Privacy Policy
Last updated: April 19, 2026
Short version: FusionLayer is zero-knowledge. Your AI conversations and memory are encrypted on your device before they leave it. We cannot read them. We don't sell data. We don't train models on your content.
1. Who we are
FusionLayer is a browser extension and sync service that lets you carry memory and context across AI tools (ChatGPT, Claude, Gemini, and others). This policy covers the Chrome extension, the web dashboard at app.fusionlayer.app, the API at api.fusionlayer.app, and the marketing site at fusionlayer.app.
2. What the extension does on your computer
When installed, the extension:
- Runs content scripts on the AI sites you use (listed in the extension's manifest) to capture the messages you send and receive, so they can be saved to your personal memory.
- Encrypts captured content on your device using AES-256-GCM with a key derived from your password via Argon2id. Encryption happens before any data leaves the browser.
- Stores a local cache in
chrome.storageso the extension works offline. - Sends encrypted blobs to our sync service (if you enable sync) so your memory is available on your other devices.
3. What data we collect
Account data (plaintext, we can read it)
- Email address (used to sign in and send critical account alerts).
- Authentication tokens.
- Subscription and billing status (if you purchase a paid plan). Payment itself is handled by our payment processor; we never see your card number.
User content (ciphertext only, we cannot read it)
- Encrypted memory blobs (your saved AI conversations, context, and custom memory entries).
- Encrypted metadata (title hashes, timestamps).
Because encryption keys are derived from your password and never leave your device, we have no technical ability to read the contents of your memory. If you forget your password and have no recovery key saved, your data becomes unrecoverable — that is the intended design.
Operational data (minimal, aggregated)
- IP address and user-agent of API requests (for rate limiting and abuse prevention). These are retained for up to 30 days and are not linked to your content.
- Crash reports and error traces (via Sentry, opt-out available).
- Anonymous usage analytics (feature counts — e.g. "extension install" — via PostHog, opt-out available). We do not record the content of your conversations.
4. What we do NOT collect
- We do not read, scan, or index your AI conversations.
- We do not sell or share your data with data brokers, advertisers, or third parties for marketing.
- We do not use your content to train machine-learning models.
- We do not track your browsing across sites the extension does not interact with.
5. Where data is stored
- On your device: extension storage, local cache. Lives in your browser profile.
- On our servers: encrypted blobs on a managed cloud provider (currently Oracle Cloud Infrastructure, EU region). Account metadata in Oracle Autonomous Database (Frankfurt, EU).
- BYO storage (optional): you can configure your own S3-compatible bucket. In this mode, we never store your blobs.
6. Sharing & disclosure
We disclose data only in these cases:
- Service providers that help us operate (payment processor, email delivery, error tracking). These providers process only what is strictly needed.
- Legal requirements — valid court order, subpoena, or law enforcement request. Because your content is encrypted client-side, we can only provide ciphertext and account metadata, not readable content.
- Business transfer — if FusionLayer is acquired, data moves to the acquirer under the same terms or better. You will be notified before any change.
7. Your rights
You can at any time:
- Access and export your data from the dashboard.
- Delete your account — this permanently erases all encrypted blobs and account metadata within 30 days.
- Revoke sync — the extension continues to work locally without sending anything to our servers.
- Opt out of crash reports and analytics in extension settings.
- Contact us for GDPR / CCPA requests (erasure, portability, access).
8. Children
FusionLayer is not directed at users under 16. If you believe a child has created an account, contact us and we will remove it.
9. International transfers
FusionLayer is operated from Israel. Servers are hosted in the EU. If you are outside these regions, your data may be transferred and processed in Israel and the EU under appropriate safeguards.
10. Changes
We may update this policy. Material changes will be announced by email (for account holders) and in a banner on this page. The "Last updated" date at the top reflects the most recent revision.
11. Contact
Privacy questions, data requests, or concerns:
- Email: [email protected]
- Support: [email protected]