Privacy policy
Effective September 25, 2026
This policy describes how DialNexa handles information when you use the Alfred Browser Connector Chrome extension with Batman.
Information the connector processes
- Device-link information: a device identifier, a public cryptographic key and its fingerprint, a general device label such as “Chrome on Mac,” and the extension version.
- Account-link information: the Batman account email shown after you explicitly approve a pairing request.
- Security and operational information: short-lived pairing credentials, connection status, creation time, last-seen time, and revocation status.
- Explicitly shared page information: the page URL without its query string or fragment, page title, rendered page text, and visible table cells. The connector does not include input values, cookies, or browsing history from other tabs.
- Website-authority checks: when Alfred is asked for a website's domain rating, Batman can ask the connector to open that site's Ahrefs authority checker and read the rendered result.
- Provider billing balances: when a Chrome profile is linked to Batman and signed into DialNexa's provider consoles (Claude Console, OpenAI platform, Sarvam dashboard, Google AI Studio, Cartesia, Soniox console), Batman can ask the connector, without a click, to open one of those consoles in a background tab (or briefly in the foreground, for a console that only draws the balance once visible) and read the account balance. Only the balance data the console itself loads is returned (for example the credit amount, or the list of organizations it belongs to) or, on a billing page, the few characters beside a “Credit balance” label. If no labelled balance is found there, up to six short snippets around amounts on that billing page are returned so the read can be corrected. On a console that switches between accounts, the connector also reports whether the expected account id is on the page (yes or no, not the text). Other page text, cookies and session tokens are never sent, and the connector refuses any other site or path.
A private device key is created and kept locally in the Chrome profile. DialNexa receives the corresponding public key, not the private key.
Shared page text can contain personal communications, financial, health, identity, or other sensitive information depending on the page you choose. Do not share a sensitive page unless you want Alfred to use that visible content for your request.
How we use this information
We use it only to link the Chrome profile to the account you approve, authenticate the connector, show whether the connector is available, let you manage or revoke linked devices, prevent abuse, and maintain service security and reliability. Page information is used only to answer the request you make to Alfred about that explicitly shared tab. Provider balances are used only to show DialNexa's own provider account balances in Batman and to alert DialNexa staff when one runs low.
Sharing and sale
We do not sell connector information, use it for advertising, or share it with data brokers. Information may be processed by service providers that operate DialNexa’s hosting, database, monitoring, and security infrastructure, and by Alfred's contracted AI provider when needed to answer your request, under DialNexa’s instructions. It may also be disclosed when required by law.
Storage and retention
Local connection state is stored in Chrome storage and the private key is stored in the Chrome profile’s IndexedDB. Short-lived pairing requests normally expire after ten minutes and become eligible for cleanup after one day. Device records remain while needed to provide and secure the service. Revoked records may retain limited audit fields. You can revoke a linked device from the extension or Batman. Batman keeps only the latest page snapshot for each linked Chrome profile and makes it unavailable to Alfred after one hour. You can clear it sooner from the extension. If you ask Alfred to read the snapshot, its content becomes part of that Alfred conversation and is retained under the same controls as the rest of the conversation. Provider balance readings are kept in Batman's check history for 30 days.
Security and limited use
Connector traffic uses HTTPS or WSS, pairing secrets are short-lived, and the server verifies a signed challenge before accepting a live device connection. Our use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Your choices
Pairing requires your explicit approval in Batman, and every page share requires a separate click in the extension. Balance reads happen only on consoles the linked profile is signed into; signing out of a console, or revoking the device, stops them. You can clear the shared page, disconnect from the extension, revoke a device in Batman, or uninstall the extension. For an access or deletion request, contact DialNexa through DialNexa’s privacy page.
Changes
If a future extension release introduces a reviewed website adapter, page mutation, or materially changes data handling, we will update this policy and the Chrome Web Store disclosures before collecting the new data.