FOR BUSINESS

A small check in your work browser.

Before sending to AI, opening an email link or uploading a file: Legacy Tools are Chrome extensions that help you notice things you might overlook in everyday work.

Decide for yourselves whether these tools fit your workplace. Review their uses, data handling and limits before trying them with a small group.

  • Processed in the browser
  • Nothing sent to our servers
  • No account
  • Public editions are free
Someone working at a laptop at an office desk. On the screen the Chrome extensions menu is open, listing Safe Privacy Mask, Safe Privacy Gate and Safe Mail Link Check. A colleague is working at the other end of the table.

WHERE IT HELPS

Start with one task

An evaluation starts by picking one situation your teams meet often. Each card names the extension for that situation, and what it does not do.

Safe Privacy Mask

Before sending text to AI

Replace email addresses and configured terms in the input field before sending. Review the result: some information may be missed.

See Safe Privacy Mask →

Safe Mail Link Check

Before opening an email link

Compare the displayed text with the destination in Gmail, Outlook on the web, Yahoo! Mail and other supported sites. It does not judge whether the destination is safe.

See Safe Mail Link Check →

Safe Attachment Check

Before uploading a file

View metadata such as location or author in supported file formats. It does not remove metadata, edit the file or block the upload.

See Safe Attachment Check →

Safe Privacy Gate

Before submitting information to a website

Prompt for a check when text or a filename matches detection rules. It does not rewrite the text or enforce a ban on sending.

See Safe Privacy Gate →

EVALUATION CHECKLIST

What to check before you adopt it

These checks cover the public Chrome Web Store editions. Transparency contains the per-product permissions and steps to inspect network traffic.

Where processing happens
The public extensions introduced here detect, replace or inspect files inside the browser. They do not send input or detection results to the developer’s servers.
Network traffic and usage collection
The public extensions themselves do not send data to external APIs or collect analytics or telemetry. This is separate from requests made by websites you use. The Legacy Tools website uses Google Analytics.
Storage and sync
Gate, Mask, Mail Link Check and Attachment Check store settings; Mask also stores rules and target sites. Other products may store collected text or registered people’s information. Safe Night Check settings may sync to other devices through Chrome.
Chrome permissions and site access
Permissions differ by product. Gate requests access to all sites; Mask uses storage, scripting and optional access for added sites. An extension can load on all sites without declaring host_permissions, so check both API permissions and where it runs.
Accounts
The public extensions are free and require no Legacy Tools account or login. Accounts for the AI or email services you use are separate.
Known limits
Supported sites, input fields and file formats are limited, and detection can miss information or flag it incorrectly. Review each product’s scope and test it on the screens your team uses.
Management, audit and support
The public extensions have no admin console, central management, audit log, SLA or organizational support contract. For organization-wide settings distribution and locking, see the management option below.
View per-product permissions, storage, traffic and inspection steps →

PUBLIC EDITIONS

Try the public editions with a small group

The editions on the Chrome Web Store can be used for a small evaluation as they are. There is one assumption they do not meet.

What they let you do

Each person adds the extension from the Chrome Web Store and configures it themselves. After checking your internal rules, limit the trial to one task and a small group.

What they assume

Public-edition questions go to the shared support desk. These editions do not meet rollout requirements that depend on organization-wide management or contractual response guarantees.

HOW TO PILOT

Try small, then decide whether to continue

Five steps are enough to decide. You can reach an answer with the scope still small, before anything goes company-wide.

  1. Choose one task
  2. Try with a few people using samples without confidential information
  3. Check permissions, data handling and usability
  4. Assess fit with your rules, including missed and incorrect detections
  5. Consider managed features if you need consistent settings

Record the product, version, sites, settings, benefits and problems so your team can decide whether to continue.

MANAGED OPTION

When you need managed settings

Safe Privacy Mask Enterprise is a separate, privately distributed product with administrator-distributed rules, settings locks and audit logs. Compare it on the product page if the public edition is not enough.

Aspect Public editions (free) Safe Privacy Mask Enterprise
Who sets the rules and settings The person using it The administrator (users can be locked out of editing)
How it is delivered Each user adds it from the Chrome Web Store A privately distributed CRX, delivered by GPO, MDM or the Admin Console
Settings distributed and locked None Yes — distributed and locked by managed policy
Audit log None Yes — no message text recorded, forwarding to your own collector available
Traffic leaving the machine None from the extension itself Only with the optional second check enabled, to the endpoint your organisation configures
Terms and support Free, one shared support form Quoted, with rollout support

Safe Privacy Mask is the only product with a managed edition. The others have no administrator-distributed build.

There is no vendor-hosted admin console. Optional secondary checks send locally masked text to your configured endpoint; audit logs can also be forwarded. Review permissions and traffic separately from the public edition.

See Enterprise differences and limits →

LIMITS

Limits and what is not guaranteed

Before you consider a rollout, here is what these tools do not take on.

  • These tools do not completely prevent data leaks or fraud, or reliably identify every danger.
  • They do not replace existing DLP, access controls or approval procedures.
  • A prompt or replacement does not decide whether you should send the information or open the link. People still need to check and decide.

NEXT STEPS

How to take it further

Everything an evaluation needs is published on this site. If something is missing, tell us through the support desk.

Permissions, storage and traffic

Per product: the permissions it asks for, what it stores, what leaves the browser, and its known limits — with the steps to check each one yourself.

Open Transparency →

What each product covers

Supported sites, input fields and file formats — and what the product does not do — are on each product page. The four situations above are the short way in.

Pick by situation →

The Chrome Web Store pages

The pages the extensions are actually distributed from: description, version, publisher, and the permission summary Chrome shows.

Distributing and managing it centrally

Rules distributed by managed policy, locked settings, what the audit log does and does not record — and what that edition cannot do.

See the Enterprise edition →