Architecture and data flow
How the extension, the desktop app, the API, the dashboard, and the detection service work together, and what happens where.
You type
in ChatGPT, email, chat, or a document
Detection runs
on European servers, in working memory
You see highlights
replace, mask, remove, or send
Dashboard
aggregated counts only, never the text
BeeSensible consists of a Chrome and Edge browser extension, a desktop app for macOS and Windows, a hosted API, an admin dashboard, and a BeeSensible-managed detection service. Together these parts detect sensitive data while someone works, and give the organisation only counts in return.
The extension only runs on the websites in its permission list: common AI tools, email and chat applications, social platforms, and the BeeSensible site itself. Which apps take part in your organisation is set by an admin in the dashboard. The desktop app does the same work in a number of desktop programs, such as Outlook, ChatGPT, Claude, and Microsoft Copilot.
What happens when you type
When a signed-in user types in a supported app, the text from the input field is checked for sensitive data. That check runs on BeeSensible infrastructure in the EU. No external AI services such as OpenAI, Anthropic, or Google are called.
Detection returns which sensitive values were found, where they are in the text, and what level they have. That response is used to draw the highlights in the page. The text is not changed automatically, and sending is not technically blocked.
Where detection runs
The browser extension and the desktop app send the text to the BeeSensible API. There detection runs in working memory and the text is then discarded. Nothing of the text is stored and nothing is written to disk. Only plain counts, with no text and no user id, go to the dashboard.
The API, the database, and the storage run on Scaleway in the Amsterdam region; the compute for the models sits on a dedicated server at Hetzner in Germany. Both are European companies rather than a European region of an American cloud: Scaleway is 96% owned by the French Iliad group, and Hetzner Online GmbH is based in Gunzenhausen, Germany. There is no US parent that could be ordered under the US CLOUD Act to hand data over.
What the extension reports about AI use
With the AI Governance module on, the extension reports which AI domain was opened, added up per organisation per day, without URL path or page content. Every sent prompt is counted per tool and use-case category. To determine that category, the first prompt of a conversation goes to the API, is sorted there, and is discarded at once; the rest of the conversation inherits the category through a cache on the device.
How often someone uses AI is tracked by the extension on the device and reported once a month as a single category (daily, weekly, occasionally). When BeeSensible shows a notice on an AI tool, it counts that the notice was shown and how it ended. None of these reports carries a user id.
Documents
Anonymising a PDF can go through the dashboard, the extension, or the desktop app. The document is processed in working memory on BeeSensible's servers in the EU and removed straight after. The dashboard counts only the number of documents and the number of items removed.
What admins see
The dashboard shows figures in aggregate, for example by period, app, data type, and level, and in AI Governance by tool and use-case category. It shows no message text and no per-employee view. What reaches the dashboard are rows without content and without a user id; exactly what those rows hold is in What we store, and what we don't.
When an organisation rolls BeeSensible out centrally, the dashboard also records the installation status per user: which version of the extension and of the desktop app is running, whether the extension was installed through policy, whether the sign-in policy is filled in, whether the user allowed the extension in private windows, whether the sign-in was managed or manual, and whether the desktop app is installed machine-wide. These are installation and configuration facts the client reports about itself, visible to the administrators of the organisation. They hold no detection content and no picture of when or how someone worked.
Sending remains the user's action
BeeSensible helps users notice sensitive data before they share it. The extension only changes text when the user chooses an action, such as replace, mask, or delete.
Requesting documents
For the data processing agreement, DPIA, or security materials, email [email protected]. We reply in Dutch or English.