Last updated 2026-07-28
Zapper is a browser extension and web dashboard that rewrites AI prompts you're about to send on Claude.ai, ChatGPT, and Gemini into scoped, execution-ready versions. This policy covers both the extension and the dashboard at dash.zapper.click.
The extension does not run in the background and does not read your conversations continuously. It reads the text in the composer box only at the moment you click Zappy. If you've turned on Power Zap (an explicit toggle, off by default), it also reads a handful of the most recent visible messages on the page at that same moment, to ground the rewrite in real context.
If your plan has Rogue Prompt Detection enabled, that same click-triggered text is also scanned for prompt-injection or malicious-command patterns. This happens in the same request as the rewrite, not a separate one, and nothing extra is read to do it.
The text you send to Zappy is sent to Zapper's own backend, authenticated with a Zapper-issued token (not an Anthropic key: the extension never holds one). The backend forwards it to Anthropic's API to generate the rewrite, using either Zapper's own hosted API key or your personal key if you've added one in Settings. We don't send your prompt text anywhere else, and we don't use it for advertising or sell it to anyone.
We don't store the content of your prompts or the rewrites Zapper produces after the request completes.
You can revoke the extension's access to your account at any time from Settings. This immediately invalidates the token. You can delete a stored Anthropic key at any time. You can turn Power Zap and Rogue Prompt Detection on or off whenever you like.
Questions about this policy or your data: rupacbuilds@gmail.com, or see Support.
This policy reflects the product as it exists today and will be updated as it changes. It's a plain-language description of current practice, not a substitute for professional legal review.