ndaact.ai has two complementary parts: a desktop app (which detects and redacts locally) and a browser extension (which protects your exchanges on claude.ai and chatgpt.com). The extension alone isn’t enough for advanced detection: it depends on the local app.
1. Install the desktop app
macOS: download the .pkg from the homepage, open it and follow the installer. The package is signed and notarized by Apple (Gatekeeper shouldn’t block installation). The app launches automatically at the end of installation — you don’t need to open anything manually. It registers to start with your session; you can disable this later from the menu bar icon’s menu. macOS will ask for notification permission on first launch — accept it to be alerted of protection status changes.
Windows: download the .msi and run it. The current release isn’t signed by a recognized publisher yet: Windows SmartScreen may show an “unknown publisher” warning. That’s expected for now; click “More info” then “Run anyway” to continue.
Once installed, the app lives in the menu bar (macOS) or notification area (Windows). Three possible icon states:
- Normal icon: protection active, detection model ready.
- Icon with a red “!” badge: local app unreachable or model unavailable — protection falls back to degraded mode (rules only, no name/organization recognition).
- Icon with an animated arrow: detection model downloading (on first launch, or during a model update).
2. Install the Chrome or Edge extension
Install the extension from the Chrome Web Store (link on the homepage). On first install, the extension automatically opens a tab on claude.ai and launches a short guided tour: it shows you how a sample of personal data gets detected and replaced by a token before sending, then restored in the reply. You can skip the tour at any time; it stays available afterward from the extension popup (“Replay guided tour”).
3. Check that protection is active
Click the extension icon in your browser toolbar. The popup shows a status indicator:
- Green: full protection active (local app + detection model available).
- Amber/degraded: local app unreachable — only deterministic rules (email, IBAN, ID numbers…) stay active; name and organization detection is disabled.
- Disabled: protection manually turned off for the current site (toggle at the top of the popup).
On claude.ai and chatgpt.com, a badge appears directly in the site’s interface to confirm the page is being monitored.
4. Link your account
Your license and subscription are managed from the desktop app, not the extension: the extension simply reads the status from the local app. If the extension shows you’re not logged in, a “Sign in via the app” button opens the sign-in flow in the desktop app — sign-in happens through your regular browser, and your credentials never pass through the extension itself.
Two devices, one license
The Solo plan covers two devices (for example your work computer and your personal one): install the app and extension on each, sign in with the same account.