Privacy model
What Joring collects, what administrators can see, and what stays private to each person.
Joring analyzes the conversations people have with AI tools, and nothing else. It does not record keystrokes, take screenshots, or read browsing history.
The browser extension owns browser capture. On macOS and Windows, the desktop agent uses source-scoped local network capture for supported applications. Signed application, host, and endpoint rules limit what can be inspected and retained, so capture access does not authorize unrelated traffic. Browser processes remain the browser extension's responsibility. The agent does not read provider transcripts, rollout databases, or application files, and it never uploads process paths, authorization headers, cookies, or API keys.
What each audience sees
| Individual | Team admin | |
|---|---|---|
| Their own prompts and responses | Yes | No |
| Aggregate adoption and fluency | Yes | Yes |
| Another person's conversation text | No | No |
| A masked excerpt from a policy violation | No | Yes |
Individuals own their conversations. The record is exportable and deletable from Settings → Privacy & Data, and it is never shown to administrators. Leaders see the shape of usage, not the text. Enforcement is the one place an administrator sees text from someone else's message: only for a message a policy flagged, only the part that caused it, masked, with a one-line description beside it. Nothing else from the conversation is shown.