Legal
Privacy Policy
Last updated: August 9, 2026
Overview
Nullgen AI Blocker (“Nullgen”, “we”, “us”) is built to protect your privacy. The free browser extension blocks text input into AI prompt fields on websites. Classification runs entirely on your device.
This policy explains what data the extension and nullgen.ai website handle, what we deliberately do not collect, and how to reach us. It applies to the free extension, the nullgen.ai website, and the Pro tier (accounts and managed deployments), as described under “Pro accounts and managed deployments” below.
On-device prompt detection
The extension uses an on-device machine-learning model to decide whether a field on a page is an AI prompt. That work happens locally in your browser (in a background context or an offscreen document, depending on the browser).
We do not operate a cloud classifier for free-tier blocking. Prompt detection does not require an account or a network round-trip to our servers.
We do not collect prompt data
We do not read, store, or transmit the text you type (or paste) into AI prompts or other fields for blocking, training, analytics, or advertising.
The blocker prevents input on fields it classifies as prompts; it does not upload those contents to Nullgen.
Error reporting (Sentry)
To keep the extension reliable, we may send crash and error reports to Sentry, a third-party error-monitoring service, when a reporting endpoint is configured for a build.
Those reports can include technical details such as stack traces, the extension version, and the browser environment. In the content script (which runs on web pages), we discard events that are not clearly from our own code and we strip the page URL and query string before anything is sent, so ordinary browsing history is not reported.
Error reports are not used to reconstruct what you typed into a prompt. On Firefox, technical and interaction data used for this purpose is declared as optional data collection in the add-on listing.
Issue and false-positive reports
If you choose to report a false positive or other issue from the extension, we receive a report that may include the page hostname and path (without query string or fragment), a structural reference to the element (such as its tag, id, name, class, XPath, or selector hint), the extension version, and a note. For a general “Report an issue” submission the note is required; for a false-positive report it is optional.
Those reports are initiated by you. Do not paste prompt text into the note field. Reports are used to improve the product and are not stored in a product database today.
Analytics (Google Analytics)
Google Analytics is not currently active in the extension or on the website: no Google Analytics tag is embedded in today’s production builds, and no usage analytics are collected. This section describes what will apply when we turn it on, so the change is not a surprise.
When enabled, Google Analytics will record aggregated interaction events — for example, page views on nullgen.ai, extension popup opens, and settings interactions — together with the technical identifiers Google uses to count usage. Google will process that data on our behalf under Google’s terms and privacy policy. We will configure analytics so that it never collects the text of AI prompts or the contents of fields on web pages.
When we enable analytics in a build or deployment, we will update this section to state exactly which events are logged, change the “Last updated” date at the top of this policy, and keep the Chrome Web Store data disclosures and Firefox data-collection declarations aligned with what is actually collected.
Data stored on your device
The extension stores a small amount of state in browser storage on your device, such as aggregate block counts (for example, how many prompts were blocked today and in total) and settings needed for the product to function.
Those counters are not broken down by website in the free product today. They are separate from Google Analytics, which — when enabled — measures usage via Google’s services rather than by uploading those local counters as prompt content.
The nullgen.ai website
Our website may use error monitoring similar to the extension, and we plan to use Google Analytics on the site as described under Analytics above. If you subscribe to our newsletter, we process the email address you provide through our email provider (Resend) so we can send product updates; you can unsubscribe at any time.
Paid plan checkout and subscription management use Stripe’s hosted checkout and billing portal. Stripe processes card payments as our payment processor; we do not store full card numbers on our servers. Stripe receives the billing details you enter there (such as card data and billing email) under Stripe’s terms and privacy policy, and we receive subscription and customer identifiers needed to keep your account in sync.
If you email support@nullgen.ai or sales@nullgen.ai, we process the contents of that correspondence to respond to you.
Pro accounts and managed deployments
Pro adds centrally managed policy for families, schools, and organizations. When you create a Pro administrator account, we collect the information needed to operate it: your email address and authentication credentials, processed through Amazon Cognito (an AWS identity service), plus the organization details you provide, such as an organization name.
Creating an account sends a one-time, 6-digit verification code to the email address you provide, so we can confirm you control it before the account is usable; that code is generated and validated by Cognito and is not something we store ourselves. Cognito hands the encrypted code to our email sender, which delivers it through our email provider (Resend) — the same provider we use for other product mail. You can instead sign in with Google — in that case Cognito exchanges an authorization code with Google’s OAuth service to verify your identity, and we receive your email address and name from Google rather than a password.
Administrators may invite additional Parents or organization members by email. We create a Cognito account for the invitee and send an invite message through Resend with a one-time link to choose their own password on nullgen.ai. If an invitee is removed, we delete their Cognito account and membership records for that organization.
When you start a paid plan or trial that requires a payment method, checkout happens on Stripe’s hosted pages. We store Stripe customer and subscription identifiers, plan interval, seat limits, and subscription status in our AWS infrastructure so we can operate your account; card numbers stay with Stripe.
To run managed deployments we store configuration and operational data in our AWS infrastructure (DynamoDB in the United States): organization and membership records, managed-user profiles (name and optional email), device identifiers, device enrollment data delivered through enterprise device-management (MDM) tooling or a device-linking flow, AI access-request records (the page URL as origin and path without query string or fragment, root-domain and website grant pattern such as `*.example.com`, requested duration, optional justification up to 500 characters, status, and resolution metadata — not prompt text), the centrally managed rule and policy configurations your administrators create, and related administrative activity records. Activity records are retained for a limited period (currently 90 days) and then deleted automatically.
When a managed user requests temporary or permanent access to an AI website, we email the assigned approvers (or, if none are assigned, owners, admins, and approvers) through Resend with the managed user’s name, organization name, website pattern, and duration. If the managed user’s optional email is set, we also email them when a request is approved or denied. Cancelling a pending request does not send email. Administrative decisions and list refreshes are also delivered to enrolled devices and the admin dashboard over an authenticated WebSocket connection.
Central management changes who configures the blocker, not where classification happens. On Pro, exactly as on the free tier, the decision about whether a field is an AI prompt is made by the model on the device, and we do not collect the text typed into prompts.
Schools and student data (FERPA and COPPA)
Schools and school districts can deploy the extension across managed student devices. In those deployments the school administers the deployment and decides what is blocked, and the school retains ownership of the policy configurations, deployment records, and metrics generated under its account. We process that data only on the school’s behalf and only to provide the service, in the capacity of a “school official” with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA); we do not use it for advertising, profiling, or any purpose the school has not authorized.
By design, the extension does not collect student education records, student prompt text, or student browsing history, and it does not create accounts for students. We do not knowingly collect personal information from children under 13, which allows school deployments consistent with the Children’s Online Privacy Protection Act (COPPA). Schools can contact support@nullgen.ai to review, export, or delete data associated with their deployment.
Children and shared devices
The free extension is often installed by a parent, teacher, or administrator on a device used by someone else. It does not create child accounts or collect information that identifies a child. For school-managed deployments, see “Schools and student data” above. If you believe we have received information we should not have, contact us and we will delete it.
European Economic Area and United Kingdom (GDPR)
Nullgen AI Blocker is distributed commercially in the European Economic Area, and if you are in the EEA or the United Kingdom the GDPR (or UK GDPR) applies to the limited personal data described in this policy. Our legal bases are: performance of a contract, for operating Pro accounts and managed deployments you sign up for; legitimate interests, for error reporting that keeps the product working, handling issue reports you choose to send, and securing our services; and consent, for newsletter signup and — where consent is required — analytics when it is enabled.
You have the right to access, rectify, and erase the personal data we hold about you, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing that already happened. To exercise these rights, contact support@nullgen.ai. You also have the right to lodge a complaint with your local supervisory authority.
Our infrastructure runs on AWS in the United States (the us-east-1 region), so data about people in the EEA or UK is transferred to and processed in the United States. Those transfers are protected by appropriate safeguards, including the European Commission’s Standard Contractual Clauses incorporated in AWS’s Data Processing Addendum and AWS’s certification under the EU-U.S. Data Privacy Framework.
California privacy rights (CCPA/CPRA)
Nullgen operates from California. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act. We also do not use or disclose sensitive personal information for purposes California residents have a right to limit.
California residents have the right to know what personal information we collect (it is described in this policy), to request its deletion or correction, and to not be discriminated against for exercising those rights. To make a request, email support@nullgen.ai. Because we collect so little personal information, we may ask for enough detail to locate any data associated with you — for example, the email address you used with us.
Changes to this policy
We may update this Privacy Policy as the product evolves. The “Last updated” date at the top of this page will change when we do. Continued use of the extension or website after an update means you accept the revised policy.
Contact
Questions about privacy: support@nullgen.ai
Nullgen
4041 MacArthur Blvd., Suite 400, Office 20
Newport Beach, CA 92660, United States
https://nullgen.ai