Off leaves every chat page untouched.
Set by your organisation's policy
Masks personal data in what you type into AI chats before it is sent, and puts the real values back into the answer.
administrator mode
The settings on this page are read-only in this browser. Your administrator can sign in here to change them.
browser policy
These settings cannot be changed here, and not by the add-on's administrator either. To change them, ask your IT department.
step 1
Two values, then Save and Check connection:
https://api.obvelo.com
for OBVELO's hosted service. If your organisation runs its own OBVELO
gateway, use the address it gave you instead.app.obvelo.com, open Gateway keys and
press Mint a key (a label such as
browser helps you recognise it later). Copy it straight
away: it is shown once. The add-on is included in every paid plan; a
key from a plan without it is refused with a message saying so.A line holding both the address and the key, separated by a space, can be pasted into either field.
Set by your organisation's policy
Set by your organisation's policy
Kept in this browser. It is sent only to the gateway address above, never to the chat site.
step 2
Off leaves every chat page untouched.
Set by your organisation's policy
A panel under the prompt lists every value that will be masked; untick one to send it in clear.
In milliseconds, 200 to 5000. Each check is billed per character of the prompt, so a shorter wait costs more.
Only applies while the panel is on screen — with no panel, Enter keeps masking, because an extension that quietly does nothing is worse than one that refuses out loud.
Set by your organisation's policy
Off: a PDF, an image, a video or a file that is too large is attached as it is, with a warning naming it. On: such a file is not attached at all. Office documents and text files are masked either way when attached with the paperclip.
Set by your organisation's policy
optional
Kept in this browser and nowhere else; they travel only inside a masking request. One entry per line, at most 200 in each list.
Add | Label after a value to name its
token. Letters and spaces only; anything else becomes
Data.
The one setting that increases what reaches the model: each value here is sent in clear, in every prompt.
optional
Narrow the check to your jurisdictions, or switch categories and labels off. The choices come from the catalogue your gateway really loaded — press Check connection to load them.
sites
Built in and on by default — masked on the way out, answers restored on screen:
The browser asks for permission for that site alone. The prompt box is found by where your cursor is.
administrator
A list of people and organisations to mask even when no rule knows
them — clients, staff, partners. One per row, with a header in any
language (name, nazwisko,
company, firma…), or a plain text file with
one value per line. At most 20 000 entries. A spreadsheet must
first be saved as CSV.
Kept in this browser only. It is never sent to the shop or to any server except inside a masking request — and then only the entries that could appear in that prompt.
No dictionary loaded.
administrator
An administrator locks every setting on this page — the gateway, the key, pausing, sites, lists, the dictionary — so they cannot be changed by accident. This is a guard against accidental changes, not a security boundary: anyone who can manage extensions in this browser can remove the extension, and the lock with it. That is what the activity trail below makes visible.
Signed in as the administrator. The page locks again after 10 minutes without activity, and when it is closed.
One file with every setting on this page, to set up the next browser the same way. Import it there before anyone else creates an administrator, or while signed in.
Settings stay as they are and become editable by whoever uses this browser.
Replaces the settings on this page. A package that carries an administrator locks this browser with that administrator's login and password.
This browser tells your OBVELO gateway a few things about the
extension itself, so an administrator can see that it is running and
how it is set up. Each event carries a random installation ID made
when the extension was installed — no name, no account, nothing that
identifies you — plus a time and at most one of: the hostname of a
chat site added or removed, the type of a file sent
unmasked (for example pdf, never its name), the
names of settings that changed (never their values),
or the number of entries in a loaded dictionary.
The events are: a heartbeat when the browser starts and at most every six hours, pausing and resuming, a site added or removed, a file attached unmasked, administrator sign-in and failed sign-in, settings changed, a dictionary loaded, and removal of the extension.
The trail never contains content — no prompt text, no masked or unmasked value, no file name, no dictionary entry. The gateway keeps the events for at most 30 days, and writes each one as a line in its log, which is kept for as long as that log is.
Press Enter once — the text in the box is replaced by its masked version and you can read exactly what is about to leave. Press Enter again, or click send, to send it.
If masking the text fails, nothing is sent. An unreachable gateway, a refused key or a page whose markup changed all leave the text untouched and say so on screen. This extension never sends unmasked text on your behalf.
Files are the exception, and it is your setting. A file OBVELO cannot mask — or cannot mask right now, because the gateway did not answer — is attached as it is, with a warning naming it. Dropped and pasted files are never masked. Switch on Block files OBVELO cannot mask above to refuse such files instead.
The key and the token map stay in the extension's own context: the page cannot read them, and the map is held in memory only — it is never written to disk. The real values are put back into the page you are looking at, so the chat site's own page can see them there, just as it sees what you type before it is masked. What the add-on keeps from the model is what gets sent.