Designspin
Last updated: 24 July 2026

Pronto Mask Privacy Policy

Pronto Mask redacts sensitive documents entirely on your device. Your images are never uploaded, not to me and not to anyone else.

Who I am

Pronto Mask is made by Jason Foster, trading as Designspin, a software engineering practice based in Norwich, UK. For anything related to your personal data, get in touch through the contact form.

The short version

Pronto Mask is a browser extension that blurs or blacks out sensitive fields (passport photos, ID numbers, faces) on images you are viewing in Gmail and Google Drive. Every part of that work happens inside your browser's memory, on your device.

I run no servers for the extension, so I never receive your images, your documents, or any data derived from them. Redaction and the Pro auto-detection features work with your network cable unplugged.

What happens on your device

  • Redaction, which covers drawing boxes, blur, pixelation, flattening, and saving the finished file, runs in your browser's memory.
  • Auto-detection (Pro) runs on-device using models bundled inside the extension. This covers the OCR that finds ID numbers and machine-readable passport lines, and the face detection that suggests face blurs. Image pixels never leave the tab.
  • Your settings, your free-tier usage counter, and your local audit history are stored in the browser's extension storage. The settings and usage counter use Chrome's standard synced storage, which means Chrome may copy them between your own signed-in browsers; they contain no document content, just preferences and a number.

What uses the network

  • Re-fetching an image you can already see. Browsers block saving an edited copy of a cross-origin image ("canvas tainting"), so the extension may re-request the bytes of an already-visible image from the site it is hosted on, meaning Google's own servers, directly from your browser. That data is used in your tab and is never sent to me or any third party.
  • Subscription status (Pro only). Payments are handled by ExtensionPay with checkout by Stripe. They receive the email address you enter at checkout and your payment details, and they tell the extension one thing: whether your subscription is active. They never see your images. I never see your card details.

That is the complete list. The extension contains no analytics, no telemetry, no tracking, and no advertising.

What I hold about you

Nothing, in almost every case. Because there are no servers, the free extension gives me no record that you exist. If you subscribe to Pro, the subscription record (your email and payment status) lives with ExtensionPay and Stripe as processors; I can see it in their dashboards in order to provide support and manage the product. That is the only personal data connected to Pronto Mask that I can access.

Your controls

  • Clear all local data any time from the extension's Settings page. It wipes settings and local history on that device.
  • Local audit entries prune themselves automatically after the retention window you configure (90 days by default).
  • Cancel a Pro subscription any time via Settings → Manage subscription; access continues to the end of the paid period.

Your rights

Under UK GDPR you can ask me to show you, correct, delete, restrict, port, or object to the processing of any personal data I hold about you. For Pronto Mask that in practice means the subscription record described above. Get in touch through the contact form and I will respond within one month.

If you are unhappy with how I have handled your data you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

A note on what Pronto Mask is for

Pronto Mask helps you visually redact documents. It does not, by itself, make you compliant with GDPR or any other regulation, and automatic detection can miss things. Always check the result before you share a redacted file.

Changes to this policy

If the extension's data handling ever changes, such as a new supplier or a new feature that touches the network, I will update this page, bump the date at the top, and note it in the extension's changelog.