Verdicts travel. Documents never do.
This policy covers the MoonGate DLP browser extension and the MoonGate endpoint agent, distributed through the Chrome Web Store to administrator-managed organizations.
Purpose
MoonGate DLP helps administrator-managed organizations prevent protected Google Drive and Notion content from reaching browser destinations that violate an organization's data-loss-prevention policy.
MoonGate is deployed by an organization's administrators for their managed browser profiles. It is not a consumer product, and it is not intended for personal use. The organization that deploys MoonGate is the controller of the data described below; MoonGate processes that data on the organization's behalf.
Data MoonGate processes on the endpoint
The MoonGate browser extension and local endpoint agent may process, on the endpoint, browser page content involved in protected copy, paste, upload, drop, download, export, sharing, publication, printing, and related enforcement actions. It also processes browser origin and destination context, document and tenant identifiers made available through managed configuration, content fingerprints, file hashes, policy version, device identity, and enforcement health.
When pattern detection is enabled by managed policy (it is on by default), the extension also scans visible page text on the configured hosts, which by default are Google Drive, Google Docs, Notion, and Linear, for sensitive patterns such as U.S. Social Security numbers. That scan runs on the endpoint. Pattern reports carry typed metadata only: detector type, match count, confidence label, action, decision, and origin metadata scrubbed so that no digits of a detected identifier remain.
Raw document text, clipboard contents, file bytes, content fingerprints, and matched pattern text are processed locally for the enforcement decision. MoonGate does not send them to the MoonGate control plane.
- raw document text
- clipboard contents
- file bytes
- content fingerprints
- matched pattern text or any digits of a detected identifier
- warn justification text (only a yes/no that one was supplied)
Data sent to the control plane
MoonGate may send privacy-minimized operational metadata:
- managed device identifiers
- source system and source document identifier
- source and destination origins and tenant identifiers, where authorized
- action and classification
- policy version
- decision and reason code
- timing and correlation ID
- health and delivery status
Use, retention, and disclosure
MoonGate uses this information only to enforce an organization's DLP policy, operate and secure the service, investigate policy events, and meet applicable legal obligations. MoonGate does not sell personal data, use it for advertising, or use it for unrelated profiling. MoonGate does not transfer this data to third parties except as necessary to operate the service or to comply with a legal obligation.
The organization operating MoonGate defines the retention period for decision and operational metadata. The approved period for this beta is:
Access is limited to authorized administrators and support personnel under the organization's security controls.
Security
MoonGate uses signed policy bundles, authenticated endpoint-to-control-plane transport, access-controlled administration, and local storage controls.
No security measure can guarantee protection against every exfiltration path, including screenshots, photography, unmanaged devices, and unsupported apps. MoonGate is browser-scoped: it is not system-wide DLP and does not claim coverage of unmanaged browsers, desktop applications, screenshots, USB devices, or every programmatic network or API path.
Beta status
MoonGate is currently distributed for private beta testing. The current scope is controlled testing against synthetic Google Drive and Notion fixtures on managed test endpoints, not production deployment or real-user pilots. This policy will be updated before that scope changes, and the effective date above will change with it.
Contact
For privacy requests or questions, contact:
If you are a user of an organization that deployed MoonGate, your organization's administrators control your policy configuration and retained metadata; contact them first for access or deletion requests.