complens.ai

Privacy policy

The short version: the complens browser extension classifies what you send to AI chat tools on your own device. The text of your messages is never transmitted to us, and our systems have no field to store it in. What we receive is metadata about flagged sends — detector name, risk score, a one-way hash, the site, the device. If you sign in with Google, we receive only your email address and Workspace domain, and we use them only to show your organization's administrator which device is whose.

1. Who we are and what this covers

complens.ai is developed and operated by Ross IT Solutions, LLC ("complens", "we", "us"). We provide an agentic data loss prevention platform: a browser extension deployed on managed devices, a cloud API that receives security events, and an administrator console. This policy covers all of them, plus this website.

In most deployments the extension is installed on your device by your employer or organization, which is the controller of the data described below and decides its configuration (observe or enforce mode, policies, retention). We process that data on the organization's behalf. Questions about a specific workplace deployment are best directed to your administrator; questions about our practices to hello@itsross.com.

2. What never leaves your device

Your content — messages, prompts, pastes, copies, printed pages, and anything else the extension inspects — is classified on your device and is not transmitted to complens. This is enforced in layers, not just promised:

3. What we do collect

The extension is active on every site, because the tools it exists to guard are not a fixed list. Being active is not the same as recording: on an ordinary page nothing matches, and a send that matches nothing produces no record at all — not a hostname, not a hash, not a counter. Everything below describes what is recorded when a detector matches.

Detection events

When a detector fires on a send to an AI chat tool, the extension reports: the detector(s) that matched (for example aws_access_key), a risk score, the SHA-256 context hash, the destination site's hostname, a timestamp, the action taken (logged, warned, blocked, or overridden), and the device and tenant identifiers.

Background requests

Some sites send your message from a background worker rather than from the page itself. Those sends are classified the same way and produce the same detection events described above, under the same on-device rules — only a fingerprint and detector labels are recorded, and a send that matches nothing produces nothing. Requests the extension itself makes to your organization's console are excluded.

Clipboard indicators

When you copy or cut text, the extension scans it on your device and, only if a detector matches, records that a copy occurred: the detector identifiers that matched, a SHA-256 hash of the copied text, its byte count, the page's hostname, and a timestamp. This lets your organization see that sensitive material was copied on one site and later submitted on another, without either the copied text or the pasted text ever being transmitted. Copies that match nothing produce no record at all, and the contents of password fields are never read.

When a send follows pasted content, the same kind of indicator may be attached to that send's event: that a paste occurred, its byte count and paste count, and the detector identifiers matched by an on-device scan. The pasted text itself never leaves your device.

Print records

When a page asks the browser to print, the extension classifies the page's visible text on your device — on a print, the rendered page is what leaves, on paper. If a detector matches, it records the detector identifiers, a SHA-256 hash, and the page's hostname. The page text itself is never transmitted, hidden content is not read, and a print that matches nothing produces no record.

File download records

On enrolled browsers, file downloads are logged as metadata only: the download's origin hostname, the file's name (basename only — never its folder or full path), its MIME type, size, and a timestamp. File contents are never read or transmitted.

Device posture

On managed devices, the extension periodically reports device posture to your organization's console: browser and extension version, the inventory of installed browser extensions (their identifiers, versions, and requested permissions, risk-scored), device attributes supplied by your organization's enterprise enrollment where available (hostname, serial number, asset tag), and the device owner as described in section 4.

Administrator accounts

Console administrators sign in with their work email. We keep the account email, tenant membership, and role.

Website

This website serves static pages and does not use analytics trackers or advertising cookies.

4. Google user data

On managed devices, the extension can verify the device owner's identity through Google sign-in (Chrome's identity API). This section is our complete disclosure of that data flow.

complens.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. How data is shared

6. Security

Events are transmitted over TLS. Devices authenticate with per-device credentials scoped to a single tenant; administrator access is authenticated separately. Tenant data is segregated: a credential for one organization cannot read or write another's data. The extension refuses to talk to a non-HTTPS backend outside local development.

7. Retention

Event and posture data is retained for the duration of the organization's subscription and per its configuration, then deleted. Because the deploying organization is the controller, deletion and export requests for workplace data are fulfilled through the organization's administrator.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data. For data processed on behalf of your organization, contact your administrator, and we will support the organization in fulfilling the request. For anything else, contact hello@itsross.com.

9. Changes

If we change this policy, we will update the effective date above; for material changes affecting Google user data or the content-never-leaves guarantee in section 2, we will notify deployed organizations before the change takes effect.

10. Contact

Ross IT Solutions, LLC — hello@itsross.com