Legal
Privacy Policy.
We build privacy technology, so we hold ourselves to the standard we sell. This policy explains what data this website processes, why, and the rights you have. In short: we collect as little as possible, nothing tracks you without your consent, and what we do process is protected with the highest possible security on our own servers in Switzerland.
1. Who is responsible
The controller for data processing on this website is NativeAI Sàrl (in formation), EPFL Innovation Park, Bâtiment C, 1015 Lausanne, Switzerland. For any privacy request, write to [email protected]. Processing follows the Swiss Federal Act on Data Protection (DSG) and, where applicable to visitors from the EU/EEA, the GDPR.
2. What we collect when you visit
When you open this website, our web server processes technical data that your browser transmits: IP address, date and time of the request, the page requested, referrer URL, browser type and operating system. These server logs are needed to deliver the website, to ensure its stability and to detect and defend against attacks. They are kept short-term and are neither merged with other data nor used to identify you.
When you contact us by email or request a demo, we process the data you provide (name, email address, company, your message) to answer you and to prepare and conduct the requested meeting. We do not use this data for anything else, and we never sell personal data.
3. Cookies, consent and the cookie banner
This website works without profiling cookies. Two things are stored on your device, both strictly functional: your dark-mode preference in local storage, and a first-party cookie named nai-consent that records that you have seen our privacy notice and what you chose. That cookie holds a choice and a timestamp, expires after twelve months, contains no identifier and is never transmitted to a third party.
Nothing else is placed on your device without your consent. If we ever introduce cookies or similar technologies that are not strictly necessary, the banner will ask you first, and those tools will stay switched off until you agree. You can decline without losing any functionality, and you can change or withdraw your choice at any time through the Cookie settings link in the footer.
4. Web analytics and tracking tools
We use none. There is no web analytics, no tag manager, no advertising or social media pixel, and no cross-site tracking of any kind on this website. We do not know who you are, which pages you visited before, or where you go next. If we introduce analytics in future, the banner will ask for your consent first (Art. 6 para. 6 DSG; Art. 6(1)(a) GDPR), nothing will be loaded from any analytics provider until you agree, and declining will cost you no functionality. Separately, we use Google Search Console, which provides aggregated statistics about how this website appears in Google search results. It requires no code on this website, sets no cookies on your device and cannot identify you.
5. Web fonts
All fonts are served from our own servers. This website makes no request to Google Fonts or any other font provider, so your IP address is not transmitted to anyone when the page loads. This website contacts no third-party provider at all.
6. How we protect your data
Data security is our business, and we protect your data with the highest possible security. This website and the systems behind it run on our own servers in a Swiss datacenter, under Swiss law, with no dependency on a public cloud. All connections are encrypted in transit (TLS). Access to personal data is restricted to the founders and protected by strict technical and organizational measures, including access controls, hardening and logging, in line with our ISO 27001-aligned information security management system.
7. Sharing and processors
We do not sell or rent personal data. We share data only where this policy provides for it, where you have consented, where a service provider processes data on our behalf under a data processing agreement, or where we are legally required to. Every processor we use is bound to the same level of protection this policy promises.
8. Where your data is processed
Personal data from this website is processed in Switzerland. Switzerland is recognized by the European Commission as a country with an adequate level of data protection. Should a tool transfer data abroad in future, we will say so in this policy, and such transfers will rely on recognized safeguards.
9. How long we keep data
We keep personal data only as long as needed for the purpose it was collected for: server logs briefly for security reasons, correspondence for as long as our exchange is active plus statutory retention periods, and consent records for as long as the consent is valid. Data that is no longer needed is deleted or anonymized.
10. Your rights
You have the right to know whether we process data about you, to receive a copy of it, to have incorrect data corrected, to have data deleted, to receive the data you provided in a portable format, to object to processing based on legitimate interest, and to withdraw any consent at any time.
To exercise any of these rights, write to [email protected]. We answer within 30 days. You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU/EEA, with your local supervisory authority.
11. Changes to this policy
We may update this policy when the website, our tools or the law change. The version published here applies. Material changes to how we use tracking tools will always be reflected in the cookie banner before they take effect.
12. NativeAI Guard Browser Extension
This section applies specifically to the NativeAI Guard Inspector browser extension for Google Chrome, published on the Chrome Web Store.
What the Extension Does
The NativeAI Guard Inspector extension enforces your organization's data loss prevention (DLP) policies by intercepting user submissions to AI platforms (such as ChatGPT, Claude, Gemini, Copilot and DeepSeek), email services and chat applications. It inspects content against security policies and blocks or redacts sensitive data before it leaves the browser.
Data Processing
The extension does not collect, store or transmit any personal data to NativeAI. All data processing occurs exclusively between your browser and your organization's own NativeAI Guard backend instance, which is deployed and managed by your organization. Submission content is analyzed locally in the browser and sent to your organization's backend for policy evaluation. It is never sent to NativeAI or any third party.
Local Storage
The extension uses chrome.storage.local (not cookies) to store the following:
- Authentication tokens (access token, refresh token) issued by your organization's identity provider
- Cache of the enforcement policies, so the extension can enforce policies without sending a network request on every action
- Extension statistics (number of blocks/allows, no user content)
- Telemetry event buffer (error metadata only, no user content or personal data)
Extension Permissions
The extension requests browser permissions including storage, identity, tabs, alarms, offscreen and host access to all URLs. The broad host permission is required because the extension is a DLP tool that must intercept submissions on any website, including websites not yet included in the policy configuration. A detailed justification of the permissions is available on the Chrome Web Store listing.
Extension Data Retention
The extension does not retain user data. Locally cached policy rules and authentication tokens are cleared when you sign out or when the browser storage is cleared. Data retention on your organization's backend is governed by your organization's own data retention policies.
Third-Party Sharing
The extension does not share any data with third parties. All traffic flows exclusively between the browser and your organization's NativeAI Guard backend.
13. Contact
For any question about this policy or about how we handle your data, or to exercise your rights, you can reach us at:
NativeAI Sàrl
EPFL Innovation Park, Bâtiment C
1015 Lausanne, Switzerland
Email: [email protected]
Privacy and legal: [email protected]
Phone: +41 22 595 63 04
Last updated: July 2026