PersonalGuard Browser Guard

Privacy protection should be clear.

PersonalGuard is a local-first browser privacy and security extension. This policy explains what the extension handles, why it is needed, and when limited information reaches a third-party service.

Effective July 27, 2026

01

On-device storage

Settings, reports, history, and scan results remain in Chrome extension storage.

02

Limited requests

Only privacy-preserving prefixes and a fixed threat feed are requested over HTTPS.

03

User control

Modules can be disabled, records can be cleared, and cleanup requires confirmation.

01

Information handled by the extension

PersonalGuard handles the following information only to provide its user-facing privacy and security features.

Web history and website identifiers

Website host names, protection-event times, the current website for per-site settings, and the source host of a downloaded file. PersonalGuard does not store full browsing URLs in its protection history.

Website content and resources

Counts of third-party hosts, visible cookies, storage keys, insecure forms, fingerprinting API signals, blocked network requests, and page elements needed for phishing warnings, popup cleanup, YouTube controls, and privacy reports.

User activity

Blocked-request activity and video playback information needed to display protection status and perform enabled video controls.

Authentication information

When the user chooses the password-breach checker, the password is hashed locally. The password and complete hash are not stored or transmitted.

Personally identifiable information

The optional Download Shield temporarily reads a completed download's local file path, which may contain the device account name. The full path is sent only to the PersonalGuard native companion on the same device for local scanning and is not uploaded or retained by the extension. Only the file name, source host, scan result, and time are stored locally.

Approximate location and IP address

Requests to the third-party services listed below use HTTPS and therefore expose the user's IP address to those services as part of normal Internet communication.

02

How information is used and stored

Extension settings, trusted sites, per-site profiles, protection history, privacy reports, rule-update metadata, and optional download-scan results are stored locally in Chrome extension storage. Temporary phishing-bypass information is stored for the browser session. Local records remain until the user clears them, removes the extension, or Chrome clears extension data.

PersonalGuard does not operate an analytics or advertising server. The publisher does not receive locally stored browsing, privacy-report, password, or download-scan data.

03

Limited third-party transfers

PersonalGuard makes these limited HTTPS requests only to provide enabled features.

Pwned Passwords

api.pwnedpasswords.com

After a user starts a breach check, PersonalGuard sends only the first five characters of the password's SHA-1 hash using the range-query method. The password and complete hash remain on the device.

SponsorBlock

sponsor.ajay.app

When Sponsor Skip is enabled, PersonalGuard sends only the first four hexadecimal characters of the SHA-256 hash of the YouTube video ID to retrieve matching community timestamps. The raw video ID remains on the device.

HaGeZi threat feed

cdn.jsdelivr.net

PersonalGuard periodically retrieves a fixed domain threat list through jsDelivr. The response is treated only as data, validated, capped, and never executed as code. No browsing history or website content is included in this request.

PersonalGuard native companion

On this device

When Download Shield is enabled, the completed download's local path is sent only to the installed companion on the same device for a Windows AMSI scan. File contents are not uploaded.

Stripe and PersonalGuard licensing

Optional lifetime purchase

If paid licenses are offered and a user chooses to purchase one, Stripe processes the payment. PersonalGuard stores the Stripe checkout and payment identifiers, purchaser email, license status, and hashed activation identifiers needed to issue and verify the license. PersonalGuard does not receive or store full payment-card details.

These transfers are necessary for the extension's disclosed security features. PersonalGuard does not sell user data, use it for advertising, use it to determine creditworthiness, or transfer it for purposes unrelated to the extension's single purpose.

04

Browser cleanup

Panic Cleanup runs only after the user confirms the action. It can close unpinned web tabs and ask Chrome to delete the previous hour of browsing history, download history, cache, cookies, form data, and site storage. Deleted browser data is not sent to the publisher.

05

Security and limited use

All external requests initiated by the extension use HTTPS. PersonalGuard does not execute remotely hosted JavaScript or WebAssembly. Downloaded threat-list entries are validated and used only as declarative blocking data.

PersonalGuard's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information is used only to provide or improve the extension's disclosed privacy and security features.

06

User choices and deletion

Users can disable individual protection modules, Sponsor Skip, automatic threat-list updates, or Download Shield. Protection history and other local records can be cleared from PersonalGuard where controls are provided. Removing the extension deletes its Chrome extension storage according to Chrome's behavior.

Changes to this policy

This policy may be updated when PersonalGuard's features or data practices change. The effective date at the top of this page identifies the current version.