privacy
privacy policy
this policy explains how pleamo collects, uses, and protects personal data, in line with UK GDPR and EU GDPR. pleamo is operated by Polarize Ltd, registered in England and Wales. it describes how the pleamo browser extension and dashboard actually work, please read it, because a security product that inspects web addresses deserves a clear explanation.
the short version
- to protect you, the extension sends us the address of a site you're about to open, its domain and page path, so we can judge whether it's dangerous.
- we strip the query string and fragment (everything after
?or#) before the address leaves your browser. that's where tokens, search terms, and personal details usually live. - we never receive the contents of the pages you visit, your keystrokes, or your form data.
- we store a history of the sites we blocked or warned you about: not a log of your safe browsing.
- checks run from your extension: through our hosted service when you're signed in, or through your own AI if you choose that option. we don't sell data, and we don't run ads.
who we are
pleamo is a product of Polarize Ltd ("we", "us"), the data controller for the personal data described here. you can reach us at hello@pleamo.app.
what we collect and why
account data
when you sign in with Google, we receive your email address, name, and profile picture from Google, and a stable account identifier. we use these to create and secure your account and to contact you about the service. our lawful basis is performance of our contract with you.
site-check data
when the extension checks a site, we process the site's domain and page path (with the query string and fragment removed), together with your account and a coarse, hashed indicator of your device/network used only to enforce plan limits and prevent abuse. we use this solely to return a safety verdict and to meter usage. our lawful basis is performance of our contract and our legitimate interest in preventing fraud and abuse of the service.
structural page signals (only for sites we flag)
when a site looks suspicious, the extension inspects the page's structure in your browser to double-check it, and sends us a small set of structural signals: whether the page has a password field, whether a form would post your password to a different website, the hostnames of the third-party scripts and frames it loads, how obfuscated its code is, and whether it prominently names a well-known brand. we do not receive the page's text, its title, your keystrokes, or anything you type. this happens only for sites we've already flagged as suspicious, never for ordinary browsing, and it lets us catch threats that hide from a server-side check.
blocked-site history
when we block or warn you about a site, we record that event (the domain, our verdict, and the reason) so you can review it in your dashboard and report mistakes. we do not record the sites we judged safe.
false-positive reports
if you tell us we got a site wrong, we store the domain and your note so we can review and correct our database. our lawful basis is our legitimate interest in improving accuracy.
AI processing
for sites we can't judge from our own database or Google Safe Browsing, we ask an AI model to assess the site's address and make a call. only the stripped address is sent for this assessment; page contents are not. the model is used to classify risk and does not make automated decisions with legal or similarly significant effects about you.
threat data sources
to block known-bad sites instantly, our database is seeded in part with malware URLs from URLhaus, a free threat feed operated by abuse.ch. we use this data only to protect you, and we never share your browsing with them.
using your own AI
pleamo can run on your own AI instead of ours. if you point it at a local model (for example Ollama on your own machine), the site address and any structural signals stay on your device and are sent only to that local model: nothing reaches us. if you point it at your own third-party AI key, those checks are sent to the provider you chose, under your own account with them, not to pleamo. in this mode we don't receive your site checks at all, and you don't need a pleamo account.
who we share data with
we use a small number of processors to run pleamo, under contract and only as needed:
- Cloudflare: hosting, storage, and network security.
- Google: sign-in, and the Safe Browsing reputation service.
- our AI provider: to assess unfamiliar site addresses.
- Stripe: to process payments (we never see your full card details).
- Google Analytics and Microsoft Clarity: website analytics, and only if you accept analytics in the cookie banner. see our cookie policy.
we do not sell your personal data, and we do not share it for advertising.
international transfers
some of our processors (Cloudflare, Google, Microsoft, Stripe, and our AI provider) operate outside the UK and EEA, including in the United States. where personal data is transferred abroad, we rely on appropriate safeguards such as the UK International Data Transfer Agreement and the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection.
how long we keep it
account data is kept while your account is active. blocked-site history and usage counters are kept only as long as they're useful to you and to abuse-prevention, and are then deleted or aggregated. you can delete your account at any time, which removes your personal data except where we must keep records by law.
your rights
under UK/EU GDPR you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to data portability. to exercise any of these, email hello@pleamo.app. you also have the right to complain to the UK Information Commissioner's Office (ICO) or your local supervisory authority.
cookies
the pleamo website uses essential cookies and, with your permission, analytics. see our cookie policy for details.
changes
we'll update this policy as pleamo evolves and note the date above. material changes will be communicated through the service.