Legal
Privacy Policy
Last updated: September 23, 2026
Overview
Nullgen, Inc. (“Nullgen”, “we”, “us”) operates Nullgen AI Blocker. The product is built to protect your privacy. The free browser extension blocks text input into AI prompt fields on websites, and the iOS app blocks known AI apps and websites on the phone. In both cases the blocking decision is made on your device.
This policy explains what data the extension, the Safari Mac app, the iOS app, and nullgen.ai website handle, what we deliberately do not collect, and how to reach us. It applies to the free extension, the Safari Mac app, the iOS app, the nullgen.ai website, and the Pro tier (accounts and managed deployments), as described under “Pro accounts and managed deployments” below.
On-device prompt detection
Prompt detection runs entirely on your device. We do not send what you type, field contents, or browsing history to our servers to decide whether a field is an AI prompt, and we do not operate a cloud classifier for blocking.
The extension may download detection updates from our content delivery network so we can improve blocking without republishing the extension. That download does not include prompt text, field contents, or browsing history.
Prompt detection does not require an account.
iOS app
The iPhone app blocks known AI apps and websites on the device. Blocking does not require an account or a subscription. It downloads a list of known AI destinations (and their logos) from our servers so blocking stays current and, if you link Nullgen Pro, the access rules your administrator or parent has assigned to the device. Those downloads carry no information about which sites you visited.
iOS shows the blocker as a VPN configuration because that is the mechanism Apple provides for filtering on a personal iPhone. It is not a traditional VPN: it does not route your internet traffic through Nullgen or any remote server, and Nullgen does not operate a resolver or proxy. When an app or browser on the phone looks up a known AI destination, the lookup is answered on the phone itself and never leaves it. Every other lookup goes to your network’s usual resolver, exactly as it would without Nullgen. We do not receive visited website names, lookups, traffic, or prompt text from the iOS app.
If you link the app to a Pro account, the phone stores device credentials and, while the app is open, keeps a connection to our servers so access-request and policy changes appear promptly. That connection carries account and device identifiers, not browsing data. Access requests sent from the app include the AI service requested, the requested duration, and an optional justification you write — never prompt text.
Crash and error reports from the app are sent to Sentry as described under “Error reporting (Sentry).” The component that performs blocking sends no reports at all. Linking Pro or buying Family through the App Store uses the Pro and Apple flows described elsewhere in this policy.
We do not collect prompt data
We do not read, store, or transmit the text you type (or paste) into AI prompts or other fields for blocking, training, analytics, or advertising.
The blocker prevents input on fields it classifies as prompts; it does not upload those contents to Nullgen. The iOS app never sees what you type in other apps or websites — it acts only on which destinations the phone tries to reach.
Error reporting (Sentry)
To keep the browser extension, the Safari Mac app, the iOS app, and the nullgen.ai website reliable, we may send crash and error reports to Sentry, a third-party error-monitoring service.
Those reports can include technical details such as stack traces, the app or extension version, and the operating system or browser environment. We do not include Sign in with Apple tokens, App Store transaction payloads, the page address, ordinary browsing history, visited website names, or DNS lookups, and error reports are not used to reconstruct what you typed into a prompt. On iOS, only the app you open can send a report; the component that performs blocking does not.
On Firefox, this kind of technical data is declared as optional data collection in the add-on listing.
Issue and false-positive reports
If you choose to report a false positive or other issue from the extension, we receive information you submit about the page (the site and path, without query string or fragment), a description of the blocked field, the extension version, and a note. For a general “Report an issue” submission the note is required; for a false-positive report it is optional.
Those reports are initiated by you. Do not paste prompt text into the note field. Reports are used to improve the product and to handle support. We may retain them, including in anonymized form, to investigate issues and improve detection.
Analytics (Google Analytics)
The nullgen.ai website uses Google Analytics to measure page views, engagement, and advertising performance. When Analytics is allowed to load, completing a paid website checkout may also send Google a purchase conversion (amount, currency, and a Stripe checkout session identifier as a transaction id) so we can measure ads.
When Analytics loads, Google may also collect and associate data as follows. Google signals: Google may use information from people who are signed into Google and have ads personalization enabled, together with our Analytics data, for cross-device measurement, demographics and interest reporting, and advertising features. User-ID: Google may collect a User-ID if one is provided so visits on this site can be joined. User-provided data: Google may collect an email address, phone number, or name you enter on nullgen.ai and associate those visits and conversions with a Google account for ads measurement. We do not send the text of AI prompts, or the contents of fields on other websites, to Google.
Google processes that data under Google’s terms and privacy policy.
In the European Economic Area, the United Kingdom, and Switzerland, Analytics loads only after you Accept on our cookie banner. If you Reject, we do not load Analytics and we do not set Google Analytics cookies.
In the United States and other countries, Analytics loads unless you opt out (Cookie settings in the website footer) or your browser sends a Global Privacy Control (GPC) signal. GPC is treated as an opt-out unless you later Accept. Opting out or rejecting means we do not load Analytics.
Your Accept or Reject choice is stored in your browser until you change it or clear site data. We do not expire that choice on a fixed schedule. When Analytics loads, Google may set its own cookies, including advertising cookies when Google signals is active; those last according to Google’s settings.
Google Analytics is not used in the browser extension or the iOS app.
Data stored on your device
The extension stores a small amount of state on your device, such as aggregate block counts (for example, how many prompts were blocked today and in total), settings needed for the product to function, and a cached copy of detection files so they are not re-downloaded on every browser start.
Those counters are not broken down by website. They are separate from Google Analytics, which — when enabled — measures website page views and ad conversions via Google’s services rather than by uploading those local counters.
The iOS app stores trial state in the phone’s keychain (which may sync through your iCloud Keychain, as described under “iOS app”), a cached list of known AI destinations, and — if you link Pro — device credentials and the access rules assigned to the device. It does not keep a log of visited sites and does not store extension-style block counters.
The nullgen.ai website
Our website may send crash and error reports to Sentry, as described under “Error reporting (Sentry),” and it uses Google Analytics on the site as described under Analytics above. If you subscribe to our newsletter, we process the email address you provide through our email provider (Resend) so we can send product marketing (such as product updates). That is the same marketing email we may send if you create a Pro account. You can unsubscribe at any time; unsubscribing stops those marketing messages, including trial reminders and the notice that a trial has ended. Transactional mail is described under “Pro accounts and managed deployments.”
Paid website checkout and subscription management use Stripe’s hosted checkout and billing portal. Stripe processes card payments as our payment processor; we do not store full card numbers on our servers. Stripe receives the billing details you enter there (such as card data and billing email) under Stripe’s terms and privacy policy, and we receive subscription and customer identifiers needed to keep your account in sync.
Family subscriptions purchased in the Safari Mac app or the iOS app are billed by Apple. We receive subscription and customer identifiers Apple provides so we can keep the account in sync; we do not receive full card numbers from Apple.
The product video page and the “Watch the product video” control on our landing pages load video from YouTube in its privacy-enhanced mode. YouTube (Google) may set cookies or collect data about playback once a video plays, under Google’s privacy policy.
If you email support@nullgen.ai or sales@nullgen.ai, we process the contents of that correspondence to respond to you.
Pro accounts and managed deployments
Pro adds centrally managed policy for families, schools, and organizations. When you create a Pro administrator account, we collect the information needed to operate it: your email address and authentication credentials, processed through Amazon Cognito (an AWS identity service), plus organization details you provide, such as an organization name.
We confirm the email address you provide before the account is usable, using a one-time code delivered by our email provider (Resend). You can instead Sign in with Apple or Google rather than a password. With Apple, we receive your email address (Apple may provide a Hide My Email relay) and name if you share it. With Google, we receive your email address and name from Google. If you use the same email with more than one of these methods, we keep a single account. Sign in with Apple on iPhone uses the same processor path as on Mac.
When you create a Pro account, we may send product marketing to that email through Resend — for example product updates, reminders that a trial is ending, and the notice that a trial has ended. Those messages include an unsubscribe link, and you can stop them at any time. Unsubscribing stops all of that marketing, including the newsletter and trial notices. Transactional mail (sign-in codes, billing notices, and invites) continues even if you unsubscribe from marketing.
Administrators may invite additional Parents or organization members by email. We create an account for the invitee and send an invite with a link to choose their own password on nullgen.ai. If an invitee is removed, we delete their account and membership records for that organization.
When you start a paid website plan or trial that requires a payment method, checkout happens on Stripe’s hosted pages. We store Stripe customer and subscription identifiers, plan interval, seat limits, and subscription status so we can operate your account; card numbers stay with Stripe. For Family purchased through the Mac App Store or the iOS App Store, we store Apple subscription identifiers and status the same way we store Stripe identifiers for website plans.
To run managed deployments we store configuration and operational data on AWS in the United States: organization and membership records, managed-user profiles (name and optional email), device identifiers, device enrollment data (from device management tooling or a device-linking flow), AI access-request records (the site requested, duration, optional justification, and status — not prompt text), the policies your administrators create, and related administrative activity records.
When a managed user requests access to an AI website, we email the assigned approvers with the managed user’s name, organization name, website, and duration. If the managed user’s optional email is set, we also email them when a request is approved or denied. The iOS app submits the same kind of access-request metadata (site, duration, optional justification — not prompt text).
On Pro, exactly as on the free product, prompt detection runs on the device, and we do not collect the text typed into prompts — including when you sign in or purchase in the Mac app or the iOS app.
Service providers
We share personal information with the following service providers only to operate the service:
Amazon Web Services (AWS) — hosting and account authentication in the United States.
Stripe — payment processing and subscription billing.
Apple — Sign in with Apple for Pro accounts, and payment processing for Family subscriptions purchased through the Mac App Store and the iOS App Store.
Resend — transactional email, product notices, and product marketing (including unsubscribe handling).
Sentry — crash and error reporting for the browser extension, the Safari Mac app, the iOS app, and the website.
Google — website analytics, ad measurement, and advertising features such as Google signals and contact details you enter on this site (subject to the consent and opt-out rules above), optional Google sign-in for Pro accounts, and YouTube video embedding on our website.
How we protect data
All connections between the extension, the apps, the dashboard, the website, and our servers use TLS. Data stored on our servers is encrypted at rest. Access to production systems is limited to staff who need it and requires multi-factor authentication. Changes to our software are reviewed before they reach production, and our infrastructure is defined in code rather than configured by hand. Databases keep continuous backups that allow point-in-time recovery. We monitor for errors and failures and maintain a documented incident response process; if an incident affects your personal data, we will notify you as applicable law requires and, where we have a contract with your organization, as that contract requires.
Security researchers can report vulnerabilities to security@nullgen.ai. Our disclosure policy is at https://nullgen.ai/trust/vulnerability-disclosure, and more detail about our architecture and controls is published at https://nullgen.ai/trust.
Deleting your data
You can delete your Pro account from Dashboard → Settings, or from the Nullgen Mac app or iOS app when you are signed in with Apple and have not completed a Family purchase. Deletion requires a confirmation step. When you confirm, we delete the personal data tied to that account (such as your name, email address, and sign-in), revoke device access for that account, stop marketing email to that address (including the newsletter if you subscribed with it), and you will not be able to sign in to it again.
If you are the account owner, deletion also covers the organization you administer: membership and managed-user records, device enrollment, access-request records, and policies for that organization. If you are an invited Parent or organization member, deletion removes your login and membership only; the organization remains.
Ending or canceling a subscription does not by itself delete your account. Family purchased through the Mac App Store or the iOS App Store is billed by Apple. Deleting your Nullgen account does not cancel that Apple subscription — cancel or change it in Apple’s subscription settings.
Schools and others who cannot use Settings, or who have a residual request, can still email privacy@nullgen.ai.
Schools and student data
Schools and school districts can deploy the extension across managed student devices. In those deployments the school administers the deployment and decides what is blocked, and the school retains ownership of the policy configurations, deployment records, and metrics generated under its account. We process that data only on the school’s behalf and only to provide the service; we do not use it for advertising, profiling, or any purpose the school has not authorized.
By design, the extension does not collect student prompt text or student browsing history, and it does not create accounts for students. A school administrator can also delete the organization’s Pro account from Settings. Schools can contact privacy@nullgen.ai to review, export, or delete data associated with their deployment.
Children and shared devices
The free extension is often installed by a parent, teacher, or administrator on a device used by someone else. It does not create child accounts or collect information that identifies a child. For school-managed deployments, see “Schools and student data” above.
A parent may install the iOS app on a child’s or shared phone. An unmanaged local trial on that phone does not create a child account. With a Family plan, a parent may create a profile for each child (a name and, optionally, an email address) in order to assign devices and approve access requests. We process those profiles on the parent’s behalf, do not create logins for children, and send those addresses only request notices — never marketing.
The nullgen.ai website and Pro accounts are not intended for children under 13 (or under 16 in the EEA or the United Kingdom), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, or that we have received information we should not have, contact privacy@nullgen.ai and we will delete it.
Legal disclosures
We disclose personal information only if required by a valid legal process, such as a subpoena or court order. If the request concerns an organization’s data, we will try to notify that organization before disclosing, unless the law prohibits notice.
Business transfers
If Nullgen is involved in a merger, acquisition, or sale of assets, personal information we hold may be transferred as part of that transaction. It will remain subject to the promises in this Privacy Policy unless you are notified of a change.
European Economic Area and United Kingdom (GDPR)
Nullgen AI Blocker is distributed commercially in the European Economic Area, and if you are in the EEA or the United Kingdom the GDPR (or UK GDPR) applies to the limited personal data described in this policy. Our legal bases are: performance of a contract, for operating Pro accounts and managed deployments you sign up for; legitimate interests, for error reporting that keeps the product working, handling issue reports you choose to send, securing our services, and sending product marketing to Pro account holders (you can object at any time via the unsubscribe link on those emails); and consent, for newsletter signup on the website and for website analytics, ad measurement, and Google advertising features (including Google signals and contact details you enter on the website) in the EEA, the United Kingdom, and Switzerland (the cookie banner and Cookie settings). Newsletter signup and Pro account marketing use the same marketing-email preference: unsubscribing from one stops the other. Creating a Pro account is not treated as consent to marketing.
You have the right to access, rectify, and erase the personal data we hold about you, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing that already happened. Pro account holders can also exercise erasure from Dashboard → Settings, or from the Nullgen Mac app or iOS app when you are signed in with Apple and have not completed a Family purchase. To withdraw analytics consent, use Cookie settings on the website or contact privacy@nullgen.ai. You also have the right to lodge a complaint with your local supervisory authority.
Our infrastructure runs on AWS in the United States, so data about people in the EEA or UK is transferred to and processed in the United States. Those transfers are protected by appropriate safeguards, including the European Commission’s Standard Contractual Clauses incorporated in AWS’s Data Processing Addendum and AWS’s certification under the EU-U.S. Data Privacy Framework. Google may also process Analytics data in the United States under Google’s terms.
California privacy rights (CCPA/CPRA)
Nullgen operates from California. We do not sell personal information for money. When website Analytics is allowed to load, we may share website visitation information and contact details you enter on this site with Google for advertising measurement and advertising features (including Google signals). Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, that can be “sharing” for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes California residents have a right to limit.
In the United States, Analytics loads by default unless you opt out (Cookie settings) or your browser sends a Global Privacy Control (GPC) signal, which we honor as an opt-out of that sharing. We do not respond to standard Do Not Track (DNT) browser requests.
In the preceding 12 months we have collected these categories of personal information: Identifiers (such as name, email address, and device identifiers, and, when Analytics loads, IP address processed by Google and an email address, phone number, or name you enter on this site); commercial information (such as plan, seat count, billing interval, and Stripe or Apple subscription identifiers); and internet or other electronic network activity (such as website analytics, advertising measurement, error reports, and issue reports you choose to send).
We keep account and deployment data until you delete the account in Settings (or the Mac or iOS app) or request deletion at privacy@nullgen.ai. Website analytics and error reports are retained by those providers as needed to provide those services. We do not publish a fixed day-count schedule for those providers.
We may also use a website newsletter address or a Pro account email for product marketing, as described under “The nullgen.ai website” and “Pro accounts and managed deployments.” That marketing shares one unsubscribe. California residents can opt out via the unsubscribe link on those emails.
California residents have the right to know what personal information we collect, to request its deletion or correction, to opt out of sharing for cross-context behavioral advertising (Cookie settings or GPC), and to not be discriminated against for exercising those rights. To make a request, email privacy@nullgen.ai. Because we collect so little personal information, we may ask for enough detail to locate any data associated with you — for example, the email address you used with us.
Changes to this policy
We may update this Privacy Policy as the product evolves. The “Last updated” date at the top of this page will change when we do. Continued use of the apps, the extension, or the website after an update means you accept the revised policy.
Contact
Questions about privacy: privacy@nullgen.ai
Security reports: security@nullgen.ai
Nullgen, Inc.
4041 MacArthur Blvd., Suite 400, Office 20
Newport Beach, CA 92660, United States
https://nullgen.ai