ClickNext AI Security Monitor

Chrome Extension — Privacy Policy

Document Information Effective Date: April 21, 2026  |  Last Updated: May 21, 2026  |  Version: 2.1.0

1. Overview

This Privacy Policy describes how the ClickNext AI Security Monitor Chrome Extension ("Extension") collects, uses, and protects information when installed and used by employees of ClickNext Co., Ltd. ("Company").

This Extension is an internal enterprise security tool. It is not intended for public consumer use. It is deployed exclusively by the Company's IT department to monitor AI tool usage across company-managed devices in compliance with corporate security policies.

1.1 Supported AI Platforms

As of version 2.0.0, the Extension monitors the following web-based AI platforms:

#PlatformURLCategory
1ChatGPTchatgpt.com / chat.openai.comChat AI
2Claudeclaude.aiChat AI
3Geminigemini.google.comChat AI
4Microsoft Copilotcopilot.microsoft.comChat AI
5DeepSeekchat.deepseek.comChat / Code AI
6Perplexityperplexity.aiSearch AI
7Grok (xAI)grok.comChat AI
8Mistralchat.mistral.aiChat AI
9Poepoe.comAI Aggregator
10HuggingChathuggingface.co/chatOpen-source AI
11NotebookLMnotebooklm.google.comResearch AI
12Google AI Studioaistudio.google.comDeveloper AI
13Meta AImeta.aiChat AI

The Extension does not monitor desktop AI applications (e.g., Cursor IDE, VS Code Copilot, Codex CLI) as these operate outside the browser environment.

⚠️ This extension is for authorized corporate use only. By installing this extension, users acknowledge they are using a company-managed device and consent to activity monitoring as described in this policy.

2. What Data Is Collected

The Extension collects the following information when employees interact with supported AI platforms:

Data TypeDescriptionPurpose
User Prompt Text Text submitted by the employee to any of the 13 supported AI platforms listed above Security scanning for data leakage prevention (DLP)
User Identity Employee's Google Workspace email address (via Chrome Identity API) Audit trail and user attribution
Device Information Device identifier / computer name Asset tracking and security correlation
AI Platform Name of AI service being accessed (e.g., ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Grok, Mistral, Poe, HuggingChat, NotebookLM, AI Studio, Meta AI) Activity reporting
Timestamp Date and time of AI interactions Audit log and monthly reporting
Security Scan Result Whether the prompt triggered a security policy (e.g., PII detected, injection attempt) Incident management and compliance

3. What Data Is NOT Collected

4. How Data Is Used

All collected data is used exclusively for the following corporate security purposes:

5. Data Transmission and Storage

Collected data is transmitted via HTTPS to the Company's internal security gateway server (clicknexttest.biz), which is operated and maintained by the ClickNext IT Security team. All data is:

6. Data Retention

Activity logs are retained for 90 days from the date of collection. After this period, records are automatically and permanently deleted from the server. Employees who leave the company may request immediate deletion of their data by contacting the IT Security team.

7. User Rights (PDPA / GDPR)

Employees have the following rights regarding their data:

To exercise any of these rights, contact: it@clicknext.com

8. Consent

This Extension is deployed via organization-level Chrome management (Google Admin Console Managed Settings). By using a company-managed device with this Extension installed, employees acknowledge and consent to the monitoring activities described in this policy, as disclosed in the Company's Employee IT Acceptable Use Policy.

9. Security

The Company implements technical and organizational measures to protect collected data, including TLS encryption in transit, access control on server infrastructure, and regular security audits of the gateway system.

10. Changes to This Policy

This policy may be updated periodically. Employees will be notified of material changes via internal communication channels. Continued use of company-managed devices after changes constitutes acceptance of the updated policy.

11. Changelog

VersionDateChanges
2.1.0May 21, 2026Updated DLP rules to use Smart Context Detection. "ClickNext" alone is no longer blocked; it is only blocked when paired with sensitive keywords.
2.0.0May 18, 2026Expanded monitoring from 3 platforms (ChatGPT, Claude, Gemini) to 13 platforms. Added support for Microsoft Copilot, DeepSeek, Perplexity, Grok, Mistral, Poe, HuggingChat, NotebookLM, Google AI Studio, and Meta AI. Removed unused googleapis.com host permission.
1.9.8May 14, 2026Security hardening: added Thai keyword blocking for sensitive terms. Fixed retry bypass vulnerability.
1.9.7May 13, 2026Added AI reply token tracking via MutationObserver. Improved Thai token estimation.
1.9.0April 21, 2026Initial release with PII detection, prompt injection blocking, and company data protection.

12. Contact Information

For questions about this privacy policy or data handling practices, contact: