All privacy policies

Effective and last updated: 29 July 2026

Extension-specific privacy policy

Published by Selfhood Studios

Nexus privacy policy.

This policy applies only to Nexus — AI Browser Agent, version 2.0.0. It explains what user data the extension handles, how the data is collected and used, where it is stored, how long it is retained, and every party it may be shared with.

Extension version
2.0.0
Selfhood account
Not required
Policy scope
Nexus only
[ 01 ]

Scope

This page is the complete, extension-specific privacy disclosure for Nexus. It does not describe another Selfhood Studios extension. The studio-wide policy remains available at /privacy.

Nexus requires no Selfhood Studios account. Extension data is processed locally unless a feature you deliberately use needs to contact a destination identified in the sharing section below.

[ 02 ]

Data collected or handled

Task prompts, saved prompts, steering messages, approvals, attachments, dictated audio and transcripts; task-relevant tab titles and URLs, page text, links, form labels and structure, screenshots, selected browser-history results, download and tab metadata, text submitted to websites, and website responses; AI responses, provider-exposed reasoning, citations, action logs, and token and usage data; provider, model, transcription, safety, and blocklist settings and API keys; conversations, memories, favorites, scheduled tasks, inbox items, clock and location preferences, weather results, and optional ChatGPT, Claude, or SuperGrok plan and quota-window information.

[ 03 ]

How collection occurs

Nexus obtains data directly from what you type, import, attach, approve, or ask it to remember; from the microphone only after you start voice dictation; and from Chrome's debugger, tabs, history, downloads, storage, and website-access capabilities only when a feature or task you invoke needs that data. It also receives responses from the model endpoints, transcription endpoints, public sources, and websites used for your task. Optional subscription-usage cards make first-party requests using the provider session already signed in within Chrome. User-created scheduled tasks can run later from the instruction saved locally.

[ 04 ]

How data is used

To answer questions; research public sources; navigate, read, click, type, submit, download, and otherwise carry out the browser task you request; show and export an auditable action trace; resume, rerun, remember, or schedule work; provide voice input, favorites, world-clock weather, and provider-usage cards; enforce confirmations and blocked domains; and estimate model usage. Nexus does not use this data for advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.

The data is not used for personalized advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.

[ 05 ]

Handling and storage

Settings, credentials, conversations, memories, favorites, saved prompts, scheduled tasks, inbox items, and the model-usage ledger are stored in chrome.storage.local in the Chrome profile where Nexus is installed. Weather responses are cached in extension localStorage. Dictation audio is processed in memory and is not saved to Nexus history. Nexus does not use Chrome Sync and has no Selfhood Studios application backend, account, analytics, advertising, or telemetry service. API keys and other local values are not separately encrypted by Nexus; they rely on Chrome profile, operating-system, and device security.

Selfhood Studios cannot inspect, recover, or restore data that remains only in your browser profile.

[ 06 ]

All parties data is shared with

No Nexus task data is routinely shared with Selfhood Studios. Depending only on the feature you enable or invoke, direct recipients are: (1) your configured AI endpoint—Anthropic, OpenAI, Google Gemini, xAI, OpenRouter, DeepSeek, local Ollama, local LM Studio, or another custom compatible endpoint—which receives its API credential plus the prompt, conversation, system instructions, task-relevant page content, tool results, source URLs or excerpts, and screenshots needed for the request; (2) your configured transcription endpoint—OpenAI, OpenRouter, Deepgram, Groq, or another custom OpenAI-compatible endpoint—which receives recorded audio and the credential needed to transcribe it; (3) DuckDuckGo, which receives privacy-screened public-search queries, and the public page origins Nexus fetches for research; (4) websites you direct Nexus to visit or operate, which receive normal browser request data, your existing cookies or account session where applicable, and any content you instruct Nexus to submit; (5) Open-Meteo, which receives place names or coordinates, units, and forecast parameters for optional weather; (6) OpenAI/ChatGPT, Anthropic/Claude, and xAI/Grok, which receive credentialed first-party requests when you enable their optional subscription-usage cards; (7) Google's favicon service, which may receive a saved favorite's hostname when Nexus has no captured icon; and (8) Selfhood Studios only if you deliberately send specific information for support, or public authorities if disclosure is legally required. Remote recipients also receive ordinary connection metadata such as IP address, request time, and browser or HTTP headers. Cloud, website, and custom-endpoint recipients may log, retain, review, or otherwise process data according to your account and organization settings, product tier, agreement, and their own privacy policy. Nexus does not sell or rent user data or share it with advertisers or data brokers.

No data is sold or rented, shared with data brokers, or transferred for personalized, retargeted, or interest-based advertising. External recipients process data under their own terms, privacy policies, account settings, and retention controls.

[ 07 ]

Retention and deletion

Local records remain until you delete them, replace them through import, reach a collection limit, or uninstall Nexus. Current limits are 200 conversations, 200 memories, 30 favorites, 100 saved prompts, 200 scheduled-task records, and 300 inbox items; older records may be displaced when a limit is reached. Weather is treated as fresh for one hour and then replaced when refreshed. Removing a local record does not delete copies already sent to a provider or website, exported files, downloads, browser history, notifications, or backups; those copies follow the recipient's or storage service's controls and retention policy.

Before uninstalling, use the extension's delete, clear, reset, or export controls where available. Uninstalling normally removes browser-managed extension storage from that Chrome profile.

[ 08 ]

Security

Remote requests containing user data or credentials use secure transport such as HTTPS or WSS, except a user-configured service that is deliberately hosted on the same device or private network. Authentication information is not publicly disclosed.

Local data relies on Chrome's extension isolation and the security of your Chrome profile, operating system, and device. No security measure is absolute; protect your device account and revoke a provider credential if you believe it has been exposed.

[ 09 ]

Chrome Web Store Limited Use disclosure

User data is used only to provide or improve Nexus's disclosed single purpose and user-facing features. Selfhood Studios does not permit personnel or contractors to read extension data. Routine human access is not possible because Selfhood Studios does not receive extension content.

The limited exceptions are when you explicitly send specific data for support, access is necessary to investigate security or abuse, disclosure is required by law, or data is first aggregated and anonymized for lawful internal operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

[ 10 ]

Notice, choices, and contact

Where a feature sends data to a third party, the transfer must be disclosed before it begins and occur only after an affirmative user action. You can avoid the transfer by not invoking or enabling that optional feature, and you can remove local data through the controls described above.

Analytics on this marketing website are separate from the extension and cannot access its stored content. Website practices are explained in the studio-wide privacy policy.

For a privacy question, rights request, or security report, contact Selfhood Studios. Do not send API keys or unrelated private content.