AI Off privacy details
No telemetry, analytics, crash reporting, fingerprinting, advertising identifiers, accounts, or AI. Recipients see connection information, including IP addresses.
Requests
Signed rules: rules.aioff.app/rules.json and rules.json.sig, every six hours. Same public feed, no identifier.
Lists: Level 3 and above fetch public GitHub domain/channel lists daily.
Images: Level 3 and above read labels locally. Cache misses fetch image bytes from their source only.
Policy: Configured hosted URLs: every 15 minutes. Static policies: no hosted request.
Sync: Not available yet. When enabled, sync.aioff.app receives passphrase-encrypted settings, a sync identifier, and a license key without name/email. Stored ciphertext is unreadable without the passphrase. Requests: during use and every six hours.
Purchases: Not available yet. Stripe or Lemon Squeezy handles payment/email under its policy; purchase notifications reach the license service. license.aioff.app uses provider/receipt identifiers for key pickup, retrying every three seconds for about one minute. Receipt/key retention: 366 days; no email customer database. Configured Resend delivery receives address/message.
Chosen links: GitHub receives opened links; reports submit only after review and Submit, containing URL/selector. Exclude private content. Email shares address/message.
Network: Subscribed tools fetch list files from rules.aioff.app on their schedule. DNS providers process DNS requests under their policies. Partner profile unavailable.
Local data and site
Local: level, paused sites, words, rules, daily per-rule counts without URLs/content, image-label cache keyed by hashed address. Only optional sync sends encrypted settings. License checks are local.
No student data/reporting in v1. Future aggregate reporting requires default-off controls, disclosure inside the extension, and a signed data privacy agreement.
Static site: no cookies, third-party scripts, or fonts. Checkout is external.