Browser extension
The browser extension adds CloakAPI’s privacy layer directly to the AI chat sites you already use. With it installed, you keep using ChatGPT, Claude, Gemini or Grok exactly as before — but personal data in your prompts is tokenised locally in your browser before the request reaches the provider, and the reply is turned back into the real values for you. It is a standalone client-side tokeniser: no desktop app required.
The extension is one of the three ways to use CloakAPI (API / SDK / proxy · Chat · browser extension). Prefer a private chat window instead of your provider’s own site? Use the portal Chat. Writing code? Start with the Quickstart.
What’s live today
- Typed-text tokenisation is live on all four sites —
chatgpt.com,claude.ai,gemini.google.comandgrok.com. Structured identifiers (emails, phones, cards, national IDs) and common personal names are tokenised on-device as you send. - File / image tokenisation is live on
claude.ai(typed prompts and uploads). On the other three sites the image path is fail-closed — it blocks rather than send an unprotected upload — pending per-site endpoint verification. - 25 interface locales.
- Coverage honesty. The extension runs the deterministic structured-identifier lane plus the name lane’s gazetteer floor and the same optional on-device NER model the other surfaces use — but names have no checksum, so rare names, unlabelled single-token brand names, thinly-covered scripts and free-form addresses or organisations can still slip. The desktop app uses the same engine and the same ruleset; it does not detect more. See Detection coverage.
Install it
Install it from the Chrome Web Store — this is the recommended path, because Chrome then keeps it up to date. The same store listing works in Microsoft Edge. If you would rather verify the bytes yourself, the Chrome zip on the downloads page is the same extension, loaded in developer mode. Firefox stays withdrawn (HTTP 410; never listed on Mozilla Add-ons) — see below; do not expect an AMO one-click. The current version, SHA-256 and signing status of every build are published in the release-integrity register — that file is the source of truth, not this page.
Chrome / Edge — from the Chrome Web Store (recommended)
- Open the CloakAPI listing in Chrome and click Add to Chrome.
- In Edge, open the same link, choose Allow extensions from other stores when Edge asks, then click Get.
The store install updates itself. Nothing else to do.
Chrome / Edge — from the zip (optional)
- Download the Chrome build (
cloakapi-extension-chrome.zip) from app.cloakapi.io/downloads and verify it against the SHA-256 published there. The Downloads page and the release-integrity register always name the current version and its checksum — this page does not repeat them, so it cannot go out of date. - Extract to a plain local folder that is NOT synced by OneDrive, Google Drive
or Dropbox — e.g.
C:\cloakapi-extensionor~/cloakapi-extension. (Sync tools drop hiddendesktop.inifiles into extracted folders, which Chrome then warns about — that file is not part of our package and is harmless if you see it.) - Open
chrome://extensions, turn on Developer mode (top right), click Load unpacked, and select the extracted folder (the one containingmanifest.json). Keep the folder in place — Chrome runs the extension from it. Chrome does not auto-update an extension loaded this way; download the new zip when a version ships, or use the store install instead.
Firefox
Withdrawn (status as of 2026-09-05). There is no current Firefox build. Both Firefox
packages that were offered — 0.1.21 (Mozilla-signed) and 0.1.22 (unsigned) — were withdrawn
on 2026-08-24, and the download link cloakapi-extension-firefox.xpi answers HTTP 410. If
about:addons lists CloakAPI, remove it; the update feed offers no version, so it will not be
re-installed. The downloads page explains why each build
was withdrawn, and the
release-integrity register
is where a new Firefox build will appear first if one is published.
The extension is published in the Chrome Web Store. It is not listed on Microsoft Edge Add-ons (Edge installs it from the Chrome Web Store) or on Firefox Add-ons (AMO); the Firefox build stays withdrawn.
Good to know
- Paid, key-backed, fail-closed. Tokenisation requires a CloakAPI account with balance. If the extension cannot tokenise a message it blocks the send rather than let raw text egress — this path does not upload the original text in that case.
- Pricing is usage-based, USD only — a flat markup on top of the underlying model cost. See pricing.
- How it works end-to-end: How privacy works.