Privacy policy for Beagle Chat
Beagle Chat by Decent Network
Privacy policy for Beagle Chat
Privacy Policy
Beagle Chat — browser extension · effective 2026-09-29
Beagle Chat for the browser is a messaging client and a Solana wallet that run entirely on your device. It has no account system and no analytics. The one service of ours that receives page or profile content is the Fill agent, and only when you press Fill with Beagle (section 2). This page says exactly what the extension keeps, where, and which network services it talks to.
- What the extension stores, and where
• Carrier identity: The keypair that is your Beagle identity (format decent-peer-tox-keypair-v1). Created on your device, stored in the extension's IndexedDB, never sent anywhere. You can export it as a file and import it into another Beagle client; anyone holding that file is you.
• Profile: The name, one-line description and avatar you choose. Sent only to the friends you add (it travels inside a friend request and over your sessions) and, if you register a beagles.eth name, published in that public record by your own action.
• Friends and messages: Your roster, pending requests and message history, in the extension's IndexedDB on this device. Messages are end-to-end encrypted between you and the friend; relays and bridges carry ciphertext.
• Private profile: Fields you fill in under Profile › Private profile (email, company, bio…), each with a disclosure policy you set. Stored on this device. Fields set to private or ask each time are never sent anywhere. When you press Fill with Beagle, fields set to public or contacts may be sent to the Fill agent to answer that form (section 2).
• Answer bank: Questions and the answers you gave on forms with Fill with Beagle, and the names and checksums of files you used, so the next form can reuse them. Stored on this device with your identity.
• Wallet: Solana seed phrases and private keys, encrypted with AES-GCM under a password you choose (PBKDF2 key derivation), in the extension's local storage. Signing happens on your device. dApp connection approvals are stored locally.
• Preferences: Language, theme, network choice, notification choices — local storage.
Nothing above is synchronised, backed up or copied to any server operated by us. Removing the extension removes it all; export your identity key and your wallet's recovery phrase first if you want to keep them. - Network services the extension talks to
• Beagle relay bridges (bridge.beagle.chat, im.beagle.chat): WebSocket connections that carry the peer's encrypted traffic to the Carrier relay network. A bridge sees your public key and your connection, not message content.
• Carrier bootstrap and relay nodes and the offline-mail relay (lens.beagle.chat): the peer-to-peer network itself. Messages to a friend who is offline wait there, encrypted, until they connect.
• Server list (beagle.chat/assets/bgservers.json): the published list of the nodes above, fetched at start.
• beagles.eth name directory (ens-gateway.beaglechat.workers.dev): read to resolve names and avatars; written only when you register or edit your own name, with a record you sign.
• Solana RPC: balance, transaction history and transaction submission for the wallet — public blockchain data, using the network you select.
• Wallet API (wallet.licode.fun): optional signed-in features of the wallet (a session token you can refresh or clear in the wallet's settings).
• Avatar images (api.beagle.chat and the public NFT CDN): CryptoPunk avatar pictures.
• Beagle Fill agent (fill.beagles.eth, operated by Decent Network), only when you press Fill with Beagle on a page. It receives:
• that page's address, title and visible text (up to 32 kB);
• the form's fields and their current values, except phone and e-mail fields and private-profile fields set to private or ask each time;
• your answer bank, and your profile and private-profile fields set to public or contacts.
These travel end-to-end encrypted over the Carrier network, like a message to a friend. The agent answers with proposed values and a price in points; the extension writes accepted answers into the page, and you submit the form yourself. The agent reads the request with a language model running on Decent Network's own hardware. Page text is not sent to any third-party AI provider. The agent keeps each request and its conversation for up to 30 days, to continue the conversation and fix errors, and then deletes them; its service logs are kept for 7 days. A points record is kept for billing: your account id, the request id, the points, and counts, with no form content. Send /forget to the Fill agent in chat at any time, and it deletes everything it holds about you except that billing record. Nothing is sold or shared with advertisers or analytics services.
Apart from the Fill agent as described, none of these receive your private keys, your message plaintext, your private profile or your browsing history.
- Browser permissions
• storage — the local data listed in section 1.
• offscreen (Chrome; in Firefox, the add-on's background page) — runs the messaging peer in a hidden extension page, so messages arrive while no Beagle window is open.
• notifications — a notice when a message or friend request arrives and no Beagle page is in front.
• sidePanel (Chrome; in Firefox, the sidebar) — the Fill with Beagle panel beside the page. It opens only when you press Fill or Keep in Dock.
• tabs / activeTab / scripting, and a content script on web pages. They are used for three things:
• the wallet provider a web page can ask to connect to;
• "Share this page", which reads the title and address of the page you are on only when you press it;
• Fill with Beagle, which reads the form and the visible text of the page you are on only when you press Fill. On F6S it also reads your own F6S member and company pages, as your browser shows them.
The extension does not read page content otherwise.
• nativeMessaging — an optional native helper for keychain storage of the wallet, only if you install it.
• Host permissions for the Beagle services in section 2 — so the extension can reach them from its own pages.
- What we do not do
• No analytics, crash reporting, advertising or tracking of any kind.
• No account, no e-mail, no phone number.
• No selling or sharing of data with third parties.
• No remote code: everything the extension runs ships inside the package.
- Your choices
• Export or delete your identity and wallet at any time from Profile and from the wallet's settings.
• Choose per field who may ever see your private profile (public, contacts, ask each time, never).
• Mark any private-profile field private and it never leaves the device, Fill included.
• Turn browser notifications off in your browser's extension settings.
- Changes and contact
Changes to this policy ship with a new version of the extension and are noted in its changelog. Questions: beagle.chat.