Excalion

ShadowSaaS - Privacy Policy

Last updated: 2026-08-26

The short version

ShadowSaaS detects unauthorized SaaS usage across your organization. It connects to an enterprise backend but is fully anonymous: no employee IDs, no full URLs, no personal browsing data. Only canonical SaaS domains are captured.

What ShadowSaaS does

ShadowSaaS identifies SaaS applications being used within an organization without IT approval. It detects shadow IT by observing which canonical SaaS domains are accessed, helping security teams understand their actual SaaS footprint and enforce governance policies.

Data collection

ShadowSaaS is designed to be fully anonymous. It does not collect employee names, user IDs, email addresses, or any personally identifiable information.

What is captured: only canonical SaaS domains (e.g., “notion.so”, “figma.com”). Full URLs, paths, query parameters, and page content are never captured. The extension strips all URL components beyond the canonical domain before any data leaves the browser.

What is required: an organization token provided by your IT team. This token associates the extension with your organization, not with you as an individual.

Network activity

ShadowSaaS connects to an enterprise backend to report detected SaaS domains. Every request includes only:

  • The organization token
  • Canonical SaaS domain names (never full URLs)
  • A timestamp

No employee identifiers, IP addresses, browser fingerprints, or personal data are included in any request.

Permissions

  • webRequest (read-only): to observe navigation requests and extract canonical SaaS domains
  • storage: to save the organization token and local configuration
  • host permissions: to detect SaaS domain access across browsing activity

Where your data lives

The organization token and local configuration are stored in chrome.storage.local. Aggregated SaaS domain data is stored on your organization’s Excalion enterprise backend. No data is stored that could identify individual employees.

If you uninstall the extension, local data is deleted automatically by Chrome.

Third-party services

ShadowSaaS connects exclusively to the Excalion enterprise backend associated with your organization token. No data is shared with any other third party.

Cookies and tracking

ShadowSaaS does not use cookies and does not track individual users. By design, the extension cannot identify which employee accessed which SaaS application.

Supported browsers

ShadowSaaS works on Chrome, Edge, and Brave. This privacy policy applies equally to all supported browsers.

Changes to this policy

Any changes will be reflected in extension updates. The date at the top of this page will be updated accordingly.

Contact

For questions about this privacy policy: hello@excalion.io