PII Shield

PII Shield – Terms of Service

Effective Date: February 6, 2026

PLEASE READ CAREFULLY. By using PII Shield, you agree to the following terms:

PII Shield is owned and operated by Vervian Inc.

1. What We Provide

PII Shield offers a Chrome browser extension and web-based dashboard that help identify and optionally redact personal information before content is submitted to AI tools, web forms, or third-party systems.

Our platform includes:

  • Configurable detection based on selected privacy laws
  • Client-side redaction and preview options
  • Team-based access control and usage reports
  • Subscription management and secure billing via Stripe

2. Detection Accuracy & Limitations

PII Shield is designed to assist your organization in identifying personal information before it is shared with AI tools and third-party systems. Our detection uses a combination of pattern matching, heuristics, and configurable law-specific rules to flag potential personal data exposure. While our detection models achieve a high success rate across diverse scenarios, and we continuously improve accuracy, PII Shield is an assistive tool — not a substitute for human review, legal counsel, or a formal data protection program.

⚠️ No Guarantee of 100% Detection

While our success rate is very high, we cannot guarantee that all personal information will be intercepted in every scenario. No automated system can achieve 100% detection. PII Shield is intended as a first line of defense that significantly reduces risk compared to no protection, but it does not eliminate the need for human judgment and organizational data handling policies. Users remain ultimately responsible for reviewing content before submission.

What We Provide

  • Visibility into AI usage patterns across your organization
  • Alignment with global privacy laws (GDPR, HIPAA, PIPEDA, etc.)
  • Flagging and reporting of potential privacy issues
  • Significantly better protection than the alternative (no protection)

PII Shield is a tool to assist compliance—not a legal guarantee of compliance.

To the maximum extent permitted by law:

  • We are not liable for any direct, indirect, incidental, or consequential damages arising from the use (or misuse) of our services.
  • This includes, but is not limited to, damages resulting from the exposure of personal information that was not detected or redacted by the tool.
  • Our total aggregate liability for any claims arising from or related to the service shall not exceed the amount you paid to PII Shield in the twelve (12) months preceding the claim.

Disclaimer of Warranties

PII Shield is provided on an "AS IS" and "AS AVAILABLE" basis, without warranties of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, accuracy of detection, completeness of coverage, or non-infringement. We do not warrant that the service will be uninterrupted, error-free, or that all personal information will be detected in all contexts.

Law Alignment Accuracy

PII Shield's privacy law mappings (e.g., which data types are relevant to GDPR, HIPAA, PIPEDA, etc.) are based on our best interpretation of applicable legislation and are provided for informational purposes only. These mappings do not constitute legal advice. Laws and their interpretations evolve over time, and our mappings may not reflect the most current requirements. You are responsible for determining which laws apply to your organization and verifying that PII Shield's configuration meets your specific compliance obligations.

3. Acceptable Use

You agree not to:

  • Use PII Shield in violation of any applicable laws or regulations
  • Attempt to reverse-engineer, duplicate, or tamper with the service
  • Share login credentials beyond your subscribed team limit
  • Use the service to scan or process data that you do not have the right to access

4. Data Storage & Encryption

What We Store

Redacted Content: When PI is redacted, we do not store the original text. The sensitive content is replaced before transmission and is never captured by our systems.
Flagged Prompts (Bypass): When a user bypasses a PI warning and sends content anyway, the prompt is stored and readable by your organization's administrators. This provides compliance visibility into potential data exposure events.
Metadata Only: We store counts and categories of detected personal information for reporting purposes, but not the content itself.

⚠️ Flagged Content Visibility

If your organization has a PII Shield license, administrators can view prompts that were flagged and bypassed. This is intentional—it enables compliance teams to monitor potential data exposure and take appropriate action.

Encryption Modes

  • 1.
    Standard Encryption (Default): Flagged content is encrypted with AES-256 using keys managed by PII Shield. In this mode, Vervian/PII Shield personnel agree not to access your data, but technically retain the ability to do so for support or legal compliance purposes. If you lose access to your account, we can help recover your data.
  • 2.
    Zero-Knowledge Encryption: Content is encrypted in your browser with a passphrase only you control. Vervian/PII Shield cannot decrypt this data under any circumstances. This mode is required for healthcare organizations (PHIPA, HIPAA) handling patient data.

🔑 Zero-Knowledge Key Loss Warning

If you enable Zero-Knowledge Encryption and lose your encryption passphrase, all stored incident data is permanently unrecoverable. Vervian/PII Shield cannot assist with recovery. Store your passphrase in a secure password manager.

Healthcare Organizations: If you handle personal health information (PHI), we strongly recommend enabling Zero-Knowledge Encryption to ensure PII Shield cannot access patient data.

5. Payment Terms

All billing is handled securely via Stripe. Subscription tiers are based on team size, and payments are billed monthly or annually depending on your selected plan.

You are responsible for maintaining an active subscription to continue using the service. Team seat limits are enforced.

6. Termination

We reserve the right to suspend or terminate your account if:

  • You violate these terms
  • You fail to pay applicable fees
  • We determine, at our discretion, that your use of the service poses a legal, security, or operational risk

You may cancel your subscription at any time through the billing dashboard.

7. Modifications

We may revise these Terms of Service from time to time. If material changes are made, we will notify you via email or a notice on your dashboard. Continued use of the service after changes take effect constitutes agreement to the updated terms.

8. Contact Information

If you have questions about these Terms of Service, please contact us at: