Nimbus for Chrome

Privacy policy

Effective 8 September 2026. This policy covers the Nimbus browser extension for Chrome and Microsoft Edge, published by Constralabs Technology Inc. (“ConstraLabs”, “we”).

The short version

Who this is for

Nimbus is a workplace tool. It only works for people who have an account with ConstraAP, the company platform it is built on. It is not a general-purpose assistant, and it cannot be used without that account.

If you use Nimbus at work, your employer administers your account and this policy sits alongside whatever agreement they have with us.

What Nimbus reads, and when

Nimbus reads something only when you ask it a question that needs it, or press a control that requires it. Each of these is a deliberate act on your part:

Underneath every answer is a line naming exactly what was read to produce it. If that line does not name a page, no page was sent.

The extension installs no permanent script on any website. The package declares no content script. Code is placed on a page at the moment you ask about that page, and it reads that page only.

You can block any site permanently with "Never read this site" in the panel. Nimbus then refuses to read it, and says so instead of quietly reading it anyway.

Nimbus reads the titles and addresses of your open tabs so you can choose between them and so the source line can name them. It does not read your browsing history, your bookmarks, your saved passwords or your autofill data, and it never builds a list of the sites you visit.

What is kept on your computer

This information is written to Chrome's local extension storage on your own machine. The extension does not transmit it anywhere.

All of it is filed under the account you signed in as, so that two colleagues sharing one computer do not see each other's conversations. This is a separation, not encryption: someone with access to your computer and your Chrome profile can read the profile's files, exactly as they could for any other extension. Protect the machine.

Signing out removes the session. Deleting a conversation deletes it. Removing the extension removes all of it.

What is sent, and where

When you ask a question, your question and whatever the source line names are sent over an encrypted connection to ConstraAP's gateway at https://ap.constralabs.ai. The gateway is operated by ConstraLabs on its own servers. It authenticates you, attaches the company information relevant to your question, and passes the request to the model that writes the answer.

Sign-in goes to https://vwcolqacmqktbwyicsbw.supabase.co, our identity provider, and to Google or Microsoft if you choose to sign in with them. Those providers handle your password on their own pages. Nimbus never sees your password.

Attachments are fetched from your mail provider using the session you already have open in your browser, in the same way that clicking the attachment yourself would. They are held in memory for the question you asked and are not written to disk unless you press Save.

The extension talks to no other servers. It loads no fonts, scripts, images or analytics from anywhere on the internet: everything it runs and displays is inside the installed package.

Who else sees it

To produce an answer, ConstraAP sends your question and its context to Anthropic, whose Claude models write the answer, under commercial terms that do not permit your content to be used to train models.

ConstraAP runs on ConstraLabs' own servers, hosted on Microsoft Azure. Microsoft supplies the infrastructure those servers run on and does not process your content for its own purposes.

Nobody else. We do not sell your data, we do not share it with advertisers or data brokers, and we do not transfer it to anyone for any purpose unrelated to giving you an answer.

What we collect, in the store's own words

The Chrome Web Store asks every extension to declare this in fixed categories. These are the ones Nimbus declares, and why.

CategoryWhat it is, here
Personally identifiable information Your account email address, which identifies you to ConstraAP and separates your conversations from a colleague's on a shared computer.
Authentication information The session token that keeps you signed in. Held on your device. Never a password: Nimbus never receives one.
Personal communications The content of an email, when you ask a question about the email you have open.
Website content The text of a page, or a screenshot of it, when you ask a question about that page.

Nimbus declares no health information, no financial or payment information, no location, no web history and no user activity. It does not monitor clicks, scrolling, mouse position or keystrokes, and it does not track what you do in your browser.

What Nimbus never does

Diagnostics

Nimbus keeps a small local log of things that went wrong, so that a fault can be understood: the kind of failure, how long something took, and which host was involved. It records shapes and numbers, never content — no page text, no email content, no addresses of the pages you visited. It stays on your computer and is shown only on a diagnostics screen that has to be asked for by address.

How long things are kept

Your choices and your rights

You can delete any conversation from the panel, block any site from being read, sign out to end the session, and uninstall the extension to remove everything it holds locally.

For data held by ConstraAP, you can ask us for a copy of it, ask us to correct it, or ask us to delete it. Where you have them, you may also have rights to object to or restrict processing, and to complain to your local data protection authority. Write to the address below and we will respond within the time the law allows. If your employer administers your account, we may need to involve them.

Children

Nimbus is a workplace tool for employees. It is not directed at children and we do not knowingly collect information from them.

Changes to this policy

If what Nimbus reads, stores or sends changes, this page changes with it, and the effective date at the top changes too. Material changes will be announced to account administrators before they take effect.

Contact

Questions about this policy, or a request about your data:
gcp@constralabs.ai

Constralabs Technology Inc.
342 Mountain Hwy, Unit 302
North Vancouver, BC V7J 2K8
Canada