Chính sách bảo mật cho Closehold
Closehold bởi Closehold LLC
Privacy Policy
Last updated: August 25, 2026
Closehold is built on a simple principle: we protect your data by never holding it. Closehold detects sensitive information the moment before it would cross into an AI tool and replaces it with reversible placeholders — and it does this on your own device, not on our servers. This policy explains, in plain terms, what the Closehold browser extension, desktop application, and website do with data, and what they deliberately never do.
This policy covers the Closehold browser extension, the Closehold desktop application it pairs with, and closehold.ai. It applies to everyone who uses Closehold, including pilot and evaluation participants.
The short version
The extension processes the prompts and files you send to AI tools only on your own machine (via a local companion app at 127.0.0.1). Nothing is sent to Closehold to be scanned.
Closehold has no account inside the extension, and performs no analytics, no tracking, no advertising, and no content collection.
We never store raw sensitive values — anywhere. Where a record of a data crossing is kept, it holds only classifications, counts, and salted one-way hashes that describe the shape and flow of data, never the value.
We never sell your data, and never use it for advertising or to determine creditworthiness.
What the browser extension does
On the AI sites it supports (such as ChatGPT, Claude, Gemini, and Microsoft Copilot), the extension reads the prompt you are about to send and any files you attach, so it can protect confidential material in place before the prompt leaves your browser. When the AI’s reply comes back, the extension restores your real values in that reply so the conversation reads normally. The AI service never receives your original values; you never have to look at placeholders.
The extension is a thin bridge. It contains none of the detection, classification, or transformation logic itself — it hands content to the Closehold desktop application running locally on your machine, which does that work and hands back a protected version. The extension activates only on the AI surfaces it supports and does not read your general browsing.
What we collect — and what we don’t
Content you send to AI tools is transmitted only to your own device (127.0.0.1) for local processing. It is not transmitted to Closehold or to any third party by the extension.
The extension uses your browser’s local storage to hold two things only: your on/off preferences and the local pairing state that links it to the desktop application. This contains no browsing history, no page content, and no prompts. There is no account, login, cookie, analytics SDK, advertising identifier, or cross-site tracker in the extension.
Where processing happens
Core detection runs locally — on your own machine, or, for organizations that choose it, on infrastructure the organization itself operates. In the organization-hosted mode, prompts are processed by a server the organization controls inside its own network (device → organization server → nothing); they are never sent to Closehold and never sent to a public cloud. Closehold’s local AI models run entirely on the device or the organization’s server.
What we never store
Closehold does not store raw sensitive values: not in logs, not in audit events, not in data-flow records, not in any default storage. Where we need to record that a crossing happened — for your own audit trail — we keep only classifications (for example, “a person’s name was protected”), counts, and salted, one-way hashes and token references that describe the shape and flow of data. The original value cannot be recovered from these records. In Closehold’s own terms, the raw value is never stored.
Reversible protection and encryption
So that your real values can be restored into an AI’s reply, Closehold keeps a local mapping between a placeholder and the value it stands for. This mapping lives only on your device. When it is persisted, it is encrypted at rest with AES-GCM, with the key held in your operating system’s keychain. It is never synced to us, and it is removed when you clear Closehold’s data or uninstall the application.
AI providers
When you use an AI tool through Closehold, that provider receives the protected version of your prompt — with sensitive values already replaced — not your original content. Closehold does not send AI providers anything beyond the protected prompt you were already sending them. How a provider handles the protected prompt it receives is governed by that provider’s own privacy policy; the purpose of Closehold is to ensure the provider never sees the raw values in the first place.
Optional cloud and organization features
Some features are optional and off unless you or your organization enable them — for example, a hosted data-flow graph or organization-wide administration. When enabled, these receive only de-identified signal: classifications, counts, and salted hashes. They never receive raw sensitive values or the content of your prompts. Administrative dashboards are payload-free by design: an administrator can see that (for example) a category of data was protected and how often, never the data itself.
Extension permissions
The extension requests only the permissions its function requires:
storage — your on/off preferences and the local pairing state. No content, no browsing data.
nativeMessaging — to pair with the Closehold desktop application on your own machine, which is where content is processed. This is the core of the privacy model.
declarativeNetRequest — to ensure a file upload to an AI service carries the protected copy rather than the original. Scoped to the supported AI sites.
alarms — to periodically re-check whether the desktop application is still running. No network activity.
Host access (127.0.0.1 and the supported AI sites) — 127.0.0.1 is your own Closehold application, the only place content is sent for analysis. The AI-site access lets the extension read the prompt you are about to send, protect it, and restore values in the reply, on those sites only.
Data retention
We retain no content from your AI conversations, because none of it reaches us. Data created by Closehold — your preferences, the local reversible mappings, local audit records, and downloaded local AI models — lives on your device until you clear it or uninstall. Uninstalling the desktop application removes the local AI models and reversible mappings it created.
Security
Processing happens locally, which removes the largest privacy risk — sending sensitive content to a third party — entirely. The browser extension authenticates to the local application with a per-install pairing token, so an arbitrary web page cannot call it. Persisted mappings are encrypted at rest. Closehold is designed to fail toward protection: if it cannot scan content, it does not silently let that content through.
Your choices
You can turn protection on or off at any time from the extension.
You can clear Closehold’s local data, or uninstall the application, to remove the data it created on your device.
Organizations evaluating or deploying Closehold can request a Data Processing Agreement (DPA).
For any request regarding data Closehold may hold about you, contact us using the details below. Because Closehold is designed so that your content stays on your own device, in most cases we do not hold personal data about you to begin with.
Children’s privacy
Closehold is a workplace and productivity tool. It is not directed to children under 16, and we do not knowingly collect personal information from children.
International users
Because core processing is local to your device or your organization’s infrastructure, your prompt content does not cross a border to reach Closehold — it does not reach Closehold at all. Where optional cloud features are enabled, only de-identified signal is involved.
Changes to this policy
We may update this policy as Closehold evolves. When we do, we will revise the “Last updated” date above and post the new version at this address. Material changes will be made clear.
Contact
Questions about this policy, a data request, or a Data Processing Agreement (DPA)? Email privacy@closehold.ai, or use our contact form.