Academy CanLup · Legal information
Academy Extension Privacy Policy
Data, permissions and limits of the “Academy — desktop companion” extension for Google Chrome.
Purpose and scope
The “Academy — desktop companion” Chrome extension, listed as “Academy — питомец на рабочем столе”, connects Academy at academy.canlup.com to a separately installed companion system component on your computer. This is its single purpose. The extension is distributed free of charge; access to Academy functions is governed separately.
This policy covers the distributed extension package version 0.9.36 and its described messaging. It supplements Academy’s general policy. Extension data is subject to the narrower limits here; website and desktop application capabilities are not attributed to the extension.
Data passing through the extension
Sources are the open Academy page, Chrome’s technical sender information and the system component’s responses. The extension processes personal and authentication information; a claim that it processes no personal data would be inaccurate.
- Account and device identifiers, and the selected workspace or its identifier when needed for a companion setting.
- A one-time pairing code, a signed verification challenge and access attestation, used to connect the system component to an authorised account.
- Companion preferences: enabled state, launch at sign-in and selected workspace; connection state and responses to these commands.
- System component status: platform, architecture, application version and channel, supported capabilities, update state, and Vault synchronisation status and counts of restored items, conflicts or errors. Vault content is not included in this exchange.
- Temporary window, tab, document and request identifiers and the Academy page address, used to validate the permitted source and associate the companion with its window. This is not collection of browsing history from other sites.
Permissions and technical limits
Access to https://academy.canlup.com/* enables messaging between Academy and the extension. The nativeMessaging permission enables Chrome Native Messaging with the local component. The handler accepts only the defined discovery, access verification, status and companion configuration commands and validates the request source.
The extension does not request Chrome history or cookies API access and does not read other websites’ content, files, conversations, the screen or microphone. It does not collect passwords, biometric templates or advertising data. Incognito operation is disabled.
File reading, screen capture, dictation and AI conversations belong to separately authorised Academy and desktop application features. Their content does not pass through this extension’s four commands. Extension executable code is included in the package; remotely hosted executable code is not loaded.
Purpose, sharing and Limited Use
Data is used only to connect the companion, check access, configure it and report status, and for necessary security and reliability of those functions. Local messages go to the system component on the same computer; the component and page contact Academy over HTTPS to verify access. The extension itself does not send separate analytics to third-party servers.
The use and transfer of information received by the extension comply with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is not used for personalised advertising, advertising profiles, creditworthiness assessment or other unrelated purposes.
Transfers are limited to those permitted by Chrome Web Store rules when necessary for the stated function, legal compliance or security. Human reading is permitted only with your express permission for specific information, for security, to comply with law, or for internal operations using aggregated, anonymised data. General acceptance of a policy is not that permission.
Storage and protection
The extension holds pending requests and open-window information in memory and releases them when requests finish, the relevant window closes or the connection ends. It does not maintain persistent storage of user messages or browsing history.
Preferences, device pairing and necessary security records may be stored separately by the system component and Academy. Signed challenges and attestations have limited validity. Installing the extension alone does not grant access to an account or someone else’s workspace.
Server retention and processing by external providers are described in the general policy. The extension does not make all Academy processing exclusively local to the user’s computer.
Disabling, deletion and contact
Disable or remove the extension in Chrome to stop messaging through it. Companion settings and connected-device permissions are available in Academy. Removing the extension does not delete your account, server records, local Vault or the separately installed desktop application.
For access, correction, deletion or withdrawal of an earlier consent, email batsaaleksey@gmail.com. Sign-in is not required. Do not send pairing secrets or passwords.
Personal data operator: Баца Алла Антоновна. Russian taxpayer identification number: 890603453994. A self-employed professional income tax payer, without individual entrepreneur status, in the Russian Federation. Personal data enquiries: batsaaleksey@gmail.com.
Changes to this document
The version and date appear at the top of this page. Changes to the extension’s data, permissions or purpose require updates to this policy and Chrome Web Store disclosures and any necessary consent before new processing. A new edition does not retrospectively change earlier consent. The language switch displays the same rules in translation.