OBVELO
browser add-on · settings
not checked

Masks personal data in what you type into AI chats before it is sent, and puts the real values back into the answer.

step 1

Connect to your gateway

Two values, then Save and Check connection:

  1. Gateway address — https://api.obvelo.com for OBVELO's hosted service. If your organisation runs its own OBVELO gateway, use the address it gave you instead.
  2. Gateway key — sign in to your OBVELO account at app.obvelo.com, open Gateway keys and press Mint a key (a label such as browser helps you recognise it later). Copy it straight away: it is shown once. The add-on is included in every paid plan; a key from a plan without it is refused with a message saying so.
  3. Press Save settings at the bottom. The browser asks for permission to reach the gateway address — allow it, or nothing can be masked.

A line holding both the address and the key, separated by a space, can be pasted into either field.

Kept in this browser. It is sent only to the gateway address above, never to the chat site.

step 2

How it behaves

Off leaves every chat page untouched.

A panel under the prompt lists every value that will be masked; untick one to send it in clear.

In milliseconds, 200 to 5000. Each check is billed per character of the prompt, so a shorter wait costs more.

Only applies while the panel is on screen — with no panel, Enter keeps masking, because an extension that quietly does nothing is worse than one that refuses out loud.

Off: a PDF, an image, a video or a file that is too large is attached as it is, with a warning naming it. On: such a file is not attached at all. Office documents and text files are masked either way when attached with the paperclip.

optional

Your own lists

Kept in this browser and nowhere else; they travel only inside a masking request. One entry per line, at most 200 in each list.

Add | Label after a value to name its token. Letters and spaces only; anything else becomes Data.

The one setting that increases what reaches the model: each value here is sent in clear, in every prompt.

optional

What to check

Narrow the check to your jurisdictions, or switch categories and labels off. The choices come from the catalogue your gateway really loaded — press Check connection to load them.

sites

Where it runs

Built in and on by default — masked on the way out, answers restored on screen:

The browser asks for permission for that site alone. The prompt box is found by where your cursor is.

administrator

Organisation dictionary

A list of people and organisations to mask even when no rule knows them — clients, staff, partners. One per row, with a header in any language (name, nazwisko, company, firma…), or a plain text file with one value per line. At most 20 000 entries. A spreadsheet must first be saved as CSV.

Kept in this browser only. It is never sent to the shop or to any server except inside a masking request — and then only the entries that could appear in that prompt.

No dictionary loaded.

administrator

Administrator

An administrator locks every setting on this page — the gateway, the key, pausing, sites, lists, the dictionary — so they cannot be changed by accident. This is a guard against accidental changes, not a security boundary: anyone who can manage extensions in this browser can remove the extension, and the lock with it. That is what the activity trail below makes visible.

What your administrator can see: the activity trail

This browser tells your OBVELO gateway a few things about the extension itself, so an administrator can see that it is running and how it is set up. Each event carries a random installation ID made when the extension was installed — no name, no account, nothing that identifies you — plus a time and at most one of: the hostname of a chat site added or removed, the type of a file sent unmasked (for example pdf, never its name), the names of settings that changed (never their values), or the number of entries in a loaded dictionary.

The events are: a heartbeat when the browser starts and at most every six hours, pausing and resuming, a site added or removed, a file attached unmasked, administrator sign-in and failed sign-in, settings changed, a dictionary loaded, and removal of the extension.

The trail never contains content — no prompt text, no masked or unmasked value, no file name, no dictionary entry. The gateway keeps the events for at most 30 days, and writes each one as a line in its log, which is kept for as long as that log is.

Export the configuration

This file is a secret. It contains the gateway key, which lets anyone mask on your account, and — if you include it — the organisation dictionary, which is a list of people. Keep it where you keep passwords, send it only over a channel you would send the key over, and delete it once the next browser is set up. It carries the administrator's password HASH, never the password.

How it works, and what happens when something fails

Press Enter once — the text in the box is replaced by its masked version and you can read exactly what is about to leave. Press Enter again, or click send, to send it.

If masking the text fails, nothing is sent. An unreachable gateway, a refused key or a page whose markup changed all leave the text untouched and say so on screen. This extension never sends unmasked text on your behalf.

Files are the exception, and it is your setting. A file OBVELO cannot mask — or cannot mask right now, because the gateway did not answer — is attached as it is, with a warning naming it. Dropped and pasted files are never masked. Switch on Block files OBVELO cannot mask above to refuse such files instead.

The key and the token map stay in the extension's own context: the page cannot read them, and the map is held in memory only — it is never written to disk. The real values are put back into the page you are looking at, so the chat site's own page can see them there, just as it sees what you type before it is masked. What the add-on keeps from the model is what gets sent.