nag — Privacy Policy
nag is a Chrome extension and companion service that chases people for documents and information on your behalf — drafting, sending, and following up on outreach emails, and checking replies against what you asked for. This policy explains what data nag handles, why, and how it is protected. It applies to the nag browser extension and its backend service (together, “nag”, “we”, “us”).
1. Summary
- We collect only what is needed to run the chases you set up — your account details, the credentials you connect, the pages you choose to act on, and the messages exchanged in a chase.
- We do not sell your data, use it for advertising, or use it to assess creditworthiness or lending.
- Sensitive credentials and tokens are encrypted at rest.
- Your data is shared only with the providers you yourself choose (your AI provider and your email provider) in order to perform the actions you request.
2. Data we collect
Account and authentication
- Account details: the email address and password you register with. Passwords are stored only as a salted hash, never in plain text.
- Connected credentials: your AI provider API key, your email provider (Gmail / Outlook) OAuth access and refresh tokens, and — if you connect it — your WhatsApp Business credentials. These are encrypted at rest and used only to act on your behalf.
- Session: a login token stored locally in the browser so you stay signed in.
Content you act on
- Page content: when you start a chase from a page, the extension reads that page’s visible text, links, and its title and URL, in order to pre-fill the request (for example, detecting the recipient’s name and email). This happens only when you initiate a chase, and only for the tab you are viewing — nag does not track your browsing.
- Chase details: the recipient’s name and contact details, a description of what you are requesting, and the criteria a reply must satisfy.
Communications and documents
- Messages: the outreach emails nag drafts and sends on your behalf, and the replies received to those messages.
- Uploaded and attached files: documents the recipient sends by email or uploads through the secure upload link, including any text extracted from them for verification. These may contain financial or other personal information depending on what you are chasing.
We do not collect health data, precise location, or behavioural analytics (clicks, keystrokes, mouse movement, or browsing history).
3. How we use your data
- To run the chases you create: composing, sending, and following up on messages, and receiving replies.
- To verify whether a reply or document satisfies the requirements you specified.
- To authenticate you and keep you signed in.
- To operate, secure, and debug the service.
We use your data only for nag’s single purpose — helping you obtain documents and information from other people. We do not use it for any unrelated purpose.
4. Who we share it with
We do not sell or rent your data. We share it only as needed to provide the service you requested:
- Your AI provider (e.g. Anthropic or OpenAI, per the key you configure): message and document content is sent to your chosen provider to draft messages and verify replies.
- Your email provider (Google / Microsoft): to send messages and read the replies to those messages, using the access you granted.
- Infrastructure providers that host the service (hosting and database) act as our processors under contract and only to run nag.
We do not transfer your data to third parties except for these approved uses, and never to determine creditworthiness or for lending purposes.
5. Storage and security
- Sensitive secrets (AI keys, OAuth tokens, WhatsApp credentials) are encrypted at rest using AES-256-GCM.
- Passwords are stored only as salted hashes.
- Access to your data requires your authenticated session.
- The recipient upload link is a single-purpose, upload-only credential scoped to one chase, and it stops working once the chase ends or the link expires. Uploaded files are screened, and dangerous file types are rejected before storage.
6. Data retention
We keep your chases and their associated data for as long as your account is active, so you can review past chases. You can archive and permanently delete individual chases from within the app. When you delete a chase, its messages, attachments, and requirements are deleted with it. If you ask us to delete your account, we remove your account data, including connected credentials.
7. Your choices and rights
- Disconnect any AI, email, or WhatsApp connection at any time in the extension’s settings.
- Archive or permanently delete individual chases.
- Request access to, correction of, or deletion of your personal data by contacting us.
8. Children
nag is not directed to children and is intended for use by adults in a professional or personal administrative capacity.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a new “last updated” date.
10. Contact
Questions or requests about your data: CONTACT_EMAIL_PLACEHOLDER.