BeavBeav

Effective: June 24, 2026 · Updated: June 25, 2026

Privacy Policy

This policy explains how Beav collects, uses, stores, shares, and protects your personal information, and how you can exercise your privacy rights.

1. Scope

This policy applies to the Beav (formerly RedBox) desktop app, browser extension, official website, official accounts, official AI features, credit top-ups, membership, and related services.

Beav offers both local and connected capabilities. Workspaces, material, drafts, knowledge bases, settings, and logs are stored on your device by default. When you sign in to an official account, top up, use official models, sync settings, submit feedback, enable the browser extension, or call third-party models, the related information may be sent to us or to third-party services.

2. Information We Collect

Account and sign-in information: phone number, SMS verification results, WeChat login identifiers, nicknames, avatars, user IDs, login and refresh tokens, account region, membership status, and device sign-in state.

Transaction and entitlement information: top-up amounts, order numbers, payment status, the transaction data returned by payment channels, credit balances and changes, model call records, membership purchases, and details needed for invoices or after-sales service.

AI and content-processing information: prompts, conversations, and task goals you enter, plus text, images, audio, video, web content, comments, and knowledge-base fragments you upload or import, along with generated results, model parameters, usage records, and error messages. This content leaves your device only when you use official AI, cloud processing, online models, or feedback uploads.

Local app and device information: app version, system type, device or installation identifiers, language, theme, window and feature settings, crash and diagnostic logs, performance data, extension connection state, and necessary network request logs.

Browser extension information: when you actively use the extension to capture, control, or send web content, we may process page titles, URLs, your selected text, images, comments, page structure, screenshots, operation results, or extension state. The extension never reads, submits, or publishes unrelated page content without your authorization.

Feedback and support information: the issue descriptions, contact details, screenshots, logs, diagnostic packages, related accounts, orders, and communication records you submit.

3. How We Use Information

To provide registration and sign-in, identity verification, account security, region switching, membership recognition, device management, and risk prevention.

To complete top-ups, payment verification, credit settlement and deduction, pricing display, billing inquiries, abnormal transaction handling, membership benefit delivery, and support processing.

To provide AI chat, text generation, image generation, video generation, speech processing, material understanding, knowledge-base retrieval, browser capture, automation, file export, and local workspace management.

For fault diagnosis, security audits, anti-fraud, abuse detection, service maintenance, performance optimization, version compatibility, data backup, and necessary statistics.

With your consent or another lawful basis, to send service notices, order updates, security alerts, important agreement changes, feature changes, and after-sales messages.

4. Extension Permissions and Local Files

The browser extension may request permissions such as current tab, tabs, side panel, context menu, local storage, script injection, host permissions, native messaging, browser debugging, downloads, navigation, clipboard, bookmarks, history, sessions, tab groups, and notifications. These permissions power tasks you start yourself: saving pages, saving selected text, capturing material, connecting to the local desktop app, and browser control.

By default, the extension sends content you capture to the Beav desktop service running on your own machine. Unless you deliberately use official cloud features, third-party models, feedback uploads, payment sign-in, or sync, we do not upload your local files.

You can manage permissions and data through system settings, browser extension management, Beav settings, or by deleting local files. Turning off a permission may disable the matching feature.

5. Entrusted Processing, Sharing, and Third Parties

To deliver the service, we may provide necessary information to payment providers, SMS providers, WeChat login, model providers, cloud providers, object storage, diagnostics and analytics services, and browser or operating system features. We share the minimum necessary and require partners to protect your information under applicable law and contract.

When you choose a custom model service or a third-party API key, your inputs, material, and requests are sent to that third party per your configuration. Their data handling is governed by their own terms and privacy policy, which you should review before use.

Without your separate consent or a lawful basis, we never sell or publicly disclose your personal information.

6. Sensitive Personal Information and Minors

For specific features you may submit phone numbers, payment details, images of faces or people, voice material, account dashboard screenshots, location clues, identity documents, information about minors, or other sensitive personal information. We process sensitive personal information only for a specific purpose, with clear necessity, and under strict protective measures.

Please do not put ID numbers, bank card numbers, passwords, verification codes, precise addresses, minors' privacy, medical records, financial accounts, or other people's sensitive information into prompts, screenshots, material, feedback, or knowledge bases unless they are essential to the task.

Beav is intended mainly for adults with full civil capacity. Users under 18 should use the service with a guardian's consent and guidance.

7. Where and How Long We Store Data

When operating services for mainland China users within the mainland, we store the related personal information domestically in principle. If personal information must leave the country because you choose an overseas model, an overseas account region, or a cross-border service, or where otherwise permitted by law, we give notice, obtain separate consent, or complete the required compliance measures.

We keep personal information only for the shortest period necessary for the processing purpose. Account, order, payment, credit, transaction, and security logs are retained for the periods required by law, accounting, tax, cybersecurity, e-commerce, and dispute-resolution rules. Retention of local files is yours to manage.

When the retention period ends or the purpose no longer applies, we delete or anonymize the information, unless the law requires otherwise or retention is necessary for dispute resolution or security audits.

8. Security

We protect personal information with access control, least-privilege design, transport encryption, token protection, log sanitization, risk monitoring, incident handling, backups, and security audits.

No internet environment is completely safe. If a personal information security incident occurs or is likely to occur, we will take remedial measures as the law requires and notify affected users and authorities through in-app notices, site announcements, SMS, email, or other reasonable means.

9. Your Rights

You may lawfully request access to, copies of, corrections to, or deletion of your personal information, withdraw consent, close your account, obtain a copy of your personal information, ask us to explain our processing rules, and restrict or refuse unnecessary processing.

You can submit requests through in-app settings, system permissions, browser extension management, account pages, the feedback entry, or our official contact channels. To protect account security we may ask you to verify your identity, and we respond within legally required timeframes.

Withdrawing consent, deleting information, or closing your account may disable part or all of the features. Information that the law requires us to keep, or that is needed for a contract, dispute handling, or a security audit, may not be deletable immediately, but we stop using it for unrelated purposes.

10. Policy Updates and Contact Us

We may update this policy as the service, laws, third-party providers, or our processing practices change. Material changes are announced through in-app prompts, site notices, pop-ups, messages, or other reasonable means.

For questions, complaints, reports, or requests about this policy or our data handling, contact us via the in-app feedback entry or GitHub Issues: https://github.com/Jamailar/Beav/issues.