Privacy Policy — Layer Security

Last updated: July 5, 2026 · Applies to the “Layer Security” Chrome extension.

Layer Security helps organizations understand and govern how AI services are used on company devices. This policy explains exactly what the extension does and does not collect. The description below matches the actual behavior of the software.

What we collect (metadata only)

What we do NOT collect

How detection works (why broad host access is required)

Storage and transmission

The extension operates in one of two modes:

  1. Standalone mode (default): detection metadata is stored only on the device (chrome.storage.local) and is not sent anywhere. Up to the most recent 500 records are kept (older ones are deleted automatically). The user can clear all records at any time.
  2. Organization mode (only when connected to a console): if the organization deploys the extension and configures a “console URL and device enrollment key,” the metadata and guard events described above (metadata only, never prompt content) are sent to the organization’s own management console. That destination is a server operated by the customer organization — not a shared cloud operated by the developer. When no enrollment key is configured, organization mode is inactive and the extension runs in standalone mode.

Permissions

PermissionWhy it is used
webRequestTo inspect the structure (LLM API schema) of outgoing requests.
storageTo store detection history and settings on the device, and to receive administrator policy.
alarmsTo periodically retry unsent data and synchronize policy.
<all_urls>AI can be used on any domain or self-hosted endpoint, so detection cannot be limited to specific sites. The content script (personal-information guard) also runs on all sites to check content before it is sent.

Guards (optional)

The personal-information guard and unapproved-AI guard operate only when enabled by the organization’s policy. All checks are performed on the device. The personal-information guard inspects content immediately before it is sent to an AI service and never stores or transmits the value itself — only the category label is recorded. In “warn” mode the user may choose to proceed; this is a safeguard against accidental disclosure, not employee surveillance.

Third parties

We do not sell data or share it with third parties. In organization mode, data is sent only to the management console of the organization that deployed the extension. The extension does not execute remote code — all scripts are bundled in the package.

Contact

Layer Security (Totsuka Tech LLC)
Email: contact@layersecurity.jp
Web: layersecurity.jp

This English policy is the canonical privacy policy referenced from the Chrome Web Store listing. A Japanese version is available on request.