Legal · Jesto DLP Extension

Jesto DLP Extension Privacy Policy

Last updated: 1 September 2026

This policy explains how the Jesto DLP Policy Extension — a browser extension for managed devices — handles data. The extension sends no data to any remote server and holds no personal data of its own.

The Jesto DLP Extension is part of the Jesto Data Loss Prevention product, which is part of the Jesto platform. This page covers the browser extension only. Other components of the endpoint management software are covered by the agreement between Jesto and the organisation that deployed them, and our main Jesto Privacy Policy may also apply to those components.

1. What this extension is

The Jesto DLP Extension is an administrative tool. It is installed on a device by the organisation that manages that device, as part of that organisation's endpoint management software, and it enforces that organisation's web-access and data-loss-prevention policy. It is not intended for, and is not useful for, individual installation.

The extension holds no policy of its own. It reads the policy your administrator has configured from the management software running on the same computer and applies it to page navigation, downloads, and file uploads.

The extension does not send data to any remote server. Every network request it makes goes to http://127.0.0.1:18472 — a process running on the same device, installed by your administrator. The extension has no other network peer, including the developer.

2. What data the extension processes

To decide whether an action is permitted by your organisation's policy, and to record enforcement for your administrator, the extension processes:

DataWhy
Page URL and hostnameTo evaluate a page against the web-access policy and to record a block.
Page titleTo identify the page in the administrator's record.
Download filename and originating siteTo apply file-type and domain rules to downloads.
File name, size, and type for files you uploadTo evaluate an upload against data-protection rules before it leaves the device.
Browser user agent and timestampTo attribute an enforcement record to a device and a moment in time.

What the extension does not do

  • It does not transmit the contents of your files. For an upload, only the file's name, size, and type are evaluated — never the bytes.
  • It does not collect names, email addresses, or other personal identifiers.
  • It does not collect passwords, credentials, PINs, or other authentication data.
  • It does not collect financial, payment, or health information.
  • It does not read the content of your personal messages or email bodies.
  • It does not track location.

3. Where the data goes

The extension passes what it processes to the management software on the same device, which forwards enforcement records to the management server operated by the organisation that deployed it — your employer or the body that administers your device.

That organisation is the controller of this data and decides how long it is kept and who may see it. Questions about access, retention, or deletion should go to your own IT administrator, who can act on them; the extension developer holds none of this data and cannot.

4. Data sharing

  • Data is not sold or transferred to third parties.
  • Data is not used for any purpose beyond enforcing and recording your organisation's policy.
  • Data is not used to determine creditworthiness or for lending purposes.
  • Data is not used for advertising or profiling.

5. Permissions and why they are needed

The extension requests broad host access because the sites an organisation's policy governs are configured by that organisation, differ between organisations, and change without the extension being rebuilt. A data-protection control that covered only a fixed list of sites would be bypassed by using any site not on that list.

  • Access to all sites — to apply policy wherever the administrator has configured it.
  • Access to 127.0.0.1:18472 — to read policy from the local management software. This is the extension's only network peer.
  • Blocking, navigation, and request permissions — to prevent a disallowed page from loading and to distinguish a page you opened from the assets that page loads.
  • Downloads — to cancel a download the policy disallows.
  • Notifications — to tell you when policy has blocked something, rather than leaving a page that appears broken.
  • Storage and alarms — to cache policy so enforcement survives a browser restart, and to refresh it when the administrator changes it.

6. Your choices

This extension is installed and managed by your organisation, and cannot be removed by the user of a managed device. If you believe it has been installed on a device your organisation does not administer, contact your IT department. If a site has been blocked in error, the block page includes a Request access option that sends a request to your administrator.

7. Changes to this policy

If this policy changes, the date at the top of this page is updated and the new version is published at this address.

8. Contact

For questions about the extension itself, use the support channel published with your deployment. For questions about your own data — what was recorded, how long it is kept, or to request deletion — contact your organisation's IT administrator, who is the controller of that data. General queries can be sent to support@jesto.ai.