PRIVACY ARCHITECTURE

The prompt stays inside.

ReDLP is designed around a precise boundary: inspect sensitive content locally, enforce policy before transmission, and send only the operational metadata administrators need.

ZERO PROMPT CONTENT

Evidence that policy worked does not require a copy of the content.

ReDirective processes necessary tenant, device, user, policy, health, and event metadata. “Zero Prompt Content” describes what the control plane is designed not to receive—not an inaccurate claim that the service knows nothing.

The endpoint makes the content decision. The cloud supports administration, integrity, health, and metadata-only evidence.

DESIGNED NOT TO TRANSMIT
  • Prompt text or prompt snippets
  • Password or API-key values
  • Access tokens or private-key material
  • Source code or trade-secret text
  • Uploaded file contents
  • Original replaced text
  • Transformed prompts
  • Clipboard or general browser contents
PERMITTED OPERATIONAL METADATA
  • Tenant, device, and pseudonymous user identifiers
  • Policy, publication, rule, and sequence identifiers
  • AI application and adapter version
  • Action and detection category
  • Timestamp, health, queue depth, and support reference
  • Authentication and lifecycle outcomes
  • Agent, service, and protocol versions
  • Administrative audit metadata
SEPARATE PATHS

Content is evaluated locally. Metadata follows a different channel.

ENDPOINT CONTENT PATHIntent → local policy → safe outcomePrompt content: NOT PRESENT in ReDirective cloud
CONTROL-PLANE PATHSigned policy ↔ health + eventsClosed operational schemas only
BROWSER EXTENSION DATA USE

Local enforcement at the moment of submission.

Last updated July 23, 2026

The ReDLP Browser Extension has one purpose: apply organization-defined data-protection policy locally before a user submits content to a supported AI website. It operates only on ChatGPT, Claude, Gemini, and Microsoft Copilot browser applications.

When a user clicks Send or presses Enter, the extension reads the current AI composer, pauses the submission, and sends the content through Chrome Native Messaging to the locally installed ReDLP Agent for evaluation. It does not continuously record keystrokes or collect unrelated browsing activity.

Data processed locally

  • Website content the user attempts to submit to a supported AI application
  • Personal identifiers, authentication information, or personal communications when present in that submission
  • The transformed submission only when policy requires Redact or Replace
  • Content-free application mode and fail-open or fail-closed posture

Data not collected by the extension

  • General web history or activity on unsupported websites
  • Health, financial, location, advertising, or creditworthiness profiles
  • Prompt histories, analytics profiles, or content for model training
  • Passwords, credentials, matched values, or prompts for ReDirective cloud storage
WHY PERMISSIONS ARE REQUIRED
  • Site access: locate the composer and gate submission on the four supported AI websites.
  • Native messaging: request a decision from the local ReDLP Agent.
  • Storage: retain only bounded, content-free application mode, failure behavior, and expiration metadata for safe fallback behavior.
  • Network rules: block a narrowly scoped ChatGPT preparation route that can transmit composer fragments before the normal submission event.
  • Management: call getSelf() only to report whether ReDLP itself was installed normally, by an administrator, or for development.
  • Alarms: run a five-minute, content-free local health heartbeat.
USE, SHARING, AND RETENTION
  • The extension contains no remote executable code, advertising, or behavioral analytics.
  • ReDirective does not sell extension data or use it for advertising, lending, creditworthiness, or purposes unrelated to local policy enforcement.
  • The extension does not transmit prompt content to the ReDirective control plane or to third parties.
  • After an Allow, approved Warn, or Replace decision, the AI provider receives only the submission the user chose to send; a Block decision releases nothing.
  • Content-free posture remains in browser-local storage and is ignored after its signed expiration time. Removing the extension clears its local storage under browser control.
  • Administrative events contain closed operational metadata such as application, action, category, policy sequence, endpoint, timestamp, and support reference.

ReDLP's use of browser data is limited to providing and improving its single stated enforcement purpose. Data is not transferred for personalized advertising, unrelated analytics, human review outside an authorized security or support purpose, or sale to data brokers.

Questions or deletion requests concerning ReDirective-controlled account and operational metadata can be submitted through the privacy review form. Content intentionally sent to an AI provider is governed by that provider and the user's or organization's agreement with it.

TRACE THE BOUNDARY

Review the privacy model against your requirements.

Bring your data classes, logging standards, endpoint assumptions, and prohibited-content rules.