Cana, a product of Colate Ltd (“Cana”, “we”, “us”), provides an agentic workspace for teams — chat, walkie-talkie channels, AI-assisted runs, and file sharing. This policy explains what we collect, why, and your choices.
Information we collect
- Account information — your email address and profile details, to create and secure your account.
- Content you create — messages, walkie-talkie posts, files and images you upload or share into Cana, AI prompts, and related metadata. This is the content needed to provide the service.
- Identifiers — a user ID and, on mobile, a device token used solely to deliver push notifications you’ve enabled.
How we use your information
We use your information only to operate and provide Cana: to authenticate you, deliver and store your messages and files, run AI features you invoke, send push notifications you’ve enabled, and keep the service secure and reliable. We do not use your data for advertising.
What we do NOT do
- We do not use third-party analytics, advertising, or tracking SDKs.
- We do not track you across other companies’ apps or websites.
- We do not sell your personal information.
Sharing
We share data only with infrastructure providers that host and run the service on our behalf (e.g., cloud hosting, AI model providers used to fulfill your requests), under agreements that limit their use to providing those services. We may disclose information if required by law.
Data retention & deletion
We retain your account and content while your account is active. You can request deletion of your account and associated content by contacting us (see below); we delete it within a reasonable period, except where retention is required by law.
Security
We protect your data with encryption in transit, access controls, and standard operational safeguards.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data. Contact us to exercise them.
Cana Companion (Chrome extension)
Cana Companion is a Chrome extension that connects tabs you authorize to Cana Desktop running on your own computer. It is covered by this policy; the specifics below describe what the extension itself handles.
What the extension handles
Only for Chrome tabs you explicitly connect to Cana, and tabs Cana creates for you:
- Page URLs, titles, text, DOM structure, element attributes, computed styles, selectors, XPath, and element bounds.
- Screenshots requested by you or your Cana agent.
- Page console output.
- Network request metadata such as URL, method, status, timing, errors, resource type, and limited WebSocket frame previews.
- Browser actions and form text entered through Cana.
- Messages and files you choose to send from the extension side panel, and Stop/interrupt commands.
- A random pairing credential used to authenticate the locally installed extension to Cana Desktop.
How the extension uses it
Only to connect tabs you authorized to Cana Desktop, carry out browser actions you request, return browser context to your active Cana session, and show connection status in the extension’s own interface.
Where that data goes
The extension talks to Cana Desktop on the same computer over a loopback-only WebSocket (127.0.0.1, ports 47615–47634). It contains no extension analytics, no advertising SDKs, and no separate remote backend. Cana Desktop may send context to AI or model providers you have configured; that processing is controlled by Cana Desktop and covered by the rest of this policy.
Storage and retention
- The pairing credential and the identifiers of tabs you authorized are stored in
chrome.storage.localand are never synced through Chrome. - Network, console, and activity buffers are kept in memory and are lost when the extension worker or browser session ends.
- The desktop-side pairing credential is stored in Cana’s private app-data directory with owner-only access.
Your control
- Pairing never starts on its own: the extension asks to pair only after you click Pair with Cana Desktop in the popup, and the request must then be approved in Cana Desktop.
- Existing tabs are not connected until you click Use this tab. That grant covers the tab until you release or close it, including pages it later navigates to. Managed tabs are collected into a purple “Cana” tab group so the extent of the grant is visible at a glance.
- You can close managed tabs, stop browser work, unpair the extension in Cana Desktop, remove the extension, or clear its storage. Unpairing invalidates the credential and requires a new explicit desktop approval.
Extension security
After pairing, the credential is never transmitted again: each side proves possession of it with an HMAC challenge/response, so a process that answers on a loopback port can neither obtain the credential nor issue commands. The desktop accepts connections only from a valid Chrome extension origin and binds the credential to that extension ID. Commands are allowlisted, URLs are limited to HTTP and HTTPS, automation code is injected only into tabs you authorized, and no remotely hosted code is executed.
The extension does not sell your data, use it for personalized advertising, or share it with data brokers.
Children
Cana is not directed to children under 13 (or the relevant age in your jurisdiction) and we do not knowingly collect their data.
Changes
We’ll post any changes here and update the “Last updated” date.
Contact
Questions or requests? Email us at connect@colate.io — see also our Support page.