Privacy Policy for Arth.Find
Last Updated: September 29, 2026
Welcome to Arth.Find ("we," "our," or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, and protect your information when you use the Arth.Find Chrome Extension and its associated backend service.
This policy is designed to comply with global privacy standards, the Google Chrome Web Store Developer Terms, and India's Digital Personal Data Protection (DPDP) Act.
1. Data Collection & Processing Boundaries
Arth.Find operates on a "Privacy by Design" model. We only process data absolutely required to deliver context-aware word explanations.
- Text Selection & Context: When you highlight text, the extension sends the selected word/phrase and the immediate surrounding context to our backend (
POST /define) to compute the definition. This data is processed transiently in memory and is never permanently logged, stored, or indexed on our backend servers. - API Keys (BYOK Mode): If you choose to provide your own LLM provider API key (Google Gemini, OpenAI, or NVIDIA NIM), this key is sent once via
POST /credentials. It is instantly encrypted on the server, and only an opaque, secure reference token is stored. The raw key is never returned to the extension and is never stored in plaintext. - Local Data Storage: The extension uses Chrome's local storage API to remember your theme configurations, background wallpaper choices, and local session preferences. This data stays entirely on your physical machine.
2. Encryption and Security Architecture
We employ industry-standard cryptographic practices to ensure your data remains safe:
- In-Transit Protection: All communications between the Arth.Find extension client and the backend server are encrypted using Secure Sockets Layer / Transport Layer Security (SSL/TLS) HTTPS protocols.
- At-Rest API Key Encryption: In Bring Your Own Key (BYOK) mode, credentials are fully encrypted using an isolated server-side
CREDENTIAL_ENCRYPTION_KEY. Plaintext keys are never visible to server operators or database logs.
3. Data Storage, Retainment, and Third-Party API Sharing
- No Selling or Monetization: We strictly do not sell, rent, trade, or weaponize user data for marketing, profiling, or credit scoring.
- Third-Party LLM Processing: To generate definitions, text context is transmitted securely to the LLM provider configured by the user or the application fallback environment (Google Gemini, OpenAI, or NVIDIA NIM). These entities process data in accordance with their respective API privacy terms, which generally prohibit using API data to train models.
4. Compliance with India's DPDP Act
As an application developed and managed under the framework of Indian laws, we strictly adhere to the Digital Personal Data Protection (DPDP) Act:
- Data Minimization: We only request processing privileges for the exact text you explicitly highlight.
- Explicit Consent: By installing the extension and highlighting text, you provide clear, affirmative consent for transient processing of that text snippet.
- Right to Erasure & Access (BYOK Data): Since we do not maintain user accounts or persistent history logs, we hold no personal data profile on you. If you use BYOK mode and wish to revoke or erase your encrypted credential token, you can purge your local extension storage or contact us to invalidate the token reference on the backend.
- Data Principal Grievances: For queries, complaints, or exercising your rights under the DPDP Act, you can contact our designated Data Principal Grievance support through our official support channel: [contact email or link to be added]
5. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect extension updates or legal revisions. Continued use of the extension after updates constitutes acceptance of the modified policy.