Nimbus for Chrome
Privacy policy
Effective 8 September 2026. This policy covers the Nimbus browser extension for Chrome and Microsoft Edge, published by Constralabs Technology Inc. (“ConstraLabs”, “we”).
The short version
- Nimbus reads a page or an email only for the question you asked, and names what it read underneath every answer.
- Nothing runs on any page until you ask. There is no script watching your browsing.
- Your conversations stay on your own computer.
- Nimbus prepares work. It never sends, submits, posts, pays or files anything for you.
- No advertising, no analytics, no tracking, no sale or transfer of your data to anyone.
Who this is for
Nimbus is a workplace tool. It only works for people who have an account with ConstraAP, the company platform it is built on. It is not a general-purpose assistant, and it cannot be used without that account.
If you use Nimbus at work, your employer administers your account and this policy sits alongside whatever agreement they have with us.
What Nimbus reads, and when
Nimbus reads something only when you ask it a question that needs it, or press a control that requires it. Each of these is a deliberate act on your part:
- The page you are on. When you ask about it, its text is extracted and sent with your question.
- Another open tab. Only if you pick it from the list in the panel.
- A screenshot. Only when you ask for one, so that Nimbus can see a layout rather than only read text.
- The email you have open. In Gmail or Outlook, when you ask about it. This includes the earlier messages in the conversation and their quoted history.
- Attachments and files. Only the ones you choose, or the ones on the email you are asking about.
- A text selection. When you right-click and choose "Rewrite with Nimbus".
Underneath every answer is a line naming exactly what was read to produce it. If that line does not name a page, no page was sent.
The extension installs no permanent script on any website. The package declares no content script. Code is placed on a page at the moment you ask about that page, and it reads that page only.
You can block any site permanently with "Never read this site" in the panel. Nimbus then refuses to read it, and says so instead of quietly reading it anyway.
Nimbus reads the titles and addresses of your open tabs so you can choose between them and so the source line can name them. It does not read your browsing history, your bookmarks, your saved passwords or your autofill data, and it never builds a list of the sites you visit.
What is kept on your computer
This information is written to Chrome's local extension storage on your own machine. The extension does not transmit it anywhere.
- Your conversations with Nimbus, and the answers in them.
- The prepared reply cards in the Work Inbox.
- Counts of how much you have used Nimbus, by day, kept for 60 days and then dropped.
- The sites you have blocked with "Never read this site".
- Your appearance choice, text size, and which conversation you had open.
- Your sign-in session.
- A capped local record of the steps an agent task took, with typed values, passwords and tokens stripped out before it is written.
All of it is filed under the account you signed in as, so that two colleagues sharing one computer do not see each other's conversations. This is a separation, not encryption: someone with access to your computer and your Chrome profile can read the profile's files, exactly as they could for any other extension. Protect the machine.
Signing out removes the session. Deleting a conversation deletes it. Removing the extension removes all of it.
What is sent, and where
When you ask a question, your question and whatever the source line names are
sent over an encrypted connection to ConstraAP's gateway at
https://ap.constralabs.ai. The gateway is operated by ConstraLabs
on its own servers. It authenticates you,
attaches the company information relevant to your question, and passes the
request to the model that writes the answer.
Sign-in goes to https://vwcolqacmqktbwyicsbw.supabase.co,
our identity provider, and to Google or Microsoft if you choose to sign in with
them. Those providers handle your password on their own pages. Nimbus never
sees your password.
Attachments are fetched from your mail provider using the session you already have open in your browser, in the same way that clicking the attachment yourself would. They are held in memory for the question you asked and are not written to disk unless you press Save.
The extension talks to no other servers. It loads no fonts, scripts, images or analytics from anywhere on the internet: everything it runs and displays is inside the installed package.
Who else sees it
To produce an answer, ConstraAP sends your question and its context to Anthropic, whose Claude models write the answer, under commercial terms that do not permit your content to be used to train models.
ConstraAP runs on ConstraLabs' own servers, hosted on Microsoft Azure. Microsoft supplies the infrastructure those servers run on and does not process your content for its own purposes.
Nobody else. We do not sell your data, we do not share it with advertisers or data brokers, and we do not transfer it to anyone for any purpose unrelated to giving you an answer.
What we collect, in the store's own words
The Chrome Web Store asks every extension to declare this in fixed categories. These are the ones Nimbus declares, and why.
| Category | What it is, here |
|---|---|
| Personally identifiable information | Your account email address, which identifies you to ConstraAP and separates your conversations from a colleague's on a shared computer. |
| Authentication information | The session token that keeps you signed in. Held on your device. Never a password: Nimbus never receives one. |
| Personal communications | The content of an email, when you ask a question about the email you have open. |
| Website content | The text of a page, or a screenshot of it, when you ask a question about that page. |
Nimbus declares no health information, no financial or payment information, no location, no web history and no user activity. It does not monitor clicks, scrolling, mouse position or keystrokes, and it does not track what you do in your browser.
What Nimbus never does
- It never sends. Nimbus drafts a reply and places it in your compose box unsent. There is no Send button in Nimbus. Submitting, sending, paying, publishing and deleting are yours, done by you, in the site's own interface.
- It never acts without being asked. Agent mode shows you a plan and waits for you to approve it, reports each step as it goes, and refuses outright to press a control that would send, pay, delete, publish or sign you out.
- It never runs code from the internet. Everything it executes ships inside the package, which is published unminified so that it can be read and checked.
- It never advertises or profiles you. There is no advertising, no analytics service, and no tracking of any kind.
Diagnostics
Nimbus keeps a small local log of things that went wrong, so that a fault can be understood: the kind of failure, how long something took, and which host was involved. It records shapes and numbers, never content — no page text, no email content, no addresses of the pages you visited. It stays on your computer and is shown only on a diagnostics screen that has to be asked for by address.
How long things are kept
- On your computer: until you delete the conversation, sign out, or remove the extension. Usage counts drop off after 60 days on their own.
- At ConstraAP: the content of a turn is kept for up to 60 days and is then deleted. Your account record is kept for as long as you have an account.
Your choices and your rights
You can delete any conversation from the panel, block any site from being read, sign out to end the session, and uninstall the extension to remove everything it holds locally.
For data held by ConstraAP, you can ask us for a copy of it, ask us to correct it, or ask us to delete it. Where you have them, you may also have rights to object to or restrict processing, and to complain to your local data protection authority. Write to the address below and we will respond within the time the law allows. If your employer administers your account, we may need to involve them.
Children
Nimbus is a workplace tool for employees. It is not directed at children and we do not knowingly collect information from them.
Changes to this policy
If what Nimbus reads, stores or sends changes, this page changes with it, and the effective date at the top changes too. Material changes will be announced to account administrators before they take effect.
Contact
Questions about this policy, or a request about your data:
gcp@constralabs.ai
Constralabs Technology Inc.
342 Mountain Hwy, Unit 302
North Vancouver, BC V7J 2K8
Canada