Smartflow Edge privacy

Aperion / Smartflow. This page is the privacy policy for the Chrome extension (ID nhikdojhpifjjjodfadncfjkpmimkejb).

What it collects

Hostnames of sites the browser navigates to, if they match a known AI product or a host your admin put on a block/allow list. Example: chatgpt.com. Not the path, not the title, not the page body, not the prompt.

If you enroll the browser, it also stores a device id, the proxy URL you pointed it at, and (when SSO is configured) the email the identity provider returned.

Policy text your admin signed may be prepended on sanctioned chat UIs. That text is company policy, not something we scrape from the page.

Where it goes

Counts and enroll data go to the Smartflow API your admin set as the proxy URL (your company gateway, not a third-party analytics shop).

If the optional native host is installed, Edge writes a local audit line under ~/.halo/ and ~/.aperion-shield/ on that machine. Prompt previews are stripped before disk.

What it does not do

It does not MITM TLS. It does not screen-record. It does not sell data. It does not send traffic to us unless your proxy URL is our hosted gateway and your company is a customer.

Permissions

webNavigation and site access exist so we can count AI hosts and so declarativeNetRequest can block hosts the signed policy names. identity is company SSO enroll. nativeMessaging is the local ledger; it no-ops if the host is missing. storage holds enroll state on the device.

Contact

privacy@aperion.ai