyrillic or Thai is not scored low, it is not detected at all. Patterns with a fixed shape — identification and account numbers, and terms a customer adds themselves — match in any script.
4. Our commitments about use
These are commitments, not descriptions, and they mirror obligations we have taken on contractually.
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not run advertising, and we do not permit anyone to pay us to influence what the Service does.
We do not train models on your content. We do not use prompt text, token-to-value mappings, or a customer’s custom detection terms to train, fine-tune, or evaluate any machine learning model, our own or anyone else’s.
The only thing we derive from customer use is counts. We may record that a detection category fired, how often, and which category it was, in order to improve detection quality. We do not derive, keep, disclose or export the underlying values, the prompt text, or a customer’s detection terms, and we do not identify the customer. This is the whole of it. If you read a broader phrase such as “anonymized data” anywhere in connection with Aporta, it does not describe a wider right, because we do not have one.
We do not transfer personal data to anyone except the sub-processors listed at aportasystems.com/legal/subprocessors, other than where a law or a valid legal process requires it.
The AI tools themselves are not ours. ChatGPT, Claude, Gemini, Copilot and Perplexity are not engaged by us and are not our sub-processors. Your text goes to them from your browser, directly, under their terms and under whatever account you hold with them. What we do is reduce what is sent and record what was. We report the account tier and training opt-out status we can observe so your employer can manage that relationship, but it is theirs to manage, not ours.
5. Data we handle as a controller
| What | Why | How long |
|—|—|—|
| Name, work email, employer, role — for administrators and users | To create and secure accounts, authenticate sign-in, and provide support | For the account’s life, then up to 24 months |
| Inquiry details you send us through the website or by email | To answer you and to keep a record of what was discussed | Up to 24 months from last contact |
| Device and coverage telemetry: extension version, health, coverage tier, detection counts | To show an administrator whether protection is actually working on each device | As stated in the Order Form |
| Server logs: IP address, user agent, timestamps, request paths | Security, abuse prevention, and diagnosing faults | Up to 12 months |
| Aggregate usage analytics for the marketing site and the dashboard: page path, referrer, and coarse device and country information | To see which pages are used and where visitors arrive from | Aggregate only, held by the analytics service; not linked to an account |
| Billing contact name and email, subscription and invoice records | To bill for the Service and keep financial records | For the account’s life, then as tax and accounting law requires |
We rely on the performance of our contract with our customers, and on our legitimate interest in operating and securing the Service, as the bases for this processing where a lawful basis is required.
Neither our website nor the dashboard sets advertising or cross-site tracking cookies. The cookies we do set are the ones needed to keep you signed in and to keep the session secure. We measure page views and referrers on both, using a cookieless analytics service provided by the infrastructure provider already listed on our sub-processor page. It sets no cookie, stores nothing on your device, and does not identify individual visitors — inside the dashboard that means we can see that a page was used, and cannot see which of your people used it. There is no consent banner on either, because there is nothing to consent to.
6. Who else handles it
We use a small number of providers, each listed with its purpose, the data it touches, and its location, at aportasystems.com/legal/subprocessors. Most run the Service itself. Two do not, and they are on the list for the same reason. Our business email, document storage and support correspondence run on Microsoft 365, and personal data reaches it whenever a customer writes to us or signs something. Our billing runs on Stripe, which holds the billing contact and the invoice history; card details go to Stripe directly and never reach us. A provider that holds your correspondence or your invoices is handling your personal data as surely as one that runs our servers, and a list that covered only the second would be a list chosen to look short.
One of them is also not purely acting on our instructions. Our payment processor uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. We are telling you that because it is true of every payment processor and is rarely said out loud. That page is versioned, and superseded versions stay available, so the list in effect on any past date can be established. Customers get at least thirty days’ notice before we add or replace a provider, and may object on reasonable data protection grounds.
Each of them is under a written data processing agreement with us, and we remain responsible to you for what they do.
We will not claim those agreements are in every respect as protective as the commitments we make to you, because in one respect they are not. We give you thirty days’ notice before adding or replacing a provider, and a right to object. Four of our own providers give us less than that. One gives fourteen days by updating a web page we are responsible for monitoring. One gives fourteen days by written notice, and treats silence for fourteen days as agreement. One gives ten days by email, and treats silence for ten days as agreement. One reserves the right to replace a provider urgently and tell us afterwards. So for a change that starts in one of those chains, we cannot give you the thirty days we promise — we would give you what we have, as soon as we have it. We would rather say that plainly than promise a chain of notice we cannot enforce.
Each of these companies also engages its own vendors. Our detection compute provider does not operate physical infrastructure at all; it schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.
7. Where processing happens
Everything we store is stored in the United States. That includes the encrypted token vault, the per-customer databases, and the audit record. For the audit record this is enforced by a jurisdictional restriction on the storage itself rather than by a location preference, which means it is a property of the storage and not a setting that can drift.
Processing is a different question, and the honest answer is more complicated. Our detection compute is in the United States. But the requests that reach it are authenticated and routed through a global edge network that runs at whichever location is nearest to the person making the request. If you use the Service while outside the United States, your text is processed in transit at a location outside the United States. It is not stored there and is not kept after the request finishes.
We do not currently offer a configuration that confines processing to a chosen region, and we will not say otherwise. Where a transfer out of the European Economic Area, the United Kingdom or Switzerland is in scope, we enter into the applicable Standard Contractual Clauses with the customer.
8. Security, and what it does and does not cover
Our technical and organizational measures are set out in Schedule 3 to the Data Processing Agreement rather than summarized here, because a summary of security measures tends to read as a stronger promise than the detail supports. What follows is the part most often misread.
Connections use TLS. That protects text on the wire between your browser and our infrastructure. It does not mean your text is encrypted end to end. TLS terminates at our edge, which means the text you type is present in unencrypted form on our infrastructure while detection runs, and detected values are handled in unencrypted form when the product restores them for you. The strong encryption we apply is to data at rest — the token vault and the audit record — which is a different stage in the life of that data.
We separate keys, so reading the audit record gives no ability to unmask a token. Roles that handle support have no access to prompt text. Sending something already tokenized requires an approval, and for the most sensitive categories — social security and government identification numbers, payment card and financial account numbers, and credentials — that approval requires two people. This is enforced in the product and cannot be lowered by a customer setting. One exception, and we state it because a floor described as absolute would be inaccurate: a customer with a single operator may elect sole-operator status when their account is set up, and on that account the approval is given by that one person behind a typed confirmation. The record says self-approved, in those words, and no report renders it as approved by two people.
We hold no third-party security certification today. Our roadmap is stated in Exhibit B to our Standard Terms. We will not represent otherwise, and we would rather lose a deal to that answer than win one by implying a certification we do not have.
9. Retention, deletion, and what survives
When a customer asks us to delete their data, we do. But audit records are hash-chained, so removing one breaks the verification that makes the record worth keeping, and they are held under a seven-year retention configuration. We will not tell you that configuration makes them undeletable: we tested it, and an account credential can remove an object held under it. What the record gives you is that tampering is detected, not that it is prevented. So rather than delete, we destroy the encryption key, which makes those records permanently and irreversibly unreadable by anyone, including us. The encrypted object remains in existence. We confirm the key destruction in writing.
We will not tell a customer their data has been deleted, because three things outlive our deletion:
- the tokenized conversation history sitting in each user’s account with the AI vendor, which is governed by that vendor’s terms and which we cannot reach; and
- the encrypted, key-destroyed audit objects described above, which exist but cannot be read.
A third is partly in place. A customer can be issued a sealed, encrypted export of their own token mappings. Opening it requires their own recovery code, which we do not hold — so we cannot read an export, and no system of ours is involved in reading one. What is not yet built is the rest. Nothing places a bundle into the customer’s own Drive or OneDrive on a schedule. And the software that opens a bundle is our browser extension, which we distribute through the Chrome and Edge stores: a customer who has it installed can open their export, but one who reinstalled or moved to a new device after we had ceased to exist could not obtain it. Until a standalone reader exists that involves nothing of ours, the export is something a customer holds and can read today rather than continuity they can rely on indefinitely, and we do not describe it as the latter.
We give every departing customer a written statement of exactly what survives and where.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, to opt out of sale or sharing — which is straightforward for us, because we do neither — and not to be discriminated against for exercising any of them.
For data we hold as a controller, write to [email protected] and we will respond within the time the applicable law allows.
For anything processed through the Service, the customer who deployed Aporta is the controller and you should approach them. If you approach us instead, we will pass your request to them and assist them in answering it. We cannot act on it ourselves, because doing so would mean acting on their data without their instruction.
If you are in the European Economic Area or the United Kingdom you may complain to your supervisory authority.
11. Children
The Service is sold to businesses for use by their employees and contractors. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. Personal data about a child could in principle appear inside text an employee types — in a family law matter, for example. That is content our customer controls, and their AI-use policy is the control on it, not us.
12. Changes to this page
This page carries a version number and a date, both visible above. A published version is never edited in place: a correction, even a typographical one, produces a new version. Every superseded version stays available at a permanent address, so the text in force on any past date can be produced.
Where a change is material and adverse to a customer, we notify the contact on each active Order Form. Posting a change on this page is not by itself notice of that kind.
13. Contact
Aporta Systems, LLC 116 Agnes Road, Suite 200 Knoxville, Tennessee 37919 United States
We have not appointed an EU or UK representative under Article 27, because we do not currently offer the Service to individuals in those territories or monitor their behavior. If that changes, we will appoint one and say so here.