Pastes a stack trace into ChatGPT. Doesn't notice it contains an AWS access key. The key is now in OpenAI's logs.
A free Chrome extension that masks API keys, passwords, SSNs, and credit cards locally in your browser — before they ever reach ChatGPT, Claude, Gemini, Perplexity, or Copilot.
Install free for ChromeNo backend. No database. No analytics. No telemetry. No account. We never see what you type, what's detected, or what the AI returns. Everything happens locally, on your device.
Most don't realize where it goes, who can read it, or whether it becomes training data. Here's what happens at every company, every day.
Pastes a stack trace into ChatGPT. Doesn't notice it contains an AWS access key. The key is now in OpenAI's logs.
Asks ChatGPT to summarize a patient note. The patient's SSN and full name go to a third party with no HIPAA agreement.
Drops an employee complaint into Claude for help drafting a response. Salary, names, and grievances are now in someone else's system.
Pastes a tax return for ChatGPT to "explain in plain English." Bank account numbers and tax IDs leave the firm.
You paste content into ChatGPT, Claude, Gemini, Perplexity, or Copilot like you always do.
AI Leak Guard scans your paste in your browser. If it finds sensitive data, it replaces those parts with safe placeholders like [SSN] or [AWS_KEY].
The AI tool receives the masked version. Your sensitive data never leaves your device.
We start with sensitive data where missing the detection is costly and false positives are rare. More categories will arrive as opt-in detection packs.
These create too many false positives at this version. We may add opt-in detection packs for these in future releases.
Not VC-funded. Not data brokers. Not building toward acquisition. Just small, focused tools that respect your data — built the way we'd want them built if they ran on our own systems.
View the source on GitHubYes. AI Leak Guard is free for individuals and will stay free. We may eventually offer a paid team version with dashboards and policies, but the individual extension stays free.
No. No backend, no analytics, no telemetry. The extension makes one daily outbound request to download updated detection patterns — it's one-way, no data goes the other direction. You can verify this in our open-source code.
Names and emails are common in normal conversation. Detecting them would create constant false positives that interrupt your workflow. We're starting with high-confidence categories (API keys, financial data, credentials) where the cost of NOT detecting is high and false positives are rare.
Click the Undo button on the toast notification when something is masked. The original text is restored. You can also disable the extension entirely from the popup if you want.
No. Detection runs on each paste, completes in under 5 milliseconds for typical content, and uses no network resources except the daily rules update. The extension is under 200KB total.
Chrome and Chromium-based browsers (Edge, Brave, Arc) currently work. Firefox and Safari support is planned but not yet available.
No account. No email. No tracking. Click install and the extension is on. You can disable it any time from the popup.
Install free for Chromegithub.com/zabcore/ai-leak-guard · MIT licensed