Privacy Policy
How Nextania Technologies Private Limited collects, uses, and protects your information when you use BEAST — Making Life Elegant.
Who We Are
Developer and publisher of BEAST — Making Life Elegant.
Website: nextania.in · Support: nextaniatechnologies@gmail.com
BEAST — Making Life Elegant (“BEAST”, “the Extension”, “we”, “us”, or “our”) is a Chrome browser extension developed and maintained by Nextania Technologies Private Limited. This Privacy Policy governs all data handling practices associated with the Extension and our related services.
By installing or using BEAST — Making Life Elegant, you agree to the practices described in this Privacy Policy. If you do not agree, please uninstall the Extension.
Scope of This Policy
This Privacy Policy applies to:
- The BEAST — Making Life Elegant Chrome Extension (version 1.6.0 and above, including v2.0.0, v2.1.0, v2.2.0, v2.3.0, and v2.4.0)
- Our backend infrastructure at architectx2.nextaniatechnologies.workers.dev and the Team delivery relay at beast-focus-relay.nextaniatechnologies.workers.dev
- Our website at nextania.in
- All subscription and payment flows associated with BEAST
- The voice typing, AI Polish, Select-to-Slides, document analysis, and community features introduced in v2.1.0
- The Focus Grid life-planner with its copilots, the Claudy prompt companion, Autopilot, reminders, sticky notes, and the multilingual wellness companion introduced in v2.2.0
- The features introduced in v2.3.0: the Focus Grid Team copilot for task delegation, Gamify Education learning games, the YouTube watch-and-question quiz, the YouTube comment-assistant and reminder companions, Claudy’s ability to send an open Gmail message to your Focus Grid on your explicit click, and cosmetic refinements to the interface and icons
- The features introduced in v2.4.0: Resume Studio (build a polished résumé from details you enter, with optional AI expansion of sparse entries); the Select-to-Slides deck engine now optionally illustrating slides with openly-licensed images from Wikimedia Commons and NASA; the Focus Grid Files evidence tracker and Agent-Crafted Checklists; the Field Helper Reminders drafts helper that inserts a message you composed into a Gmail compose box on your click; a permanent, privacy-positive coupling that binds one email to one license key to one BEAST ID so nothing need ever be re-collected; and refinements to input focus, notifications, and the interface
This policy does not apply to third-party services we integrate with (such as Cashfree or OpenAI), which maintain their own privacy policies linked in Section 7.
What We Collect
We collect the minimum data necessary to provide the Extension’s features. The table below details every category of data we handle.
| Data | Purpose | Where Stored | Sent to Server? |
|---|---|---|---|
| Email address | License delivery, purchase confirmation, support | Our server | Yes — only at purchase |
| License key | Validating your subscription on every AI request | Local storage | Yes — header on each AI call |
| Career profile name, skills, goals, preferences | Powering Opportunity Radar job matching | Local storage | Only when you click “Scan” |
| Tone & mode preference | Remembering your preferred writing style | Local storage | No |
| Focus Grid content tasks, notes, reminders & completion tallies for the copilots | Letting you plan and track your work, finance, health & social life | Local storage | No — never leaves your device |
| Focus Grid Team task task text + random Focus IDs, when you delegate | Delivering a task you choose to send to a teammate | Relay (temporary, auto-deleted) | Yes — only when you click Send; removed on accept/reject |
| Team contacts names & IDs you save | Letting you pick a teammate by name instead of ID | Local storage | No — never leaves your device |
| Prompt text on AI chat sites Claudy · Claude, ChatGPT, Gemini | Refining a prompt you wrote, or sending a response you choose into your Focus Grid | Not stored | Yes — only when you click Claudy’s action |
| Open email text Claudy on Gmail → Focus Grid | Sending the message you are reading to your own Focus Grid to act on | Local storage | No — written only to your device, never synced |
| Learning-game topic Gamify Education | Generating word puzzles, riddles, or word banks for class | Not stored | Yes — processed and discarded |
| Wellness language preference Aurelia companion | Showing gentle wellness phrases in your chosen language | Local storage | Only a language name, only for a custom tongue you type |
| Radar scan results | Displaying your last scan without re-fetching | Local storage | No |
| Text submitted via sidebar email drafts, prompts, form descriptions | Processing your AI request and returning a result | Not stored | Yes — processed and discarded |
| Microphone audio spoken words, voice typing | Transcribing your speech to text while you dictate | Not stored | Yes — streamed while dictating, then discarded |
| Selected or focused field text AI Polish & Select-to-Slides | Rephrasing your text or turning a passage into slides | Not stored | Yes — only when you click the action button |
| Uploaded documents Analyzer / Demystify | Extracting and analysing the document you choose | Not stored | Yes — processed and discarded |
| Email address (free trial) | Delivering your free-trial key and preventing trial recycling | Our server | Yes — only at trial signup |
| Community post content Godzilla Community | Sharing your post publicly under an anonymous codename | Firebase (temporary, public) | Yes — shown publicly, auto-expires |
| Quiz session data teacher’s questions, student names, scores | Facilitating live quiz/race sessions via BEAST Quiz | Firebase Firestore (temporary) | Yes — deleted within seventy-five minutes |
What We Do Not Collect
- Your email content — We do not read, store, or scan your Gmail inbox. Email text is only processed when you explicitly press a BEAST action button.
- Browsing history — We do not track which websites you visit.
- Webpage content — We do not read, scrape, or transmit the content of any non-Gmail webpage you visit — except text you explicitly select, or place your cursor in, and then submit via a BEAST action button (such as AI Polish or Select-to-Slides). That text is processed on demand to fulfil your request and is never stored. On the AI chat sites Claude, ChatGPT, and Gemini, the Claudy companion reads the prompt box, or the latest AI response, only at the moment you click its action — never passively, never in the background — and that text is processed on demand and never stored.
- Keystrokes or form data — We do not log anything you type outside of BEAST’s own sidebar. Text you deliberately submit to a BEAST action — for example AI Polish, Select-to-Slides, or voice typing — is processed only at that moment and is never logged or stored. BEAST’s writing helpers never attach to password fields or one-time-code / OTP fields, as proven by code in Section 5G.
- Cookies — We do not use cookies for tracking or analytics.
- Personal financial data — Payment processing is handled entirely by Cashfree (INR) and PayPal (international/USD). We never see or store your card details.
- Student personal data beyond the session — Student names and registration numbers entered during BEAST Quiz are never retained beyond seventy-five minutes and are never used for any purpose other than the live quiz session.
- A directory of users — The Focus Grid Team feature keeps no central directory of people. Focus IDs are random codes, shared only by the people who already know each other, and the names you assign to them live only on your own device.
Trial Fingerprinting
When you install BEAST for the first time, our server creates a one-way cryptographic hash (SHA-256) of your IP address and browser user-agent string. This hash is used solely to prevent the same device from claiming multiple free trials. The raw IP address is never stored — only the irreversible hash. It expires automatically after 365 days.
If you start your free trial by email, we additionally store a one-way hash of your email address, bound to your trial key, for the same single purpose — ensuring one fair trial per person and preventing trial recycling. Your trial key is delivered to your inbox; the email itself is used only to send that key and is never sold, shared, or used for marketing without your consent.
Why BEAST Appears on Every Webpage
BEAST — Making Life Elegant injects a small floating button (✦) into every browser tab. We want to be fully transparent about why this is necessary and what it does — and does not — do.
Real Use Cases That Require Cross-Tab Presence
- Reading a job posting on LinkedIn or Naukri → opening Opportunity Radar to match it against your profile
- Visiting a client’s website → drafting a professional outreach email without switching tabs
- Reading a research paper → composing a cold email to the author
- Reviewing a competitor’s product page → generating a market intelligence brief
- Browsing any website → writing a LinkedIn post, blog draft, or business proposal via Beast Unleashed
What the Injected Button Does and Does Not Do
| The floating button (✦) | Does | Does Not |
|---|---|---|
| Visual presence | Renders a small button at the edge of the screen | Cover, obscure, or interact with page content |
| Data access | Activates features only on explicit user click | Read, scan, or transmit any page content |
| Page interaction | Opens the BEAST sidebar when clicked | Modify, inject into, or interfere with the host page |
| Background activity | Nothing — completely dormant until clicked | Run scripts, make network requests, or track activity |
The host_permissions: <all_urls> permission is required for our chrome.scripting API to inject the sidebar UI into non-Gmail tabs. Without it, BEAST would be unusable on any website outside Google, defeating its core purpose as a browser-wide productivity companion.
Gmail Automation — Zero Data Storage, Verified by Code
The Complete Data Journey — Proven by Source Code
We believe transparency earns trust. Below is the actual source code from both the BEAST Chrome Extension (content.js) and the Nextania Cloudflare Worker — the complete chain from the moment you click to the moment your AI response appears. You can verify every line.
① Extension — Reading the Email content.js · checkEmail() + triggerAutoReply()
When you open an email, BEAST reads the subject line, sender, and up to 800 characters of body text from the Gmail DOM — only if auto-reply is enabled or you click an action button. This text lives exclusively in the browser’s memory and is never written to any storage.
// Reads email from Gmail DOM — on user action only. // Text is held in browser memory. Never written to storage. function checkEmail() { let emailBody = ""; for (const s of ["div.a3s.aiL", "div[data-message-id] .ii.gt div"]) { const el = document.querySelector(s); if (el) { emailBody = el.innerText.trim().slice(0, 800); break; } } // Passed directly to callWorker() — never stored anywhere if (autoReply) triggerAutoReply(sender, subject, emailBody); } async function triggerAutoReply(sender, subject, body) { const sys = `You are an elite email assistant. Tone: ${tone}. Write a reply. 3-5 sentences. Return ONLY the reply body.`; // Email text flows directly into callWorker() — no storage call currentDraft = await callWorker(sys, `From: ${sender}\nSubject: ${subject}\n\n${body}`); // currentDraft holds only the AI reply — displayed in sidebar render("draft", { mode: "reply", draft: currentDraft }); }
② Extension — Sending to Worker content.js · callWorker()
The email text is transmitted over HTTPS to our Cloudflare Worker — authenticated by your license key. No third-party service other than our Worker receives this data.
async function callWorker(sys, usr, maxTokens = 1000) { // Sent over HTTPS — license key authenticates the request const r = await fetch(WORKER_URL, { method: "POST", headers: { "Content-Type": "application/json", "X-Nextania-License-Key": licenseKey, }, body: JSON.stringify({ agent: "beast_mailer", request_payload: { model: "gpt-4.1-mini", input: sys + usr } }) }); const d = await r.json(); // Returns only output_text — the AI reply. Nothing else. return (d.output_text || "").trim(); }
③ Worker — Processing and Discarding ArchitectX2 Worker · /architect/v1/job
The Worker receives the request, validates your license, passes the text to OpenAI’s API, and immediately returns the AI response. The only data written to storage is the token count deducted from your quota — never the email content.
// ① Validate license — reject if inactive or expired const status = await env.LICENSE_KV.get(`license:${licenseKey}:status`); if (status !== "active") return json({ error: "License inactive" }, 403); // ② Extract text from request — held only in memory const { model, input, temperature, max_output_tokens } = body?.request_payload || {}; // ③ Pass to OpenAI — text leaves our system here const oa = await fetch("https://api.openai.com/v1/responses", { method: "POST", body: JSON.stringify({ model, input, temperature, max_output_tokens }), }); // ④ Extract AI reply text const output_text = extractOutputText(data); // ⑤ Only token count is stored — NEVER the email content const used = Number(data?.usage?.total_tokens || 0); await env.LICENSE_KV.put( `license:${licenseKey}:base_tokens_remaining`, String(remaining - used) // quota deduction only ); // ⑥ Return AI reply — request object is garbage collected return json({ ok: true, output_text });
② Memory only — Email text exists solely in the browser’s JavaScript memory. No
localStorage, no chrome.storage, no IndexedDB write ever occurs.③ HTTPS encrypted — Text is transmitted to our Worker over TLS. No intermediate party can intercept it.
④ Worker discards immediately — The Worker holds the text only for the duration of the OpenAI API call. Once the response is returned, the request object is garbage-collected by the Cloudflare runtime.
⑤ Only quota is stored — The single
KV.put() call in the entire job endpoint writes only the token count deduction — never the email text, never the AI response.⑥ No ad networks, ever — There is no advertising SDK, analytics tracker, or data broker integration anywhere in the BEAST codebase. Nextania’s only revenue is your direct subscription fee.
Voice Typing — Zero Audio Storage, Verified by Code
offscreen Permissionsoffscreen permission lets BEAST hold this microphone access once, at the extension level, inside a dedicated offscreen document — so dictation works across the websites where you write without each site prompting you separately. These are the narrowest permissions that make voice typing possible; they are used for nothing else.The Complete Audio Journey — Proven by Source Code
As with Gmail, we show you the real path your voice takes — from the moment you speak to the moment text appears in your field. You can verify every line.
① Extension — Capturing & Releasing the Audio field-helper.js · offscreen.js
Audio is recorded into an in-memory blob only while you dictate. The instant you stop, the microphone is released, the audio is sent for transcription, and the blob is dropped — never written to localStorage, chrome.storage, IndexedDB, or disk.
// Mic opens ONLY when you press 🎤 and start dictating. // Audio lives in memory as a Blob — never written to storage. async function startDictation() { const stream = await navigator.mediaDevices.getUserMedia({ audio: true }); const rec = new MediaRecorder(stream); const chunks = []; rec.ondataavailable = e => chunks.push(e.data); rec.onstop = async () => { // Stop the mic immediately — the capture window is over stream.getTracks().forEach(t => t.stop()); const audio = new Blob(chunks, { type: "audio/webm" }); // Sent straight to our Worker for transcription — never saved const text = await sendToTranscribe(audio); insertAtCaret(text); // text appears in your field; audio is dropped }; rec.start(); // recording begins only on your explicit action }
② Worker — Transcribing & Discarding ArchitectX2 Worker · /architect/v1/transcribe
The Worker validates your license, passes the audio to OpenAI’s Whisper model, returns the transcript, and writes only the token count to storage. The audio blob is never persisted and is garbage-collected the moment the request ends.
// ① Validate license — reject if inactive or expired const status = await env.LICENSE_KV.get(`license:${licenseKey}:status`); if (status !== "active") return json({ error: "License inactive" }, 403); // ② Receive the audio — held only in memory for this request const form = await request.formData(); const audio = form.get("file"); // never written to KV or disk // ③ Transcribe with OpenAI Whisper — audio leaves our system here const fd = new FormData(); fd.append("model", "whisper-1"); fd.append("file", audio, "speech.webm"); const r = await fetch("https://api.openai.com/v1/audio/transcriptions", { method: "POST", body: fd, }); const { text } = await r.json(); // the transcript only // ④ Only the token count is stored — NEVER the audio or transcript await env.LICENSE_KV.put( `license:${licenseKey}:base_tokens_remaining`, String(remaining - used) // quota deduction only ); // ⑤ Return the text — the audio Blob is garbage collected return json({ ok: true, text });
② Memory only — Audio exists solely as an in-memory blob. No
localStorage, chrome.storage, IndexedDB, or disk write ever occurs.③ HTTPS encrypted — Audio is transmitted to our Worker over TLS; no intermediate party can intercept it.
④ Transcribe then discard — The Worker holds the audio only for the Whisper call. Neither the audio nor the transcript is written to storage; both are garbage-collected when the request ends.
⑤ Only quota is stored — The single
KV.put() in the transcribe endpoint writes only the token-count deduction — never your voice, never the text.Focus Grid & Claudy — Stored Locally, Verified by Code
What the Focus Grid Stores — and Where
The Focus Grid is a personal planner. The things you type into it never travel to Nextania. The table in Section 3 lists this content; here is the precise technical guarantee.
// Each copilot is saved as ONE object in the browser's own // storage. There is no fetch(), no server call — ever. function saveCop() { const data = { q1, q2, q3, q4, notes: copNotes }; // Written only to the user's own device / Chrome profile chrome.storage.sync.set({ ["fgCop_" + cop]: JSON.stringify(data) }); } // Reading it back is equally local — no network involved. function loadCop() { chrome.storage.sync.get(["fgCop_" + cop], function(d) { /* renders your tasks on screen — stays on device */ }); }
Claudy — Reads Only on Your Click
On Claude, ChatGPT, and Gemini, the Claudy companion can refine a prompt you wrote, or send an AI response you choose into your Focus Grid. It reads that text only at the instant you click its action — never passively, never in the background.
// Nothing is read until YOU click. No timers, no scraping. refineButton.addEventListener("click", function() { const draft = readPromptBox(); // only the box you typed in // Sent to our Worker to return a cleaner prompt, then discarded chrome.runtime.sendMessage({ type: "beastClaudy", text: draft }); }); // "Send to BEAST" hands a response YOU chose to the local grid sendButton.addEventListener("click", function() { const reply = latestResponseText(); // only the one reply chrome.storage.local.set({ fgAutopilotMailbox: { text: reply } }); });
chrome.storage on your own device; there is no network call in the save or load path.② Click-only reading — Claudy reads a prompt or a response solely inside a click handler; it never runs on a timer or reads the page in the background.
③ Processed then discarded — Text sent for prompt-refinement is returned to you and never stored or logged.
④ No advertising, ever — None of this data touches an ad network, analytics tracker, or data broker. There are none anywhere in BEAST.
Claudy on Gmail — Sending an Email to Your Focus Grid
New in v2.3.0: when you are reading an email, Claudy can place that message into your own Focus Grid so you can act on it. This happens only when you click “Send this email to BEAST”. The message is written to a local-only mailbox key on your device — it is never sent to our servers and never synced to the cloud. Claudy on Gmail runs only in the top frame of mail.google.com and does nothing on its own.
// Runs only on mail.google.com, top frame. Acts only on click. function doSend() { const body = latestMessageText(); // the open message you chose if (!body) return; const text = (subject ? "Email: " + subject + "\n\n" : "") + body; // Written ONLY to your device's local storage — never synced, // never sent to Nextania. The Focus Grid reads it locally. chrome.storage.local.set({ fgAutopilotMailbox: { text: text.slice(0, 16000), ts: Date.now() } }); }
chrome.storage.local — it is never transmitted to Nextania’s servers, never synced, and used solely to let your own Focus Grid act on a message you chose. Claudy on Gmail never reads your inbox in the background; it reads a message only at the moment you click.Focus Grid Team — A Delivery Relay That Forgets, Verified by Code
The Team Data Journey — Proven by Source Code
This feature is the one place in BEAST where task text briefly rests on a server, so we show the exact code — including, most importantly, the lines that delete your data. You can verify every line in the published focus-relay-worker.js.
① Sending — Queued Only for Delivery focus-relay-worker.js · /v1/send
When you click Send, the task text and the random Focus IDs are placed in the recipient’s inbox so they can collect it. Each stored item carries a time-to-live (TTL) so it cannot linger.
// A task is queued ONLY so the recipient can collect it. // Every stored value carries an auto-expiry (TTL). const INBOX_TTL_SECONDS = 60 * 60 * 24 * 60; // 60 days, then auto-deleted inbox.push(entry); // Written with expirationTtl — Cloudflare KV deletes it automatically await env.TASKS.put(inboxKey, JSON.stringify(inbox), { expirationTtl: INBOX_TTL_SECONDS });
② Deletion — Removed the Instant It Is Collected focus-relay-worker.js · /v1/respond
The moment the recipient accepts or rejects the task, it is spliced out of storage — it no longer exists on the server. This is the heart of the privacy design, so we highlight it.
// ★ THE DELETION ★ — the task is removed from storage the // instant the recipient accepts or rejects it. const removed = inbox.splice(idx, 1)[0]; // ← removed from the inbox await putArray(env, inboxKey, inbox, INBOX_TTL_SECONDS); // The task text is now gone from the server. Only a small // status flag (pending → accepted/rejected) remains for the // sender's own receipt, and it too auto-expires by TTL.
③ Reject Forever — A User-Controlled Block focus-relay-worker.js · reject_forever
To protect users from unwanted task spam, a recipient can choose Reject Forever. This removes the task, adds the sender to a personal block list, and sweeps out any other tasks from that sender. Afterwards, anything that sender tries to send is silently dropped and never stored — a privacy-protective control that the recipient alone commands.
// The recipient blocks a sender. Their future tasks are // silently dropped — never queued, never stored, no notice. if (action === "reject_forever" && removed && removed.fromId) { const blocked = await getArray(env, "block:" + myId); if (blocked.indexOf(removed.fromId) === -1) { blocked.push(removed.fromId); await putArray(env, "block:" + myId, blocked, ID_TTL_SECONDS); } // Sweep out any other queued tasks from this sender const swept = inbox.filter(t => t.fromId !== removed.fromId); await putArray(env, inboxKey, swept, INBOX_TTL_SECONDS); } // In /v1/send: a blocked sender's task is silently discarded const blocked = await getArray(env, "block:" + to); if (blocked.indexOf(senderId) !== -1) { return json({ ok: true }); // looks normal, but goes nowhere }
② Deleted on collection —
inbox.splice() removes the task from storage the instant it is accepted or rejected.③ Auto-expiry — Every stored value carries an
expirationTtl; Cloudflare KV deletes anything uncollected automatically, with no action needed.④ No directory — Focus IDs are random codes shared only between people who know each other; we keep no searchable list of users.
⑤ Contacts stay local — The names you assign to IDs are saved only on your own device, never on our servers.
⑥ User-controlled anti-spam — Reject Forever lets a recipient permanently block a sender; blocked tasks are silently dropped and never stored.
Gamify Education — Zero Storage, Verified by Code
For the Random Association game, images of an everyday object and a topic are fetched from Wikimedia / Wikipedia’s public APIs to display side by side. Only the search word travels to Wikipedia; no personal data is involved, and nothing is stored.
// The teacher types a topic. It is sent to the AI Worker to // generate puzzles. The result is rendered on screen only — // there is no storage call anywhere in this path. var prompt = buildPrompt(curGame, topic); callWorker({ model: "gpt-4.1-mini", input: prompt }) .then(function(raw) { var arr = parseJSONArray(raw); startStage(arr); // shown on screen — never written to storage });
chrome.storage or server write in the game path; content lives in memory while you play. ③ Public images only — Random Association fetches images from Wikipedia’s public API using a search word, with no personal data and no storage.YouTube Companions — Comment Help & Reminders, Zero Storage
The YouTube watch-and-question feature (BEAST Quiz · Watch) lets a teacher turn a lecture video into quiz questions. As with all BEAST AI features, the transcript text is processed on demand to generate questions and is not retained — and any resulting live quiz session follows the same strict deletion rules described in Section 7A (auto-deleted within seventy-five minutes by three independent mechanisms).
// The Starfish helps you write/categorise a comment only when // you click. It composes text into YOUR comment box — it does // not store the comment, the video, or your activity anywhere. helpButton.addEventListener("click", function() { const draft = readCommentDraft(); // only your comment box // Sent to the AI Worker to return a polished comment, // inserted back into your box — never stored or logged. callWorker(draft).then(insertIntoCommentBox); });
Password & OTP Fields — Never Touched, Verified by Code
if (tag === "INPUT") { const t = (el.getAttribute("type") || "text").toLowerCase(); if (t === "password") return false; // never on passwords // Never on one-time-code / OTP / card / PIN fields const ac = (el.getAttribute("autocomplete") || "").toLowerCase(); if (ac === "one-time-code" || ac === "cc-number" || ac === "cc-csc") return false; const hint = (name + id + ariaLabel + placeholder).toLowerCase(); if (/\b(otp|one-time|2fa|mfa|verification code|passcode| security code|auth code|cvv|cvc|pin)\b/.test(hint)) return false; // sensitive — BEAST stays away }
type="password" field is rejected outright. ② OTP & codes excluded — fields marked as one-time-codes, or named like OTP / 2FA / verification / CVV / PIN, are rejected too. ③ Helpers appear only on ordinary writing fields — exactly where you would want writing assistance, and nowhere sensitive.Resume Studio — Built On Your Device, Verified by Code
// Your résumé draft is saved ONLY to your own device. // There is no server call in the save or load path. function saveDraft() { chrome.storage.local.set({ beastResumeDraft: JSON.stringify(model) }); } // The .docx is assembled in your browser and downloaded to you. // Your photo is embedded locally — it never leaves the device. const blob = buildDocxBytes(model); // built in-page triggerDownload(blob); // saved to your computer // AI enhancement is OPTIONAL and sends only chosen fields, // returning polished text — nothing is stored on our servers. const improved = await callWorker(enhancePrompt, chosenText);
chrome.storage.local on your own device. ② Local document — the résumé file is generated in your browser and downloaded to you; the photo is embedded locally and never uploaded. ③ Optional AI, no storage — enhancement sends only the fields you choose, returns polished text, and stores nothing on our servers.Slide Images — Only Free, Legal Sources, Verified by Code
// The ONLY two image endpoints BEAST ever calls. // A search word travels — never any personal data. const WIKIMEDIA = "https://commons.wikimedia.org/w/api.php"; const NASA = "https://images-api.nasa.gov/search"; // Each image is credited on the slide with author + licence, // captured from the source's own metadata. return { url, source: author + " / " + license + " · Wikimedia Commons" }; // If no free image is found, the slide stays text-only. if (!meta) { slide.template = "textOnly"; }
How We Use Your Data
License Key & Email
Used to validate your subscription on every AI request, deliver your license key after purchase, and communicate essential service updates. We do not send marketing emails without your explicit consent.
Career Profile Data
Stored locally on your device. Sent to our AI worker only when you click “Scan Opportunities Now.” Used solely to generate personalised job and opportunity matches. Never used for advertising or shared with third parties.
AI-Submitted Text
Text you type into BEAST’s sidebar is transmitted to our Cloudflare Worker, passed to the AI model, and the result is returned to you. This data is processed in real-time and is not stored, logged, or used for model training.
Voice Typing Audio
When you dictate, your microphone audio is streamed to our Cloudflare Worker, transcribed by OpenAI Whisper, and the audio is discarded the moment transcription completes. Only the resulting text is returned to your field. Audio is never stored, never used for profiling, and never used to train any model. See Section 5B for the source-code proof.
On-Page Text — AI Polish & Select-to-Slides
When you click AI Polish or Select-to-Slides, the specific text you selected or focused is sent to our Worker, processed by the AI model, and returned to you (a rephrased version, or a slide deck). This happens only on your explicit click, is processed in real-time, and is not stored, logged, or used for training. These helpers never attach to password or one-time-code fields (see Section 5G).
Focus Grid & Claudy
Everything you place in the Focus Grid — tasks, notes, reminders, and progress across your copilots — is stored only on your own device and, if you choose, synced through your own Chrome profile. It is never transmitted to Nextania, never read for advertising, and never shared. Claudy reads a prompt or an AI response only when you click its action, processes it to return your result, and then discards it. When you ask Claudy on Gmail to send an open email to your Focus Grid, that message is written only to your device’s local storage and is never synced or sent to our servers. The wellness companion shows gentle phrases from a built-in local library; only when you type a custom mother tongue does a language name travel to our Worker to fetch fresh phrases, and no personal text is involved.
Focus Grid Team — Task Delegation
When you deliberately delegate a task in the Team copilot, the task text and the random Focus IDs are relayed through our delivery server solely so the recipient can collect it. The task is removed the instant it is accepted or rejected, and any uncollected task auto-expires. We keep no directory of users, and the contact names you save live only on your own device. Full source-code proof — including the deletion and anti-spam code — is in Section 5D.
Gamify Education & YouTube Companions
The learning-game topic you type is sent to our Worker only to generate puzzles, and is never stored. The YouTube comment-assistant and reminder companions act only when you click and store nothing on our servers. See Sections 5E and 5F.
Stock Tree — Educational, Historical Analysis Only
The Stock Tree examines the past factors that historically supported or suppressed a stock’s growth, purely for education and understanding. The stock name you enter is processed by our AI Worker to generate this historical analysis and is not stored. The Stock Tree does not predict future performance and is not financial, investment, or trading advice; any decisions you make remain your own.
Free Trial & Email
If you start a free trial by email, your address is used solely to deliver your trial key and, as a one-way hash, to ensure one fair trial per person. It is never sold, shared with data brokers, or used for marketing without your explicit consent.
We Never
- Sell your data to any third party
- Use your data for advertising
- Share your data with data brokers
- Use your data to train AI models
Third-Party Services
BEAST integrates with the following third-party services. Each has its own privacy policy governing their data handling.
| Service | Purpose | Data Shared |
|---|---|---|
| Cloudflare Workers | AI request processing, license validation & Team task delivery relay | License key, submitted text; Team task text & random IDs (temporary, auto-deleted) |
| OpenAI | AI text generation (GPT-4.1 Mini) | Submitted prompts only |
| OpenAI Whisper | Speech-to-text transcription for voice typing | Dictated audio only (transcribed, then discarded) |
| Google Gemini | AI text generation (fallback) | Submitted prompts only |
| Wikimedia Commons / Wikipedia | Openly-licensed public images for Beast Tourism, Random Association & Select-to-Slides decks | A search word only — no personal data, nothing stored |
| NASA Image Library | Public-domain images for space & science slide decks (Select-to-Slides) | A search word only — no personal data, nothing stored |
| Cashfree | Payment processing for license purchase | Email & payment details (handled directly by Cashfree) |
| PayPal | International payment processing (USD) | Email & payment details (handled directly by PayPal) |
| Resend | Transactional email — license key delivery | Email address, license key |
| allorigins.win / corsproxy.io | LinkedIn profile proxy for Radar enrichment | LinkedIn URL (only when you provide it) |
| Google Firebase Firestore | Real-time relay for BEAST Quiz live sessions | Temporary quiz session data — auto-deleted within seventy-five minutes |
BEAST Quiz — Student Data & Privacy
BEAST Quiz is designed with student privacy as a first principle. The session data flow is as follows:
- Data entered: Student name and registration number only — entered voluntarily to join a live session. No email address is collected or stored.
- Storage: Held temporarily in Google Firebase Firestore solely to relay real-time session information between teacher and students.
- Deletion — Mechanism 1: Immediately and permanently deleted the moment the teacher downloads results (Quiz), ends the race (Race), or ends the Engage session — whichever comes first.
- Deletion — Mechanism 2: Automatically deleted after seventy-five minutes via a client-side cleanup timer, regardless of teacher action.
- Deletion — Mechanism 3: Firebase TTL (Time-to-Live) policy auto-deletes every session document server-side at exactly seventy-five minutes from creation — an independent server-enforced guarantee that operates even if the browser is closed.
- No retention: No student data is retained, exported, logged, or used for any purpose beyond the live session.
Verified by Code — Our Deletion Implementation
In the spirit of full transparency, the following is the actual deletion function from BEAST Quiz and the TTL timestamp field — both verifiable in our published extension source:
// Called on: teacher downloads results, ends race, // ends session, or 75-minute auto-timer fires. function deleteSessionData(sessionCode, raceCode, engageCode) { var ops = []; if (sessionCode) ops.push(deleteCollection("sessions", sessionCode)); if (raceCode) ops.push(deleteCollection("races", raceCode)); if (engageCode) ops.push(deleteCollection("engage", engageCode)); return Promise.all(ops).catch(function() {}); } // Every session document carries a server-enforced // TTL timestamp — Firebase auto-deletes at 75 minutes. expireAt: new FSTimestamp(new Date(Date.now() + 75 * 60 * 1000))
deleteSessionData() fires the moment the teacher downloads results, ends the race, or ends the session.② Client timer — A seventy-five-minute JavaScript timer calls
deleteSessionData() automatically, regardless of teacher action.③ Firebase TTL — A server-side TTL policy deletes every document at the
expireAt timestamp — seventy-five minutes from creation — even if the browser is closed or crashed.Data Retention
| Data | Retention Period |
|---|---|
| Email address & license key | Duration of subscription + 90 days for support purposes |
| Career profile & preferences | Stored locally — deleted when you uninstall the Extension or clear browser data |
| Resume Studio draft & photo | Stored locally on your device — kept until you clear it, uninstall the Extension, or clear browser data; the generated document and photo are never uploaded to our servers |
| Focus Grid content tasks, notes, reminders, copilots | Stored locally on your device / synced to your own Chrome profile — kept until you delete it or uninstall the Extension; never sent to our servers |
| Focus Grid Team task delegated task text & IDs | On the delivery relay only until accepted or rejected (then deleted immediately); any uncollected task auto-expires by server TTL (60 days). Contacts you save stay only on your device. |
| Open email sent to Focus Grid Claudy on Gmail | Stored only on your own device (local storage); never synced or sent to our servers; cleared when you clear browser data or uninstall |
| Wellness language preference | Stored locally — deleted when you uninstall the Extension or clear browser data |
| Trial fingerprint hash | 365 days from installation, then automatically deleted |
| AI-submitted text | Not retained — processed in real-time and discarded immediately |
| Learning-game topic Gamify Education | Not retained — processed to generate puzzles, then discarded; nothing stored on our servers |
| Voice typing audio | Not retained — transcribed in real-time and discarded immediately |
| Trial email binding (hashed) | Up to 365 days, or until the trial expires — solely to prevent trial recycling |
| Uploaded documents Analyzer / Demystify | Not retained — extracted and processed in real-time, then discarded |
| Community posts Godzilla Community | Stored temporarily (about twenty-four hours) and shown publicly, then auto-expired |
| Quiz session data questions, student names, scores | Deleted immediately when teacher downloads results or ends session — maximum seventy-five minutes enforced by both client-side timer and Firebase TTL server-side policy |
You may request deletion of your email and license data at any time by contacting nextaniatechnologies@gmail.com. We will action deletion requests within 30 days.
Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted via HTTPS/TLS
- License keys are validated via HMAC-signed request headers
- No sensitive data is stored in plaintext
- Our worker runs on Cloudflare’s enterprise-grade infrastructure
- Payment data never touches our servers — handled by Cashfree’s PCI-DSS compliant systems
If you believe you have discovered a security vulnerability, please contact us immediately at nextaniatechnologies@gmail.com.
Your Rights
Regardless of your location, you have the following rights with respect to your personal data:
Access
You may request a copy of the personal data we hold about you (email address and license key).
Correction
You may request correction of inaccurate data at any time.
Deletion
You may request deletion of your account data. Local data (career profile, preferences, Focus Grid content, saved Team contacts) can be deleted by uninstalling the Extension or clearing Chrome’s extension storage.
Portability
You may request your data in a portable, machine-readable format.
Opt-Out of Communications
You may opt out of non-essential communications at any time by emailing us.
To exercise any of these rights, contact nextaniatechnologies@gmail.com. We respond within 30 days.
Children’s Privacy
BEAST — Making Life Elegant is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at nextaniatechnologies@gmail.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page and, for material changes, notify you via the Chrome Web Store listing or a notice within the Extension.
Your continued use of BEAST — Making Life Elegant after any change constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:
Private Limited