Privacy Policy – aYOUne Companion
aYOUne Companion – Chrome extension by tolinax UG (haftungsbeschränkt) · Last updated: October 2, 2026
Summary: The aYOUne Companion extension does not collect, sell, or share personal data with third parties. All data is transmitted exclusively to the aYOUne platform servers (*.ayoune.app) under your existing platform account and is subject to the aYOUne Platform Privacy Policy.
1. Who We Are
The aYOUne Companion Chrome Extension is developed and published by:
tolinax UG (haftungsbeschränkt), Oberhof 4, 83700 Oberhof, Germany
Represented by: Maximilian Hanrieder
Email: privacy@tolinax.com
Website: https://ayoune.app
2. What Data We Process
2.1 Authentication Tokens
When you log in via login.ayoune.app, the extension captures a JWT (JSON Web Token) and a refresh token. The JWT is held in chrome.storage.session – in-memory only; it is never written to disk, never synced to your Google account, and is cleared when the browser closes. The refresh token is stored in chrome.storage.local (device-local, not synced). These tokens authenticate your requests to the aYOUne platform. They are never sent to any third-party server.
2.2 User Preferences
Your toolbar settings (position mode, enabled KPI chips, wallboard selection, disabled sites) are stored locally in chrome.storage.sync and synced across your Chrome instances via your Google account. No preference data is sent to aYOUne servers.
2.3 AI Copilot & Communication Side Panel
The side panel embeds the aYOUne communication workspace directly from your platform account (an iframe of pwa.ayoune.app/embed/comm-sidebar). Conversations and any AI Copilot interactions take place inside that embedded platform page under your existing aYOUne session and are governed by the aYOUne Platform Privacy Policy. The extension itself does not store conversation history. Separately, the "AI Copilot fragen" and "Translate" context-menu actions send the text you explicitly select to ai.ayoune.app to return an answer or translation.
2.4 Page Content (Context Menu Actions)
When you explicitly trigger a context menu action (e.g., "Save page as journal entry", "Ask AI Copilot"), the extension reads the current page's URL, title, and/or selected text. This data is sent to the relevant aYOUne API endpoint to perform the requested action. Page content is never read or transmitted without an explicit user action – the only exceptions are the two lookups described in 2.9, which send a single search term or name to your own aYOUne account and can be switched off.
2.5 Product and Order Data (Marketplace Imports)
When you click "Import Product" on Amazon or AliExpress, or "Import Orders", the extension scrapes product/order data visible on the page and transmits it to your aYOUne platform account. This data is stored in your aYOUne tenant database and is subject to your organization's data retention policies.
2.6 Phone Number Detection
The phone number detection feature scans visible text on web pages for phone number patterns. All processing is done locally in your browser. No page content or detected phone numbers are transmitted to any server. The feature only creates local click-to-call links.
2.7 Notifications (WebSocket Push + Polling)
The extension maintains an authenticated WebSocket connection to notifier.ayoune.app to receive new CRM/platform notifications in real time, and polls crm-api.ayoune.app/notifications every 60 seconds as a fallback. Only your own notification metadata (title, timestamp, link, level) is received and used to display desktop alerts and the in-page notification bell. No page content is sent over the WebSocket channel.
2.8 Lead Import from Connected Sites (Explicit Consent Required)
A small set of allow-listed sites (LinkedIn, Amazon, AliExpress) may send the extension a proposed CRM lead. The extension never creates a lead in your aYOUne CRM from such a request silently. Instead it shows you an in-page confirmation dialog displaying the proposed lead fields; the lead is sent to crm-api.ayoune.app/leads and stored in your tenant only after you explicitly click "Lead anlegen" (Create lead). If you cancel, dismiss the dialog, or no eligible tab is visible, nothing is written. The connecting site never receives your authentication token or the result of the write.
2.9 Automatic Lookups on Google and LinkedIn (can be switched off)
On a Google search results page the extension sends the search term from the address bar to monitoring-api.ayoune.app to show whether your organization tracks this keyword and at which position. On a LinkedIn profile page it sends the name, headline and current company shown on the profile to crm-api.ayoune.app to show whether this person already exists in your CRM. Both lookups go exclusively to your own aYOUne account, the lookup itself stores nothing, and each can be switched off in the extension settings under “Features”.
2.10 Feedback with Screenshot and Dictation
When you start a feedback from the side panel, the extension takes a screenshot of the visible tab and lets you annotate it locally. Only if you allow microphone access, your dictation is transcribed live via ai.ayoune.app; the audio is streamed for transcription only and is not stored by the extension. The annotated image, the text and the page address are sent to your aYOUne account only when you click “Submit” (“Absenden”).
2.11 Browser Control by the AI Copilot (off by default)
The extension can let the aYOUne AI Copilot operate a browser tab on your request (open a page, read it, click, type). This feature is switched off by default and only becomes available after you enable “Allow the Copilot to control this browser” in the extension settings. Even then:
- every new control session must be approved by you in a confirmation window (no answer within 60 seconds counts as a refusal);
- the Copilot only works in its own, separately opened and visibly marked tab with a “Stop” button – never in your other tabs;
- the
debuggerpermission is attached to that tab only for the duration of a single click or keystroke; Chrome shows its own notice while it is attached; - submitting a form, ordering or paying is refused unless it has been explicitly approved for that website;
- the content of that tab (page text, screenshots of that tab) is transmitted exclusively to your aYOUne account to answer your request. The extension executes only its own fixed set of commands – no code is downloaded or executed.
An idle session ends automatically after two minutes; switching the setting off ends a running session immediately.
3. Data We Do NOT Collect
- Browsing history or visited URLs (except when you explicitly trigger an action)
- Keystrokes or form data (except what the Copilot types into its own tab during a session you approved, see 2.11)
- Personal data from third-party websites (LinkedIn, Amazon, AliExpress data is only scraped when you click an import button, and proposed CRM leads from connected sites are only saved after you confirm an in-page dialog — see 2.8)
- Analytics, telemetry, or usage tracking data
- Advertising identifiers or fingerprinting data
4. Where Data Is Sent
| Data Type | Destination | Purpose |
|---|---|---|
| API requests | *.ayoune.app | All business data operations (CRM, tasks, products, AI, etc.) |
| Authentication | login.ayoune.app, auth.ayoune.app | Login, token refresh, customer switching |
| Real-time notifications | notifier.ayoune.app (WebSocket) | Live push of your own notification events |
| File uploads | uploads.ayoune.app | Screenshots, product images |
No data is ever sent to third-party services, advertising networks, or analytics providers. All data transmission is exclusively between the extension and the aYOUne platform infrastructure operated by tolinax UG.
5. Data Storage
| Storage | Contents | Scope |
|---|---|---|
chrome.storage.session | JWT (access token) | In-memory only – never written to disk, cleared on browser close |
chrome.storage.sync | Toolbar settings, feature flags, disabled sites | Synced across Chrome instances via Google account |
chrome.storage.local | Refresh token, wallboard cache, KPI cache, customer list, notification state/stack | Local to device, not synced |
All cached data has short TTLs (10 seconds to 5 minutes) and is automatically refreshed. Logging out clears all authentication tokens and cached data.
6. Permissions Explained
| Permission | Why It's Needed |
|---|---|
activeTab | Access the current tab's URL/title when you trigger an action (bookmark, journal entry, AI context) |
scripting | Inject UI elements: toast notifications, screenshot picker, product import buttons (all using Shadow DOM isolation) |
storage | Persist your login tokens, preferences, and local caches |
tabs | Capture JWT from login redirect URL; detect page type for context-aware actions |
contextMenus | Create the right-click action menu |
notifications | Show desktop alerts for new CRM notifications |
alarms | Schedule the 60-second notification polling interval |
sidePanel | Host the embedded aYOUne communication side panel (AI Copilot, phone, video, chat, notifications) |
debugger | Browser control by the AI Copilot (2.11): off by default, every session needs your approval, only the Copilot's own marked tab, attached only for a single click or keystroke |
identity | Secure sign-in via chrome.identity.launchWebAuthFlow (PKCE) to your aYOUne account; receives only your aYOUne session token, never your Google identity/profile |
host_permissions: <all_urls> | The toolbar and phone detection features run on all pages. Toast notifications and picker modals can be triggered on any page via context menu. |
7. Content Scripts
The extension injects scripts into web pages for the following purposes:
- Action bar (all pages, off by default – appears only after you select a wallboard): Displays live figures of your organization. Uses closed Shadow DOM and does not read page content. Can be disabled per site.
- aYOUne website detection (all pages): Reads only the
<meta name="ayoune:*">tags of pages delivered by aYOUne to offer “Edit page”. Processed locally, nothing is sent. - Phone detection (all pages): Scans for phone numbers locally. No data leaves your browser. Auto-disconnects after 5 minutes.
- Google search (Google search pages): Shows your keyword ranking data above the results (lookup of the search term, see 2.9).
- LinkedIn (profile pages): Enables lead import and shows whether the person is in your CRM (lookup of the name, see 2.9).
- Amazon / AliExpress (product and order pages): Enables product and order imports when you click the import button.
8. Third-Party Services
The extension does not integrate with any third-party analytics, advertising, or tracking services. All data is sent exclusively to the aYOUne platform infrastructure (*.ayoune.app) operated by tolinax UG. The extension makes no direct connection to any third-party service.
9. Data Retention
- Local storage: Cleared on logout. Cached data expires automatically (10s–5min TTLs).
- Server-side data: Data created through the extension (leads, tasks, journal entries, products, orders) is stored in your aYOUne tenant and subject to the aYOUne Platform Privacy Policy and your organization's data retention settings.
10. Your Rights (GDPR)
As an EU-based company, we comply with the General Data Protection Regulation (GDPR). You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Data portability — receive your data in a structured format
- Object to processing of your data
To exercise these rights, contact privacy@tolinax.com.
11. Children's Privacy
The aYOUne Companion extension is a business tool and is not intended for use by children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected in the "Last updated" date above. For significant changes, we will notify users through the extension or via email.
13. Contact
For privacy-related questions or concerns:
tolinax UG (haftungsbeschränkt)
Email: privacy@tolinax.com
Website: https://ayoune.app
© 2026 tolinax UG (haftungsbeschränkt). All rights reserved.