Privacy Policy

Last updated: August 31, 2026

This policy explains how PHI Mask and phimask.com process data. PHI Mask is an independent project operated by PHIMask.com.

1. Scope

This policy applies to phimask.com, the online masker at /mask-data, the PHI Mask Chrome extension, license and pilot requests, security reports, support correspondence, and paid commercial or enterprise use of PHI Mask.

When a customer has a separate written agreement with PHIMask.com, that agreement controls if it says something different from this public policy.

2. Website, access, and feedback data

phimask.com uses PostHog for product analytics and privacy-configured session replay across the site, including /mask-data. PostHog may set cookies and capture page views, clicks, interface interactions, referrer, device and browser type, approximate location derived from IP address, and a PostHog-assigned visitor identifier. Session replay masks all text and inputs as asterisks and blocks images, SVG, video, iframe, and canvas content before anything is sent.

On eligible public marketing pages, /mask-data, and /tools/* pages, PHI Mask also uses the Reddit Pixel to measure entrance visits from Reddit advertising. It sends PageVisit and standard browser, referrer, and page URL signals to Reddit, but it does not receive pasted text, files, detected identifiers, filenames, or masking results; health-topic articles and other redaction routes are excluded.

When you use an offer link, PHIMask.com records the offer and approved campaign attribution needed to apply the offer and connect a completed purchase to that visit. Offer endpoints use the caller address transiently to enforce request limits; neither the address nor the temporary derived key is added to the offer-attribution collections. Those collections also exclude user agents, raw URLs, email addresses, Stripe customer IDs, payment-card data, and masking content. Standard infrastructure logs remain separate as described below.

The site and related feedback channels also receive data you choose to submit, plus standard infrastructure logs. You can opt out of PostHog analytics through your browser's tracking controls or by blocking analytics cookies. Opting out does not affect access to the site.

PostHog, the Reddit Pixel, and the public-use meter do not run inside the Chrome extension or its feedback form. After you open feedback, a hidden delivery frame uses phimask.com hosting and sends only the rating and optional comment you choose, not masking content.

  • License, pilot, and enterprise requests: name, work email, company, team-size selection, expected masking-volume selection, compliance selections, and any message you submit.
  • Security reports and support: reporter contact details, affected area, summary, details, and related correspondence you submit through private channels.
  • Product feedback and issue reports: the rating and optional comment you submit, an optional reply email, and the current masked/redacted result only when you select the attachment option. PHI Mask does not include your original input, original file, filename, detected real values, or reversible placeholder map.
  • PHI Mask free-use meter: IP address, request timestamp, user agent, request path, standard request metadata needed to count public free uses, and two yes/no device-state flags (whether the page load was a reload and whether the tab observed the browser offline) used only to decide whether offline loading is worth building. Pasted text, files, masked output, detected identifiers, and file metadata are not sent for this meter.
  • Content-free masker session summary: aggregate document and detection-category counts, manual-mask count, a duration bucket, detector version, locale, copy/download/restore flags, and an unexpected-request count. It does not include text, filenames, mappings, or per-value data. The summary is sent to PostHog only after the tab leaves the masking route; a local buffer may hold it for up to 14 days so closing the tab does not lose it.
  • Offer-link attribution: a bounded offer code, opaque attribution ID, approved partner and campaign identifiers, allowlisted UTM values, and timestamps. After a verified purchase, the matching record may also contain Stripe Checkout, subscription, and promotion identifiers; billing period and currency; and subtotal, discount, and total summaries.
  • Paid checkout: Stripe collects the billing identity, address, payment method, and transaction data you enter in its hosted Checkout. PHIMask.com receives the subscription, invoice, payment status, and license details needed to provide and administer the purchase.
  • Standard hosting logs: IP address, user agent, request path, and request timestamp, kept for abuse prevention, security, reliability, and debugging.
  • Reddit advertising measurement: PageVisit events and standard browser, referrer, and page URL signals on eligible public marketing pages, /mask-data, and /tools/* pages.

3. Online masking at /mask-data

The online masker processes pasted text and uploaded files in the active browser tab. Masking itself does not send PHIMask.com your pasted text, uploaded files, masked output, detected identifiers, file metadata, or the placeholder mapping used to reverse the swap. Reloading or closing the tab ends that masking session.

If you copy masked text into ChatGPT, Claude, an API model, or another model provider, that provider relationship is separate from PHI Mask unless your written agreement says otherwise.

4. Chrome extension data

On a website you allow PHI Mask to cover, the extension handles the clipboard, paste, drag-and-drop, upload, composer, and supported reply content needed to mask values and restore placeholders. It processes that content locally. It does not send clipboard contents, files, source text, masked output, detected values, or recovery pairs to PHIMask.com.

Full source text, full masked text, live swap maps, and selected files stay in extension memory. Closing or reloading the frame ends that current-frame state.

The active frame keeps the source text and local detection result for up to three delivered text pastes so exact repeats do not need another detection pass. A conversation change, access or masking-profile reset, navigation, or tab close clears this cache.

Up to five recent original-and-masked recovery copies may remain in the active frame for 30 seconds so an interrupted paste can be recovered.

All JavaScript, WebAssembly, OCR workers, OCR cores, language data, and feedback-form code that can access extension APIs are included in the extension package and loaded from its chrome-extension:// origin. The extension has no CDN fallback and does not fetch code to execute. A hidden sandboxed delivery frame on phimask.com cannot access extension APIs or masking content.

  • clipboardRead: while a covered site's composer is focused, the extension may read clipboard text or an image to prepare local masking before a paste. The active frame keeps the source text and local detection result for up to three delivered text pastes so exact repeats do not need another detection pass. A conversation change, access or masking-profile reset, navigation, or tab close clears this cache. Clipboard contents are not sent to PHIMask.com. Only placeholder and original-value pairs actually delivered in a supported conversation may enter the recovery record described below.
  • scripting and host access: load the bundled masking engine on the built-in assistant sites and on other websites only when you choose Every website. The extension uses page content needed for masking, delivery, and supported reply restoration. It does not create or transmit a browsing-history or keystroke log.
  • chrome.storage.local: keeps fixed settings and extension lifecycle state, including website coverage, masking profile, use choice, setup progress, installation time, and first successful mask time. It does not keep clipboard contents, files, source text, masked output, filenames, or page content.
  • chrome.storage.local masking counts: a separate record keeps whole-number totals of values masked and values you chose to show, counted by category, with per-day totals for the last 90 days and the date counting started. It holds no detected values, placeholders, filenames, websites, or page content, and it is not sent to PHIMask.com. Clearing the extension's local data through Chrome removes it.
  • Extension localStorage: the file-review surface may remember fixed automatic-masking category and profile choices. It does not store document content or detected values.
  • chrome.storage.session: on supported, non-Incognito ChatGPT and Claude conversations, keeps the delivered placeholder and original-value pairs, the exact site origin, a canonical conversation identifier, and timestamps needed to restore replies after a reload. These records expire after up to 24 hours of inactivity or when Chrome ends the extension session, whichever happens first. Forget this chat and Forget all chats remove them earlier. Unsupported pages and Incognito remain current-frame only.

5. What PHIMask.com receives from masking

PHIMask.com does not receive masking content or masking counts from /mask-data or the Chrome extension. If you submit masked content on a covered website, that website receives what you chose to submit under its own terms. The extension feedback form sends only the rating and optional comment you deliberately submit. A PHI Mask product issue report may also send an optional reply email and an optional current masked/redacted result; the attachment is off by default.

6. How we use website and support data

  • Responding to license, pilot, and enterprise requests about evaluation, commercial, or enterprise access.
  • Operating the public free-use meter, preventing abuse, securing the site, debugging reliability issues, and preparing support follow-up.
  • Understanding how phimask.com pages, including /mask-data, are used through privacy-configured PostHog analytics and session replay so we can improve navigation, onboarding, and support.
  • Applying approved offers, attributing offer visits to campaigns or partners, confirming completed purchases, and administering subscriptions and licenses.
  • Improving PHI Mask documentation, access flows, support workflows, and product behavior.
  • We do not use feedback data, diagnostic data, prompts, code, files, masked content, or customer content to train foundation models.

7. Chrome Web Store Limited Use

PHI Mask's use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses that information only to provide its masking, delivery, reply-restoration, website-coverage, and preference features. It does not sell the information, use it for advertising or credit decisions, transfer it for unrelated purposes, or transfer it to PHIMask personnel for human review.

8. Privacy safeguards

We use safeguards intended to protect user and customer data, including limited retention periods for sensitive information, restricted access to private submissions, role-based production access, encryption in transit, encryption at rest where supported by our infrastructure providers, and policies against using feedback for model training.

9. Sharing and subprocessors

We do not sell, rent, or trade your information. We share website and support data only with service providers needed to operate PHI Mask, with your organization if you use PHI Mask under an organization license, and with authorities when required by law. Chrome extension masking content and recovery pairs are not shared with these service providers.

  • Google Cloud Platform: hosting, storage, database, security, and logging infrastructure.
  • Stripe: hosted Checkout, offer-eligibility checks, payment processing, subscription and invoice administration, and billing records.
  • PostHog: product analytics and privacy-configured session replay across phimask.com, including /mask-data; replay text and inputs are masked as asterisks and visual media/canvas are blocked.
  • Reddit: advertising measurement through the Reddit Pixel on eligible public marketing pages, /mask-data, and /tools/* pages.
  • Resend: private transactional email delivery for access, support, security, and product issue reports, including an optional masked/redacted attachment you explicitly submit.
  • Slack: internal operational notifications for access requests, support, and security reports.

10. Retention and deletion

Chrome extension settings remain in chrome.storage.local until you change them, clear the extension's data, or uninstall it. Current-frame masking data ends with the frame. Supported conversation recovery records remain in chrome.storage.session for up to 24 hours of inactivity or until Chrome ends the extension session, and the toolbar popup can remove them earlier. A content-free /mask-data session summary may remain in the site's local buffer for up to 14 days and is removed when it is flushed or rejected as expired.

Offer-visit attribution records are set to expire after 90 days. Verified offer-conversion records are set to expire after 730 days. Stripe subscriptions, invoices, payment records, and related PHI Mask billing or license records follow the separate retention required for account administration, accounting, dispute handling, security, and legal obligations.

License, pilot, enterprise, support, security-report, and product-issue records are retained while we respond to, support, or improve the service, then deleted or archived when they are no longer needed. Free-use meter metadata and hosting logs are retained only as long as needed for abuse prevention, security, reliability, and debugging unless a longer period is legally required.

You can ask us to delete access-request data, support records, security-report submissions, or product-issue reports unless we need to keep them for security, legal, abuse-prevention, accounting, or contractual reasons. Deletion requests are completed within 30 days where legally and operationally possible.

11. Your choices and rights

You can change extension settings, reset masking counts, and delete conversation recovery records in the toolbar popup, or clear the extension's local data through Chrome. You can request access to, correction of, export of, or deletion of data held by PHIMask.com through the request form at https://phimask.com/#apply. We respond within 48 hours. Residents of the EEA, UK, California, and Canada may exercise their GDPR, CCPA, and PIPEDA rights through the same form.

12. Commercial terms, changes, and contact

Commercial and enterprise use is also subject to PHI Mask's Commercial Terms of Service at https://phimask.com/commercial. Material changes to this policy are announced by email to affected contacts when appropriate, and the date above is updated. Questions: reach us through the request form at https://phimask.com/#apply.