Privacy policy for Locke Extension
Locke Extension by Sonomos
Locke Privacy Policy
This policy covers the Locke product — the desktop app and the browser extension. Our websites are covered separately by the Website Privacy Policy.
Last Updated: August 16, 2026
The short version. Locke reads what you are about to send to an AI tool, finds the sensitive parts, and masks them — all of that happens on your own machine. We never receive the content Locke inspects, so there is no copy of it on our servers to leak, subpoena, or sell. The masked message you then send goes straight from your device to the AI provider you chose; it does not pass through us. Locke does talk to our servers for a few things that are not your content — signing you in, checking your subscription, syncing your own settings, and updates — and Section 3 lists every one of them.
Which policy do you need? This one covers the Locke product. Our Website Privacy Policy covers our websites — sonomos.ai and every sonomos.ai subdomain, including support.sonomos.ai and trust.sonomos.ai. A single set of Terms of Service covers both.
This Locke Privacy Policy for Sonomos, Inc., doing business as Sonomos, a Delaware corporation with its principal place of business at 9924 Kika Court #2416, San Diego, CA 92129 ("Sonomos," "we," "us," or "our"), describes how and why we access, collect, store, use, and/or share ("process") personal information in connection with Sonomos Locke.
If you do not agree with our policies and practices, please do not install or use Locke. If you have questions, contact us at info@sonomos.ai.
- What This Policy Covers
In Short: The Locke software itself, in every form we ship it.
1.1 The Product. "Locke" means the Sonomos Locke product in each of the forms we distribute it:
- The Locke desktop application — including its local daemon, graphical application, command-line tools, installers, updates, and documentation, for Windows and Linux, with macOS planned.
- The Locke browser extension — including Dagger (detection) and Cloak (masking), together with related local software components, on every browser we support.
1.2 Why This Policy Is Separate. Our websites and Locke are different kinds of thing, and treating them under one privacy policy would make that policy less accurate about both. A website processes your data on a server. Locke processes your data on your computer, and is specifically engineered so that we cannot see it. Those facts deserve to be stated plainly rather than averaged together, so we publish them separately.
1.3 What This Policy Does Not Cover. This policy does not cover our websites — sonomos.ai and its subdomains — which are governed by the Website Privacy Policy at sonomos.ai/privacy. It also does not cover the third-party AI tools and services you use Locke with, such as ChatGPT, Claude, Gemini, or a locally hosted model. Once you choose to send a message, the receiving service handles it under its own privacy policy. Locke's role is to determine what is in that message before you send it.
- What Stays on Your Device
In Short: All of your content. Every part of the detection and masking pipeline runs locally.
The following happen entirely on your device. The content involved is never transmitted to Sonomos, and Locke never sends it anywhere on its own initiative. What you subsequently choose to send to an AI provider is covered by Section 3.
- The content you type, paste, dictate, or scan. Locke inspects it in memory on your machine.
- Files and attachments you scan. Document parsing and inspection is performed locally.
- Detection. Sensitive-data detection uses on-device pattern matching and on-device machine-learning models. No cloud model, inference API, or remote classifier is involved.
- Masking. Sensitive values are replaced locally, before the message leaves your device.
- What was detected. The categories, counts, positions, and values of anything Locke finds stay on your device. We do not receive detection results, not even in aggregate or anonymized form.
- Detection results. Counts and categories of what Locke found are written to a local database on your device, as metadata only — the type, the count, the timestamp, and the length of the match, never the matched text itself.
- Your reports. Compliance and activity reports are generated locally from local data and are yours to export or delete. We do not receive them.
Because this content is never transmitted to us, we cannot produce it in response to a subpoena, disclose it in a breach, sell it, or use it to train a model. That is a property of the architecture, not a promise about our intentions.
- What Locke Sends to Our Servers
In Short: Enough to confirm you are licensed and to keep the software up to date. Nothing about your content.
Locke makes a small, fixed set of network requests to us:
License validation and subscription status. Locke checks that your subscription is active. The desktop application repeats this check periodically while it is running. The request carries your account identifier and subscription tier, and no content, detection data, or usage data. Like any network request, it discloses your IP address and the fact that Locke is running to us.
Account authentication. Locke requires a Sonomos account. When you sign in, Locke authenticates through our authentication provider, Clerk, which holds your name, email address, and session activity. Signing in is required to use Locke.
Your settings. The settings you configure — including which AI services you have asked Locke to monitor and which categories of sensitive data you have enabled — are synced to your account so that they follow you across devices and, on team plans, so that your administrator can apply a policy. This is a record of your configuration choices. It is not a record of the sites you visit, and it carries none of your content.
Update checks and delivery. The desktop application checks for updates through our designated release channel. The browser extension is updated automatically through the applicable browser marketplace, such as the Chrome Web Store, under that marketplace's own terms.
Support messages and crash reports. If something goes wrong, Locke can send us a crash report, and you can send us a support message from inside the app. Neither is automatic. We show you the exact contents before anything is sent, and nothing goes anywhere unless you choose to send it. A crash report contains the error and a stack trace, from which we strip file paths and email addresses, along with your app version and platform, and an email address only if you give us one.
Certificate checks. Aside from the requests above, the only other connection Locke initiates on its own behalf is a standard TLS certificate-revocation check.
Requests you direct. When you send a prompt to an AI provider, that request goes to the provider you chose, at your direction. We are not the recipient of it and it does not pass through our servers.
- What Locke Never Does
Locke does not:
- Transmit, log, or store any content you type, paste, or scan.
- Send detected sensitive values, categories, or counts to any server.
- Use cloud-based AI or machine-learning services for content analysis.
- Collect browsing history, page content, keystrokes, or interaction data.
- Use cookies, web beacons, pixels, fingerprinting, or any tracking mechanism.
- Collect behavioural telemetry, usage analytics, or performance metrics. Locke has no background analytics channel. Crash reports and support messages exist, but only travel when you send them, as described in Section 3.
- Sell, rent, or share any data for advertising, profiling, or any other purpose.
- Use your data to train our models or anyone else's.
Locke collects no usage analytics, so we cannot see what you detect, what you mask, or what you type. What we can see is that a licence check happened for your account, and what settings you chose. We do not build a usage history out of that, and we retain only your current subscription status — but we would rather tell you that is a commitment we are making than let you believe the architecture makes it impossible.
- Personal Information We Hold Because of Locke
In Short: Your account and billing record. That is the whole list.
Using Locke requires a Sonomos account, and a paid tier requires a subscription. The personal information behind those — your name, email address, account identifier, and subscription and billing records — is described in full in the Website Privacy Policy, including how long it is kept and how to have it deleted. Locke's own account and settings data is held by our authentication provider, Clerk, and in our hosted database, provided by Supabase; billing runs through Stripe.
Beyond that account record, Locke causes us to hold your synced settings, as described in Section 3. Installing, running, or using Locke does not cause us to collect anything else.
In the categories used by California law, in the preceding 12 months Locke has caused us to process: A. Identifiers (account identifier and email address, for authentication and licence validation), and F. Internet or other electronic network activity, limited to the IP address and connection metadata that any network request necessarily discloses, and to the configuration you have chosen. No other category — including G. Geolocation, K. Inferences, and L. Sensitive personal information — is collected by Locke.
- Permissions Locke Requests
In Short: The access required to read a text box before you hit send, and nothing more.
6.1 Browser extension. The extension requests permission to read and modify text input fields on a fixed list of supported AI interfaces, declared in its manifest and visible to you at install time. It uses that access solely to detect and mask sensitive data in what you are about to send. It does not use those permissions to collect, record, or transmit page content, and it does not run on sites outside that list. Some entries on the list are whole domains rather than a single page — for instance, a search engine that has an AI feature — which means the extension loads on other pages of that domain too. It inspects only what you type into an input field, wherever it runs.
6.2 Desktop application. The desktop application requires operating-system access sufficient to observe and modify text you are entering into the AI applications you have chosen to protect. That access is used only for detection and masking, on your device, in memory. Which applications Locke is active in is under your control in the app's settings.
6.3 Local storage. Locke stores your settings and locally generated reports on your device. Uninstalling Locke, or clearing its data from within the app, removes them.
- Retention
Your content — Never retained by us, because it is never transmitted to us. On your own device, content is held only transiently in memory during inspection and is not written to disk by Locke.
Detection results and reports — Retained on your device, under your control. By default Locke keeps them indefinitely rather than deleting them on a schedule, because they are yours and we would rather not throw away your record without being asked. You can delete them at any time from within Locke, and uninstalling removes them.
Your synced settings — Held for as long as your account is open, and deleted with it.
Account and billing records — Retained as set out in the Website Privacy Policy, which explains why billing records are kept longer than the rest.
License-validation requests — Not retained as a usage history. We hold your current subscription status, not a log of when you used Locke.
- Security
Local-first architecture — The strongest control here is structural: content that never leaves your device cannot be intercepted, breached, or compelled from us.
Encryption in transit — TLS for license validation, authentication, and update delivery.
Signed releases — Desktop releases are signed, and browser-extension updates are distributed through the applicable browser marketplace.
Least privilege — Locke requests only the access it needs to inspect the text you are about to send.
What local processing does not protect against. Running on your device means Locke's protection is bounded by your device's own security. It cannot defend against malware, keyloggers, screen capture, unauthorized physical access, or a compromised operating system. It also cannot recover data you have already sent to a third party. More detail on our threat model is on the Locke security page.
Detection is not perfect. Locke uses pattern matching and on-device machine learning, and can produce both false positives and false negatives. It is a tool to support your judgment, not a substitute for it, and using it does not by itself constitute compliance with HIPAA, GDPR, GLBA, or any other framework.
- Children
Locke is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children under 18. If we learn that we have, we will deactivate the account and delete the data. Contact info@sonomos.ai if you become aware of any such collection.
- Your Privacy Rights
The rights described in the Website Privacy Policy — including the CCPA/CPRA rights of California residents, the rights available under other US state privacy laws, and GDPR, UK GDPR, PIPEDA, and Australian and New Zealand equivalents — apply in full to the personal information we hold in connection with Locke.
Because that information is a single account record, you do not need to submit separate requests for our websites and for Locke. One request covers both. To exercise a right, visit sonomos.ai/contact, email info@sonomos.ai, or write to Sonomos, Inc., 9924 Kika Court #2416, San Diego, CA 92129. We respond to verified requests within 45 days.
We cannot act on a request concerning the content Locke processed on your device, because we never held it. That data is under your control: you can delete it yourself from within Locke or by uninstalling it.
- International Users
Our account, licensing, and billing infrastructure is hosted in the United States. If you use Locke from outside the United States, the account information described in Section 5 will be transferred to and processed in the United States, under Standard Contractual Clauses and other appropriate safeguards where required.
The content Locke inspects is not transferred anywhere. It is processed on your device, in your own jurisdiction, and never crosses a border on our account.
- Verifying These Claims
A privacy product should not ask for faith. Our Trust & Transparency page sets out what actually leaves your device in checkable terms, along with an honest account of what is not yet true, and our Locke security page describes the architecture in more detail. If you find a discrepancy between this policy and Locke's behavior, tell us at info@sonomos.ai — we would rather fix it than defend it.
- Changes to This Policy
We may update this policy from time to time. Material changes will be indicated by an updated "Last Updated" date above and may include direct notification. If a future release of Locke changes what it sends to our servers, we will update this policy before that release ships, not after.
- Contact Us
Sonomos, Inc.
9924 Kika Court #2416
San Diego, CA 92129
United States
General: info@sonomos.ai
Online: sonomos.ai/contact