Priority Governance
Extension privacy notice

Free Shadow AI Scan — Privacy Notice

Last updated: 8/20/2026

This notice covers the Free Shadow AI Scan Chrome extension. It supplements, and does not replace, the Priority Governance Privacy Policy and Terms.

The short version

The extension processes your browsing history locally, inside your browser. Priority Governance does not receive, store, or transmit your browsing history or your scan results.

What the extension accesses

With your permission, the extension reads web addresses in the browsing history available to your Chrome profile for the period you select. It compares the hostname — and, where a rule requires it, the path — against a reviewed list of known AI-service websites bundled with the extension. Query strings and fragments are not used for matching. Entries that do not match are discarded during processing. Only service-level matches, counts, and last-seen dates reach the report.

Chrome supplies history entries for the whole period you select; the extension necessarily reads them in order to decide which ones match. It does not receive only the matching ones.

The history permission is optional. It is not granted when you install the extension. The extension displays an explanation before the scan action; Chrome requests the optional history permission only after you click the button to run a scan. If you decline the permission, no history is read and no report is produced.

What the extension does with it

For entries that do match, the extension counts visits within your selected period and records the date each service was last seen. Matched web addresses are held only long enough to count those visits and are then discarded; they never appear in the report and never leave your browser.

The report is generated in the memory of an extension page. The extension does not use Chrome storage APIs to persist scan results. Closing the tab discards the extension's in-memory report unless you choose to retain a copy using your browser's print or save-as-PDF function.

What the extension does not inspect, retain, or transmit

The extension does not inspect page content, prompts, files, passwords, cookies, form fields, bookmarks, or open tabs. It has no account system, no sign-in, and no email field.

History web addresses may contain paths or query information placed there by a website, and such information can sometimes include a name or an identifier. The extension neither seeks nor extracts it: query strings and fragments are not used for detection, non-matching entries and matched web addresses are discarded during local processing, and no raw web address appears in the report or leaves your browser.

How to read our data statements precisely

Six different things are often collapsed into the single word “collection”. They are not the same, and only the first two happen here:

Local access — the extension reads history entries on your device
Yes, with your permission, for the period you select
Local ephemeral handling — entries are compared and counted in memory
Yes, and discarded during processing
Persistent storage by the extension — scan data written to extension storage or a database
No. The extension does not use Chrome storage APIs to persist scan results
Off-device transmission by the extension
No scan-derived data is transmitted off the device
Developer receipt — Priority Governance receiving browsing history or scan results
No
Third-party sharing by Priority Governance
No

Network activity

The extension initiates no analytics, telemetry, API, synchronization, or other background network requests. It contains no tracking pixel, remote code, external font, or content delivery network reference. All assets, including the detection list, ship inside the extension package.

The only outbound action is user-initiated: a link you may choose to click, which opens the Priority Governance website at prioritygovernance.com/scan-results?source=chrome-extension. That address is fixed in the extension's source code and carries only a generic source tag — no service names, counts, dates, identifiers, or other information derived from your scan. If you do not click the link, the extension makes no user-initiated request to the Priority Governance website.

Website analytics

If you do visit the website, ordinary web analytics apply as described in the Priority Governance Privacy Policy. Those analytics record a page visit; they cannot and do not receive anything about your scan.

Chrome synchronization

If Chrome synchronization is enabled on your profile, the history available to that profile may include activity from other devices signed in to the same account. The extension cannot distinguish which device an entry came from. We describe the scope as “the history available to this Chrome profile” for this reason, and we do not claim single-device visibility.

Removing access

The report page includes a button that removes the history permission. You may also remove the permission, or uninstall the extension, from chrome://extensions at any time. Priority Governance does not receive or persist your browsing history or scan results and therefore does not possess those data for deletion on your behalf.

Children

The extension is intended for use by adults in an organizational context and is not directed to children.

Changes

Material changes to this notice will be reflected in a new version published with the extension and dated above.

Contact

Priority Governance LLC
P.O. Box 591
Como, Colorado 80432
jason@prioritygovernance.com

See also: how the scan works, Priority Governance Privacy Policy, and Terms. This notice covers the extension specifically and supplements those documents.