Architecture and data flow
How the extension, the desktop app, the API, the dashboard, and the detection service work together, and what happens where.
You type
in ChatGPT, email, chat, or a document
Detection runs
on your device, or in the EU cloud
You see highlights
replace, mask, remove, or send
Dashboard
aggregated counts only, never the text
BeeSensible consists of a Chrome and Edge browser extension, a desktop app for macOS and Windows, a hosted API, an admin dashboard, and a BeeSensible-managed detection service. Together these parts detect sensitive data while someone works, and give the organisation only counts in return.
The extension only runs on the websites in its permission list: common AI tools, email and chat applications, social platforms, and the BeeSensible site itself. Which apps take part in your organisation is set by an admin in the dashboard. The desktop app does the same work in a number of desktop programs, such as Outlook, ChatGPT, Claude, and Microsoft Copilot.
What happens when you type
When a signed-in user types in a supported app, the text from the input field is checked for sensitive data. Depending on how the organisation is set up, that check runs on the user's own machine, through the desktop app, or on BeeSensible infrastructure in the EU. Either way, no external AI services such as OpenAI, Anthropic, or Google are called.
Detection returns which sensitive values were found, where they are in the text, and what level they have. That response is used to draw the highlights in the page. The text is not changed automatically, and sending is not technically blocked.
Where detection runs
On the machine itself. Through the desktop app, the detection engine runs locally, for the browser extension as well. The text being checked stays on the device. Only plain counts, with no text and no user id, go to the dashboard.
In the EU cloud. Without the desktop app, the browser extension sends the text to the BeeSensible API. There detection runs in working memory and the text is then discarded. Nothing of the text is stored. The API, the database, and the storage run on Scaleway in the Amsterdam region; the compute for the models sits at Hetzner in Germany. This is the zero-install alternative.
What the extension reports about AI use
With the AI Governance module on, the extension reports which AI domain was opened, added up per organisation per day, without URL path or page content. Every sent prompt is counted per tool and use-case category. To determine that category, in cloud mode the first prompt of a conversation goes to the API, is sorted there, and is discarded at once; the rest of the conversation inherits the category through a cache on the device. In on-device mode the desktop app does that sorting itself, without the prompt leaving the machine.
How often someone uses AI is tracked by the extension on the device and reported once a month as a single category (daily, weekly, occasionally). When BeeSensible shows a notice on an AI tool, it counts that the notice was shown and how it ended. None of these reports carries a user id.
Documents
Anonymising a PDF goes through the desktop app on the device itself, or through the dashboard and the extension on BeeSensible's servers in the EU. In the latter case the document is processed in working memory and removed straight after. The dashboard counts only the number of documents and the number of items removed.
What admins see
The dashboard shows figures in aggregate, for example by period, app, data type, and level, and in AI Governance by tool and use-case category. It shows no message text and no per-employee view. What reaches the dashboard are rows without content and without a user id; exactly what those rows hold is in What we store, and what we don't.
When an organisation rolls BeeSensible out centrally, the dashboard also records the installation status per user: which version of the extension and of the desktop app is running, whether the extension was installed through policy, whether the sign-in policy is filled in, whether the user allowed the extension in private windows, whether the sign-in was managed or manual, and whether the desktop app is installed machine-wide. These are installation and configuration facts the client reports about itself, visible to the administrators of the organisation. They hold no detection content and no picture of when or how someone worked.
Sending remains the user's action
BeeSensible helps users notice sensitive data before they share it. The extension only changes text when the user chooses an action, such as replace, mask, or delete.
Requesting documents
For the data processing agreement, DPIA, or security materials, email trust@beesensible.eu. We reply in Dutch or English.