Plain-language policy

Your page stays yours.

Privacy Lens works on the page already open in your browser. Most features never send page content anywhere. Optional image screening is clearly separated and stays off until you enable it.

Effective August 4, 2026 · Privacy Lens 0.5

Who and what this covers

This policy covers the Privacy Lens browser extension, its product and documentation pages, and the optional image-classification connection. Wiplash AI produces Privacy Lens.

If you configure another company’s classifier, that company’s policy also applies to the image request it receives.

Information the extension handles

Privacy Lens reads visible page text, values in form and editable fields, page elements, open tab titles and URLs, and the settings you choose so it can apply the controls you request. This processing stays in your browser and does not send that information to Wiplash.

If you contact support, Wiplash receives the contact details and message you choose to provide.

What runs locally

Privacy Lens checks visible text and form values for the secret types and custom rules you select, including contact details, payment-card numbers, and supported Bitcoin and crypto key formats. It applies blur, image covers, text redactions, field covers, and tab-title changes inside your browser.

Field protection is visual: Privacy Lens does not replace, submit, store, or transmit the value the page receives. There is no account, analytics SDK, advertising SDK, or browsing-history sync.

What is stored

The extension uses browser storage for your settings, custom terms, custom regex rules, optional API configuration, widget position, and any site rules you choose to remember. Protected tab selections may also be held in browser session storage.

These settings stay until you change or reset them, remove them through browser controls, or uninstall the extension.

Optional image screening

Image screening is disabled by default. If you enable it, the extension downloads a page image, rasterizes it to JPEG, limits the longest edge to 512 pixels, and sends that compressed image to the endpoint shown in Settings.

The endpoint operator may receive the compressed image, your IP address, request timing, and any bearer token you configure. The extension does not add the page URL, page title, page text, tab ID, browsing history, or redaction rules to that request.

The Wiplash classifier processes image bytes in memory and does not retain them. It may keep a short-lived, process-local verdict under a salted image fingerprint so repeated copies of the same image do not need to be classified again. The fingerprint cannot be used to reconstruct the image and disappears when the service restarts. If you choose another endpoint, its operator controls its own retention and privacy practices.

How information is used

Local page information is used only to find selected secrets, draw privacy effects, manage protected tabs, restore the page, and remember rules you ask the extension to save.

Optional image bytes are used only to return a safe or unsafe score. Support messages are used to answer the request and investigate reported problems.

Sharing and service providers

Privacy Lens does not sell personal information or share it for targeted advertising. Local page data is not provided to Wiplash or an analytics company.

When image screening is enabled, the configured endpoint operator receives the request described above. Wiplash may also disclose information if required by law or to protect users and the service, subject to applicable law.

Your choice is the basis

The extension’s optional image transfer starts only after you enable the feature. You can withdraw that choice at any time by turning image screening off. Other page controls run at your request and store settings you choose.

Transfers and location

Local extension data stays in the browser profile managed by your browser and device. An optional classifier request goes wherever the configured endpoint is hosted. Check that operator’s location and transfer terms before using it with sensitive images.

Retention

The Wiplash classifier holds an uploaded image only in memory while producing a verdict and does not log or retain the image bytes. Cached verdicts use salted fingerprints in process memory and are discarded on expiry or service restart. A custom endpoint sets its own retention period.

Support correspondence may be retained as needed to answer the request, maintain security records, and meet legal obligations.

Browser permissions

  • Storage saves the preferences and site rules described above.
  • Tabs lets you select tab titles to disguise and restore.
  • Website access lets Privacy Lens apply reversible privacy effects to ordinary HTTP and HTTPS pages.

Your controls and rights

You can restore the current page from the widget, remove remembered site rules, clear individual custom rules, or reset every setting from the Settings page. Removing the extension removes its extension-managed local storage under the browser’s normal removal behavior.

Depending on where you live, you may also have rights to ask about, correct, delete, restrict, or receive personal information held by Wiplash, and to complain to a privacy regulator. Contact support to make a request.

Cookies and tracking

The local product, privacy, API documentation, and demo pages included in this repository set no cookies and contain no analytics or advertising trackers. Links to other sites are governed by those sites’ policies.

Security and limits

Privacy Lens is a presentation aid, not an access-control system. It changes what is rendered on screen but does not encrypt the page or change the source data. Review a page before sharing it, especially when a site uses unusual rendering or browser-owned UI.

Children

Privacy Lens is not directed to children. The optional classifier is intended for adults configuring privacy controls, and the demo may contain fictional adult-styled material. Do not use the optional transfer for a child’s image without the authority and consent required by law.

Changes and contact

If this policy changes materially, the effective date above will change and the updated policy will be included with the product. For questions or rights requests, email support@wiplash.ai or contact Wiplash through wiplash.ai.