Privacy Policy

AI Assistant for YouTube (Chrome extension). Effective September 22, 2026.

The short version

  • To use the assistant you create an account with your email address and a password.
  • When you send a message, your question and the URL of the YouTube page you're on go to our server so the AI can answer.
  • We don't read other tabs, track your browsing, or show ads, and we never sell your data.
  • Conversation history lives only in server memory and is erased whenever the server restarts.

What we collect

AI Assistant for YouTube ("the extension", "we", "us") is built and maintained by Akash Dabhane. It collects only what it needs to answer your questions.

Account information

When you register or sign in, you enter an email address and a password. They are sent directly from the extension to our authentication provider, Supabase. Our own server never receives or stores your password.

Session tokens

After you sign in, Supabase returns an access token, a refresh token, and basic account details (such as your email address and user ID). The extension stores these in your browser's local extension storage so you stay signed in. Each request to our server includes the access token so we can confirm it's you.

Your questions and the current page URL

When you send a message, the extension sends the following to our server:

  • the text of your question
  • the URL of the YouTube tab you're viewing, which tells the assistant which video, channel, or playlist you mean
  • your user ID, which keeps your conversation separate from other users' conversations

The URL is read only when you send a message, and only from the active tab.

What we don't collect

  • Your browsing history, or any page other than the one you're on when you send a message
  • The content of YouTube pages, your YouTube account, or your watch history
  • Keystrokes, clicks, mouse movement, or other activity tracking
  • Your location, contacts, or payment information
  • Analytics, advertising identifiers, or tracking cookies

How we use it

  • We use your email and session tokens to create your account, sign you in, and verify each request.
  • We use your question and the page URL to fetch the relevant public YouTube data and generate an answer.
  • We keep your recent messages in server memory so the assistant can follow up on earlier questions in the same conversation.

We use this data only to provide the extension's features. We don't use it for advertising, profiling, or any unrelated purpose.

Third-party services

Answering your questions requires the services below. Each one receives only what it needs.

Service What it does Data it receives
Supabase Account sign-up, sign-in, and token verification Email, password, session tokens
Render Hosts our backend server Everything sent to our server, as described above
Google Gemini API The AI model that writes the answers Your question, the page URL, conversation context, and YouTube data fetched for the answer
YouTube API Services Provides public video, channel, playlist, comment, and transcript data Video, channel, and playlist IDs and search terms, never your account details

We may switch AI model providers in the future (for example, to Groq). If we do, we will update this policy.

The extension uses YouTube API Services. By using the extension you agree to be bound by the YouTube Terms of Service. For how Google handles data, see the Google Privacy Policy.

Storage and retention

  • In your browser: Session tokens and account details stay in local extension storage until you log out or uninstall the extension.
  • Conversation history: This is held in our server's memory only and is never written to a database. It is erased whenever the server restarts or redeploys, which happens regularly.
  • Your account: Your email and account record stay in Supabase until you ask us to delete them.
  • Server logs: Our hosting provider may keep standard technical logs, such as request times and error messages, for a limited period to help with reliability.

Sharing and selling

We do not sell, rent, or trade your data. We do not share it with advertisers or data brokers. We share data only with the services listed above, only to operate the extension, or when the law requires it.

Chrome Web Store disclosure

The use of information received from the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We don't transfer user data to third parties except as needed to provide the extension's single purpose. We don't use it for creditworthiness or lending, and we don't let people read it except where necessary for security, legal compliance, or with your consent.

Security

All communication between the extension, our server, and Supabase uses HTTPS. Our server checks your access token with Supabase before handling any request. No method of storage or transmission is completely secure, but we take reasonable steps to protect your data.

Your choices

  • Log out: Use the logout button in the sidebar. This removes your tokens from your browser.
  • Uninstall: Removing the extension deletes everything it stored in your browser.
  • Delete your account: Email us from the address you registered with, and we will delete your account within 30 days.
  • Access your data: Email us to ask what account data we hold about you.

Children

The extension is not directed at children under 13, and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If we change what we collect or how we use it, we will update this page and its effective date. For significant changes, we will also note them in the extension's Chrome Web Store listing.

Contact

For questions or deletion requests, email Akash Dabhane at akash.dev.code@gmail.com.