Security & Privacy
Your GHL billing data is sensitive. Here's exactly how we protect it — no marketing fluff, just the technical reality.
The audit runs in your browser, not on our servers
The Chrome extension reads GoHighLevel's own billing and AI-usage APIs inside the agency session you're already signed in to, read-only. All the math — categorizing charges, computing cost per minute — happens locally. Nothing leaves your browser until you choose to save a report.
No password, no OAuth, no session token stored
We never ask for your HighLevel password and there is no OAuth app or marketplace integration. The extension uses the login in your open GHL tab, and your session token is never sent to us or written into any report.
Only billing numbers are ever stored
A saved report contains dollars, minutes, call counts, charge descriptions, model names and sub-account names — nothing else. No call recordings, no transcripts, no contact data, no message content. If it isn't on the bill, it isn't in the report.
Encryption in transit and at rest
Saved reports travel over TLS 1.2+ (HTTPS) and are stored in a Postgres database encrypted with AES-256 at the storage layer. Even with physical access to the disks, the data would be unreadable.
Keys instead of accounts, enforced at the database
Your free key is the only credential, and it stays in your browser. Every table has Row-Level Security enabled with no public access policies — saved reports are reachable only through our server-side functions, which check your key and serve only your own reports.
Share links are opt-in, unlisted, and revocable
Reports are private by default. Sharing one creates a read-only link with an unguessable token that exposes the report's numbers and nothing about your key or other reports. You can revoke it at any time, and report pages are blocked from search engines and AI crawlers in robots.txt.
A note on zero-knowledge encryption
Saved reports are not zero-knowledge: our server has to read a report's numbers to list your library and to serve a share link you create. What we've done instead is shrink what the server ever sees — the audit itself runs in your browser, and a saved report contains only billing figures — and protect that remainder with encryption in transit and at rest plus database-level access controls. If you never save a report, nothing is stored at all.
Data practices
- •We never sell your data to third parties.
- •We never see your GHL password and never hold an OAuth token — there is nothing of your HighLevel login to leak.
- •You can delete any saved report at any time from My audits, and revoke any share link.
- •The Chrome extension runs entirely in your browser — billing data is only sent to us when you choose to save a report.
Have a security question? Ask Fer directly