Privacy Policy

Last updated: September 17, 2026

This policy explains how PHI Mask and phimask.com process data. PHI Mask is an independent project operated by PHIMask.com.

1. Scope

This policy applies to phimask.com, the online masker at /mask-data, the PHI Mask Chrome extension, license and pilot requests, security reports, support correspondence, and paid commercial or enterprise use of PHI Mask.

When a customer has a separate written agreement with PHIMask.com, that agreement controls if it says something different from this public policy.

2. Website, access, and feedback data

phimask.com uses PostHog for product analytics and privacy-configured session replay across the site, including /mask-data. PostHog may set cookies and capture page views, clicks, interface interactions, referrer, device and browser type, approximate location derived from IP address, and a PostHog-assigned visitor identifier. Session replay masks all text and inputs as asterisks and blocks images, SVG, video, iframe, and canvas content before anything is sent.

On eligible public marketing pages, /mask-data, and /tools/* pages, PHI Mask also uses the Reddit Pixel to measure entrance visits from Reddit advertising. It sends PageVisit and standard browser, referrer, and page URL signals to Reddit, but it does not receive pasted text, files, detected identifiers, filenames, or masking results; health-topic articles and other redaction routes are excluded.

On those same eligible routes, PHI Mask uses the OpenAI Ads Measurement Pixel to preserve ChatGPT ad attribution. The Pixel may store OpenAI's click reference (oppref) in a first-party cookie and send attribution, page path, referrer, and browser measurement signals to OpenAI. The current website integration calls only the SDK initialization command. It sends no conversion events or customer data, including pasted text, uploaded files, detected identifiers, filenames, or masking results.

When you use an offer link, PHIMask.com records the offer and approved campaign attribution needed to apply the offer and connect a completed purchase to that visit. Offer endpoints use the caller address transiently to enforce request limits; neither the address nor the temporary derived key is added to the offer-attribution collections. Those collections also exclude user agents, raw URLs, email addresses, Stripe customer IDs, payment-card data, and masking content. Standard infrastructure logs remain separate as described below.

The site and related feedback channels also receive data you choose to submit, plus standard infrastructure logs. You can opt out of PostHog analytics through your browser's tracking controls or by blocking analytics cookies. You can prevent Reddit and OpenAI advertising measurement by blocking their scripts or network requests. Opting out does not affect access to the site.

The Chrome extension does not load PostHog code, session replay, the Reddit Pixel, the OpenAI Ads Measurement Pixel, or the public-use meter. When daily totals are enabled, a PHIMask.com server forwards only the daily summary described below to PostHog. After you open feedback, a hidden delivery frame sends only the rating and optional comment you choose, not masking content.

  • License, pilot, and enterprise requests: name, work email, company, team-size selection, expected masking-volume selection, compliance selections, and any message you submit.
  • Security reports and support: reporter contact details, affected area, summary, details, and related correspondence you submit through private channels.
  • Product feedback and issue reports: the rating and optional comment you submit, an optional reply email, and the current masked/redacted result only when you select the attachment option. PHI Mask does not include your original input, original file, filename, detected real values, or reversible placeholder map.
  • PHI Mask free-use meter: IP address, request timestamp, user agent, request path, standard request metadata needed to count public free uses, and two yes/no device-state flags (whether the page load was a reload and whether the tab observed the browser offline) used only to decide whether offline loading is worth building. Pasted text, files, masked output, detected identifiers, and file metadata are not sent for this meter.
  • Content-free masker session summary: aggregate document and detection-category counts, manual-mask count, a duration bucket, detector version, locale, copy/download/restore flags, and an unexpected-request count. It does not include text, filenames, mappings, or per-value data. The summary is sent to PostHog only after the tab leaves the masking route; a local buffer may hold it for up to 14 days so closing the tab does not lose it.
  • Offer-link attribution: a bounded offer code, opaque attribution ID, approved partner and campaign identifiers, allowlisted UTM values, and timestamps. After a verified purchase, the matching record may also contain Stripe Checkout, subscription, and promotion identifiers; billing period and currency; and subtotal, discount, and total summaries.
  • Paid checkout: Stripe collects the billing identity, address, payment method, and transaction data you enter in its hosted Checkout. PHIMask.com receives the subscription, invoice, payment status, and license details needed to provide and administer the purchase.
  • Standard hosting logs: IP address, user agent, request path, and request timestamp, kept for abuse prevention, security, reliability, and debugging.
  • Reddit advertising measurement: PageVisit events and standard browser, referrer, and page URL signals on eligible public marketing pages, /mask-data, and /tools/* pages.
  • OpenAI advertising measurement: SDK initialization and attribution signals, including the OpenAI click reference (oppref) when present, page path, referrer, and browser measurement data on eligible public marketing pages, /mask-data, and /tools/* pages. The current website integration sends no conversion events or customer data.

3. Online masking at /mask-data

The online masker processes pasted text and uploaded files in the active browser tab. Masking itself does not send PHIMask.com your pasted text, uploaded files, masked output, detected identifiers, file metadata, or the placeholder mapping used to reverse the swap. Reloading or closing the tab ends that masking session.

If you copy masked text into ChatGPT, Claude, an API model, or another model provider, that provider relationship is separate from PHI Mask unless your written agreement says otherwise.

4. Chrome extension data

License activation and renewal send your key, extension version, coarse browser and operating system, and preferred browser language to our licensing service. We keep weekly aggregate counts to understand platform health and language demand, without storing these signals against your key or customer record. These counts do not include masking content, a persistent installation ID, or location. They are separate from optional daily masking totals.

Chrome 0.4.2 adds optional daily usage summaries: counts of text masks, PDFs masked, images uploaded, images pasted, and detector-load failures, together with the local calendar day, extension version, and a random report ID that changes each day. No text, files, detected categories, websites, filenames, account details, persistent browser ID, or exact activity times are included. Private-window activity is excluded. Firefox does not send these summaries.

Send daily totals is on by default outside Europe and opt-in for Europe or uncertain browser signals. The default uses the browser's language-region and timezone, not a location lookup, and does not change your masking settings. You can change the choice in the toolbar popup and inspect the actual messages waiting to send. Turning it off deletes unsent reports. It does not affect masking or license activation.

A completed day's summary is sent on the next ordinary extension activity, not at a scheduled midnight wake-up. Up to four completed reports wait locally for delivery. Retries reuse the same report ID; reports older than 14 days are discarded. Existing local masking statistics are never uploaded. Reports are not linked to license keys or website analytics identities.

On a website you allow PHI Mask to cover, the extension handles the clipboard, paste, drag-and-drop, upload, composer, and supported reply content needed to mask values and restore placeholders. It processes that content locally. It does not send clipboard contents, files, source text, masked output, detected values, or recovery pairs to PHIMask.com.

Full source text, full masked text, live swap maps, and selected files stay in extension memory. Closing or reloading the frame ends that current-frame state.

The active frame keeps the source text and local detection result for up to three delivered text pastes so exact repeats do not need another detection pass. A conversation change, access or masking-profile reset, navigation, or tab close clears this cache.

Up to five recent original-and-masked recovery copies may remain in the active frame for 30 seconds so an interrupted paste can be recovered.

All JavaScript, WebAssembly, OCR workers, OCR cores, language data, and feedback-form code that can access extension APIs are included in the extension package and loaded from its chrome-extension:// origin. The extension has no CDN fallback and does not fetch code to execute. A hidden sandboxed delivery frame on phimask.com cannot access extension APIs or masking content.

  • clipboardRead: while a covered site's composer is focused, the extension may read clipboard text or an image to prepare local masking before a paste. The active frame keeps the source text and local detection result for up to three delivered text pastes so exact repeats do not need another detection pass. A conversation change, access or masking-profile reset, navigation, or tab close clears this cache. Clipboard contents are not sent to PHIMask.com. Only placeholder and original-value pairs actually delivered in a supported conversation may enter the recovery record described below.
  • scripting and host access: load the bundled masking engine only on the supported assistant hosts over HTTPS. The extension uses page content needed for masking, delivery, and supported reply restoration. It does not create or transmit a browsing-history or keystroke log.
  • chrome.storage.local: keeps fixed settings and extension lifecycle state, including website coverage, masking profile, use choice, setup progress, installation time, and first successful mask time. It does not keep clipboard contents, files, source text, masked output, filenames, or page content.
  • chrome.storage.local masking counts: a separate record keeps whole-number totals of values masked and values you chose to show, counted by category, with per-day totals for the last 90 days and the date counting started. It holds no detected values, placeholders, filenames, websites, or page content, and it is not sent to PHIMask.com. Clearing the extension's local data through Chrome removes it.
  • Extension localStorage: the file-review surface may remember fixed automatic-masking category and profile choices. It does not store document content or detected values.
  • chrome.storage.session: on supported, non-Incognito ChatGPT and Claude conversations, keeps the delivered placeholder and original-value pairs, the exact site origin, a canonical conversation identifier, and timestamps needed to restore replies after a reload. These records expire after up to 24 hours of inactivity or when Chrome ends the extension session, whichever happens first. Forget this chat and Forget all chats remove them earlier. Unsupported pages and Incognito remain current-frame only.

5. What PHIMask.com receives from masking

PHIMask.com does not receive your text, files, detected values, or recovery mappings from masking. It receives the content-free website summaries described in section 2 and, when enabled, the extension's daily usage summaries described in section 4. If you submit masked content on another website, that website receives what you chose to submit under its own terms. Feedback and issue reports send only what you deliberately submit; attaching a masked result is off by default.

6. How we use website and support data

  • Responding to license, pilot, and enterprise requests about evaluation, commercial, or enterprise access.
  • Operating the public free-use meter, preventing abuse, securing the site, debugging reliability issues, and preparing support follow-up.
  • Understanding how phimask.com pages, including /mask-data, are used through privacy-configured PostHog analytics and session replay so we can improve navigation, onboarding, and support.
  • Preserving ChatGPT ad attribution for campaign reporting.
  • Applying approved offers, attributing offer visits to campaigns or partners, confirming completed purchases, and administering subscriptions and licenses.
  • Improving PHI Mask documentation, access flows, support workflows, and product behavior.
  • We do not use feedback data, diagnostic data, prompts, code, files, masked content, or customer content to train foundation models.

7. Chrome Web Store Limited Use

PHI Mask's use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses that information to provide its masking, delivery, reply-restoration, website-coverage, and preference features. Optional content-free daily summaries help us measure use and detector-load reliability. We do not sell this information, use it for advertising or credit decisions, or transfer it for unrelated purposes. Masking content is not sent for human review.

8. Privacy safeguards

We use safeguards intended to protect user and customer data, including limited retention periods for sensitive information, restricted access to private submissions, role-based production access, encryption in transit, encryption at rest where supported by our infrastructure providers, and policies against using feedback for model training.

9. Sharing and subprocessors

We do not sell, rent, or trade your information. We share website and support data only with service providers needed to operate PHI Mask, with your organization if you use PHI Mask under an organization license, and with authorities when required by law. Chrome extension masking content and recovery pairs are not shared with these service providers.

  • Google Cloud Platform: hosting, storage, database, security, and logging infrastructure.
  • Stripe: hosted Checkout, offer-eligibility checks, payment processing, subscription and invoice administration, and billing records.
  • PostHog: product analytics and privacy-configured session replay across phimask.com, including /mask-data; replay text and inputs are masked as asterisks and visual media/canvas are blocked.
  • Reddit: advertising measurement through the Reddit Pixel on eligible public marketing pages, /mask-data, and /tools/* pages.
  • OpenAI: Ads Measurement Pixel for ChatGPT campaign attribution on eligible public marketing pages, /mask-data, and /tools/* pages. The current website integration sends SDK initialization and attribution signals, not conversion events or customer data.
  • Resend: private transactional email delivery for access, support, security, and product issue reports, including an optional masked/redacted attachment you explicitly submit.
  • Slack: internal operational notifications for access requests, support, and security reports.

10. Retention and deletion

Daily extension report records in our database are set to expire after 90 days. Aggregate totals are retained indefinitely. PostHog receives the content-free summaries for product-use and reliability trends; its analytics retention is separate from the database expiry. IP-keyed request-limit records are kept separately and set to expire after one hour. Hosting infrastructure may retain connection metadata under its separate logging policy; IP addresses are never added to report rows or forwarded to PostHog.

Chrome extension settings remain in chrome.storage.local until you change them, clear the extension's data, or uninstall it. Current-frame masking data ends with the frame. Supported conversation recovery records remain in chrome.storage.session for up to 24 hours of inactivity or until Chrome ends the extension session, and the toolbar popup can remove them earlier. A content-free /mask-data session summary may remain in the site's local buffer for up to 14 days and is removed when it is flushed or rejected as expired.

Offer-visit attribution records are set to expire after 90 days. Verified offer-conversion records are set to expire after 730 days. Stripe subscriptions, invoices, payment records, and related PHI Mask billing or license records follow the separate retention required for account administration, accounting, dispute handling, security, and legal obligations.

License, pilot, enterprise, support, security-report, and product-issue records are retained while we respond to, support, or improve the service, then deleted or archived when they are no longer needed. Free-use meter metadata and hosting logs are retained only as long as needed for abuse prevention, security, reliability, and debugging unless a longer period is legally required.

You can ask us to delete access-request data, support records, security-report submissions, or product-issue reports unless we need to keep them for security, legal, abuse-prevention, accounting, or contractual reasons. Deletion requests are completed within 30 days where legally and operationally possible.

11. Your choices and rights

Turn off Send daily totals in the extension popup to stop future reports and delete unsent summaries. This cannot retract a request already received. Each day's random report ID is independent; we cannot look up a browser's reporting history by its account or license key.

You can change extension settings, reset masking counts, and delete conversation recovery records in the toolbar popup, or clear the extension's local data through Chrome. You can request access to, correction of, export of, or deletion of data held by PHIMask.com through the request form at https://phimask.com/#apply. We respond within 48 hours. Residents of the EEA, UK, California, and Canada may exercise their GDPR, CCPA, and PIPEDA rights through the same form.

12. Commercial terms, changes, and contact

Commercial and enterprise use is also subject to PHI Mask's Commercial Terms of Service at https://phimask.com/commercial. Material changes to this policy are announced by email to affected contacts when appropriate, and the date above is updated. Questions: reach us through the request form at https://phimask.com/#apply.