Skip to content
Back to blog
Company30 Jul 20268 min readRanjan Singh

Why we built Protect

The leak happens at the paste, which is the last moment the data is still yours. Four documented incidents show what happens after that moment, and why we made the clipboard guard free for everyone.

In short

Omit Protect is a clipboard guard that redacts personal data out of what a person copies, before the paste leaves the machine. Protect is free for everyone permanently and needs no licence key. Data-loss-prevention tools watch files move, so a person copying four lines of a record into an unmanaged browser tab is structurally invisible to them.

Every tool we had built before Protect assumed you would open it. You would find the file, drag it in, look at what was detected, and save a redacted copy. That model works. It is still exactly how Omit Redact works. But it only ever protects the data you remembered to protect.

The data that leaks is the data nobody stopped to think about, and it leaves through a paste.

A paste is a strange little moment, and we think it is the most important one in this whole category. It is the last instant the data is still yours. Still on your disk, still inside your policy, still governed by rules you wrote. One keystroke later it belongs to a service you do not run, on hardware you cannot inspect, under a retention schedule someone else decides. There is no undo. In most cases there is not even a record that it happened.

The moment corporate DLP cannot see

Data-loss prevention watches files move. Attachments, uploads, endpoint egress, sanctioned SaaS apps. It is good at that, and if you have it, keep it. What it is structurally unable to see is a person highlighting four lines of a patient record, pressing Ctrl+C, switching to a personal browser profile that the company does not manage, and pressing Ctrl+V into a chat box. No file moved. No monitored app was involved. The account is not on the tenant, and the tab is not on the allowlist. From the perspective of every control the organisation paid for, nothing happened.

That gap is not an oversight in anyone's product. It is where the category boundary happens to fall. The controls sit around the data, and the paste happens inside the ring. So the question we kept circling was a simple one. If we cannot see the paste from the outside, can we get underneath it?

Four times a private conversation stopped being private

The reason that moment matters so much is that everything downstream of it is somebody else's decision, and those decisions change without warning. Here are four documented cases from the last eighteen months, none of which involved an attacker breaking anything.

Aug 20254,500 chats

Shared ChatGPT conversations were indexed by Google

An opt-in discoverable checkbox. OpenAI removed it on 1 August 2025.

Jul 2026Shared links

Claude conversations and Artifacts surfaced the same way

Anthropic said the feature worked as intended. Critics noted Google Docs links do not behave like this.

Jul 20258M+ users

A VPN extension intercepted prompts and responses

Shipped as a silent auto-update. Data went to a broker. The listing advertised protecting you from this.

Jan 2026900k+ users

Two extensions harvested chats and every tab URL

On a thirty minute cycle. One of them carried Google's Featured badge.

Fast Company found roughly 4,500 shared ChatGPT conversations reachable through an ordinary Google site search. Not leaked, not breached. Indexed. The reporting describes people working through addiction, physical abuse, and suicidal ideation in conversations that a search engine had quietly filed away. The cause was an opt-in checkbox labelled "Make this chat discoverable" that many users did not read as "publish this to the open web". OpenAI's CISO, Dane Stuckey, removed the option on 1 August 2025. You can read the Fast Company report and The Register's coverage of the removal.

Then the same shape of thing happened to Claude. On 26 July 2026, a search restricted to Anthropic's share domain surfaced shared Claude conversations and Artifacts. Reporting described a medical report on a real patient, clinical trial results carrying patient names, documents listing the names and phone numbers of primary-school-aged children, internal-only company documents, and employee reviews.

Anthropic's position was that the feature worked as intended: "These shareable links are not guessable or discoverable unless people choose to share them themselves." That is a fair description of the mechanism, and it is worth stating plainly rather than paraphrasing into something worse. The criticism, equally fairly, was that a Google Docs link shared the same way does not become searchable, and the difference is a single instruction to search engines that Anthropic had chosen not to send. Both things are true at once. See TechCrunch and Axios.

We are not interested in scoring points off either company. Two independent teams, both staffed by careful people, shipped a sharing feature whose default behaviour surprised their own users. That is the pattern, not the brand on it.

The third case is stranger, because the tool doing the collecting was sold as the protection. Koi Security found that Urban VPN Proxy version 5.5.0, which shipped on 9 July 2025 as a silent auto-update, was intercepting both prompts and responses across ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok and Meta AI. Counting seven sibling extensions from the same publisher, that is more than 8 million users. The captured data went to the data broker BiScience. The detail that stays with me is the store listing, which advertised that the extension "protect[s] people from entering personal information into AI chatbots". Malwarebytes has the write-up.

And on 6 January 2026, OX Security reported two more Chrome extensions harvesting ChatGPT and DeepSeek chats along with every open tab URL, on a thirty minute cycle. One had 600,000 users and carried Google's own "Featured" badge. The other had 300,000. More than 900,000 users between them, all of whom had done the responsible thing and installed from the official store. The Hacker News has the details.

The pattern, not the villain

Line those four up and the common thread is not malice, and it is not any one company being careless. It is that the moment you paste, you hand control of that text to a chain of decisions you are not part of: a default someone set, a checkbox someone worded, an auto-update someone shipped, a review process that let a badge through. You can be a diligent person, using a mainstream product, on an official channel, following your employer's policy, and still end up in three of those four stories.

Which brings the whole thing back to the paste. It is the only point in that chain where you still have the data and the decision at the same time. Every control after it is a request that someone else behave the way you expected.

So Protect sits at the paste

So Protect sits there. It is a clipboard guard: it runs in the tray, it watches for a paste into an AI tool, and it redacts the sensitive values out on the way in. The model receives PERSON and IBAN and MRN where the names and the account numbers were. Detection runs on your machine, with the same engine that redacts a PDF in Omit Redact, so nothing goes anywhere to be checked for whether it should have gone anywhere. That last part matters more than it sounds. A cloud guard would have to upload your clipboard in order to decide whether your clipboard was safe to upload.

When you do need the real value in the box, Ctrl+Alt+V pastes the original. That is deliberate, and it is recorded, so the exception is a decision you made rather than a habit you fell into.

What Protect is not

Being straight about the limits: Protect is not a network control and it will not stop a determined person. Anyone can retype a name, screenshot a record, or use a machine you do not manage. It is aimed squarely at the accidental paste, the one that accounts for the volume, and it does nothing about the deliberate one. It also cannot help with data that has already left, and none of the four incidents above would have been undone by a clipboard guard installed the next morning. And it is not a compliance certificate. It is a control you can point at, with a local report of what it did, which is a different and more modest thing than an attestation.

Why it is free

We charge for Omit Redact. We do not charge for Protect, and we are not going to. Partly this is a straightforward judgement about what the paste problem is: it is not an enterprise problem that happens to affect individuals, it is an everyone problem. A per-seat price on the clipboard would mean the people most likely to paste a patient record into a consumer chatbot, which is to say people without a security budget, are exactly the people who would not have it. Partly it is that we would rather be judged on the thing we sell. If Protect is any good, some of the people running it will eventually have a folder of PDFs to redact, and then we can have a conversation about money. If it is not any good, charging for it would not have saved us.

Protect is included in Omit Redact and it stays on when the trial ends. No key, no account, no expiry.

Omit Redact is in beta for Windows, and the installer is not code signed yet, so SmartScreen will warn you the first time. We would rather tell you that here than have you find out on the download page.

Get the next one by email

New benchmarks and release notes as they go up. Nothing else, and unsubscribe by replying.

New posts onlyunsubscribe by replying