Catalyst Privacy Policy (DealArena Chrome extension)

Last updated: 2026-07-28 · Version v1.1

This policy covers Catalyst, the DealArena Chrome extension (the "Extension"), installed from the Chrome Web Store. It supplements DealArena.io's site-wide privacy policy (dealarena.io/privacy) and is specific to data the Extension collects in your browser.

We have one goal: be honest about the trade. The Extension contributes anonymized profile observations to a shared contact pool. In return, every DealArena user — including you — gets free contact enrichment, AI-drafted outreach, and signals on every prospect they view. This is the data moat the product is built on. We tell you what we collect, give you per-category controls, and let you revoke at any time.

Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

In plain English: data collected by Catalyst is used to provide and improve the user-facing features described below. It is never sold, never used for advertising or credit-scoring, and is not read by humans except with your consent, for security and abuse review, or where the law requires it.


1. What we collect

1.1 On data-collection sites (LinkedIn, Sales Navigator, Apollo, ZoomInfo)

When you visit a profile or search-result page on these sites, the Extension reads the visible text of the page (the same text rendered in your browser) and may send to DealArena's backend:

We do NOT collect: - Your LinkedIn login session, cookies, password, OAuth tokens, or any auth state. - Direct messages, InMail conversations, or anything in your inbox. - Pages outside the listed data-collection sites (except as described in §1.2 below).

1.2 On other sites (universal capture surfaces)

The Extension's floating widget and pipeline-match badge are optional and off by default. They run only after you explicitly grant Chrome's all-websites permission from the popup or the onboarding screen, and you can revoke that grant at any time (popup → Turn off, or chrome://extensions → site access). When granted, they run on all websites excluding the listed data-collection sites and dealarena.io itself. Their behavior:

The Extension does NOT silently transmit page content from non-data-collection sites. Read-only widget + opt-in capture only.

1.3 What you actively contribute via right-click / popup / capture

When you choose to capture a page (popup "+ as Prospect" / right-click context menu), the cleaned page text and URL are sent to DealArena's backend. If the page contains email addresses, those addresses may enter the shared contact pool — this is intentional and is the primary mechanism for free contact enrichment across users.

You can disable contribution-mode entirely (read-only Extension) at any time. See §3.

1.4 AI processing (large language models)

Three Extension features send text to a large language model to do their job. The processing happens on DealArena's servers, not in your browser, and the text is passed to a third-party model provider acting as our sub-processor:

Our model sub-processors are Anthropic (all tiers today) and Groq (free-tier features as they migrate to it). Both process the text under commercial API terms; the data is not used to train their models. DealArena retains the extracted record, not the model conversation; captured page text may be held up to 90 days in the capture log for debugging and abuse review (§5), then deleted.


2. How we use the data

We do NOT: - Sell your data to third parties. - Use observations for ad targeting or marketing analytics. - Build a profile of you — observations are about prospects you view, not about your own browsing.


3. Your controls

Per-category toggles (Settings → Extension privacy & data)

Consent revocation

Settings → Extension privacy & data → "Revoke consent". This:

Account deletion

Deleting your DealArena account (Settings → Delete account) hard-deletes all your prospects, settings, ICP definition, consent record, and ledger. Anonymized observations remain in the shared pool because they are no longer linked to your account.


4. EU / UK / EFTA users

If your IP geolocates to an EU/UK/EFTA country (via Cloudflare's Cf-Ipcountry header at the time of consent), the Extension issues you a category='read_only' consent record. Contribution endpoints will 403 for read-only consent; the rest of the Extension features (drawer lookups, ICP scoring, draft outreach, signals) work the same as for non-EU users.

This is a temporary stance until v1.x ships granular GDPR-style consent flows. We'd rather exclude you from contribution than risk a non-compliant collection pipeline.


5. Data retention

Data Retention
profile_observations Indefinite (anonymized by 90-day hash scrub)
contact_graph_entries Indefinite (deduped, no per-user attribution)
extension_capture_log 90 days for debugging / abuse review
extension_consent Permanent audit trail (granted_at + revoked_at)
credit_ledger Permanent (billing history)

Account deletion hard-deletes everything attributable to your account.


6. Security


7. Contact

This document is canonical. The version published at dealarena.io/extension/privacy is the same content rendered from this file.