Kitestring Browser Extension — Privacy Policy

Last updated: June 30, 2026

Overview

The Kitestring browser extension is a workplace analytics tool deployed by organizations to their teams. It helps organizations understand how their people use web-based AI tools, and helps individuals improve their own AI use by learning from peers. This policy explains what the extension processes, what it transmits, and what it deliberately does not.

Kitestring is provided to you by your organization. Your organization is the controller of the data the extension produces; Kitestring operates as its processor.

What the extension does

When you use a supported web-based AI tool (currently ChatGPT, Claude, Gemini, Perplexity, Mistral, DeepSeek, Grok, and the Gemini assistant inside Google Workspace — Google Docs, Sheets, Slides, and Drive) in a browser where the extension is installed, the extension processes your interactions locally in order to generate de-identified usage signals.

In Google Workspace, the extension processes only the request you type to the Gemini assistant (for example, “help me write a summary”). It does not read the contents of your documents, spreadsheets, presentations, or files, and it does not access Gmail at all. That request text is de-identified on your device in the same way as any other prompt, described below.

How your prompts are de-identified, and what is stored

Your prompts are processed locally before anything is transmitted. The extension removes common personal identifiers from your prompt text on your device, including email addresses, web addresses (URLs), phone numbers, payment card numbers, government identification numbers such as Social Security numbers, street addresses, dates, and multi-word capitalized names.

This on-device step is automated and rule-based — it uses pattern matching for structured identifiers (such as emails, URLs, phone numbers, and dates) and a capitalization heuristic for multi-word names. On its own, this step would not catch names written in lowercase, single-word names, or identifiers in unusual formats — which is why a second pass runs on Kitestring’s servers, described below.

After this processing, what is transmitted to Kitestring is a de-identified skeleton of the prompt — a reduced representation with recognized identifiers removed — together with lightweight metadata.

Before this skeleton is stored or analyzed, Kitestring applies a second, automated de-identification pass on its servers. This server-side step uses named-entity recognition to remove personal and organization names — including the lowercase and single-word names the on-device step does not catch — while keeping the general wording needed to classify the type of work. Only this further-reduced skeleton is stored or analyzed; the prompt text is processed transiently in memory to perform this step and is never written to storage.

Both de-identification steps are automated. Together they remove the large majority of personal identifiers, but no automated system is perfect, and you should not assume that every piece of personal information will be removed in all cases.

Your AI responses are not transmitted. The content of the responses you receive from AI tools is not sent to Kitestring. Only a count of the response length (number of characters) is recorded.

Your raw conversations are never stored. Kitestring does not retain the original text of your prompts or responses. What is sent from your device is the de-identified skeleton described above, which is further de-identified on the server before it is stored; response content is never transmitted at all.

What information Kitestring receives

What Kitestring does not do

How the information is used

The de-identified signals are used to give your organization’s leadership visibility into AI adoption and spend at an aggregate level, and to power a coaching experience that helps team members improve how they use AI by learning from anonymized peer patterns. People administering Kitestring see patterns, classifications, and totals — not the content of what you typed.

Permissions

The extension requests only the access it needs to do the above:

Data sharing

Kitestring shares the processed signals with your organization, which deployed the extension. Kitestring does not sell your information or share it with third parties for their own purposes, except service providers acting on Kitestring’s behalf under contract, or where required by law.

Data retention

Kitestring retains the de-identified information it receives only as long as needed for the purposes described in this policy, applying different periods by data type:

Aggregated or anonymized statistics that cannot be linked to an individual may be retained beyond these periods.

Your choices and rights

Kitestring is deployed by your organization, which decides whether and how it is used; your use may be governed by your organization’s workplace and monitoring policies. Because your organization is the controller of this data:

Contact

Questions about this policy can be directed to help@getkitestring.com.

Changes

We may update this policy. Material changes will be reflected by the “Last updated” date above.