Privacy Policy for the Google Chrome Extension „AI Security Assistant“
1. Data Controller
Responsible for data collection, processing, and usage under the General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG) is:
Gato Dynamics (in formation) Aljoscha Jürgen Hösselbarth
Weinstr. 12, 94469 Deggendorf, Germany
Phone: +49 991 40543055 | Email: support@gatodynamics.tech
Website: https://gatodynamics.tech
2. Core Principle, Purpose Limitation & Local Gato Sentry („Privacy by Design“)
- Exclusive Purpose: The browser extension „AI Security Assistant LIVE“ serves exclusively to protect the user in real time from fraudulent websites, fake shops, phishing emails, manipulated payment demands, and everyday online fraud.
- No Profiling & No Sale of Data: At no point are user profiles created, browsing histories tracked, or personal data sold or transferred to advertising networks or data brokers.
- Local Gato Sentry (Real-Time Protection Without Tracking): The integrated live sentry monitors the domain opened in the active tab completely locally on your device. Your general browsing path is neither logged nor transmitted to external servers.
- Targeted Data Transmission Only Upon Active Inspection: Encrypted transmission to our AI security analysis takes place only when an inspection is actively initiated:
- By manually clicking „Start Check“, „Tab URL“, or „Screen Scan“.
- By selecting and right-clicking via the context menu.
- By automatic triggering of in-depth inspection for critical threat patterns.
3. Essential Browser Functions & Technical Necessity (§ 25 TDDDG & GDPR)
To reliably protect you from fraud, the extension utilizes the following technically necessary browser functions:
- Sidepanel and Menu Display: Enables displaying the security assistant as a sidepanel, toolbar popup, or standalone window directly in your browser. This display occurs purely locally on your machine without transmitting personal data.
- Webpage & Screen Inspection:
- Local Domain Detection for Sentry: Enables the local Gato Sentry to check the current domain for fake shop indicators – purely locally on your device without recording browsing history.
- Webpage Inspection: Reads the title and URL of the active webpage upon clicking „Tab URL“ or during active inspection to verify certificate and safety parameters.
- 1-Click Screen Scan (Visual Image Analysis): Captures a transient screenshot of the currently visible viewport upon clicking „Screen Scan“ to analyze suspicious emails or layouts via visual AI. This image is held transiently in RAM, transmitted in encrypted form, and immediately deleted after analysis.
- Right-Click Quick Inspection: Allows you to highlight text snippets, suspicious emails, or links on websites and submit them directly for AI inspection via context menu. Active only in the moment of clicking.
- Local Device Storage:
- Local Security Archive: Your recent inspection reports remain 100% locally on your computer and can be deleted at any time with a single click.
- Free Trial & License Status: Securely stores the status of your 24-hour free trial and Pro subscription locally on your machine to unlock features.
Legal Basis: Section 25(2) No. 2 TDDDG (technically strictly necessary for the service requested by the user) and Art. 6(1)(b) GDPR (contract performance / service provision).
4. AI Security Analysis via Google Cloud & Gemini Enterprise
To perform in-depth semantic and visual fraud detection, the extension utilizes APIs (Cloud Functions & Vertex AI) provided by Google Cloud (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland):
- Server Location: All backend functions are hosted in region
europe-west3(Frankfurt am Main, Germany). - End-to-End Encryption: All data transmissions are exclusively secured via Transport Layer Security (TLS 1.3 / HTTPS).
- Transient Processing & No AI Training: Submitted data is processed purely transiently. Google and Gato Dynamics under no circumstances use your submitted content to train foundational AI models. Data is discarded immediately upon report delivery.
- Legal Basis: Art. 6(1)(b) GDPR.
- License Verification & Abuse Prevention: To prevent license abuse and enforce fair-use limits on the server side, the technical subscription ID generated by Stripe is verified for validity in our secure security database (Art. 6(1)(b) and (f) GDPR).
5. Payment Processing for Pro Subscriptions (Stripe)
If you choose a paid Pro subscription (3.45 € / month, monthly cancellable), payment processing is handled by the certified payment processor:
Stripe Payments Europe, Limited (SPEL)
1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
- Processed Data: Payment and transaction details are processed directly by Stripe via a secure API. Gato Dynamics never stores complete credit card numbers or bank details.
- Certification: Stripe is certified under the highest industry security standard (PCI-DSS Level 1).
- Legal Basis: Art. 6(1)(b) GDPR.
6. Retention Periods & Voluntary Reporting of Inaccurate AI Content
- Analysis Data (Texts & Screenshots): Processed transiently and deleted immediately from server RAM after analysis.
- Voluntary Reporting of Inaccurate AI Content (Report Button): If you actively use the "Report AI Response" feature, the reported text snippet, the AI response, and a timestamp are stored encrypted in our secure Firestore database and transmitted to our support team to analyze inaccuracies, improve system quality, and fulfill transparency obligations under Art. 50(1) EU AI Act (Legal basis: Art. 6(1)(a) and (f) GDPR). The data is deleted upon completion of the review.
- Local Security Archive: Stored locally on your device until manually cleared or until the extension is uninstalled.
- Subscription & Invoicing Data: Retained in accordance with statutory fiscal and commercial retention periods (Sections 147 AO, 257 HGB: up to 10 years).
7. Your Rights as a Data Subject Under GDPR
Under the General Data Protection Regulation, you are entitled to the following rights:
- Right of Withdrawal (Art. 7(3) GDPR): You can revoke browser permissions at any time via
chrome://extensionsor uninstall the extension. - Right of Access (Art. 15 GDPR): You can request information about your personal data processed by us.
- Right to Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
- Right to Erasure (Art. 17 GDPR): You can request the immediate deletion of your data.
- Right to Restriction of Processing (Art. 18 GDPR): You can request the restriction of processing.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your data in a structured, standard format.
- Right to Object (Art. 21 GDPR): You can object at any time to processing based on legitimate interests (Art. 6(1)(f) GDPR).
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Website: https://www.baylda.bayern.de
8. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy when new features are added or statutory regulations change. The current version is always accessible in the extension settings and on https://gatodynamics.tech.