← Back to HomePrivacy Policy
Last updated: July 29, 2026
1. What HideMyDoc Does
HideMyDoc is a Chrome extension and companion web app that anonymizes sensitive information in your documents before you share them with third-party AI chatbots (ChatGPT.com, Claude.ai, and Gemini). The extension replaces identifiable data—such as names, organizations, numbers, dates, and custom terms—with placeholders, and reverses the mapping locally when displaying AI responses back to you.
2. Processing That Happens Only on Your Device
The extension's core document pipeline runs entirely in your browser. The following data never reaches our servers:
- Your original files. File reading and text extraction (including PDF processing) happen locally inside the extension. Raw files are never uploaded to us, and the extension is designed to prevent them from being uploaded to the AI chat platform itself.
- Anonymization. Sensitive-term detection and placeholder substitution run locally in the extension.
- Placeholder mappings. The mapping between placeholders and original values is stored only in your browser—in the extension's sandboxed Chrome storage and, if you use the web app, in your browser's local database (IndexedDB) for the web app. It is never transmitted to our servers.
- De-anonymization. Restoring original values inside AI responses happens locally on the page.
3. Data We Collect on Our Servers
3.1 Account Information
When you create an account, your email address and password are managed by Supabase Auth (passwords are hashed; we never see them). A session token (JWT) is stored in your browser and synced between the web app and the extension so you only have to sign in once. It is used solely to authenticate you.
3.2 Onboarding Profile
During sign-up we may ask for your name, position/title, industry, intended use case, and how you heard about us. This information is stored with your account and used to understand who uses HideMyDoc and to improve the product. Providing it is optional, and you can request its deletion at any time (see Section 8).
That is the complete list. Account sign-in and the onboarding survey are the only things our server-side infrastructure is used for. Your documents and their contents are never part of it.
4. Sites the Extension Accesses, and Why
- ChatGPT.com, Claude.ai, Gemini: The extension injects its controls into the chat interface, swaps placeholders in the composer and in AI responses, and blocks raw file drops so originals aren't accidentally uploaded. This processing is local; page content is not sent to our servers.
- ChatGPT Custom Instructions: With your action, the extension can read and update your ChatGPT Custom Instructions (using your existing ChatGPT session) to add rules that tell ChatGPT how to handle placeholders. This is a direct browser-to-OpenAI interaction; the content does not pass through our servers.
- The HideMyDoc web app: Used to sync your sign-in session and your saved (already-anonymized) documents between the web app and the extension, locally within your browser.
5. Data We Do NOT Collect
- We do not collect browsing history or web activity outside the sites listed above.
- We do not receive your documents in any form—original or anonymized—or your placeholder mappings. We operate no document-processing servers; anonymization runs entirely in the extension on your device.
- We do not log keystrokes, mouse movements, or clicks.
- We do not use analytics, tracking pixels, or third-party tracking scripts in the extension.
6. Third-Party Services
- Supabase: Authentication and account storage (email, hashed password, onboarding profile).
- Vercel: Hosts the HideMyDoc web app.
- ChatGPT.com (OpenAI), Claude.ai (Anthropic), Gemini (Google): You interact with these platforms directly through their own interfaces. Anonymized text you choose to send them is governed by their privacy policies.
7. Data Storage & Security
- Documents, mappings, and cached data live in Chrome's extension storage and your browser's IndexedDB, both sandboxed to your device.
- All communication with Supabase (authentication and the onboarding survey) occurs over HTTPS.
- Authentication tokens are sent via Authorization headers, not stored in URLs.
8. Data Retention & Deletion
Document content and anonymization mappings exist only in your browser. You can delete them at any time by removing individual documents in the extension or web app, clearing the extension's storage, or uninstalling the extension.
To delete your account, including your email and onboarding profile, contact us at the address below and we will remove it.
9. Remote Code
The extension does not load or execute any remote code. All JavaScript, including the Supabase client and PDF processing libraries, is bundled within the extension package.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the extension after changes constitutes acceptance of the revised policy.
11. Contact
If you have questions about this Privacy Policy or want to request data deletion, contact us at: hidemydoc@gmail.com