Fendr Browser Extension Privacy Policy
Last Updated: January 2026
What This Extension Does
Fendr is a data loss prevention (DLP) browser extension that helps organisations protect sensitive information by monitoring and blocking risky actions on unauthorized websites, including:
- Paste events
- File uploads
- Prompt/text submissions
- OAuth/Drive/Picker integration attempts
What Data We Collect (Extension Only)
When you perform a monitored action, we collect:
Always Collected:
- Event type (paste_block, file_upload_success, prompt_block, etc.)
- Website domain (e.g., "chatgpt.com") – never full URLs or page content
- Timestamp
- Coarse size/count buckets (e.g., "33-64 characters", "1-5 files")
- Browser type and extension version
Conditionally Collected (based on your organisation's settings):
- Matched keyword identifiers (e.g., "salary", "confidential") – never the actual text
- Keyword theme categories (e.g., "financial", "hr_sensitive")
- Filenames (first 10, names only, no paths, non-personal tools only)
- Email domain (domain-only, e.g., "acme.com", never full addresses)
For DNR Blocking (OAuth/Drive/Picker):
- Initiator website domain
- Blocked endpoint family (normalized URL path, digits bucketed)
What Data We DON'T Collect
- Page content or HTML
- Clipboard text (we hash 8 characters locally for same-domain bypass, expires in 5 min, never transmitted)
- Typed text or prompt content
- File contents
- Passwords
- Cookies
- Request/response headers or bodies
- Query strings
- Full email addresses
Why We Need Access to All Websites
The extension requests <all_urls> permission because:
- Data loss can occur on any website, including new or unclassified services
- We must monitor user-initiated paste, upload, and submit events across all sites
- We block cross-site integration attempts (OAuth/Drive) by matching request patterns
We do not access, read, or scrape page content, passwords, or form data.
How We Use This Data
- Enforce your organisation's DLP policy (block or allow actions)
- Generate audit logs for compliance
- Alert administrators to risky data flows
- Improve service reliability (aggregated/anonymized only)
We never sell user data.
Data Storage & Retention
- Telemetry: Typically 30-180 days (configurable by your organisation)
- Local cache: Policy data only, refreshed daily via HTTPS
- All data encrypted in transit and at rest
Third-Party Services (Sub-Processors)
We use trusted providers for:
- Cloud hosting (encrypted storage)
- Error monitoring
- Analytics (aggregated only)
Your Rights
Contact your organisation's IT administrator or email info@fendr.tech to:
- Access your data
- Request deletion
- Object to processing
Enterprise Deployment
Fendr is deployed by your organisation. Your IT administrator controls:
- Policy settings
- Data retention
- Feature enablement