Privacy & data handling
What we collect, where it goes, how long it stays. This page covers the Token Canopy website (tokencanopy.com) and the Token Canopy account and workspace service (app.tokencanopy.com, auth.tokencanopy.com), operated by Mnexa, Inc. Last updated 2026-07-24.
The short version
- This website is static. It sets no cookies, runs no analytics or tracking scripts, and makes no third-party requests from your browser.
- If you sign in, we store the account profile our sign-in provider gives us (email, name, avatar) plus the workspace records needed to run the service — nothing else.
- Your content lives in our products, not here. Emails your agents send and receive stay in e2a; files your agents store stay in AgentDrive. Each product documents its own data handling — AgentDrive's is at agentdrive.run/privacy.
- We do not sell personal data and we do not run ads.
The website
tokencanopy.com is a fully static site served from a CDN. It uses self-hosted fonts, sets no cookies, and loads nothing from third parties at runtime. Our CDN and hosting providers keep standard access logs (request path, timestamp, IP address, user agent) for operating and securing the site.
Signing in — your Token Canopy account
Sign-in is handled by WorkOS AuthKit on our behalf. You can sign in with Google or with an email code (Magic Auth). We never see or store a password for you.
- What we receive and store:your email address and whether it is verified, your name, your avatar image URL, and the account identifiers issued by WorkOS. If you sign in with Google, we also receive Google's stable account identifier (the OIDC
subject), which we use for exactly one thing: linking you to a product account you already own — a matching email alone is never enough to link accounts. - What Google shares with us: your basic profile (name, email address, profile picture) via the standard OpenID Connect scopes. We request no other Google scopes and no access to any Google service data.
- What we create around it: a workspace record, your membership in it, and a mapping to your product account(s) in e2a or AgentDrive. The mapping stores only opaque account identifiers — no product content or product credentials ever live in the Token Canopy database.
- Session cookie: signing in sets one cookie,
tc_session, a signed,HttpOnlysession cookie on app.tokencanopy.com. We use no advertising or analytics cookies. - Single sign-on to products: auth.tokencanopy.com acts as an OpenID Connect provider for our own products. When you use Token Canopy to sign in to a product, we pass that product your identity claims (account id, email, name) — nothing more.
Google user data
If you sign in with Google, this is the complete picture of how we handle the data Google shares with us — stated in the terms Google's policies ask us to disclose:
- Access. We request only the non-sensitive OpenID Connect scopes (
openid,email,profile): your name, email address, profile picture, and Google's stable account identifier. We request no access to Gmail, Drive, Calendar, or any other Google service data. - Use. Signing you in and linking you to product accounts you already own. Nothing else — no advertising, no profiling, no automated decision-making.
- Storage. Stored in our database on Google Cloud infrastructure in the United States, for as long as your Token Canopy account exists.
- Sharing. Never sold, and never shared beyond the sub-processors listed below and the identity claims passed to our own products when you sign in to them.
- Deletion. Deleting your Token Canopy account (below) removes the Google profile data we hold.
- Revocation.You can revoke Token Canopy's access to your Google account at any time from myaccount.google.com/permissions. Revoking access stops future sign-ins with Google; it does not by itself delete the data we already hold — email us for that.
Token Canopy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your content stays in the products
Token Canopy is the account and workspace layer over our products; it does not hold product content. Emails and mailbox data live in e2a; stored files and artifacts live in AgentDrive. Each product keeps its own API and credentials, and its own data-handling rules:
- AgentDrive publishes its own privacy disclosure at agentdrive.run/privacy.
- e2a has not yet published a standalone privacy page; until it does, questions about e2a data handling are covered by the contact below and answered the same way.
What gets sent to third parties
- WorkOS (sign-in).All sign-in goes through WorkOS, which sees your email address and the identity-provider response. WorkOS's privacy policy applies to that exchange.
- Google (only if you sign in with Google).The standard OAuth round-trip carries your Google profile response. Google's privacy policy applies to your Google account.
- Google Cloud (hosting). The account service and its database run on Google Cloud infrastructure in the United States.
- Cloudflare (DNS and CDN). Traffic to our domains passes through Cloudflare, which sees standard connection metadata.
- No analytics, no tracking pixels, no third-party JS. No Token Canopy page runs Google Analytics, Segment, Mixpanel, or any session-replay tool.
Logs & retention
- Application and request logs (method, path, status, latency, source IP) are retained for 30 days by default.
- We keep an audit log of account-level actions (sign-ins, workspace changes, account linking) for as long as your account exists — it's how we can answer “what happened to my account?”
- Database backups are kept for up to 7 days for disaster recovery. Deleted data is removed from the live database immediately but may persist in a backup snapshot until it ages out.
Deleting your account
Email us (below) to delete your Token Canopy account. We delete your principal, workspace, membership, and product-mapping records. Deleting the Token Canopy account does not by itself delete your product data — your e2a mailbox or AgentDrive drive — because those accounts can outlive the overlay; each product's own deletion flow removes product content, and we will walk you through both in one request if that's what you want.
EU & UK users — your rights under the GDPR
Mnexa, Inc. is the data controller for your Token Canopy account data. If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR / UK GDPR gives you the rights below. We honour them for all users regardless of location.
Legal bases for processing
- Contract. Authenticating you and maintaining your workspace and product links is processing necessary to provide the service you asked for.
- Legitimate interests. Security logging, abuse prevention, and operating the service — balanced against your rights.
Your rights
You may exercise the rights of access, rectification, erasure, restriction, portability, and objection, and you may lodge a complaint with your local supervisory authority. To exercise any right, email us at the address below. We respond within 30 days. We do not sell personal data and do not use it for advertising or for automated decision-making with legal effects.
International data transfers
Our infrastructure and sub-processors are in the United States, so your data is transferred to and stored in the US. Where that involves EEA/UK personal data, the transfer relies on the EU-U.S. / UK Data Privacy Framework certifications of our sub-processors and/or the European Commission's Standard Contractual Clauses.
Sub-processors
- Google Cloud (US) — application hosting and database.
- WorkOS (US) — authentication.
- Cloudflare (US) — DNS, CDN, and static site hosting.
Business customers who need a signed Data Processing Agreement can request one at the contact below.
Contact
Questions, data-export requests, deletion requests, or anything else privacy-related: [email protected].