Privacy policy for NowPilot
NowPilot by Ananjan Nandi
Privacy policy for NowPilot
NowPilot Privacy Policy
This Privacy Policy explains how NowPilot, Inc. ("NowPilot", "we", "us", or "our") collects, uses, and shares information when you use the NowPilot browser extension and corresponding web app that links to this Policy (together, the "Services").
By using the Services, you agree to this Policy. If you do not agree, please do not use the Services.
1. Scope
This Policy applies to:
- The NowPilot browser extension and dashboard
- Our support and communication channels
It does not apply to third-party websites or services we do not control.
2. What We Collect
We aim for data minimisation and only collect what we need to enable our app's features.
2.1 Account & Login
- Email address and a user identifier
- If you sign up with email + password: your email and a salted, hashed password (never stored in plaintext)
- Authentication tokens and basic session metadata (e.g., expiry)
2.2 Extension Activity (for user-facing features)
- Active tab metadata: URL, domain, and title of the active tab to detect tab changes and trigger interventions (timers, overlays, chatbot, blocking). We do not collect page content or DOM.
- Aggregated activity summaries: periodic summaries derived from tab-change events.
- Chatbot & overlay data: messages you type into the extension's chatbot and settings needed to run interventions.
2.3 Web App & Service Logs
- Standard server logs
- Basic telemetry needed for reliability and security (e.g., rate limiting, performance metrics)
We do not embed third-party trackers in the extension.
2.4 Support & Communications
If you contact us, we collect your message and contact details so we can respond.
3. What We Don't Collect
We deliberately do not collect:
- Page content or DOM from sites you visit
- Form inputs or keystrokes outside the extension's own UI
- Screenshots or screen recordings of pages
- Precise geolocation (e.g., GPS coordinates)
4. How We Use Your Information
We use information to:
4.1 Provide Core Features
- Detect active tab changes (URL/title) and show in-page overlays, timers, and focus interventions
- Generate activity summaries and focus reports for you
- Authenticate you, maintain sessions, and apply your preferences
4.2 AI / LLM Features
To power coaching and chatbot responses, we send:
- Your chatbot messages
- Relevant focus context (goals, timers, high-level categories)
- Aggregated activity summaries
to third-party large language model ("LLM") providers.
These providers act as processors:
- They may only use this data to provide AI features to NowPilot
- We configure them so your data is not used to train models for other customers or for their own advertising or profiling
4.3 Security, Reliability & Improvement
- Operate, secure, and troubleshoot the Services
- Prevent fraud, abuse, or misuse
- Use aggregated and/or de-identified data to understand usage and improve features (not to build advertising profiles)
4.4 Communications & Legal
- Send service notices (security alerts, policy changes, important product updates)
- Send optional product updates
- Comply with legal obligations and enforce our terms
We do not sell your personal data and do not use it for behavioural or cross-context advertising.
5. Legal Bases (EEA/UK)
Where the EU/EEA GDPR or UK GDPR applies, we process your personal data based on:
- Contract – to provide the Services you request
- Legitimate interests – to keep the Services secure and useful in ways that do not override your rights
- Consent – where required (e.g., certain marketing)
- Legal obligation – where we must comply with law or lawful requests
6. Sharing & Disclosure
We share data only as needed:
6.1 Service Providers
With third-party processors that help us run the Services, such as:
- Authentication and data platforms
- Cloud hosting/infrastructure
- Logging, monitoring, and error handling
- Customer support tools
- AI / LLM providers (for chatbot and coaching features)
They may only use your data to provide services to us and must protect it appropriately. We do not allow them to use your data for their own ads or to train general models for others.
6.2 Legal & Safety
We may share information if we believe it is reasonably necessary to:
- Comply with laws, legal processes, or government requests
- Protect the rights, property, or safety of NowPilot, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
6.3 Business Transfers
If we are involved in a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy or equivalent protections. However, we are incorporated as a Public Benefit Corporation to safeguard your interests.
6.4 With Your Direction
We may share data in other ways when you explicitly ask us to (for example, exporting your data to another service).
7. International Transfers
Your information may be processed in your country and in other countries where we or our providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses or equivalent legal mechanisms) for cross-border transfers.
8. Your Choices & Rights
8.1 Controls
- In the extension: pause tracking, show/hide overlays, or sign out to stop data transmission.
- In the web app: change data retention settings (where available).
- In emails: opt out of marketing at any time via the unsubscribe link. We may still send essential service notices.
8.2 Rights
Depending on your location, you may have rights to:
- Access, correct, or delete your personal data
- Object to or restrict certain processing
- Port your data to another service
- Withdraw consent where processing is based on consent
To exercise rights, contact us at team@nowpilot.ai. We may ask for information to verify your identity. You may also have the right to contact your local data protection authority.
California (CPRA)
If you are a California resident:
- We do not "sell" or "share" personal information as defined by the CPRA
- You can request access, deletion, and correction of personal information by contacting [Contact Email]
- We will not discriminate against you for exercising your rights
10. Chrome Web Store & Limited Use
The extension uses a minimal set of permissions, such as:
tabs,webNavigation,storage,alarms, and- Content scripts to render an overlay using Shadow DOM isolation
What we access
- Active tab URL, domain, and title
- Minimal runtime signals (e.g., heartbeat, overlay/timer state)
What we don't access
- No page content/DOM
- No form inputs or keystrokes outside the extension UI
- No background scraping of websites
- No screenshots
- No remote code execution (all scripts are packaged with the extension)
Limited Use
Our use of browsing activity and other data obtained through Chrome APIs is limited to providing and improving the focus-related, user-facing features described in this Policy and in our Chrome Web Store listing. We do not use this data for unrelated purposes such as advertising or data brokering.
Where we use Google APIs, the use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you (for example, by email, in-app notice, or prominent notice on our site). Your continued use of the Services after the effective date means you accept the updated Policy.
12. Contact
For questions, requests, or complaints about this Policy or our data practices, please contact:
- Email: team@nowpilot.ai
- Address: St 104C, 141 Ayrshire Farm Ln, Stanford 94305