ShadowSaaS - Privacy Policy
Last updated: 2026-08-26
The short version
ShadowSaaS detects unauthorized SaaS usage across your organization. It connects to an enterprise backend but is fully anonymous: no employee IDs, no full URLs, no personal browsing data. Only canonical SaaS domains are captured.
What ShadowSaaS does
ShadowSaaS identifies SaaS applications being used within an organization without IT approval. It detects shadow IT by observing which canonical SaaS domains are accessed, helping security teams understand their actual SaaS footprint and enforce governance policies.
Data collection
ShadowSaaS is designed to be fully anonymous. It does not collect employee names, user IDs, email addresses, or any personally identifiable information.
What is captured: only canonical SaaS domains (e.g., “notion.so”, “figma.com”). Full URLs, paths, query parameters, and page content are never captured. The extension strips all URL components beyond the canonical domain before any data leaves the browser.
What is required: an organization token provided by your IT team. This token associates the extension with your organization, not with you as an individual.
Network activity
ShadowSaaS connects to an enterprise backend to report detected SaaS domains. Every request includes only:
- The organization token
- Canonical SaaS domain names (never full URLs)
- A timestamp
No employee identifiers, IP addresses, browser fingerprints, or personal data are included in any request.
Permissions
- webRequest (read-only): to observe navigation requests and extract canonical SaaS domains
- storage: to save the organization token and local configuration
- host permissions: to detect SaaS domain access across browsing activity
Where your data lives
The organization token and local configuration are stored in chrome.storage.local. Aggregated SaaS domain data is stored on your organization’s Excalion enterprise backend. No data is stored that could identify individual employees.
If you uninstall the extension, local data is deleted automatically by Chrome.
Third-party services
ShadowSaaS connects exclusively to the Excalion enterprise backend associated with your organization token. No data is shared with any other third party.
Cookies and tracking
ShadowSaaS does not use cookies and does not track individual users. By design, the extension cannot identify which employee accessed which SaaS application.
Supported browsers
ShadowSaaS works on Chrome, Edge, and Brave. This privacy policy applies equally to all supported browsers.
Changes to this policy
Any changes will be reflected in extension updates. The date at the top of this page will be updated accordingly.
Contact
For questions about this privacy policy: hello@excalion.io