The essentials: you approve each NetSuite account. Carmen uses your current role. We use data to deliver and protect Carmen, not for advertising, data sales or lending decisions.
Information we handle
- Account settings: approved NetSuite website addresses and administrator-managed account rules. The extension stores approved addresses locally in your browser.
- Chat and business data: questions, responses, permitted conversation context, account/user/role identifiers and NetSuite records needed for your request. Depending on the question and your permissions, this may include customer or vendor details, invoices, bills and financial balances.
- Page context: where enabled and requested, the type and internal ID of a saved invoice or vendor bill from its URL. The extension does not scrape page fields; NetSuite verifies the record and related customer or vendor under your current role.
- Service records: license and usage information, request references, timestamps, errors, security events and consented diagnostics needed to operate, troubleshoot and protect Carmen. Hosting services may process IP addresses and request metadata.
The extension uses your existing NetSuite session without reading or storing your password or authentication cookies. It does not collect browsing history outside approved NetSuite accounts, run advertising trackers or store conversations in extension storage.
Processing and providers
We use this information to authenticate and authorize requests, answer questions, maintain permitted conversation context, enforce license and usage limits, and support service reliability and security. Installing the extension does not grant additional NetSuite permissions.
The chat runs in your organization's NetSuite environment and connects to Carmen's hosted service. Relevant questions, context and permitted results may be processed outside your browser and NetSuite account.
Service providers include Oracle/NetSuite for the native application and, when selected, its AI service; Google Cloud for Carmen hosting and operational storage; and Cloudflare for this website's delivery and security. If your organization selects an external AI provider, relevant request content is also sent to OpenAI, Anthropic, Google Gemini, Mistral AI, Cohere, Microsoft Azure OpenAI or Amazon Bedrock using its configured API account. We do not send each request to every provider.
Your administrator can identify the selected provider. That provider's applicable service terms, account settings and retention rules also govern its processing. This policy does not promise zero provider retention or override those terms. Avoid including passwords, API keys or unnecessary sensitive information in questions.
Limited use and sharing
Pocket Detective's use of user data complies with the Chrome Web Store User Data Policy's Limited Use requirements. We limit use to providing and improving its disclosed assistant functionality and related operational needs.
We do not sell user data, share it with data brokers, use it for personalized advertising, or use it to determine creditworthiness or for lending. We do not use extension user data to train our own general-purpose AI models.
Transfers are limited to service providers necessary for this purpose, legal obligations, protection against fraud or abuse, or a business transfer with explicit prior user consent. Human access is limited to specific user-authorized support, security or legal needs, or aggregated and anonymized data for internal operations.
Storage and retention
Approved account addresses remain in local extension storage until you disconnect them or remove the extension; managed settings are controlled by your administrator. The extension does not maintain a separate local chat archive.
Chat and request history may be saved as records in your organization's NetSuite account. Carmen's hosted service retains configuration, licensing, usage, security and operational records for the periods needed for their purpose and the applicable customer settings or agreement. Provider records follow the selected provider's terms. Backup, security, dispute or legal requirements may delay final deletion.
Optional employee-name synchronization is a separate administrator-approved Carmen licensing function, described in the main privacy notice. The extension does not scrape employee names. That encrypted hosted display expires after seven days and follows the existing backup lifecycle; synchronized directory names are not added to AI prompts or metering events.
Disconnecting or uninstalling stops future extension access; it does not delete existing NetSuite records or server-side history. Contact your administrator or us to request the applicable retention details or deletion.
Your choices and browser permissions
You approve access to each NetSuite account separately. The storage permission saves account choices and reads administrator policy; scripting displays the bundled assistant on approved, browser-authorized accounts. Optional website access allows it to load that account's native Carmen configuration and chat.
Disconnect an account in extension settings, revoke its website permission, or uninstall the extension. Your administrator can also hide the bot through General Preferences → Custom Preferences → Show Carmen assistant and control Carmen access, cloud processing, history and diagnostics. Where available, the chat's page-context and conversation-context controls govern their use.
Security and processing location
We use HTTPS, access controls and current-role checks to protect service interactions. No system can guarantee absolute security. Carmen's current cloud infrastructure is in the United States; NetSuite and selected providers may process data in other locations according to their services and your organization's arrangements. Distribution availability does not determine data residency.
This policy page contains no advertising or analytics scripts. Cloudflare may process connection and security information to deliver it.
Privacy rights, contact and changes
Contact Sivoham LLC / AskCarmen at privacy@askcarmen.ai for privacy questions, retention details or requests to access, correct or delete information. For organization-controlled records, contact your NetSuite administrator as well. We may verify your identity and coordinate with your organization.
Depending on applicable law, you may also have rights to object to or restrict processing, receive portable data, withdraw consent or complain to a privacy regulator. Withdrawal does not affect processing already lawfully completed.
We update this page when practices change and revise the date above. Material changes requiring notice or consent will be presented before the changed collection or use.