Privacy Policy
Last updated: July 1, 2026
This policy covers the AIhood Witness browser extension and the server it optionally talks to (verify.authentai.com), both operated by TripleID Technologies Inc. Effective July 1, 2026. If anything below is unclear, contact us at info@aihood.ai.
What this extension is for
AIhood Witness lets you record your own conversations with AI assistants (currently ChatGPT, Claude, and Gemini) as a cryptographically signed, tamper-evident record, which you can export and share with anyone who wants to independently verify it wasn't altered after the fact. Recording only happens when you explicitly start it, on a tab you're actively using.
What we collect, and why
Conversation content: while you have a recording active, the extension reads the conversation text rendered on the page (your prompts and the AI's responses) in order to sign and store it. This content is signed and saved in your browser's local storage (IndexedDB) on your own device. It is never sent to our server in plaintext, and it never leaves your device at all unless and until you click "Export Evidence Package" yourself, at which point you choose where to save the resulting file and who to share it with — we do not receive a copy of it. Email address (only if you choose "Account-Verified Identity"): one of four signing-identity options lets you verify an email address to obtain a certificate binding your signing key to that address; if you choose this option, we receive the email address to send a one-time verification code and to issue that certificate — the other three identity options never send us an email address at all. Device PIN (only if you choose "Hardware-Backed Identity"): this option uses a physical USB security key, and the PIN you enter to unlock it is kept only in memory for the browser session and sent only to a small helper program on your own computer — never to us. Public keys and certificates: depending on which signing identity you use, we may receive and store a public key, a certificate we issue for it, and (for the hardware option) a device serial number and public key read from your security key — cryptographic material, not personal data on its own, and what makes independent verification of your exported records possible. Standard server logs: like most web servers, ours may log basic technical information (such as IP address and timestamp) for security and operational purposes; we do not use this to build behavioral profiles.
What we do not collect
We do not track which websites you visit. We do not log your clicks, mouse movements, or keystrokes. We do not collect your name, phone number, physical address, payment information, health information, or precise location. We do not use any third-party analytics or advertising SDKs — there are none in the extension's code. We do not sell your data, and we do not use it for anything other than providing the features described above.
Where your data actually lives
Your recorded conversation content and your private signing key (for the non-hardware identity options) are stored only in your own browser's local storage on your own device. We have no access to either unless you choose to export and share the result yourself. The only things that ever reach our server are: an email address (if you use that identity option), a one-time verification code exchange, a public key and the certificate we issue for it, and — for the hardware option — a device serial number, public key, and (if you choose to bind your device to your account) a signed statement linking the two.
Sharing with third parties
We do not sell or share your data with third parties for advertising or any other unrelated purpose. TripleID Technologies Inc. does not use sub-processors beyond what's needed to host the verify.authentai.com server and deliver the one-time verification email.
Your choices and rights
You can use three of the four signing-identity options (self-generated key, imported key, or hardware key) without ever giving us an email address. You can clear your locally stored identity from the extension's Options page at any time — because your conversation content and private key material live in your own browser, uninstalling the extension or clearing its storage removes them from your device. If we hold an email address, certificate, or device-binding record for you and you'd like it deleted or want a copy of it, contact us at info@aihood.ai and we will act on that request.
Children's privacy
AIhood Witness is not directed at children, and we do not knowingly collect personal information from children under 13 (or the relevant age in your jurisdiction).
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above. Continued use of the extension after a change means you accept the updated policy.
Contact
Questions about this policy or your data: info@aihood.ai or aihood@tripleid.com.