Privacy Policy for VisaMaster Pro
Your privacy, applicant data sovereignty, and security are fundamental principles at VisaMaster Pro ("we", "our", or "the Extension"), operated under MakeAIFirst. This Privacy Policy explains how our Chrome Extension collects, uses, handles, and safeguards your data.
VisaMaster Pro is an independent third-party productivity tool operated by MakeAIFirst. It is NOT affiliated with, authorized by, sponsored by, or endorsed by the Government of India, the High Commission of India, NIC, or IVAC Bangladesh. All visa processing, official fee collection, and consular approvals occur exclusively on official government portals (indianvisaonline.gov.in).
VisaMaster Pro is built on a Local-First Architecture. All applicant personal data, passport details, and intake forms are stored 100% locally on your device (using Chrome Local Storage and IndexedDB). We do NOT sell, monetize, rent, or lease any personal identifiable information (PII) to third parties under any circumstances.
1. Data We Handle and Where It Resides
- Applicant Form Data & Profiles: Full names, passport numbers, birth dates, family details, addresses, and travel details you enter or extract are stored strictly inside your browser's private local storage on your local machine.
- Document OCR Processing: When you upload a passport photo, PDF, or intake document for OCR processing, image buffers are transmitted over encrypted TLS/HTTPS connections to our stateless AI extraction endpoint. The image and extracted text are processed statelessly in transient memory and are immediately discarded. We do NOT train AI models on your documents, nor do we retain document files on our servers.
- Account & Credit Balance: If you sign in using Google Single Sign-On (SSO), we securely retain your basic Google profile identifier (Email and Name) and your current credit top-up balance in our Cloudflare D1 authentication database to manage credit provisioning across your sessions.
- Google Drive Private Sync (Optional): If you activate Google Drive Cloud Sync, the extension connects directly from your browser to your own personal Google Drive AppData folder using official Google Drive APIs. Your backup snapshots remain entirely within your private Google account.
- Error Diagnostics & Bug Reporting (Telemetry): When an unexpected runtime exception occurs, non-sensitive diagnostic telemetry (error name, sanitized stack trace, browser version, and optional account email) is reported to our secure server strictly to fix broken portal field selectors and maintain service stability. Telemetry payloads are strictly sanitized on-device before transmission to redact and exclude all applicant passport numbers, NID numbers, phone numbers, and form field values.
2. Chrome Extension Permissions Justification
| Permission | Explicit Purpose & Usage |
|---|---|
storage |
Stores your local applicant profiles, preferences, custom auto-fill mappings, and session tokens directly on your machine. |
unlimitedStorage |
Enables travel agencies and cyber cafés processing hundreds of client applications to store local IndexedDB profile queues, PDF drafts, and document assets without browser storage quota limitations. |
activeTab & scripting |
Enables the autofill script to detect form input fields on the official Indian Visa Online portal and fill them accurately when you click "AutoFill". |
identity |
Facilitates secure, 1-click Google Single Sign-On (OAuth2) for account authentication and virtual credit synchronization. |
sidePanel |
Renders the companion VisaMaster Pro workspace alongside your active visa application browser tab for seamless side-by-side workflow. |
3. Host Permissions (Least Privilege Policy)
| Scoped Host Match Pattern | Strict Purpose & Justification |
|---|---|
*://indianvisaonline.gov.in/* |
Official Indian Visa Online portal — enables DOM element detection and 1-click form autofill. |
*://indianvisa-bangladesh.nic.in/* |
IVAC Bangladesh regular portal — enables form filling and appointment page synchronization. |
https://visamasterpro-api.makeaifirst.com/* |
Backend API for Google SSO authentication, bKash/Nagad credit balance syncing, and transient OCR. |
https://www.googleapis.com/* |
Used strictly when the user initiates optional profile backups to their private Google Drive account. |
https://generativelanguage.googleapis.com/* |
Used in developer/BYOK mode if the user provides their own Gemini API key for document extraction. |
4. Data Retention and User Control
You have absolute control over your stored data at all times:
- You can view, edit, search, or permanently delete any applicant profile at any time from the extension interface.
- You can purge all archived records or wipe all local extension databases in Settings > Storage Health & Maintenance.
- Uninstalling the extension immediately purges all local storage and IndexedDB records from your browser.
5. Contact & Privacy Inquiries
If you have any questions, feedback, or data requests regarding our privacy practices, please contact our support desk:
✉️ Official Support Email: [email protected]
🏢 Publisher / Agency: MakeAIFirst (https://makeaifirst.com)
👥 Facebook Community: facebook.com/visamasterpro
▶ YouTube Channel: youtube.com/@make-ai-first