Set up Custodian
Your organisation runs a Custodian pilot and you were invited to take part. Taking part is your choice. Custodian looks at how you and AI assistants talk at work, to show you trends in strain, clarity, engagement and confidence. Nobody at your organisation sees your conversations or your results.
You stay in control
- Nothing is captured until you switch capture on, and you can pause it at any time.
- Before anything is sent you can read the queue, remove a chat, or exclude a chat for good.
- Names, emails, phone numbers and similar details are removed before your chats are stored.
- You can download everything held about you, or erase your account and all its records, by yourself.
Enter your pilot access code
Custodian gives each organisation in the pilot its own code. You received it from the person who runs the pilot at your organisation.
Access code accepted. Continue with step 1 below.
Create your account
Choose a username that is not your real name or your email. Custodian never asks who you are.
Loading…
Already registered? Open your personal dashboard.
Install the browser extension
For Chrome, Edge and Brave on a computer. If your organisation manages your browser, your IT team installs Custodian for you and you can skip to step 3.
Download the extension- Unzip the file into a folder you will keep, for example Documents/Custodian.
- Open the extensions page of your browser: type
chrome://extensions(Chrome, Brave) oredge://extensions(Edge) in the address bar. - Switch on Developer mode, choose Load unpacked, and select the folder.
- Pin Custodian to the toolbar: click the puzzle-piece icon, then the pin next to Custodian.
The browser asks for access to four sites only: ChatGPT, Claude, Gemini and Microsoft Copilot. It may remind you at start-up that a developer-mode extension is active; that is expected during the pilot.
Install the connector
For Claude Code, Codex CLI, GitHub Copilot CLI and Antigravity. One command in the terminal, with Node.js 18 or newer. macOS and Linux:
curl -LsSf https://custodian.health/install.sh | sh
Windows (two commands):
curl.exe -LsSf https://custodian.health/install.mjs -o custodian-install.mjs
node custodian-install.mjs
Then custodian login with the account from step 1, and custodian on: from then on it sends once a day by itself. The connector takes only what you write and the text of the replies, never code, files or commands. What it reads and every command.
Sign in and switch capture on
- Click the Custodian icon and sign in with the account from step 1.
- If it asks for a service address, open Service address and paste this one:
Loading… - Switch on Capture my AI chats. That switch is your consent, and switching it off withdraws it.
- Open one of the assistants. The Custodian icon shows the assistant's mark when capture works on that tab.
Only ever use the address shown on this page. Never paste one that reached you by email or chat.
What is collected, and what is not
Read this before you switch capture on.
Collected
- What you write to ChatGPT, Claude, Gemini and Microsoft Copilot, and what they answer, while capture is on.
- With the connector: what you write to Claude Code, Codex, Copilot CLI or Antigravity and the text of their replies. Never the commands run, the files read or the code written.
- The time, the name of the assistant, and the conversation it belongs to.
- Your username and a password hash, to sign you in.
Not collected
- Any other website, tab, file, keystroke or screen.
- Anything while capture is paused, or in a chat you excluded.
- Your name or email address. Custodian never asks for them.
What happens to it
- It waits in your browser and is sent once a day, or when you choose. After sending, the browser keeps no readable text.
- On arrival, names, emails, phone numbers, addresses, card and ID numbers, links and places are replaced before storage. Detection is strong, not perfect: a name typed without capitals can be missed.
- A model reads the de-identified text to estimate mental states and to rate the assistant's replies. It is not a medical device and it does not diagnose.
- Only you see your dashboard. The pilot administrator sees how many people take part, under anonymous IDs.
- HR at your organisation sees group figures only: averages and states shared by at least five participants, never your results, your conversations or your name. With fewer than five participants, HR sees nothing.