Data Usage Policy
Last updated: August 31, 2026
This policy explains how PHIMask.com uses website and support data, and how the PHI Mask Chrome extension handles local data.
1. What this covers
This policy covers data used to operate phimask.com, /mask-data, and the PHI Mask Chrome extension; run the public free-use meter; apply and attribute offers; process purchases; answer license and pilot requests; handle security reports; support customers; improve reliability; and manage commercial access.
On the PHI Mask masker route, PHIMask.com may process minimal request metadata for the public free-use meter: IP address, request timestamp, user agent, request path, standard request metadata, and two yes/no device-state flags (whether the page load was a reload and whether the tab observed the browser offline) used only to decide whether offline loading is worth building. The meter does not receive pasted text, files, masked output, detected identifiers, or file metadata.
If your organization has a separate written agreement with PHIMask.com, that agreement controls where it says something different.
2. Public-use meter, site analytics, and offers
The public free-use meter counts public use of the masker without receiving pasted text, uploaded files, masked output, detected identifiers, file metadata, or the reversible mapping.
PostHog product analytics and privacy-configured session replay may run on all public site pages, including /mask-data. Replay masks all text and inputs as asterisks and blocks images, SVG, video, iframe, and canvas content.
The Reddit Pixel may measure content-free PageVisit events on eligible public marketing pages, /mask-data, and /tools/* pages. It is not loaded on health-topic articles or other redaction routes, and it does not receive pasted text, files, detected identifiers, filenames, or masking results.
Offer links use a separate first-party attribution record to validate the offer and connect a completed Stripe purchase to the originating campaign or partner. Offer endpoints use the caller address transiently to enforce request limits; neither the address nor the temporary derived key is added to the attribution collections. Those collections also exclude user agents, raw URLs, email addresses, Stripe customer IDs, card data, and masking content.
After the tab leaves /mask-data, PostHog may receive one content-free session summary with aggregate document and detection-category counts, manual-mask count, a duration bucket, detector version, locale, copy/download/restore flags, and an unexpected-request count. A local buffer may hold that summary for up to 14 days.
- Free-use meter metadata: IP address, request timestamp, user agent, request path, standard request metadata needed for counting, abuse prevention, security, reliability, and debugging, and two yes/no device-state flags (whether the page load was a reload and whether the tab observed the browser offline) used only to decide whether offline loading is worth building.
- Product analytics: page views, clicks, other interface interactions, referrer, device and browser type, approximate location derived from IP address, and a PostHog-assigned visitor identifier on non-masker pages.
- Offer attribution: a bounded offer code, opaque attribution ID, approved partner and campaign identifiers, allowlisted UTM values, and timestamps. After a verified purchase, it also includes matching Stripe object identifiers, billing period and currency, and subtotal, discount, and total summaries.
- Paid checkout: the billing identity, address, payment method, and transaction data entered in Stripe's hosted Checkout, plus the subscription, invoice, payment status, and license details returned to PHIMask.com for administration.
- License and pilot requests: name, work email, company, team-size selection, expected masking-volume selection, compliance selections, and any message you submit.
- Security reports and support: reporter contact details, affected area, summary, details, and related correspondence you submit.
- Product issue reports: submitted notes, an optional reply email, and an optional current masked/redacted result when you explicitly select the attachment option.
- Standard hosting logs: IP address, user agent, request path, and request timestamp.
3. Chrome extension data
The Chrome extension does not run PostHog, the Reddit Pixel, the public-use meter, or PHIMask.com logging. It processes clipboard, file, composer, and supported reply content locally and does not send that content or extension analytics to PHIMask.com.
chrome.storage.local holds fixed settings and lifecycle state. On supported, non-Incognito ChatGPT and Claude conversations, chrome.storage.session may hold delivered placeholder and original-value pairs plus conversation scope and timestamps for up to 24 hours of inactivity or until Chrome ends the extension session. The toolbar popup can remove these records earlier.
chrome.storage.local also holds a separate masking-counts record: whole-number totals of values masked and values you chose to show, counted by category, with per-day totals for the last 90 days. These counts stay on the device and are not sent to PHIMask.com.
4. Data PHIMask.com does not receive from masking
PHIMask.com does not receive pasted text, uploaded files, masked output, detected identifiers, file metadata, or recovery mappings from /mask-data or the Chrome extension. Issue reports send the notes and optional masked/redacted result you choose to submit, never the original input, filename, detected real values, or recovery map.
5. How we use website and support data
We use the data described here to apply approved offers, attribute visits and verified purchases, process and administer subscriptions and licenses, respond to license, pilot, enterprise, support, security, and product issue reports, operate the free-use meter, prevent abuse, secure the site, debug reliability issues, and improve PHI Mask pages and documentation.
- We do not use feedback, prompts, code, files, masked content, diagnostics, or customer content to train foundation models.
6. Access, sharing, and retention
Access to private submissions and operational metadata is restricted to authorized personnel and service providers who need it to operate, secure, support, or improve PHI Mask. We do not sell, rent, or trade this data.
Offer-visit attribution records are set to expire after 90 days, and verified offer-conversion records are set to expire after 730 days. Stripe and PHI Mask billing, subscription, invoice, and license records follow the separate retention required for account administration, accounting, disputes, security, and legal obligations.
License, pilot, enterprise, support, security-report, and product-issue records are retained while we respond to, support, or improve the service, then deleted or archived when they are no longer needed. Free-use meter metadata and hosting logs are retained only as long as needed for abuse prevention, security, reliability, and debugging unless a longer period is legally required.
7. Related policies
For privacy safeguards and rights requests, see https://phimask.com/privacy. For commercial or enterprise use, see https://phimask.com/commercial. Questions: reach us through the request form at https://phimask.com/#apply.