How it works, and your privacy

Clotr reads what you're about to send on your own device, and only there. Here's what happens, what it keeps, and how to check it yourself.

What happens when you type something private

  1. You type or paste as you always do: in an AI chat, an email, or a message.
  2. The engine reads it on your device. It looks for passwords, ID numbers, personal details and what scammers ask for, even when they're written out in words, like "five five five". Nothing is sent anywhere to do this.
  3. If it finds something, a note says what and lets you cover it. Cover it, or send it as is: it's your call, Clotr only stops a message if you've told it to.

One engine everywhere

Each part of Clotr runs the same engine, so a detail is caught the same way wherever you type: the extension today, and the apps for Windows and Android as they come. Clotr has absolutely NO AI. It's plain pattern matching that anyone can read, and it never talks to an AI service to do its job.

Your privacy

  • Clotr doesn't send anything anywhere, no servers and no analytics, and a test checks that every single time the code changes.

  • It never saves what you typed, just what kind of thing it found, on which site, when, and what you did about it. You can look at all of it and delete it whenever you want.

  • It only runs where you say, out of the box only on AI chats, and on your email and chat apps only on the ones you pick, with your browser asking you first.

  • There's nothing to sign up for and nothing to sign in to.

Check it yourself

See what it keeps

Clotr's own page What Clotr stores shows every record it keeps, and what your browser allows it to reach: nothing outside the browser.

Watch it stay quiet

Open chrome://extensions, switch on Developer mode, and under Clotr click service worker. Its Network tab stays empty while you use it.

Read the tests

A test in the code fails every build that could send data anywhere.

Rebuild it

Every release can be rebuilt from the code, byte for byte: its checksum matches the release's SHA256SUMS.txt.

Test results

Version 1.2.0, tested 2026-10-05. I hid 6,200 personal details in 10,000 made-up messages, and this build caught every one, without a false alarm on the 3,800 that had nothing to catch. That's the set I used to find and fix what earlier versions missed, so it shows those cases are covered, not that Clotr catches everything. Typed the way people type on a phone, it caught 310 of 310. Real life is messier, so if it misses something or warns about nothing, tell me.

A score that gets worse fails the tests.