1. Overview
Shadow AI (“we,” “our,” or “us”) provides an AI spend visibility platform consisting of a web dashboard, a Chrome browser extension, and optional SDKs. This policy describes what data we collect, why we collect it, how we use it, who we share it with, and your rights regarding that data.
2. Data collected by the Chrome extension
The Shadow AI Chrome extension collects the following data when you are signed in:
- Browsing activity (AI tool pages only): The extension detects when you visit AI tool websites — including ChatGPT (chat.openai.com), Claude (claude.ai), GitHub Copilot (github.com/copilot), Google Gemini (gemini.google.com), and Perplexity (perplexity.ai). It records the domain visited, the timestamp, and the estimated session duration. It does not monitor any other websites or general browsing activity.
- Session metadata: Approximate token usage estimates and session cost estimates derived from session duration and the AI tool used. These are estimates only — the extension does not have access to actual token counts from AI providers.
- Account identifiers: Your Shadow AI user ID and organization ID, used to attribute usage data to the correct account.
The extension does not collect, read, or transmit the content of your prompts, AI responses, uploaded files, or any other conversation content. It does not collect passwords, payment information, or personal communications.
3. Data collected by the web dashboard and SDKs
- Account information: Name, work email address, and password hash (bcrypt). If you sign in with Google, we receive your name, email, and profile picture URL from Google.
- Organization data: Organization name, billing plan, and API keys you choose to connect (stored encrypted at rest with AES-256).
- AI usage events: Tool name, model used, token counts (if provided by your SDK integration), cost data, timestamps, and the user and team the event is attributed to.
- Billing data: If you connect an Anthropic or OpenAI admin API key, we poll the respective billing APIs daily to retrieve your organization-level spend totals. We store aggregate spend figures — not individual request content.
- Payment information: Stripe handles all payment card data. We do not store card numbers, CVVs, or full payment details. We store your Stripe customer ID and subscription status only.
4. How we use your data
We use the data we collect exclusively to provide the Shadow AI service:
- Displaying spend dashboards, team analytics, and usage reports
- Sending budget alerts, anomaly notifications, and weekly digest emails
- Enforcing usage policies and budget limits you configure
- Processing billing and managing your subscription
- Authenticating your account and maintaining your session
We do not sell your data. We do not use your data for advertising. We do not use your data to train AI models. We do not use your data for any purpose beyond operating the Shadow AI service.
5. Third-party service providers
We share data with the following service providers solely to operate the Shadow AI service. These providers are contractually prohibited from using your data for any other purpose:
- Supabase (Supabase Inc.) — database and storage provider. All usage data, account information, and organization data is stored in Supabase Postgres, hosted on Amazon Web Services (AWS) infrastructure in the United States. Supabase Privacy Policy
- Stripe (Stripe, Inc.) — payment processing. If you subscribe to a paid plan, your payment is processed by Stripe. We pass your email and billing details to Stripe; Stripe stores and processes all card data. Stripe Privacy Policy
- Resend (Resend, Inc.) — transactional email delivery. We use Resend to send email verification, password reset, budget alert, and weekly digest emails. We share your email address and the email content with Resend for delivery purposes only. Resend Privacy Policy
- Vercel (Vercel Inc.) — web hosting and serverless infrastructure. The Shadow AI web application and API are hosted on Vercel's platform. Request logs (IP address, user agent, endpoint) may be retained by Vercel for up to 30 days as part of standard infrastructure logging. Vercel Privacy Policy
- Upstash (Upstash, Inc.) — rate limiting. We use Upstash Redis to enforce API rate limits. Only request counts per IP or API key are stored; no personal data or usage content is passed to Upstash. Upstash Privacy Policy
- Google (Google LLC) — authentication. If you sign in with Google OAuth, Google shares your name, email address, and profile picture with us. We do not share your data back to Google beyond what is required for the OAuth flow. Google Privacy Policy
We do not share your data with any other third parties. We do not sell, rent, or trade your data.
6. Data storage and security
All data is stored in the United States. Data is encrypted in transit via TLS 1.2 or higher. Data is encrypted at rest by Supabase/AWS. API keys and third-party credentials you connect are additionally encrypted with AES-256 before being written to the database. Session tokens are HMAC-SHA256 signed. We do not store plaintext passwords — passwords are hashed using bcrypt before storage.
7. Data retention
Your data is retained for as long as your account is active. If you delete your account, all associated personal data and usage events are permanently deleted within 30 days. You may request earlier deletion by contacting us. Billing records may be retained for up to 7 years as required by applicable tax and financial regulations.
8. Your rights
You have the right to access, correct, export, or delete the personal data we hold about you. Organization admins can export or delete org-level data from the Settings page. For individual access or deletion requests, contact us at the email below. We will respond within 30 days.
9. Cookies and local storage
The web dashboard uses a single HttpOnly session cookie to keep you signed in. The Chrome extension uses Chrome's chrome.storage.local API to store your account credentials locally on your device so the extension can authenticate with the Shadow AI API. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
10. Children's privacy
Shadow AI is a business tool not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
11. Governing law
This policy is governed by the laws of the State of California, United States, without regard to conflict of law principles.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.