Tese.io Capture Chrome extension
Last updated: 5 September 2026
This section applies to the Tese.io Capture Chrome extension (Chrome Web Store item ID ohojhcgcilceoeaenbncoknjpmklokh), operated by Tese Capital Limited (“Tese.io”, “we”, “us”). It explains how the extension collects, handles, stores, and shares user data, as required by the Chrome Web Store User Data Policy. Omission of any of those four sections is not allowed; each is covered below.
Tese.io Capture is a companion for people who already have a Tese.io account. It does not create accounts.
Collection
The extension collects only data needed to sign you in, capture values you review, and (if you use it) talk to Anaya, Tese.io’s in-panel assistant. Nothing is collected in the background while the side panel is closed.
Account and authentication data
- Email address and password, entered by you on the sign-in screen and sent once to the Tese.io host you choose (api.tese.io in production, stage-api.tese.io in staging).
- After a successful sign-in: a session token (JWT), your email, and your organisation (tenant) name and ID.
Website content and form data (only after you grant the site access and take an action)
- The active tab’s URL, used to match saved capture templates and to record provenance on a submitted activity.
- Visible page text and current values of visible text-like form fields, when you turn Anaya page sharing on, ask Anaya to read the page, or extract fields for Capture Review. Explicit “read this page” requests send up to 8,000 characters; ordinary chat context sends up to 1,200 characters.
- Values you review and approve on the Capture Review screen, plus which template (if any) was used, when you save a draft or submit a capture.
- Capture templates you create (URL patterns, field selectors, parse settings, facility and date defaults).
Password fields, hidden fields, email fields, phone fields, and fields marked by the page as payment-card fields are excluded from page-text extraction. A page can still put sensitive data in an ordinary text field; do not share a page you would not want summarized.
Voice data (only if you click the microphone)
- Up to 15 seconds of microphone audio, sent to Tese.io for transcription.
Local preference and cache data
- Anaya page-sharing preference.
- Recent Anaya chat messages (up to 50 per organisation), which may include page excerpts you shared and Anaya’s replies.
- A short-term cache of capture templates, assigned activities, and organisation policy.
- Captures that failed to submit, queued locally for retry.
Dashboard presence (tese.io origins only)
- Pages on in.tese.io or stage.tese.io may ask the extension whether it is installed and whether someone is signed in. If you are signed in, the reply includes your email and tenant name. It never includes your session token. No other website can ask this.
The extension does not collect general browsing history, analytics, advertising identifiers, or telemetry. It does not read pages you have not granted it access to.
Handling
The extension handles collected data only to operate Tese.io Capture’s single purpose: helping a signed-in Tese.io user map page fields, review extracted values, submit those values into their own Tese.io tenant, and optionally ask Anaya about the current screen.
How each category is used
- Credentials — to authenticate you against the Tese.io host you selected. The password is used only for that sign-in request; the extension does not keep it.
- Session token, email, tenant — to authorize API calls, show which account is connected, and scope templates, chat, and policy to your organisation.
- Page URL, page text, and form values — to match templates, extract candidate field values, let you review them, attach provenance to a submitted activity, and (only if page sharing is on) give Anaya context for a reply you asked for.
- Approved capture payloads — to create or update an activity record in your Tese.io tenant (source: ai_extracted, tagged tese-capture).
- Templates and organisation policy — to badge matching pages, drive Capture Review and Mapping Studio, and enforce admin rules (allowed sites, Anaya on/off, voice on/off, page-text sharing, one-off captures, submit-for-approval).
- Voice audio — to produce a transcript you can send as a chat message. If the browser supports on-device speech recognition, interim text may appear locally; the final text is always the server transcription.
- Chat history — to show your recent Anaya conversation in the panel.
- Retry queue — to resubmit a capture that failed because the network or API was unavailable.
- Dashboard presence reply — so the Tese.io dashboard can show “extension installed / connected”.
When data leaves the device
Nothing is transmitted unless you take an action (sign in, submit/save a capture, send an Anaya message with sharing on, trigger “read this page”, or use the microphone). There is no background upload of page content.
Secure handling
All network traffic from the extension to Tese.io uses HTTPS. The session token is stored in the extension’s own chrome.storage.local and is read only by the background service worker. Content scripts injected into third-party pages never see it.
Limited Use
We use collected user data solely to provide and improve this extension’s disclosed user-facing features. We do not use it for advertising, retargeting, creditworthiness, or any purpose unrelated to Capture / Anaya. We do not allow humans to read user page content or chat except with your consent for support, for security investigations, to comply with law, or in aggregated anonymized form for internal operations.
Storage
On your device
The following stay in chrome.storage.local on the browser profile that installed the extension. They are not synced to Google, not readable by websites, and not written to chrome.storage.sync.
- Session token, email, tenant name/ID — until you sign out, the 24-hour JWT expires, or you uninstall the extension.
- Anaya chat history (up to 50 messages per organisation) — until you sign out, clear it, or uninstall.
- Template / assignment / policy cache — refreshed on sign-in and template sync; wiped on sign out.
- Failed-submit retry queue — until you retry successfully, discard the item, or sign out.
- Page-sharing preference — until you change it or sign out.
Signing out of Settings wipes all of the above from that browser profile.
On Tese.io servers
Data you send is stored in the same Tese.io environment and tenant you signed into:
- Activity records and templates — kept in your organisation’s Tese.io workspace for as long as the organisation retains that ESG / sustainability data, or until an authorised admin deletes them. Teammates and admins who can already see those activities in the dashboard can see captures submitted through the extension.
- Anaya chat turns — processed by Tese.io’s backend to produce a reply. Tese.io may retain prompts and replies on its servers for providing the feature, security, abuse prevention, and support, consistent with the organisation’s Tese.io account.
- Voice recordings — used to transcribe the clip and are not kept as audio after transcription.
Uninstalling the extension removes local storage only. It does not delete activity records, templates, or account data already saved in your Tese.io tenant. To delete those, use the Tese.io dashboard or email support@tese.io.
Infrastructure
Server-side storage uses Tese.io’s existing platform infrastructure (application servers and databases that already hold your organisation’s Tese.io data). Transmissions use TLS. Tese.io applies the same access controls and tenant isolation used for the rest of the platform.
Sharing
We do not sell user data. We do not share user data with third parties for advertising, analytics products, data brokers, or any purpose unrelated to the extension.
We share or disclose data only in these cases:
- Your Tese.io organisation. Submitted captures, drafts, and saved templates become data in your tenant. Authorised users of that tenant can see them in the Tese.io dashboard, the same way they see other activities.
- Tese.io operators. Tese Capital Limited staff may access account or support data when you ask for help, or as needed to operate, secure, and maintain the service.
- AI processors, only to produce the feature you invoked. Anaya chat messages, optional page excerpts, extraction requests, and voice clips are sent to Tese.io’s AI orchestration layer. That layer may call subprocessors that provide large-language-model and speech-to-text APIs (currently including OpenAI and, as a fallback in some environments, Anthropic) solely to generate a reply, extract field values, or transcribe audio. Those providers receive only the payload for that request and are not permitted to use it for advertising. They process it under their own terms as Tese.io’s processors.
- Tese.io dashboard origins. As described under Collection, in.tese.io and stage.tese.io may receive a yes/no install signal plus email and tenant name if you are signed in. No other origin receives this.
- Legal, safety, and corporate events. We may disclose data if required by law, to investigate abuse or security incidents, or as part of a merger, acquisition, or sale of assets of Tese Capital Limited.
The extension does not embed third-party SDKs, ads, or analytics. It only talks to Tese.io API hosts (api.tese.io, stage-api.tese.io, and localhost in development builds). The Chrome Web Store build does not include the localhost dashboard channel.
Permissions
- storage — session, chat, caches, retry queue, and preferences on your device.
- sidePanel — the extension UI.
- tabs — read the active tab URL so the toolbar badge can show a template match.
- scripting and activeTab, plus optional host access — read page content on a site the first time you use Capture or Anaya there. You can review or revoke a site’s access in Chrome’s extension settings.
User controls
- Turn Anaya page sharing off in the chat header at any time. With it off, Anaya only knows which screen you are on, not the page’s text.
- Your organisation admin can disable Anaya, page-text sharing, voice, one-off captures, or restrict Capture to an allow-list of sites (Settings → Integrations → Tese.io Capture).
- Sign out to wipe local extension data.
- Revoke site access or uninstall the extension in chrome://extensions.
- Request access, correction, or deletion of server-side account and activity data via your organisation admin or support@tese.io.
Children
Tese.io Capture is a workplace tool for existing Tese.io accounts. It is not directed at children under 16, and we do not knowingly collect data from them.
Contact
Tese Capital Limited. Questions about this section or your data: support@tese.io.