Privacy & data handling
What we collect, where it goes, how long it stays. This page covers the Token Canopy website (tokencanopy.com) and the Token Canopy account and workspace service (app.tokencanopy.com, auth.tokencanopy.com), plus the AgentTag Chrome extension and macOS desktop companion, operated by Mnexa, Inc. Last updated 2026-07-28.
The short version
- This website is static. It sets no cookies, runs no analytics or tracking scripts, and makes no third-party requests from your browser.
- If you sign in, we store the account profile our sign-in provider gives us (email, name, avatar) plus the workspace, entitlement, and usage records needed to run the service — nothing else.
- AgentTag processes context you choose and eligible fields on the form where you start a fill. Local fills use the AI provider configured on your Mac; Token Canopy does not receive the selected context or form contents from a Local Runtime fill.
- Your content lives in our products, not here. Emails your agents send and receive stay in e2a; files your agents store stay in AgentDrive. Each product documents its own data handling — AgentDrive's is at agentdrive.run/privacy.
- We do not sell personal data and we do not run ads.
The website
tokencanopy.com is a fully static site served from a CDN. It uses self-hosted fonts, sets no cookies, and loads nothing from third parties at runtime. Our CDN and hosting providers keep standard access logs (request path, timestamp, IP address, user agent) for operating and securing the site.
Signing in — your Token Canopy account
Sign-in is handled by WorkOS AuthKit on our behalf. You can sign in with Google or with an email code (Magic Auth). We never see or store a password for you.
- What we receive and store:your email address and whether it is verified, your name, your avatar image URL, and the account identifiers issued by WorkOS. If you sign in with Google, we also receive Google's stable account identifier (the OIDC
subject), which we use for exactly one thing: linking you to a product account you already own — a matching email alone is never enough to link accounts. - What Google shares with us: your basic profile (name, email address, profile picture) via the standard OpenID Connect scopes. We request no other Google scopes and no access to any Google service data.
- What we create around it: a workspace record, your membership in it, and a mapping to your product account(s) in e2a or AgentDrive. The mapping stores only opaque account identifiers — no product content or product credentials ever live in the Token Canopy database.
- Session cookie: signing in sets one cookie,
tc_session, a signed,HttpOnlysession cookie on app.tokencanopy.com. We use no advertising or analytics cookies. - Single sign-on to products: auth.tokencanopy.com acts as an OpenID Connect provider for our own products. When you use Token Canopy to sign in to a product, we pass that product your identity claims (account id, email, name) — nothing more.
Google user data
If you sign in with Google, this is the complete picture of how we handle the data Google shares with us — stated in the terms Google's policies ask us to disclose:
- Access. We request only the non-sensitive OpenID Connect scopes (
openid,email,profile): your name, email address, profile picture, and Google's stable account identifier. We request no access to Gmail, Drive, Calendar, or any other Google service data. - Use. Signing you in and linking you to product accounts you already own. Nothing else — no advertising, no profiling, no automated decision-making.
- Storage. Stored in our database on Google Cloud infrastructure in the United States, for as long as your Token Canopy account exists.
- Sharing. Never sold, and never shared beyond the sub-processors listed below and the identity claims passed to our own products when you sign in to them.
- Deletion. Deleting your Token Canopy account (below) removes the Google profile data we hold.
- Revocation.You can revoke Token Canopy's access to your Google account at any time from myaccount.google.com/permissions. Revoking access stops future sign-ins with Google; it does not by itself delete the data we already hold — email us for that.
Token Canopy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AgentTag — Chrome and macOS form filling
AgentTag combines a Chrome extension with a macOS desktop companion. While installed, the extension keeps bounded, session-only metadata about recent interactions on HTTP and HTTPS pages so a desktop invocation can bind to the intended tab. It inspects form contents or requests answers only when you invoke AgentTag and start a fill. It does not use this data to build a persistent browsing history, track you across sites, run advertising, or run analytics.
- Before a fill. To bind a desktop invocation to the page you were using, the extension keeps a session-scoped record of recent interactions: their time, tab and exact page URL, and a random document token. It retains at most 50 records for the Chrome session, and a record can authorize a fill only for five minutes. AgentTag does not record which key you pressed, where you clicked, or the value you entered.
- When you start a fill. The extension examines the labels, types, choices, required state, and filled-or-empty state of eligible controls on that form. It does not include existing user-entered answers in the form description sent to the agent. It applies proposed answers field by field, leaves occupied or user-edited fields alone, and does not click a submit button or call a form-submission API. AgentTag dispatches the standard field-change events that websites expect after an edit; a website may react to those events according to its own behavior, including autosave or automatic submission.
- Protected fields.AgentTag uses field type, autocomplete metadata, and label text to identify and exclude recognized password, payment-card, bank, one-time-code, government identifier, hidden, file-input, and legal-consent controls before the agent sees the form. Because identification depends on the website's markup, review every proposed answer before continuing. Depending on the context and form you deliberately choose, eligible answers may still contain contact details, location, health information, non-payment financial information, or personal communications.
- Context and Local Runtime.Files you choose are copied into AgentTag's private local store on your Mac. The Chrome extension receives source names and bounded metadata, not file bytes or local paths. During a Local Runtime fill, the selected context, safe form description, and current fill-page URL are processed through the Claude Code account and AI provider you configured. That provider's terms and privacy policy govern its processing. Mnexa does not receive the selected context or form contents through the Local Runtime path.
- Chrome storage. The extension keeps tab bindings, selected-source metadata, fill progress, and short-lived review proposals in session storage. It does not use Chrome Sync. Its only durable extension setting is whether the one-time hosted guest preview has been used.
- Accounts and profile sync. Signing in is optional until a guest allowance is exhausted and uses the Token Canopy account flow described above. AgentTag records account entitlement and fill-allowance events. Reusable answers are not saved until you review and approve them in the desktop app. If you enable Context Profile sync, selected sources and approved profile data are stored in AgentDrive and are covered by AgentDrive's privacy disclosure.
- Hosted Runtime.Hosted fills are not enabled in the current public release. If we enable them later, AgentTag will show an in-product disclosure and ask for your affirmative approval before sending the selected context and eligible form description to Token Canopy's hosted AI provider. Hosted context is encrypted in transit and at rest and deleted when the fill finishes or expires.
- Credentials and code. Account tokens remain in the macOS Keychain and never enter Chrome storage. The extension executes only JavaScript and other assets included in its published package; it does not download or execute remote JavaScript or WebAssembly.
AgentTag's use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide or improve the user-facing form-fill feature. We do not sell it, use it for advertising or creditworthiness, or allow humans to read it except with your specific consent for support, for security or legal obligations, or after aggregation and anonymization for internal operations.
Your content stays in the products
Token Canopy is the account and workspace layer over our products; it does not hold product content. Emails and mailbox data live in e2a; stored files and artifacts live in AgentDrive. Each product keeps its own API and credentials, and its own data-handling rules:
- AgentDrive publishes its own privacy disclosure at agentdrive.run/privacy.
- e2a has not yet published a standalone privacy page; until it does, questions about e2a data handling are covered by the contact below and answered the same way.
What gets sent to third parties
- WorkOS (sign-in).All sign-in goes through WorkOS, which sees your email address and the identity-provider response. WorkOS's privacy policy applies to that exchange.
- Google (only if you sign in with Google).The standard OAuth round-trip carries your Google profile response. Google's privacy policy applies to your Google account.
- Google Cloud (hosting). The account service and its database run on Google Cloud infrastructure in the United States.
- Your configured AI provider (AgentTag Local Runtime). When you start a local fill, your selected context, safe form description, and current page URL are processed through the Claude Code account and provider you configured. Mnexa does not receive that fill content.
- AgentDrive (optional AgentTag profile sync). If you enable profile sync, AgentDrive stores the selected sources and approved reusable profile data needed to provide it.
- Google Gemini (future AgentTag Hosted Runtime). Hosted fills are currently disabled. If enabled, Gemini will process the selected context and eligible form description only after the in-product disclosure and your approval.
- Cloudflare (DNS and CDN). Traffic to our domains passes through Cloudflare, which sees standard connection metadata.
- No analytics, no tracking pixels, no third-party JS. No Token Canopy page runs Google Analytics, Segment, Mixpanel, or any session-replay tool, and the AgentTag extension loads no remote code.
Logs & retention
- Application and request logs (method, path, status, latency, source IP) are retained for 30 days by default.
- We keep an audit log of account-level actions (sign-ins, workspace changes, account linking) for as long as your account exists — it's how we can answer “what happened to my account?”
- Database backups are kept for up to 7 days for disaster recovery. Deleted data is removed from the live database immediately but may persist in a backup snapshot until it ages out.
- AgentTag's Chrome tab bindings, selected-source metadata, progress, and review state are session-scoped. The desktop app keeps chosen context and approved profiles in its private local store; account credentials stay in macOS Keychain. Synced AgentTag data follows AgentDrive's retention and deletion rules.
- Token Canopy account and allowance records may include account identity, entitlement, success or failure status, and bounded operational metadata. They do not include Local Runtime source files, form-field values, or agent answers. If you sync approved answers, those contents are stored in AgentDrive as described above.
Deleting your account
Email us (below) to request deletion of your Token Canopy account. We will verify the request, remove account records that are not subject to a legal, security, fraud-prevention, billing, or dispute-retention obligation, and explain any records we must retain. Deleting the Token Canopy account does not by itself delete product data — your e2a mailbox or AgentDrive drive, including any synced AgentTag profiles — because those accounts can outlive the overlay. We will coordinate the applicable product-specific deletion steps with you. Removing the AgentTag extension clears its Chrome-managed local and session storage, but does not delete context held by the separate desktop app or data you chose to sync to AgentDrive.
EU & UK users — your rights under the GDPR
Mnexa, Inc. is the data controller for your Token Canopy account data. If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR / UK GDPR gives you the rights below. We honour them for all users regardless of location.
Legal bases for processing
- Contract. Authenticating you and maintaining your workspace and product links, and processing a user-started AgentTag fill, is necessary to provide the service you asked for.
- Legitimate interests. Security logging, abuse prevention, and operating the service — balanced against your rights.
Your rights
You may exercise the rights of access, rectification, erasure, restriction, portability, and objection, and you may lodge a complaint with your local supervisory authority. To exercise any right, email us at the address below. We respond within 30 days. We do not sell personal data and do not use it for advertising or for automated decision-making with legal effects.
International data transfers
Our infrastructure and sub-processors are in the United States, so your data is transferred to and stored in the US. Where that involves EEA/UK personal data, the transfer relies on the EU-U.S. / UK Data Privacy Framework certifications of our sub-processors and/or the European Commission's Standard Contractual Clauses.
Sub-processors
- Google Cloud (US) — application hosting and database.
- Google Gemini (US) — optional AgentTag Hosted Runtime processing, only if Hosted Runtime is enabled and you approve the in-product disclosure.
- WorkOS (US) — authentication.
- Cloudflare (US) — DNS, CDN, and static site hosting.
Business customers who need a signed Data Processing Agreement can request one at the contact below.
Contact
Questions, data-export requests, deletion requests, or anything else privacy-related: [email protected].