Privacy
What Safe-Desk and its browser extension do with your data.
This covers the Safe-Desk website at desk.sophiaxt.com, the Gate API and the Safe-Desk extension for Chrome. SOPHIA XT LLC runs all three. It describes the system as it runs today. Effective 23 September 2026.
The short version
Safe-Desk exists to keep client data out of AI tools. Text you type, paste or send through Safe-Desk is checked on our server, and client details such as Social Security numbers, account numbers and names are swapped for placeholders like [SSN_1] before an AI model sees the text. Passwords and keys are stopped. We do not store the text you send, the AI's answers or the values we catch. We keep a short record that a check happened, who ran it and what kind of thing was caught. We do not sell data, use it for advertising, or use it to train AI models.
Who is responsible
Safe-Desk is sold to firms. Your firm decides who gets an account and which rules apply, and its owner can read the firm's activity log. SOPHIA XT LLC operates the service for the firm. Questions about how your firm uses Safe-Desk go to your firm's Safe-Desk owner; questions about this policy go to us at contactus@sophiaxt.com.
Text you check
When you use the desk, the Gate API or the extension, the text goes to our server over HTTPS. The server reads it against your firm's rules in memory, swaps what it finds for placeholders and sends back the safe version. It does not write the text to the database or to a log. Error records are passed through the same scrubbing before they are kept, so an error that happens to contain a client value stores the placeholder instead.
The table that turns placeholders back into real values is sealed with AES-256-GCM and bound to your account before it leaves the server. Your browser holds that sealed copy; it cannot be read or changed there. When an answer comes back, the sealed table and the placeholder text are sent to our server, which opens the table for that one request, puts the real values back and returns the result. The table is not stored on our side.
The Chrome extension
The extension runs on chatgpt.com, chat.openai.com and claude.ai, and talks to one server: desk.sophiaxt.com. It loads no code from anywhere else.
It sends our server the text you paste or send in the chat box, so it can be checked, and the placeholder text in the AI's answers, so the real values can be shown to you. With each of these goes the name of the site (ChatGPT or Claude) and the sealed placeholder table for that conversation. When you connect the extension, it sends the one-time code from the Safe-Desk website and a label for the browser, such as "Chrome on Windows".
In the browser, the extension keeps its connection key, your name, your firm's name and whether protection is on, in Chrome's local extension storage. It keeps the sealed placeholder tables in Chrome's session storage, which Chrome clears when the browser closes. Chat pages cannot read any of this. Signing out from the extension, or disconnecting the browser from the Safe-Desk website, removes the key.
The extension does not read your browsing history, does not run on other sites, and does not collect anything from pages beyond the chat box and the AI's answers on the three sites above. What reaches ChatGPT or Claude is what you send there, with client details already replaced; those services handle it under their own terms and your own account with them. The extension's use of information follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Accounts and sign-in
For each person with an account we store a name, a work email, a password hash (scrypt) and a role. Names and emails are encrypted in the database with AES-256-GCM, and sign-in finds an account by a keyed hash of the email rather than the email itself. Sign-in sessions last up to 12 hours; we store only a hash of each session key. Each connected browser has its own key, stored only as a hash, with its label and when it was connected and last used, and it can be disconnected from the website at any time. Your IP address is used in memory to limit repeated sign-in and pairing attempts; our application does not store it, though our host's standard web server logs may.
What we keep, and for how long
| Data | Kept |
|---|---|
| Text you check, AI answers, caught values, placeholder tables | Never stored |
| Activity log: who ran a check, when, the outcome and which kinds of data were caught | 400 days |
| Audit trail: sign-ins, failed sign-ins, staff, setting and billing changes (encrypted) | 400 days |
| Error records, scrubbed of client data | 90 days after last seen |
| Your firm's client list, as one-way keyed hashes only | Until the owner replaces it |
| Usage counts: messages and AI tokens per month | While the account exists, for billing |
| Accounts, and records of connected browsers | While the account exists |
| Daily backups of the database, encrypted whole | 14 days |
| Card details | Never; Stripe holds them |
Who else processes data
We use a small number of service providers. None of them receives a value our rules catch.
| Provider | Why | What it receives |
|---|---|---|
| Hostinger | Hosting the service and sending account email | The application and its database; invitation and password emails |
| Stripe | Billing | The owner's name, email, billing address and card |
| An AI model provider | Writing answers, only if your firm uses Safe-Desk's built-in chat | Message text with caught values already replaced by placeholders |
| ntfy.sh | Phone alerts, only if the firm's owner turns them on | The firm's name, the staff member's name and the kinds of data caught; never a value |
If you use the extension, ChatGPT (OpenAI) or Claude (Anthropic) receives what you send there through your own account, after Safe-Desk has swapped out client details. We do not have access to those accounts.
What Safe-Desk cannot promise
The rules catch identifiers with a known format reliably. Names, addresses and dates without a list to match against are detected from context, which is a best effort. The extension only protects the main chat box on the sites above while it is connected and your firm's subscription is active; it cannot stop someone typing client data into another site, another browser, or a file upload. Real values shown back to you in an answer are on your screen, where other scripts on that page could read them. Safe-Desk helps a firm meet its confidentiality duties; it does not make a firm compliant with any law on its own, and it has not been audited under SOC 2.
Your choices
You can sign out of the extension or remove it from Chrome at any time. You can see and disconnect your connected browsers in Settings on the Safe-Desk website. Your firm's owner can see the firm's activity log and audit trail. To ask for a copy of your account data, a correction, or deletion of your account or your firm's data, email contactus@sophiaxt.com. Deleted data leaves our backups as they expire, within 14 days.
Changes and contact
If this policy changes, we will update this page and its effective date, and tell firm owners by email before a change that affects what we collect. SOPHIA XT LLC, sophiaxt.com, contactus@sophiaxt.com. The security page has more on how the service is protected.