Chrome Extension

Privacy Policy

NextDNS — Quick Tools  ·  Last updated: April 2026  ·  Version 2.1

Independent community project. NextDNS — Quick Tools is not affiliated with, endorsed by, or maintained by NextDNS Inc. "NextDNS" is a trademark of NextDNS Inc.

About This Policy

This Privacy Policy describes how NextDNS — Quick Tools (the "Extension") handles data on your device. We want to be transparent about what data exists, where it goes, and what we never touch.

This policy applies to the Chrome browser extension published on the Chrome Web Store. It does not apply to the NextDNS service itself — please read NextDNS's own privacy policy for information about their service.

About NextDNS — Quick Tools

NextDNS — Quick Tools is a daily-use extension that gives you quick access to your NextDNS profile controls directly from your browser toolbar. Features include one-click allowlist/denylist management, DNS cache flushing, real-time query log viewing, detailed analytics (including blocked reasons, devices, root domains, and client IPs), live connection status, and connection detail inspection (DNS-over-HTTPS / TLS / QUIC endpoints) — all by communicating directly with the NextDNS API using your own API key.

This extension is an independent, community-built project. It is not created, sponsored, or officially supported by NextDNS Inc.

Data We Collect

The Extension stores the following data locally on your device only:

All stored data lives entirely on your device in Chrome's local/session storage. No data is sent to any server operated by this extension.

Data We Do NOT Collect

This extension never collects, transmits, or stores:

There is no analytics SDK, no error-reporting service, and no third-party script of any kind loaded by this extension.

Chrome Permissions — Why We Request Them

Permission Why it is needed
storage Store your encrypted API key, profile ID, and display preferences on your device.
activeTab Read the domain of the currently open tab so you can allowlist or denylist it with one click.
browsingData Flush the browser's DNS cache when you click "Flush DNS Cache".
alarms Schedule the auto-resume timer when NextDNS protection is paused for a set duration.
notifications Show a desktop notification when NextDNS protection automatically resumes after a pause.
tabs Open the NextDNS setup page or donation page in a new tab when you click the relevant links.
api.nextdns.io Communicate with the NextDNS REST API to fetch logs, analytics, and manage your allowlist/denylist.
test.nextdns.io Check whether your browser is currently routing DNS through NextDNS (public test endpoint, no auth required).

No permissions beyond the ones listed above are requested, now or in future updates without a new policy notice.

Third-Party Services

The only external server this extension communicates with is the NextDNS API (api.nextdns.io) and the public NextDNS test endpoint (test.nextdns.io). Both are operated by NextDNS Inc. Your API key is sent to these servers as the authentication credential — this is how the NextDNS API works by design.

If you use the donation/support links in Settings, clicking them opens your browser to Polar.sh (a third-party payment processor) in a new tab. The extension does not send any data to Polar — you navigate there yourself, and Polar's own privacy policy applies to any transaction you make.

No other third-party services are involved.

Trademark & Affiliation Disclaimer

The name "NextDNS" and related branding are trademarks of NextDNS Inc. This extension uses these terms solely to describe its compatibility and function with the NextDNS service. This extension is an independent community project and has no affiliation with, endorsement from, or sponsorship by NextDNS Inc.

Your Rights & Control Over Your Data

Because all data is stored locally on your device, you are in full control:

There is no account on our end to delete, and no server-side data to request — because we never collected any.

Children's Privacy

This extension is designed for general use and is not directed at children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has used this extension and has concerns, please contact us at the address below.

Security

We take the security of your credentials seriously. Your NextDNS API key is encrypted on-device using AES-256-GCM via the browser's built-in Web Crypto API — the same standard used in online banking and secure communications. A random 12-byte initialization vector is generated for every encryption operation.

The encryption key itself is stored in Chrome's session storage (cleared when the browser closes) with a fallback to local storage. Your raw API key is never written to disk in plaintext.

If you enable PIN protection, only a SHA-256 hash of your PIN is stored — the raw PIN is never saved and cannot be recovered from the stored hash.

Transparency & Open-Source Intent

This extension is built with transparency as a core value. The source code is available for review so anyone can verify the privacy claims in this policy. There is no minified, obfuscated, or hidden code that could conceal unexpected behaviour — what you see is what runs.

If you ever have doubts about what the extension does, you can inspect the JavaScript files directly in Chrome DevTools or by extracting the extension package.

Legal Rights, Fair Use & DMCA

This extension is offered as-is for personal, non-commercial use. It interacts with the NextDNS public API under fair use — the same way any application or script using an API key would operate.

If you believe this extension infringes on any copyright, trademark, or other intellectual property right, please contact us at chromeextensions@howareyou.cc and we will respond promptly.

International Users & GDPR

Because this extension stores data only on your local device and does not transmit it to any server operated by us, there is no cross-border transfer of personal data to or from our systems. Your data stays on your machine.

If you are located in the European Economic Area (EEA) or the United Kingdom and have GDPR-related questions, please contact us at chromeextensions@howareyou.cc. Given the local-only nature of data storage, the applicable rights (access, deletion, portability) are all exercisable directly through the extension's Settings page — no request to us is needed.

Changes to This Policy

If we make material changes to this privacy policy, we will update the "Last updated" date at the top of this page. For significant changes, we may also include a note in the extension's changelog visible in the Chrome Web Store.

Continued use of the extension after a policy update constitutes acceptance of the revised terms. If you disagree with any change, you can remove the extension at any time.

Contact

For privacy questions, bug reports, feature requests, or any other inquiries:

Email: chromeextensions@howareyou.cc

We aim to respond within 5 business days.