5 items
Warns you before you paste API keys, tokens or personal IDs into an AI chat or work tool. Nothing ever leaves your device. You are debugging something, so you copy the config, drop it into ChatGPT, and ask what is wrong. It answers. Somewhere in the middle of what you pasted was a live database password. That is not carelessness. It is the shape of the tool: the fastest way to get help is to paste the whole thing, and the whole thing always has a secret in it. Leakly sits between Ctrl+V and the chat box. When the text you are pasting contains something sensitive, the paste stops and Leakly shows you exactly what it found — then offers to paste a redacted version instead. ★ IT REDACTS, IT DOESN'T JUST BLOCK Secrets are replaced with labelled placeholders — <REDACTED_AWS_KEY>, <REDACTED_DATABASE_URL> — not stars. The model on the other end still sees the structure of what you pasted, so you still get the answer you were after. The same value always becomes the same placeholder, and two different keys stay distinguishable, so your config still reads as one coherent file. ★ WHAT IT CATCHES • API keys and access tokens issued by the major cloud, payment, messaging and developer platforms, each matched by its own documented key format • JWTs, bearer tokens, and PEM/OpenSSH private keys — the whole block, not the header line • Anything labelled: API_KEY=, DB_PASSWORD=, client_secret, Authorization: • Connection strings — postgres://, mongodb+srv://, redis://, JDBC, and any URL with a password inside it • Card numbers (Luhn-checked) and IBANs (mod-97 checked) • US Social Security numbers, Aadhaar numbers (Verhoeff-checked) and Indian PANs • Unlabelled high-entropy strings — the tokens nothing else knows the shape of • Anything you add yourself, as a regular expression, for your company's own employee numbers, ticket ids and customer references ★ IT VALIDATES, SO IT DOESN'T CRY WOLF A sixteen-digit number is not a card until the Luhn checksum agrees. Twelve digits are not an Aadhaar until the Verhoeff check digit agrees. A commit hash, a UUID and a minified bundle all look random and none of them are secrets. Leakly checks before it interrupts, because a guard that fires on ordinary code is one you switch off by Friday — and then it is guarding nothing. ★ WHERE IT RUNS — AND WHERE IT DOESN'T Leakly runs on a short, fixed list of AI chat assistants and team collaboration tools. The full list is printed in the settings page, so you can read it before you install rather than take it on trust. That list is the whole of it. Leakly does not ask for permission to read every website. If you want it somewhere else — an internal wiki, a notes app, a support desk — you add that one site and grant that one permission yourself. ★ NOTHING LEAVES YOUR BROWSER No account. No server. No analytics. No network requests at all — there is no fetch, no socket and no remote script anywhere in the code, and the build refuses to package a version that has any. Enterprise AI-DLP products send your pastes to a cloud service to decide whether they were sensitive. Leakly decides on your machine, which is the only place that answer was ever needed. The values it finds are never stored. When you tell it to always allow a value, it keeps a salted one-way hash, not the value — an allowlist full of plaintext secrets would make the guard the leak. ★ SMALL THINGS THAT MATTER • Choose per site: ask every time, redact certain matches silently, or off • Enter is the safe choice, Escape cancels, and a stray click never sends • Ctrl+Z after a redaction works, because the paste goes through the editor's own undo stack • Dragged-in text is checked too — it is a paste that skips the clipboard • Uncertain matches always stop for a decision and are never redacted silently • A local counter of what it has caught, because a guard that mostly does nothing should be able to show its work Free, and free of the things that usually pay for free.
Aug 19, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.