Privacy Policy

Last updated: August 25, 2026

Closehold is built on a simple principle: we protect your data by never holding it. Closehold detects sensitive information the moment before it would cross into an AI tool and replaces it with reversible placeholders — and it does this on your own device, not on our servers. This policy explains, in plain terms, what the Closehold browser extension, desktop application, and website do with data, and what they deliberately never do.

This policy covers the Closehold browser extension, the Closehold desktop application it pairs with, and closehold.ai. It applies to everyone who uses Closehold, including pilot and evaluation participants.

The short version

What the browser extension does

On the AI sites it supports (such as ChatGPT, Claude, Gemini, and Microsoft Copilot), the extension reads the prompt you are about to send and any files you attach, so it can protect confidential material in place before the prompt leaves your browser. When the AI’s reply comes back, the extension restores your real values in that reply so the conversation reads normally. The AI service never receives your original values; you never have to look at placeholders.

The extension is a thin bridge. It contains none of the detection, classification, or transformation logic itself — it hands content to the Closehold desktop application running locally on your machine, which does that work and hands back a protected version. The extension activates only on the AI surfaces it supports and does not read your general browsing.

The email advisory option

Closehold offers an opt-in email advisory for Gmail and Outlook on the web. It is off by default; you turn it on from the extension. When on, it reads the email draft you are writing — on your own device, via the same local application — and flags content that should probably not leave in an email (credentials, financial details, government identifiers, health information, confidential business content) before you press send. It is advisory only: it never rewrites your email, and it never blocks one — when a draft is flagged, Closehold asks once before the send proceeds, and one click sends it unchanged. It never transmits your draft anywhere except to the Closehold application on your own machine. Ordinary email content — names, addresses, phone numbers — is deliberately not flagged. Typing and drafts are never recorded; when you make a send decision over a flagged draft, Closehold keeps only a payload-free record (categories and counts — never your text, never an address). When the option is off, the extension does not read your mail at all.

What we collect — and what we don’t

Content you send to AI tools is transmitted only to your own device (127.0.0.1) for local processing. It is not transmitted to Closehold or to any third party by the extension.

The extension uses your browser’s local storage to hold two things only: your on/off preferences and the local pairing state that links it to the desktop application. This contains no browsing history, no page content, and no prompts. There is no account, login, cookie, analytics SDK, advertising identifier, or cross-site tracker in the extension.

Where processing happens

Core detection runs locally — on your own machine, or, for organizations that choose it, on infrastructure the organization itself operates. In the organization-hosted mode, prompts are processed by a server the organization controls inside its own network (device → organization server → nothing); they are never sent to Closehold and never sent to a public cloud. Closehold’s local AI models run entirely on the device or the organization’s server.

What we never store

Closehold does not store raw sensitive values: not in logs, not in audit events, not in data-flow records, not in any default storage. Where we need to record that a crossing happened — for your own audit trail — we keep only classifications (for example, “a person’s name was protected”), counts, and salted, one-way hashes and token references that describe the shape and flow of data. The original value cannot be recovered from these records. In Closehold’s own terms, the raw value is never stored.

Reversible protection and encryption

So that your real values can be restored into an AI’s reply, Closehold keeps a local mapping between a placeholder and the value it stands for. This mapping lives only on your device. When it is persisted, it is encrypted at rest with AES-GCM, with the key held in your operating system’s keychain. It is never synced to us, and it is removed when you clear Closehold’s data or uninstall the application.

AI providers

When you use an AI tool through Closehold, that provider receives the protected version of your prompt — with sensitive values already replaced — not your original content. Closehold does not send AI providers anything beyond the protected prompt you were already sending them. How a provider handles the protected prompt it receives is governed by that provider’s own privacy policy; the purpose of Closehold is to ensure the provider never sees the raw values in the first place.

Optional cloud and organization features

Some features are optional and off unless you or your organization enable them — for example, a hosted data-flow graph or organization-wide administration. When enabled, these receive only de-identified signal: classifications, counts, and salted hashes. They never receive raw sensitive values or the content of your prompts. Administrative dashboards are payload-free by design: an administrator can see that (for example) a category of data was protected and how often, never the data itself.

Extension permissions

The extension requests only the permissions its function requires:

Data retention

We retain no content from your AI conversations, because none of it reaches us. Data created by Closehold — your preferences, the local reversible mappings, local audit records, and downloaded local AI models — lives on your device until you clear it or uninstall. Uninstalling the desktop application removes the local AI models and reversible mappings it created.

Security

Processing happens locally, which removes the largest privacy risk — sending sensitive content to a third party — entirely. The browser extension authenticates to the local application with a per-install pairing token, so an arbitrary web page cannot call it. Persisted mappings are encrypted at rest. Closehold is designed to fail toward protection: if it cannot scan content, it does not silently let that content through.

Your choices

Children’s privacy

Closehold is a workplace and productivity tool. It is not directed to children under 16, and we do not knowingly collect personal information from children.

International users

Because core processing is local to your device or your organization’s infrastructure, your prompt content does not cross a border to reach Closehold — it does not reach Closehold at all. Where optional cloud features are enabled, only de-identified signal is involved.

Changes to this policy

We may update this policy as Closehold evolves. When we do, we will revise the “Last updated” date above and post the new version at this address. Material changes will be made clear.

Contact

Questions about this policy, a data request, or a Data Processing Agreement (DPA)? Email privacy@closehold.ai, or use our contact form.