AI Side Translator — Privacy Policy
1. Product and scope
AI Side Translator is a bring-your-own-key (BYOK) browser extension. You select and configure your own supported AI translation provider and supply your own API key. No developer-owned provider API key is bundled with the extension. You are responsible for your own provider account, key, usage, quota, billing, and provider settings.
2.1 YouTube subtitle translation
Subtitle Translation is off by default. If you explicitly enable it on a supported YouTube watch page, AI Side Translator reads the live caption text displayed by YouTube and sends that caption text to the AI provider you configured for translation. If you have configured translation rules, glossary entries, or do-not-translate terms, those settings may also be included when needed to perform the requested translation.
The extension does not capture audio, video frames, screenshots, burned-in subtitles, or hidden transcripts. It does not use OCR or speech-to-text for subtitle translation. Subtitle translations are not saved to Translation History and are not persisted by the extension. Subtitle data is not sent to the developer and is not used for analytics, advertising, tracking, profiling, or sale.
2. Information stored in your browser
Non-sensitive configuration is stored persistently in your browser profile using
the browser's extension storage (chrome.storage.local):
- Provider selection, API Base URL, model, and translation settings (languages, display mode, temperature, token limits, feature toggles).
- Your glossary, do-not-translate terms, and style rules.
- A non-sensitive privacy-consent record: the version number of the privacy disclosure you accepted and a random local consent-generation identifier (see section 12). The record contains no translated text, selected or page content, API keys, provider requests, browsing history, or provider details, and it is never sent anywhere.
Sensitive data is kept only in session storage
(chrome.storage.session) — memory-backed, not written to disk by the
extension (the only exception is the explicit opt-in key-inclusive settings
export described in section 7), and cleared when the browser session ends (or
the extension is reloaded or updated):
- Your provider API key(s), stored per provider for the current browser session only. You re-enter keys after the browser closes.
- Translation history: up to 30 recent items for the current browser session, each containing the source text you translated, the translated result, the languages, the mode, and the provider and model used. You can delete individual items or clear all history in the side panel; it also clears when the browser closes.
- Temporary "pending translation" data: when you trigger a translation before the side panel is open, the selected text (and optional page context) is held so the panel can pick it up. At most one such record exists at a time — storing a new one overwrites the stored one — and it is cleared once consumed, and in any case when the browser session ends.
The extension does not use chrome.storage.sync; nothing is synced
across devices. Access to both storage areas is restricted to trusted extension
contexts — content scripts running in web pages cannot read them (this is access
isolation, not encryption). Browser extension storage is not an encrypted or
hardware-backed secret vault, and session storage does not protect against
malware, a compromised device or browser profile, or someone using the
extension's developer tools — protect your device and profile.
3. Information sent to the provider you select
When you request a translation, or enable an automatic translation feature, the extension may send the following directly from your browser to the provider you configured:
- Text you enter manually, text you select, visible page text, newly loaded page text while auto-translate on scroll is enabled, and live YouTube caption text when you explicitly enable Subtitle Translation.
- If you enable "Use page context": the page title, hostname, and nearby page text.
- A compact subset of your glossary, translation rules, and do-not-translate terms when applicable.
- The system and user prompts required to perform the selected operation.
- Your API key, in the provider-specific authentication header.
Provider API Base URLs must use HTTPS — the extension refuses to send requests to non-HTTPS provider endpoints. Requests go directly from your browser to the provider; they do not pass through any developer-controlled proxy or server.
4. Provider responses
Translated responses are displayed to you in the side panel or applied to the page you chose to translate. For side-panel translations, the source text and translated result are also saved to the session-only translation history described above until you delete them or the browser session ends.
5. Developer access and collection
The extension has no developer translation backend, no proxy, no developer-controlled database, no telemetry, no analytics, no advertising, no account or login system, and it loads no remote JavaScript. The developer does not sell user data. The developer does not receive your API keys, your translation content, or your browsing activity through any developer-operated server — there is none. There is no developer-controlled location for your data: it lives locally in your browser (section 2) and with the provider you chose to send it to (sections 3 and 6) — plus anything you export yourself and translations applied into pages you chose to translate (sections 4 and 9).
6. Third-party providers
You choose which provider receives your translation requests. That provider's processing and retention of your data are governed by the provider's own privacy policy, terms, retention practices, model-training settings, account configuration, and any agreements you have with them. This extension cannot control or guarantee what a provider retains or whether it trains on submitted data. Do not submit data you are not authorized to send to your provider. Where available, use provider spending limits, scoped or restricted keys, and revocation controls.
7. API-key handling
- You enter your own key; no developer key is bundled.
- Keys are kept only in session storage for the current browser session (memory-backed, never written to disk) — you re-enter your key after the browser closes. They are masked by default in the UI; you can deliberately reveal your own key with the Show control.
- Keys are not sent to content scripts and are not synchronized via
chrome.storage.sync. - Keys are sent to your configured provider when you run a connection test or a translation. A connection test sends only a fixed, built-in test prompt, the configured model name, and request parameters — never your text, page context, glossary, or history.
- Settings export excludes API keys by default. If you explicitly opt in to a key-inclusive export, the exported file contains your currently loaded session keys in plain text on your filesystem — protect that file. Keys you import are likewise kept for the current browser session only.
- Session storage is not encryption: it avoids writing keys to disk, but it does not protect against malware, a compromised device or profile, or the extension's developer tools — see section 2.
8. Translation history and temporary data
The side panel keeps at most 30 history items in session storage for the current browser session. Each item stores the source text, translated text, source and target languages, translation mode, provider preset, and model name, plus a timestamp. You can remove individual items or clear all history at any time in the side panel, and history also clears when the browser session ends. Temporary pending-translation records hold the text you asked to translate (and optional page context) in session storage until the side panel next opens and consumes them; at most one record exists at a time (storing a new one overwrites the stored one), and it is cleared once consumed and when the session ends.
9. Data retention and deletion
- Non-sensitive settings and glossary/rules remain until you change or delete them through the extension's controls or uninstall the extension. API keys, translation history, and pending-translation records are session-only: they clear automatically when the browser session ends (and history keeps only the 30 most recent items; pending records clear once consumed).
- Uninstalling the extension removes its extension-local storage in accordance with your browser's behavior.
- Settings files you export remain wherever you saved them — delete them yourself when no longer needed.
- Data already sent to a provider is retained or deleted according to that provider's policies; manage it through your provider account.
10. Security
- Provider endpoints must use HTTPS; the extension refuses non-HTTPS provider Base URLs.
- Credential-bearing provider requests are not followed through redirects.
- Content scripts cannot directly read trusted extension storage.
- API keys, translation history, and pending text are held only in memory-backed session storage — not written to disk by the extension (except an explicit opt-in key-inclusive export you save yourself) and cleared when the browser session ends.
- Release verification scans the source code, the built extension output, and the reachable Git history for credential-like values before packaging.
These controls reduce risk; they do not protect against malware, a compromised device or browser profile, a malicious provider, or a user exposing their own key. The extension is not end-to-end encrypted messaging software and makes no such claim.
11. Chrome Web Store User Data Policy
AI Side Translator's use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
12. First-use consent and consent controls
Before any translation feature handles your data, the extension shows a first-use privacy disclosure in the side panel and requires an explicit "Agree and continue" action. Until you agree:
- No API key can be entered, imported, or stored.
- No text is captured from pages, no page text is scanned, no page context is collected, and nothing is sent to any provider.
- No translation history or pending-translation record is created.
- The translation context menu is absent, and hover translation and auto-translate stay inactive regardless of saved preferences.
Choosing "Not now" keeps everything paused, and opening this privacy policy from the disclosure does not count as agreement. Consent is versioned: if the extension's data practices change materially, the disclosure version is increased and the first-use disclosure returns before any further data handling. Your acceptance is recorded locally as the non-sensitive record described in section 2 (the disclosure version plus a random local consent-generation identifier), so the extension can remember and enforce your choice; nothing about your acceptance is transmitted anywhere.
You can withdraw consent at any time with "Reset privacy consent" in the side-panel Settings. Resetting removes the consent record, clears your session API keys, translation history, and pending text, stops hover and auto-translate behavior, removes the translation context menu, and returns the extension to the first-use disclosure. Ordinary non-sensitive preferences (languages, provider settings, glossary, rules) are kept, and the reset itself sends nothing anywhere.
13. Changes and contact
Material changes to this policy will be reflected by updating this page and its "Last updated" date before the corresponding extension version is submitted to the Chrome Web Store. Questions and requests: translator@zhezhongtech.com.