Privacy Policy — BEAST — Making Life Elegant | Nextania Technologies Private Limited
BEAST — Making Life Elegant
Nextania Technologies Private Limited
Privacy Policy
Legal Document

Privacy Policy

How Nextania Technologies Private Limited collects, uses, and protects your information when you use BEAST — Making Life Elegant.

Effective: 13 March 2026
Last Updated: 03 July 2026
Version 2.4.0
01

Who We Are

🏛
Nextania Technologies Private Limited
Registered company incorporated under the Companies Act, 2013, India.
Developer and publisher of BEAST — Making Life Elegant.
Website: nextania.in  ·  Support: nextaniatechnologies@gmail.com

BEAST — Making Life Elegant (“BEAST”, “the Extension”, “we”, “us”, or “our”) is a Chrome browser extension developed and maintained by Nextania Technologies Private Limited. This Privacy Policy governs all data handling practices associated with the Extension and our related services.

By installing or using BEAST — Making Life Elegant, you agree to the practices described in this Privacy Policy. If you do not agree, please uninstall the Extension.

02

Scope of This Policy

This Privacy Policy applies to:

  • The BEAST — Making Life Elegant Chrome Extension (version 1.6.0 and above, including v2.0.0, v2.1.0, v2.2.0, v2.3.0, and v2.4.0)
  • Our backend infrastructure at architectx2.nextaniatechnologies.workers.dev and the Team delivery relay at beast-focus-relay.nextaniatechnologies.workers.dev
  • Our website at nextania.in
  • All subscription and payment flows associated with BEAST
  • The voice typing, AI Polish, Select-to-Slides, document analysis, and community features introduced in v2.1.0
  • The Focus Grid life-planner with its copilots, the Claudy prompt companion, Autopilot, reminders, sticky notes, and the multilingual wellness companion introduced in v2.2.0
  • The features introduced in v2.3.0: the Focus Grid Team copilot for task delegation, Gamify Education learning games, the YouTube watch-and-question quiz, the YouTube comment-assistant and reminder companions, Claudy’s ability to send an open Gmail message to your Focus Grid on your explicit click, and cosmetic refinements to the interface and icons
  • The features introduced in v2.4.0: Resume Studio (build a polished résumé from details you enter, with optional AI expansion of sparse entries); the Select-to-Slides deck engine now optionally illustrating slides with openly-licensed images from Wikimedia Commons and NASA; the Focus Grid Files evidence tracker and Agent-Crafted Checklists; the Field Helper Reminders drafts helper that inserts a message you composed into a Gmail compose box on your click; a permanent, privacy-positive coupling that binds one email to one license key to one BEAST ID so nothing need ever be re-collected; and refinements to input focus, notifications, and the interface

This policy does not apply to third-party services we integrate with (such as Cashfree or OpenAI), which maintain their own privacy policies linked in Section 7.

03

What We Collect

We collect the minimum data necessary to provide the Extension’s features. The table below details every category of data we handle.

DataPurposeWhere StoredSent to Server?
Email addressLicense delivery, purchase confirmation, supportOur serverYes — only at purchase
License keyValidating your subscription on every AI requestLocal storageYes — header on each AI call
Career profile
name, skills, goals, preferences
Powering Opportunity Radar job matchingLocal storageOnly when you click “Scan”
Tone & mode preferenceRemembering your preferred writing styleLocal storageNo
Focus Grid content
tasks, notes, reminders & completion tallies for the copilots
Letting you plan and track your work, finance, health & social lifeLocal storageNo — never leaves your device
Focus Grid Team task
task text + random Focus IDs, when you delegate
Delivering a task you choose to send to a teammateRelay (temporary, auto-deleted)Yes — only when you click Send; removed on accept/reject
Team contacts
names & IDs you save
Letting you pick a teammate by name instead of IDLocal storageNo — never leaves your device
Prompt text on AI chat sites
Claudy · Claude, ChatGPT, Gemini
Refining a prompt you wrote, or sending a response you choose into your Focus GridNot storedYes — only when you click Claudy’s action
Open email text
Claudy on Gmail → Focus Grid
Sending the message you are reading to your own Focus Grid to act onLocal storageNo — written only to your device, never synced
Learning-game topic
Gamify Education
Generating word puzzles, riddles, or word banks for classNot storedYes — processed and discarded
Wellness language preference
Aurelia companion
Showing gentle wellness phrases in your chosen languageLocal storageOnly a language name, only for a custom tongue you type
Radar scan resultsDisplaying your last scan without re-fetchingLocal storageNo
Text submitted via sidebar
email drafts, prompts, form descriptions
Processing your AI request and returning a resultNot storedYes — processed and discarded
Microphone audio
spoken words, voice typing
Transcribing your speech to text while you dictateNot storedYes — streamed while dictating, then discarded
Selected or focused field text
AI Polish & Select-to-Slides
Rephrasing your text or turning a passage into slidesNot storedYes — only when you click the action button
Uploaded documents
Analyzer / Demystify
Extracting and analysing the document you chooseNot storedYes — processed and discarded
Email address (free trial)Delivering your free-trial key and preventing trial recyclingOur serverYes — only at trial signup
Community post content
Godzilla Community
Sharing your post publicly under an anonymous codenameFirebase (temporary, public)Yes — shown publicly, auto-expires
Quiz session data
teacher’s questions, student names, scores
Facilitating live quiz/race sessions via BEAST QuizFirebase Firestore (temporary)Yes — deleted within seventy-five minutes
⚠️
Important — Text You Submit
When you use AI features, the text you type into BEAST is sent to our Cloudflare Worker for processing, passed to an AI model, and the result is returned to you. We do not store, log, or retain this text beyond the time needed to generate your response.
BEAST Quiz — Automatic Data Deletion
Quiz session data is stored temporarily in Google Firebase Firestore solely to relay live session information between teacher and students. All data is permanently deleted through three independent mechanisms: immediately when the teacher downloads results, ends the race, or ends the session manually; automatically after seventy-five minutes via a client-side cleanup timer regardless of teacher action; and server-side auto-deletion enforced by Firebase TTL (Time-to-Live) policies set to seventy-five minutes. No quiz data is ever retained beyond the session. The actual deletion code and Firebase TTL implementation are published and verifiable in Section 7A of this policy.
🎤
Voice Typing — Audio Is Never Stored
When you use voice typing, microphone audio is captured only while you are actively dictating, streamed to our Cloudflare Worker for transcription, converted to text, and then immediately discarded. We never store, log, cache, or replay your audio — only the resulting text is returned to your screen, and only your token count is recorded. The full data journey is proven by source code in Section 5B.
Focus Grid — Your Plans Stay on Your Device
Everything in the Focus Grid — your tasks, notes, reminders, and progress across all copilots — is stored only on your own device and, if you choose, synced through your own Chrome profile. It is never sent to our servers, never read for advertising, and never shared. The full data path is proven by source code in Section 5C. The one exception is the optional Team copilot, where a task you deliberately delegate is briefly relayed to its recipient and then deleted — explained in full, with code, in Section 5D.
🌐
Godzilla Community — Public by Design
Godzilla Community is the one BEAST feature where data is shared by intent: anything you choose to post is displayed publicly to other community members under an anonymous codename, never your email or real name. Posts are stored temporarily (about twenty-four hours) and then expire automatically. Please share only what you are comfortable showing publicly.
🔑
One Email, One Key, One Identity — By Design
BEAST binds one email address to one license key to one BEAST ID, permanently. When you renew or change your plan, credit is added to the same key — a new one is never minted, and your BEAST ID never changes. This is a privacy-positive choice: because your identity is stable, nothing needs to be re-collected, you never re-enter your key, and your teammates keep the same ID for you across reinstalls and new devices. We still keep no directory of users — BEAST IDs remain random codes shared only between people who already know each other.
04

What We Do Not Collect

Our Firm Commitments
The following data is never collected, stored, or transmitted by BEAST — Making Life Elegant under any circumstances.
  • Your email content — We do not read, store, or scan your Gmail inbox. Email text is only processed when you explicitly press a BEAST action button.
  • Browsing history — We do not track which websites you visit.
  • Webpage content — We do not read, scrape, or transmit the content of any non-Gmail webpage you visit — except text you explicitly select, or place your cursor in, and then submit via a BEAST action button (such as AI Polish or Select-to-Slides). That text is processed on demand to fulfil your request and is never stored. On the AI chat sites Claude, ChatGPT, and Gemini, the Claudy companion reads the prompt box, or the latest AI response, only at the moment you click its action — never passively, never in the background — and that text is processed on demand and never stored.
  • Keystrokes or form data — We do not log anything you type outside of BEAST’s own sidebar. Text you deliberately submit to a BEAST action — for example AI Polish, Select-to-Slides, or voice typing — is processed only at that moment and is never logged or stored. BEAST’s writing helpers never attach to password fields or one-time-code / OTP fields, as proven by code in Section 5G.
  • Cookies — We do not use cookies for tracking or analytics.
  • Personal financial data — Payment processing is handled entirely by Cashfree (INR) and PayPal (international/USD). We never see or store your card details.
  • Student personal data beyond the session — Student names and registration numbers entered during BEAST Quiz are never retained beyond seventy-five minutes and are never used for any purpose other than the live quiz session.
  • A directory of users — The Focus Grid Team feature keeps no central directory of people. Focus IDs are random codes, shared only by the people who already know each other, and the names you assign to them live only on your own device.

Trial Fingerprinting

When you install BEAST for the first time, our server creates a one-way cryptographic hash (SHA-256) of your IP address and browser user-agent string. This hash is used solely to prevent the same device from claiming multiple free trials. The raw IP address is never stored — only the irreversible hash. It expires automatically after 365 days.

If you start your free trial by email, we additionally store a one-way hash of your email address, bound to your trial key, for the same single purpose — ensuring one fair trial per person and preventing trial recycling. Your trial key is delivered to your inbox; the email itself is used only to send that key and is never sold, shared, or used for marketing without your consent.

05

Why BEAST Appears on Every Webpage

BEAST — Making Life Elegant injects a small floating button (✦) into every browser tab. We want to be fully transparent about why this is necessary and what it does — and does not — do.

ℹ️
The Core Reason
Productivity and inspiration do not happen only inside Gmail. Our users need AI writing assistance, career tools, and communication support across every website they visit throughout their workday.

Real Use Cases That Require Cross-Tab Presence

  • Reading a job posting on LinkedIn or Naukri → opening Opportunity Radar to match it against your profile
  • Visiting a client’s website → drafting a professional outreach email without switching tabs
  • Reading a research paper → composing a cold email to the author
  • Reviewing a competitor’s product page → generating a market intelligence brief
  • Browsing any website → writing a LinkedIn post, blog draft, or business proposal via Beast Unleashed

What the Injected Button Does and Does Not Do

The floating button (✦)DoesDoes Not
Visual presenceRenders a small button at the edge of the screenCover, obscure, or interact with page content
Data accessActivates features only on explicit user clickRead, scan, or transmit any page content
Page interactionOpens the BEAST sidebar when clickedModify, inject into, or interfere with the host page
Background activityNothing — completely dormant until clickedRun scripts, make network requests, or track activity

The host_permissions: <all_urls> permission is required for our chrome.scripting API to inject the sidebar UI into non-Gmail tabs. Without it, BEAST would be unusable on any website outside Google, defeating its core purpose as a browser-wide productivity companion.

05 — A

Gmail Automation — Zero Data Storage, Verified by Code

🔒
Our Absolute Commitment on Gmail
BEAST reads email content only when you explicitly press an action button. The text is processed in real-time and the AI response is returned directly to your screen. No email content is ever stored, logged, cached, or transmitted to any party other than the AI model for the sole purpose of generating your requested response. BEAST has never and will never integrate any advertising network, analytics tracker, or data monetisation layer. Our only revenue source is your direct subscription fee.

The Complete Data Journey — Proven by Source Code

We believe transparency earns trust. Below is the actual source code from both the BEAST Chrome Extension (content.js) and the Nextania Cloudflare Worker — the complete chain from the moment you click to the moment your AI response appears. You can verify every line.

① Extension — Reading the Email content.js · checkEmail() + triggerAutoReply()

When you open an email, BEAST reads the subject line, sender, and up to 800 characters of body text from the Gmail DOM — only if auto-reply is enabled or you click an action button. This text lives exclusively in the browser’s memory and is never written to any storage.

BEAST CHROME EXTENSION · content.js · EMAIL READING
// Reads email from Gmail DOM — on user action only.
// Text is held in browser memory. Never written to storage.
function checkEmail() {
  let emailBody = "";
  for (const s of ["div.a3s.aiL", "div[data-message-id] .ii.gt div"]) {
    const el = document.querySelector(s);
    if (el) { emailBody = el.innerText.trim().slice(0, 800); break; }
  }
  // Passed directly to callWorker() — never stored anywhere
  if (autoReply) triggerAutoReply(sender, subject, emailBody);
}

async function triggerAutoReply(sender, subject, body) {
  const sys = `You are an elite email assistant. Tone: ${tone}.
Write a reply. 3-5 sentences. Return ONLY the reply body.`;
  // Email text flows directly into callWorker() — no storage call
  currentDraft = await callWorker(sys,
    `From: ${sender}\nSubject: ${subject}\n\n${body}`);
  // currentDraft holds only the AI reply — displayed in sidebar
  render("draft", { mode: "reply", draft: currentDraft });
}

② Extension — Sending to Worker content.js · callWorker()

The email text is transmitted over HTTPS to our Cloudflare Worker — authenticated by your license key. No third-party service other than our Worker receives this data.

BEAST CHROME EXTENSION · content.js · callWorker()
async function callWorker(sys, usr, maxTokens = 1000) {
  // Sent over HTTPS — license key authenticates the request
  const r = await fetch(WORKER_URL, {
    method: "POST",
    headers: {
      "Content-Type":           "application/json",
      "X-Nextania-License-Key": licenseKey,
    },
    body: JSON.stringify({
      agent: "beast_mailer",
      request_payload: { model: "gpt-4.1-mini", input: sys + usr }
    })
  });
  const d = await r.json();
  // Returns only output_text — the AI reply. Nothing else.
  return (d.output_text || "").trim();
}

③ Worker — Processing and Discarding ArchitectX2 Worker · /architect/v1/job

The Worker receives the request, validates your license, passes the text to OpenAI’s API, and immediately returns the AI response. The only data written to storage is the token count deducted from your quota — never the email content.

NEXTANIA CLOUDFLARE WORKER · ArchitectX2 v4.1 · /architect/v1/job
// ① Validate license — reject if inactive or expired
const status = await env.LICENSE_KV.get(`license:${licenseKey}:status`);
if (status !== "active") return json({ error: "License inactive" }, 403);

// ② Extract text from request — held only in memory
const { model, input, temperature, max_output_tokens }
  = body?.request_payload || {};

// ③ Pass to OpenAI — text leaves our system here
const oa = await fetch("https://api.openai.com/v1/responses", {
  method: "POST",
  body: JSON.stringify({ model, input, temperature, max_output_tokens }),
});

// ④ Extract AI reply text
const output_text = extractOutputText(data);

// ⑤ Only token count is stored — NEVER the email content
const used = Number(data?.usage?.total_tokens || 0);
await env.LICENSE_KV.put(
  `license:${licenseKey}:base_tokens_remaining`,
  String(remaining - used)  // quota deduction only
);

// ⑥ Return AI reply — request object is garbage collected
return json({ ok: true, output_text });
ℹ️
What the Code Proves — Six Guarantees
① On-demand only — Email text is read from the Gmail DOM only when you open an email with auto-reply enabled or click an action button.
② Memory only — Email text exists solely in the browser’s JavaScript memory. No localStorage, no chrome.storage, no IndexedDB write ever occurs.
③ HTTPS encrypted — Text is transmitted to our Worker over TLS. No intermediate party can intercept it.
④ Worker discards immediately — The Worker holds the text only for the duration of the OpenAI API call. Once the response is returned, the request object is garbage-collected by the Cloudflare runtime.
⑤ Only quota is stored — The single KV.put() call in the entire job endpoint writes only the token count deduction — never the email text, never the AI response.
⑥ No ad networks, ever — There is no advertising SDK, analytics tracker, or data broker integration anywhere in the BEAST codebase. Nextania’s only revenue is your direct subscription fee.
Nextania’s Firm Public Commitment
Nextania Technologies Private Limited hereby publicly commits that BEAST — Making Life Elegant has never and will never: display advertisements; integrate any advertising network or ad SDK; share user data with data brokers; use email content or browsing behaviour for profiling; or monetise user data in any form. This commitment is permanent and unconditional. Our business model is and will always remain direct subscription only.
05 — B

Voice Typing — Zero Audio Storage, Verified by Code

🎤
Our Absolute Commitment on Your Voice
BEAST captures microphone audio only while you are actively dictating — after you press the 🎤 and begin speaking. The audio is streamed to our Cloudflare Worker, transcribed into text, and the audio is then immediately and permanently discarded. No audio is ever stored, logged, cached, replayed, or transmitted to any party other than the transcription model for the sole purpose of converting your speech to text. Only the resulting text is returned to your screen, and only your token count is recorded against your quota.
🔑
Why BEAST Needs the Microphone & offscreen Permissions
Voice typing requires microphone access, requested through Chrome’s own permission prompt — so you grant it knowingly, and your browser shows a recording indicator whenever the mic is live. The offscreen permission lets BEAST hold this microphone access once, at the extension level, inside a dedicated offscreen document — so dictation works across the websites where you write without each site prompting you separately. These are the narrowest permissions that make voice typing possible; they are used for nothing else.

The Complete Audio Journey — Proven by Source Code

As with Gmail, we show you the real path your voice takes — from the moment you speak to the moment text appears in your field. You can verify every line.

① Extension — Capturing & Releasing the Audio field-helper.js · offscreen.js

Audio is recorded into an in-memory blob only while you dictate. The instant you stop, the microphone is released, the audio is sent for transcription, and the blob is dropped — never written to localStorage, chrome.storage, IndexedDB, or disk.

BEAST CHROME EXTENSION · offscreen.js · AUDIO CAPTURE
// Mic opens ONLY when you press 🎤 and start dictating.
// Audio lives in memory as a Blob — never written to storage.
async function startDictation() {
  const stream = await navigator.mediaDevices.getUserMedia({ audio: true });
  const rec = new MediaRecorder(stream);
  const chunks = [];
  rec.ondataavailable = e => chunks.push(e.data);

  rec.onstop = async () => {
    // Stop the mic immediately — the capture window is over
    stream.getTracks().forEach(t => t.stop());
    const audio = new Blob(chunks, { type: "audio/webm" });
    // Sent straight to our Worker for transcription — never saved
    const text = await sendToTranscribe(audio);
    insertAtCaret(text);  // text appears in your field; audio is dropped
  };
  rec.start();            // recording begins only on your explicit action
}

② Worker — Transcribing & Discarding ArchitectX2 Worker · /architect/v1/transcribe

The Worker validates your license, passes the audio to OpenAI’s Whisper model, returns the transcript, and writes only the token count to storage. The audio blob is never persisted and is garbage-collected the moment the request ends.

NEXTANIA CLOUDFLARE WORKER · ArchitectX2 v4.1 · /architect/v1/transcribe
// ① Validate license — reject if inactive or expired
const status = await env.LICENSE_KV.get(`license:${licenseKey}:status`);
if (status !== "active") return json({ error: "License inactive" }, 403);

// ② Receive the audio — held only in memory for this request
const form = await request.formData();
const audio = form.get("file");          // never written to KV or disk

// ③ Transcribe with OpenAI Whisper — audio leaves our system here
const fd = new FormData();
fd.append("model", "whisper-1");
fd.append("file", audio, "speech.webm");
const r = await fetch("https://api.openai.com/v1/audio/transcriptions", {
  method: "POST", body: fd,
});
const { text } = await r.json();         // the transcript only

// ④ Only the token count is stored — NEVER the audio or transcript
await env.LICENSE_KV.put(
  `license:${licenseKey}:base_tokens_remaining`,
  String(remaining - used)  // quota deduction only
);

// ⑤ Return the text — the audio Blob is garbage collected
return json({ ok: true, text });
ℹ️
What the Code Proves — Five Guarantees
① On-demand only — The microphone opens only after you press 🎤 and begin dictating, and closes the instant you stop.
② Memory only — Audio exists solely as an in-memory blob. No localStorage, chrome.storage, IndexedDB, or disk write ever occurs.
③ HTTPS encrypted — Audio is transmitted to our Worker over TLS; no intermediate party can intercept it.
④ Transcribe then discard — The Worker holds the audio only for the Whisper call. Neither the audio nor the transcript is written to storage; both are garbage-collected when the request ends.
⑤ Only quota is stored — The single KV.put() in the transcribe endpoint writes only the token-count deduction — never your voice, never the text.
05 — C

Focus Grid & Claudy — Stored Locally, Verified by Code

Your Plans Stay on Your Device
The Focus Grid life-planner — every task, note, reminder, and progress tally across your copilots — is stored only on your own device, in Chrome’s local and synced storage. None of this content is ever sent to our servers, read for advertising, or shared with anyone. It lives with you, syncs through your own Google account if you choose, and is deleted the moment you clear it or uninstall the Extension. The single exception is the optional Team copilot, where a task you deliberately delegate is relayed to its recipient and then deleted — covered in Section 5D.

What the Focus Grid Stores — and Where

The Focus Grid is a personal planner. The things you type into it never travel to Nextania. The table in Section 3 lists this content; here is the precise technical guarantee.

BEAST CHROME EXTENSION · focus-grid.js · LOCAL-ONLY STORAGE
// Each copilot is saved as ONE object in the browser's own
// storage. There is no fetch(), no server call — ever.
function saveCop() {
  const data = { q1, q2, q3, q4, notes: copNotes };
  // Written only to the user's own device / Chrome profile
  chrome.storage.sync.set({ ["fgCop_" + cop]: JSON.stringify(data) });
}

// Reading it back is equally local — no network involved.
function loadCop() {
  chrome.storage.sync.get(["fgCop_" + cop], function(d) {
    /* renders your tasks on screen — stays on device */
  });
}

Claudy — Reads Only on Your Click

On Claude, ChatGPT, and Gemini, the Claudy companion can refine a prompt you wrote, or send an AI response you choose into your Focus Grid. It reads that text only at the instant you click its action — never passively, never in the background.

BEAST CHROME EXTENSION · claudy.js · ACTION-ONLY READING
// Nothing is read until YOU click. No timers, no scraping.
refineButton.addEventListener("click", function() {
  const draft = readPromptBox();      // only the box you typed in
  // Sent to our Worker to return a cleaner prompt, then discarded
  chrome.runtime.sendMessage({ type: "beastClaudy", text: draft });
});

// "Send to BEAST" hands a response YOU chose to the local grid
sendButton.addEventListener("click", function() {
  const reply = latestResponseText();   // only the one reply
  chrome.storage.local.set({ fgAutopilotMailbox: { text: reply } });
});
ℹ️
What the Code Proves — Four Guarantees
① Local by design — Focus Grid content is written only to chrome.storage on your own device; there is no network call in the save or load path.
② Click-only reading — Claudy reads a prompt or a response solely inside a click handler; it never runs on a timer or reads the page in the background.
③ Processed then discarded — Text sent for prompt-refinement is returned to you and never stored or logged.
④ No advertising, ever — None of this data touches an ad network, analytics tracker, or data broker. There are none anywhere in BEAST.

Claudy on Gmail — Sending an Email to Your Focus Grid

New in v2.3.0: when you are reading an email, Claudy can place that message into your own Focus Grid so you can act on it. This happens only when you click “Send this email to BEAST”. The message is written to a local-only mailbox key on your device — it is never sent to our servers and never synced to the cloud. Claudy on Gmail runs only in the top frame of mail.google.com and does nothing on its own.

BEAST CHROME EXTENSION · gmail-claudy.js · CLICK-ONLY, LOCAL-ONLY
// Runs only on mail.google.com, top frame. Acts only on click.
function doSend() {
  const body = latestMessageText();   // the open message you chose
  if (!body) return;
  const text = (subject ? "Email: " + subject + "\n\n" : "") + body;
  // Written ONLY to your device's local storage — never synced,
  // never sent to Nextania. The Focus Grid reads it locally.
  chrome.storage.local.set({
    fgAutopilotMailbox: { text: text.slice(0, 16000), ts: Date.now() }
  });
}
🔒
Claudy on Gmail — On-Device Only
The email you send to your Focus Grid is stored only on your own device via chrome.storage.local — it is never transmitted to Nextania’s servers, never synced, and used solely to let your own Focus Grid act on a message you chose. Claudy on Gmail never reads your inbox in the background; it reads a message only at the moment you click.
05 — D

Focus Grid Team — A Delivery Relay That Forgets, Verified by Code

🤝
What the Team Copilot Is — and Is Not
The optional Team copilot lets you delegate a task to a teammate. Because two browsers cannot talk to each other directly, a task you choose to send is briefly relayed through our server — like a letter resting in a letterbox until it is collected. The relay is a delivery mechanism, not a database. A task is stored only until its recipient accepts or rejects it, at which point it is immediately removed. Anything left uncollected is automatically deleted by a server-enforced expiry. There is no central directory of users: Focus IDs are random codes, and the names you give them live only on your own device.

The Team Data Journey — Proven by Source Code

This feature is the one place in BEAST where task text briefly rests on a server, so we show the exact code — including, most importantly, the lines that delete your data. You can verify every line in the published focus-relay-worker.js.

① Sending — Queued Only for Delivery focus-relay-worker.js · /v1/send

When you click Send, the task text and the random Focus IDs are placed in the recipient’s inbox so they can collect it. Each stored item carries a time-to-live (TTL) so it cannot linger.

NEXTANIA CLOUDFLARE WORKER · focus-relay-worker.js · /v1/send
// A task is queued ONLY so the recipient can collect it.
// Every stored value carries an auto-expiry (TTL).
const INBOX_TTL_SECONDS = 60 * 60 * 24 * 60;  // 60 days, then auto-deleted

inbox.push(entry);
// Written with expirationTtl — Cloudflare KV deletes it automatically
await env.TASKS.put(inboxKey, JSON.stringify(inbox),
  { expirationTtl: INBOX_TTL_SECONDS });

② Deletion — Removed the Instant It Is Collected focus-relay-worker.js · /v1/respond

The moment the recipient accepts or rejects the task, it is spliced out of storage — it no longer exists on the server. This is the heart of the privacy design, so we highlight it.

NEXTANIA CLOUDFLARE WORKER · focus-relay-worker.js · DELETION ON ACCEPT / REJECT
// ★ THE DELETION ★ — the task is removed from storage the
// instant the recipient accepts or rejects it.
const removed = inbox.splice(idx, 1)[0];   // ← removed from the inbox
await putArray(env, inboxKey, inbox, INBOX_TTL_SECONDS);
// The task text is now gone from the server. Only a small
// status flag (pending → accepted/rejected) remains for the
// sender's own receipt, and it too auto-expires by TTL.

③ Reject Forever — A User-Controlled Block focus-relay-worker.js · reject_forever

To protect users from unwanted task spam, a recipient can choose Reject Forever. This removes the task, adds the sender to a personal block list, and sweeps out any other tasks from that sender. Afterwards, anything that sender tries to send is silently dropped and never stored — a privacy-protective control that the recipient alone commands.

NEXTANIA CLOUDFLARE WORKER · focus-relay-worker.js · REJECT FOREVER (ANTI-SPAM)
// The recipient blocks a sender. Their future tasks are
// silently dropped — never queued, never stored, no notice.
if (action === "reject_forever" && removed && removed.fromId) {
  const blocked = await getArray(env, "block:" + myId);
  if (blocked.indexOf(removed.fromId) === -1) {
    blocked.push(removed.fromId);
    await putArray(env, "block:" + myId, blocked, ID_TTL_SECONDS);
  }
  // Sweep out any other queued tasks from this sender
  const swept = inbox.filter(t => t.fromId !== removed.fromId);
  await putArray(env, inboxKey, swept, INBOX_TTL_SECONDS);
}

// In /v1/send: a blocked sender's task is silently discarded
const blocked = await getArray(env, "block:" + to);
if (blocked.indexOf(senderId) !== -1) {
  return json({ ok: true });  // looks normal, but goes nowhere
}
ℹ️
What the Code Proves — Six Guarantees
① Delivery only — Task text is stored only so the recipient can collect it; the relay is a letterbox, not a database.
② Deleted on collectioninbox.splice() removes the task from storage the instant it is accepted or rejected.
③ Auto-expiry — Every stored value carries an expirationTtl; Cloudflare KV deletes anything uncollected automatically, with no action needed.
④ No directory — Focus IDs are random codes shared only between people who know each other; we keep no searchable list of users.
⑤ Contacts stay local — The names you assign to IDs are saved only on your own device, never on our servers.
⑥ User-controlled anti-spamReject Forever lets a recipient permanently block a sender; blocked tasks are silently dropped and never stored.
Minimal, Anonymous, Transient
The Team relay handles the minimum data needed to deliver a task you chose to send — the task text, two random IDs, and an optional display name you type. It holds no email addresses, no real identities, and no directory. It keeps your task only until it is collected, and forgets it thereafter. This is delivery, not surveillance.
05 — E

Gamify Education — Zero Storage, Verified by Code

🎮
Learning Games That Store Nothing
The Gamify Education games — Find the Word, Who Am I?, Dumb Charades, and Random Association — take only the topic you type (for example “Quantum Physics”), send it to our AI Worker to generate puzzles, and show the result on screen. No topic, no generated content, and no game data is ever stored on any server. Everything lives only in the browser while the game is on screen, and disappears when you leave.

For the Random Association game, images of an everyday object and a topic are fetched from Wikimedia / Wikipedia’s public APIs to display side by side. Only the search word travels to Wikipedia; no personal data is involved, and nothing is stored.

BEAST CHROME EXTENSION · beast-quiz.js · GAMIFY — TOPIC IN, PUZZLES OUT, NOTHING STORED
// The teacher types a topic. It is sent to the AI Worker to
// generate puzzles. The result is rendered on screen only —
// there is no storage call anywhere in this path.
var prompt = buildPrompt(curGame, topic);
callWorker({ model: "gpt-4.1-mini", input: prompt })
  .then(function(raw) {
    var arr = parseJSONArray(raw);
    startStage(arr);   // shown on screen — never written to storage
  });
ℹ️
What the Code Proves
① Topic in, puzzles out — only the topic you type is sent, only to generate the game. ② No storage — there is no chrome.storage or server write in the game path; content lives in memory while you play. ③ Public images only — Random Association fetches images from Wikipedia’s public API using a search word, with no personal data and no storage.
05 — F

YouTube Companions — Comment Help & Reminders, Zero Storage

🌟
The Starfish & the Octopus
On YouTube, two gentle companions can help you when you ask. The comment-assistant (Starfish) helps you compose and categorise comments on a video you are watching. The reminder companion (Octopus) offers a gentle nudge. Neither stores your data on our servers. They act only when you choose, help with the comment you are writing, and any preference they keep lives only on your own device.

The YouTube watch-and-question feature (BEAST Quiz · Watch) lets a teacher turn a lecture video into quiz questions. As with all BEAST AI features, the transcript text is processed on demand to generate questions and is not retained — and any resulting live quiz session follows the same strict deletion rules described in Section 7A (auto-deleted within seventy-five minutes by three independent mechanisms).

BEAST CHROME EXTENSION · comment-starfish.js · HELP ON DEMAND, NO STORAGE
// The Starfish helps you write/categorise a comment only when
// you click. It composes text into YOUR comment box — it does
// not store the comment, the video, or your activity anywhere.
helpButton.addEventListener("click", function() {
  const draft = readCommentDraft();   // only your comment box
  // Sent to the AI Worker to return a polished comment,
  // inserted back into your box — never stored or logged.
  callWorker(draft).then(insertIntoCommentBox);
});
ℹ️
What the Code Proves
① On click only — the companions act solely when you choose; they never read your viewing in the background. ② No server storage — comments, videos, and viewing activity are never stored on our servers. ③ On-device preferences — any small preference (such as whether a companion is shown) lives only in your own browser storage.
05 — G

Password & OTP Fields — Never Touched, Verified by Code

🛡️
BEAST Stays Away From Your Secrets
BEAST’s on-page writing helpers (the AI Polish, business-format, and voice-typing icons) attach only to ordinary writing fields. They are explicitly blocked from password fields, one-time-code (OTP) fields, two-factor codes, card numbers, CVV/CVC, and PIN fields. Your secrets are never read, never assisted, and never touched.
BEAST CHROME EXTENSION · field-helper.js · isEditable() — SENSITIVE FIELDS EXCLUDED
if (tag === "INPUT") {
  const t = (el.getAttribute("type") || "text").toLowerCase();
  if (t === "password") return false;   // never on passwords

  // Never on one-time-code / OTP / card / PIN fields
  const ac = (el.getAttribute("autocomplete") || "").toLowerCase();
  if (ac === "one-time-code" || ac === "cc-number" ||
      ac === "cc-csc") return false;

  const hint = (name + id + ariaLabel + placeholder).toLowerCase();
  if (/\b(otp|one-time|2fa|mfa|verification code|passcode|
        security code|auth code|cvv|cvc|pin)\b/.test(hint))
    return false;   // sensitive — BEAST stays away
}
ℹ️
What the Code Proves
① Passwords excluded — any type="password" field is rejected outright. ② OTP & codes excluded — fields marked as one-time-codes, or named like OTP / 2FA / verification / CVV / PIN, are rejected too. ③ Helpers appear only on ordinary writing fields — exactly where you would want writing assistance, and nowhere sensitive.
05 — H

Resume Studio — Built On Your Device, Verified by Code

📄
Your Résumé Details Stay With You
Resume Studio helps you build a polished résumé from details you enter — your name, education, experience, skills, and an optional photo. Everything you type is saved only on your own device as a single draft, and the finished document is generated in your browser and downloaded straight to your computer. The optional AI enhancement, which expands sparse entries into fuller phrasing, sends only the specific fields you choose to enhance — and never invents employers, titles, dates, or grades. Your photo never leaves your device; it is embedded locally into the document.
BEAST CHROME EXTENSION · resume-builder.js · LOCAL DRAFT + LOCAL DOCUMENT
// Your résumé draft is saved ONLY to your own device.
// There is no server call in the save or load path.
function saveDraft() {
  chrome.storage.local.set({ beastResumeDraft: JSON.stringify(model) });
}

// The .docx is assembled in your browser and downloaded to you.
// Your photo is embedded locally — it never leaves the device.
const blob = buildDocxBytes(model);   // built in-page
triggerDownload(blob);              // saved to your computer

// AI enhancement is OPTIONAL and sends only chosen fields,
// returning polished text — nothing is stored on our servers.
const improved = await callWorker(enhancePrompt, chosenText);
ℹ️
What the Code Proves
① Local draft — your entries are saved only to chrome.storage.local on your own device. ② Local document — the résumé file is generated in your browser and downloaded to you; the photo is embedded locally and never uploaded. ③ Optional AI, no storage — enhancement sends only the fields you choose, returns polished text, and stores nothing on our servers.
05 — I

Slide Images — Only Free, Legal Sources, Verified by Code

🎨
Images Come Only From Wikimedia Commons & NASA
When you turn a passage of text into a slide deck, BEAST may illustrate a slide with a relevant photograph. These images are fetched only from two openly-licensed public sources — Wikimedia Commons and NASA — using a short search word derived from the slide topic. No personal data is sent in these requests, and each image is credited on the slide with its author and licence. If no suitable free image is found, the slide simply stays text-only. BEAST never fetches images from any other source.
BEAST CHROME EXTENSION · pptx-lite.js · FREE-SOURCE IMAGE FETCH ONLY
// The ONLY two image endpoints BEAST ever calls.
// A search word travels — never any personal data.
const WIKIMEDIA = "https://commons.wikimedia.org/w/api.php";
const NASA      = "https://images-api.nasa.gov/search";

// Each image is credited on the slide with author + licence,
// captured from the source's own metadata.
return { url, source: author + " / " + license +
                       " · Wikimedia Commons" };

// If no free image is found, the slide stays text-only.
if (!meta) { slide.template = "textOnly"; }
ℹ️
What the Code Proves
① Two legal sources only — images are fetched solely from Wikimedia Commons and NASA, both openly licensed. ② No personal data — only a topic-derived search word is sent; nothing about you travels with the request. ③ Attributed & graceful — each image is credited with its author and licence, and slides fall back to text-only when no free image fits.
06

How We Use Your Data

License Key & Email

Used to validate your subscription on every AI request, deliver your license key after purchase, and communicate essential service updates. We do not send marketing emails without your explicit consent.

Career Profile Data

Stored locally on your device. Sent to our AI worker only when you click “Scan Opportunities Now.” Used solely to generate personalised job and opportunity matches. Never used for advertising or shared with third parties.

AI-Submitted Text

Text you type into BEAST’s sidebar is transmitted to our Cloudflare Worker, passed to the AI model, and the result is returned to you. This data is processed in real-time and is not stored, logged, or used for model training.

Voice Typing Audio

When you dictate, your microphone audio is streamed to our Cloudflare Worker, transcribed by OpenAI Whisper, and the audio is discarded the moment transcription completes. Only the resulting text is returned to your field. Audio is never stored, never used for profiling, and never used to train any model. See Section 5B for the source-code proof.

On-Page Text — AI Polish & Select-to-Slides

When you click AI Polish or Select-to-Slides, the specific text you selected or focused is sent to our Worker, processed by the AI model, and returned to you (a rephrased version, or a slide deck). This happens only on your explicit click, is processed in real-time, and is not stored, logged, or used for training. These helpers never attach to password or one-time-code fields (see Section 5G).

Focus Grid & Claudy

Everything you place in the Focus Grid — tasks, notes, reminders, and progress across your copilots — is stored only on your own device and, if you choose, synced through your own Chrome profile. It is never transmitted to Nextania, never read for advertising, and never shared. Claudy reads a prompt or an AI response only when you click its action, processes it to return your result, and then discards it. When you ask Claudy on Gmail to send an open email to your Focus Grid, that message is written only to your device’s local storage and is never synced or sent to our servers. The wellness companion shows gentle phrases from a built-in local library; only when you type a custom mother tongue does a language name travel to our Worker to fetch fresh phrases, and no personal text is involved.

Focus Grid Team — Task Delegation

When you deliberately delegate a task in the Team copilot, the task text and the random Focus IDs are relayed through our delivery server solely so the recipient can collect it. The task is removed the instant it is accepted or rejected, and any uncollected task auto-expires. We keep no directory of users, and the contact names you save live only on your own device. Full source-code proof — including the deletion and anti-spam code — is in Section 5D.

Gamify Education & YouTube Companions

The learning-game topic you type is sent to our Worker only to generate puzzles, and is never stored. The YouTube comment-assistant and reminder companions act only when you click and store nothing on our servers. See Sections 5E and 5F.

Stock Tree — Educational, Historical Analysis Only

The Stock Tree examines the past factors that historically supported or suppressed a stock’s growth, purely for education and understanding. The stock name you enter is processed by our AI Worker to generate this historical analysis and is not stored. The Stock Tree does not predict future performance and is not financial, investment, or trading advice; any decisions you make remain your own.

Free Trial & Email

If you start a free trial by email, your address is used solely to deliver your trial key and, as a one-way hash, to ensure one fair trial per person. It is never sold, shared with data brokers, or used for marketing without your explicit consent.

We Never

  • Sell your data to any third party
  • Use your data for advertising
  • Share your data with data brokers
  • Use your data to train AI models
🛡️
No Advertising. No Trackers. No Data Sales. Ever.
BEAST — Making Life Elegant contains no advertising network, no ad SDK, no analytics tracker, no cookies, and no data-broker integration of any kind — not in the sidebar, not in the Focus Grid, not in Claudy, not in the Team relay, not in the games, not anywhere in the codebase. We do not profile you, we do not sell or share your data, and we never use your content to train AI models. Our only source of revenue is your direct subscription. This commitment is permanent and unconditional.
📜
Chrome Web Store — Limited Use Compliance
BEAST — Making Life Elegant’s collection and use of information received through the Extension, and from any Google APIs, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use user data only to provide and improve the user-facing features described in this policy, and for no other purpose.
07

Third-Party Services

BEAST integrates with the following third-party services. Each has its own privacy policy governing their data handling.

ServicePurposeData Shared
Cloudflare WorkersAI request processing, license validation & Team task delivery relayLicense key, submitted text; Team task text & random IDs (temporary, auto-deleted)
OpenAIAI text generation (GPT-4.1 Mini)Submitted prompts only
OpenAI WhisperSpeech-to-text transcription for voice typingDictated audio only (transcribed, then discarded)
Google GeminiAI text generation (fallback)Submitted prompts only
Wikimedia Commons / WikipediaOpenly-licensed public images for Beast Tourism, Random Association & Select-to-Slides decksA search word only — no personal data, nothing stored
NASA Image LibraryPublic-domain images for space & science slide decks (Select-to-Slides)A search word only — no personal data, nothing stored
CashfreePayment processing for license purchaseEmail & payment details (handled directly by Cashfree)
PayPalInternational payment processing (USD)Email & payment details (handled directly by PayPal)
ResendTransactional email — license key deliveryEmail address, license key
allorigins.win / corsproxy.ioLinkedIn profile proxy for Radar enrichmentLinkedIn URL (only when you provide it)
Google Firebase FirestoreReal-time relay for BEAST Quiz live sessionsTemporary quiz session data — auto-deleted within seventy-five minutes
07 — A

BEAST Quiz — Student Data & Privacy

🎓
BEAST Quiz — Student Data
Students who join a BEAST Quiz session enter only their name and registration number voluntarily to participate. No email address is collected. Students do not need a BEAST account or license key. Student data exists only for the duration of the live session and is permanently deleted the moment the session ends. No student data is shared with any third party or used for any purpose beyond the live session.

BEAST Quiz is designed with student privacy as a first principle. The session data flow is as follows:

  • Data entered: Student name and registration number only — entered voluntarily to join a live session. No email address is collected or stored.
  • Storage: Held temporarily in Google Firebase Firestore solely to relay real-time session information between teacher and students.
  • Deletion — Mechanism 1: Immediately and permanently deleted the moment the teacher downloads results (Quiz), ends the race (Race), or ends the Engage session — whichever comes first.
  • Deletion — Mechanism 2: Automatically deleted after seventy-five minutes via a client-side cleanup timer, regardless of teacher action.
  • Deletion — Mechanism 3: Firebase TTL (Time-to-Live) policy auto-deletes every session document server-side at exactly seventy-five minutes from creation — an independent server-enforced guarantee that operates even if the browser is closed.
  • No retention: No student data is retained, exported, logged, or used for any purpose beyond the live session.

Verified by Code — Our Deletion Implementation

In the spirit of full transparency, the following is the actual deletion function from BEAST Quiz and the TTL timestamp field — both verifiable in our published extension source:

BEAST QUIZ · beast-quiz.js · DATA DELETION
// Called on: teacher downloads results, ends race,
// ends session, or 75-minute auto-timer fires.
function deleteSessionData(sessionCode, raceCode, engageCode) {
  var ops = [];
  if (sessionCode) ops.push(deleteCollection("sessions", sessionCode));
  if (raceCode)    ops.push(deleteCollection("races",    raceCode));
  if (engageCode)  ops.push(deleteCollection("engage",   engageCode));
  return Promise.all(ops).catch(function() {});
}

// Every session document carries a server-enforced
// TTL timestamp — Firebase auto-deletes at 75 minutes.
expireAt: new FSTimestamp(new Date(Date.now() + 75 * 60 * 1000))
ℹ️
Three Independent Deletion Guarantees
① Teacher actiondeleteSessionData() fires the moment the teacher downloads results, ends the race, or ends the session.
② Client timer — A seventy-five-minute JavaScript timer calls deleteSessionData() automatically, regardless of teacher action.
③ Firebase TTL — A server-side TTL policy deletes every document at the expireAt timestamp — seventy-five minutes from creation — even if the browser is closed or crashed.
08

Data Retention

DataRetention Period
Email address & license keyDuration of subscription + 90 days for support purposes
Career profile & preferencesStored locally — deleted when you uninstall the Extension or clear browser data
Resume Studio draft & photoStored locally on your device — kept until you clear it, uninstall the Extension, or clear browser data; the generated document and photo are never uploaded to our servers
Focus Grid content
tasks, notes, reminders, copilots
Stored locally on your device / synced to your own Chrome profile — kept until you delete it or uninstall the Extension; never sent to our servers
Focus Grid Team task
delegated task text & IDs
On the delivery relay only until accepted or rejected (then deleted immediately); any uncollected task auto-expires by server TTL (60 days). Contacts you save stay only on your device.
Open email sent to Focus Grid
Claudy on Gmail
Stored only on your own device (local storage); never synced or sent to our servers; cleared when you clear browser data or uninstall
Wellness language preferenceStored locally — deleted when you uninstall the Extension or clear browser data
Trial fingerprint hash365 days from installation, then automatically deleted
AI-submitted textNot retained — processed in real-time and discarded immediately
Learning-game topic
Gamify Education
Not retained — processed to generate puzzles, then discarded; nothing stored on our servers
Voice typing audioNot retained — transcribed in real-time and discarded immediately
Trial email binding (hashed)Up to 365 days, or until the trial expires — solely to prevent trial recycling
Uploaded documents
Analyzer / Demystify
Not retained — extracted and processed in real-time, then discarded
Community posts
Godzilla Community
Stored temporarily (about twenty-four hours) and shown publicly, then auto-expired
Quiz session data
questions, student names, scores
Deleted immediately when teacher downloads results or ends session — maximum seventy-five minutes enforced by both client-side timer and Firebase TTL server-side policy

You may request deletion of your email and license data at any time by contacting nextaniatechnologies@gmail.com. We will action deletion requests within 30 days.

09

Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted via HTTPS/TLS
  • License keys are validated via HMAC-signed request headers
  • No sensitive data is stored in plaintext
  • Our worker runs on Cloudflare’s enterprise-grade infrastructure
  • Payment data never touches our servers — handled by Cashfree’s PCI-DSS compliant systems

If you believe you have discovered a security vulnerability, please contact us immediately at nextaniatechnologies@gmail.com.

10

Your Rights

Regardless of your location, you have the following rights with respect to your personal data:

Access

You may request a copy of the personal data we hold about you (email address and license key).

Correction

You may request correction of inaccurate data at any time.

Deletion

You may request deletion of your account data. Local data (career profile, preferences, Focus Grid content, saved Team contacts) can be deleted by uninstalling the Extension or clearing Chrome’s extension storage.

Portability

You may request your data in a portable, machine-readable format.

Opt-Out of Communications

You may opt out of non-essential communications at any time by emailing us.

To exercise any of these rights, contact nextaniatechnologies@gmail.com. We respond within 30 days.

11

Children’s Privacy

BEAST — Making Life Elegant is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at nextaniatechnologies@gmail.com and we will delete it promptly.

12

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page and, for material changes, notify you via the Chrome Web Store listing or a notice within the Extension.

Your continued use of BEAST — Making Life Elegant after any change constitutes acceptance of the updated policy.

13

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:

Legal Entity
Nextania Technologies
Private Limited
Extension
Chrome Extension v2.4.0
Location
Chennai, India