complens.ai
Privacy policy
Effective July 23, 2026
The short version: the complens browser extension classifies what you send to AI chat tools on your own device. The text of your messages is never transmitted to us, and our systems have no field to store it in. What we receive is metadata about flagged sends — detector name, risk score, a one-way hash, the site, the device. If you sign in with Google, we receive only your email address and Workspace domain, and we use them only to show your organization's administrator which device is whose.
1. Who we are and what this covers
complens.ai is developed and operated by Ross IT Solutions, LLC ("complens", "we", "us"). We provide an agentic data loss prevention platform: a browser extension deployed on managed devices, a cloud API that receives security events, and an administrator console. This policy covers all of them, plus this website.
In most deployments the extension is installed on your device by your employer or organization, which is the controller of the data described below and decides its configuration (observe or enforce mode, policies, retention). We process that data on the organization's behalf. Questions about a specific workplace deployment are best directed to your administrator; questions about our practices to hello@itsross.com.
2. What never leaves your device
The content of your messages, prompts, and pastes is classified on your device and is not transmitted to complens. This is enforced in layers, not just promised:
- Classification (pattern matching and the local model) runs inside the browser on your machine, and works with no network connection.
- Events carry a SHA-256 hash of the flagged context — a one-way fingerprint used to correlate repeats — plus detector metadata. There is no content field in the event schema.
- Our ingest API drops any unrecognized field before storage, so even a malfunctioning or modified client cannot cause message text to be stored.
- Sends that the engine classifies as benign produce no event at all — no hostname, no hash, no counter. Ordinary browsing generates zero telemetry.
3. What we do collect
Detection events
When a detector fires on a send to an AI chat tool, the extension reports:
the detector(s) that matched (for example aws_access_key), a
risk score, the SHA-256 context hash, the destination site's hostname, a
timestamp, the action taken (logged, warned, blocked, or overridden), and
the device and tenant identifiers.
Device posture
On managed devices, the extension periodically reports device posture to your organization's console: browser and extension version, the inventory of installed browser extensions (their identifiers, versions, and requested permissions, risk-scored), device attributes supplied by your organization's enterprise enrollment where available (hostname, serial number, asset tag), and the device owner as described in section 4.
Administrator accounts
Console administrators sign in with their work email. We keep the account email, tenant membership, and role.
Website
This website serves static pages and does not use analytics trackers or advertising cookies.
4. Google user data
On managed devices, the extension can verify the device owner's identity
through Google sign-in (Chrome's identity API). This section is
our complete disclosure of that data flow.
- What we request: the
openidandemailscopes only. We do not request or receive access to Gmail, Drive, Calendar, Contacts, or any other Google service or content. - What we receive: your Google account email address and, for Google Workspace accounts, the Workspace domain.
- How we use it: for a single purpose — attributing a managed device to its verified owner in your organization's administrator console. The email is shown to your organization's administrators alongside that device's security events and posture.
- Token handling: the OAuth access token is used once, server-side, to verify the identity claim with Google, and is then discarded. It is never stored, logged, or returned by our API.
- What we never do with Google user data: we do not sell it, do not use it for advertising, do not use it to train models, and do not transfer it to third parties except as required to provide the service to your organization or as required by law. Humans do not read it except with your organization's consent, for security purposes, or to comply with applicable law.
complens.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. How data is shared
- With your organization: the events and posture described above are visible to your organization's console administrators — that is the product.
- SIEM export: your organization's administrator may configure forwarding of events (the same metadata-only records) to the organization's own security tooling.
- Service providers: we use cloud infrastructure providers to host the service. They process data on our instructions and do not use it for their own purposes.
- No sale, no ads: we do not sell personal data and do not use it for advertising.
- Legal: we may disclose data where required by law or to protect the rights, safety, and security of complens, our customers, or others.
6. Security
Events are transmitted over TLS. Devices authenticate with per-device credentials scoped to a single tenant; administrator access is authenticated separately. Tenant data is segregated: a credential for one organization cannot read or write another's data. The extension refuses to talk to a non-HTTPS backend outside local development.
7. Retention
Event and posture data is retained for the duration of the organization's subscription and per its configuration, then deleted. Because the deploying organization is the controller, deletion and export requests for workplace data are fulfilled through the organization's administrator.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data. For data processed on behalf of your organization, contact your administrator, and we will support the organization in fulfilling the request. For anything else, contact hello@itsross.com.
9. Changes
If we change this policy, we will update the effective date above; for material changes affecting Google user data or the content-never-leaves guarantee in section 2, we will notify deployed organizations before the change takes effect.
10. Contact
Ross IT Solutions, LLC — hello@itsross.com