← Back to download

EGL Trace — Privacy Policy

Effective date: 2026-08-20

Overview

EGL Trace is a browser extension, part of the Mr Q EGL™ AI governance platform. It captures the AI conversations you choose to track on supported platforms (ChatGPT, Claude, Gemini, DeepSeek) so you can review, organize, export, and (where available) create governance artifacts from your work. It also records source attribution — where the text you pasted into an AI conversation came from (e.g. a Google Doc, Sheet, Gmail message, Microsoft 365 document, or any web page).

EGL Trace is local-first: capture happens in your browser, and your data is stored locally. By default it also syncs to your private Mr Q EGL account to enable artifact creation and organization across your projects. You can turn sync off at any time with the in-extension toggle to keep everything local.

Sign-in

The store version of the extension is not pre-configured with an account. To sync sessions you sign in with your Mr Q EGL account email and password: the extension sends the credentials to the platform, which verifies them with its authentication provider and issues a device token that is stored locally in your browser and used to authenticate sync. Signing out deletes the stored token. The extension does not store the password; you can also create a free individual or student account at portal.qlabresearch.com/signup and sign in the same way.

What we collect

  • AI conversation content — the prompts and responses you send on supported AI platforms.
  • Source-attribution context — the app, page, and document or thread title you copied from (e.g. a Google Doc, Sheet, Gmail message, Microsoft 365 document, or web page), plus the selected text/range where applicable. This is recorded when you copy text to paste into an AI conversation.
  • Local PII flags — the extension scans text locally for sensitive patterns (emails, phone numbers, API keys, tokens, private keys, card numbers, SSNs) and labels them.
  • Account identity — your email (for sign-in and account resolution), your account type (e.g. student, individual, employee), and a locally stored device token. On the platform download page, the email and account type are embedded when you download the extension. The password is sent to the platform's authentication provider for verification at sign-in and is not stored by the extension.

Where your data is stored

All captured data is stored locally in your browser using chrome.storage.local, capped to the most recent 5,000 log entries.

When sync to account is on (the default), captured sessions are transmitted to your private Mr Q EGL platform account so they can appear in the platform for artifact creation, project organization, and export. You can view, organize, or delete these sessions from the extension popup or the Mr Q platform.

Sync and local-only mode

EGL Trace includes a sync toggle in the extension popup, defaulting to On:

  • Sync to account (On): captured sessions are uploaded to your Mr Q EGL account to enable artifact creation and organization.
  • Local only (Off): everything stays in your browser. Nothing is transmitted. Your existing locally captured data remains available.

You can change this at any time. When sync is turned off, the background worker stops transmitting to the platform immediately.

Does the extension transmit data?

Only to the Mr Q EGL platform (our own service). Your email is sent to the platform to request a sign-in code, and captured sessions are transmitted only when sync is enabled. When sync is off, nothing other than the optional sign-in request is transmitted. There are no third-party analytics beacons, no advertisers, and no remote code. Captured data is never sold or shared with third parties for marketing.

Permissions

  • storage — to save your captured logs locally.
  • Host permissions for the sites the extension needs to operate on:
    • AI platforms (chatgpt.com, chat.openai.com, claude.ai, gemini.google.com, chat.deepseek.com) — to detect and capture the prompts and responses you submit.
    • Google Workspace and Microsoft 365(docs.google.com, sheets.google.com, mail.google.com, office.com, microsoftonline.com) — to record the source document, spreadsheet, or email thread when you copy text from them.
    • General web pages — to record the page title and copied text when you copy from any other website into an AI conversation (source attribution). The extension does not read page content other than the copy events used for source attribution.

No page content other than your AI conversations and source-attribution context is captured, stored, or transmitted.

Your control

  • View: the popup shows your sessions and turns.
  • Export: export your sessions as CSV at any time.
  • Delete: delete individual sessions entirely — they are removed and not run through the platform.
  • Local-only mode: turn sync off to keep everything on your device.
  • Clear: clear all locally stored logs.

Contact

For questions about this policy, contact privacy@qlabresearch.com.

© 2026 QLab Research (Pty) Ltd. An independent applied-AI laboratory.