Privacy Policy — VexAI
VexAI is a browser extension that translates web pages, images, comics and documents, answers questions about the page you are reading, and dubs YouTube videos. This policy explains exactly what data the extension handles, where it goes, how long it is kept, and what control you have over it.
We do not sell your data. We do not use it for advertising. The extension contains no analytics, tracking pixels, or telemetry of any kind.
1. Summary
| Do we sell or share data with data brokers? | No. |
| Do we use your data for advertising? | No. |
| Is there analytics or usage tracking in the extension? | No. The extension sends no telemetry. |
| Do we read your browsing history? | No. We never collect a list of sites you visit. |
| Is an account required? | No. Web page translation, the selection popup and local OCR work without one; AI features require signing in with Google. |
| Is my content used to train AI models? | Not by us. See §5 for the one case where a third-party provider may do so (the optional free model in Page Assistant). |
2. What the extension does not do
These are worth stating plainly, because the extension requests broad permissions:
- It does not run in the background collecting the pages you visit. Page content is read only at the moment you invoke a feature on that page (for example, you click "Translate" or turn on page reading in the Page Assistant).
- It does not transmit your cookies, passwords, or form data to us or to any third party. See §7 for the one narrow use of cookies.
- It does not record your keystrokes. The only keyboard listener that runs on pages reacts to the extension's own shortcuts (Alt+Q / Alt+W / Alt+S) and ignores every other key; nothing is stored or sent.
- It does not contain analytics, crash reporting, session recording, fingerprinting, or advertising code.
- It does not scan, index, or bulk-read your Google Drive, Gmail, Sheets or Docs. See §8.
3. Account data
Signing in is optional; it is required only for AI-powered features and for purchasing credits.
When you sign in with Google, we receive from Google and store on our servers:
- your Google account ID
- your email address
- your display name
- your profile picture URL
We store this in our database (hosted on Supabase) together with your credit balance. We use it to identify your account, apply your credit balance, and contact you about your purchases. We do not receive or store your Google password.
Your session token and profile are also stored locally in your browser (chrome.storage.local) so you stay signed in.
Free-credit abuse prevention. New accounts receive free credits once per device. To enforce this, the extension creates a random installation ID the first time you sign in and keeps it in chrome.storage.local; it is not derived from your hardware or browser characteristics. At sign-in our server receives this ID and the IP address of the request, and stores only a keyed hash (HMAC-SHA256) of each — never the raw values — together with whether free credits were granted. The hashed IP address is deleted after 30 days. The hashed installation ID is kept to stop the same device claiming free credits again, including after the account is deleted. Neither is used for anything else.
Daily free allowances. Some features have a free daily allowance (for example, a number of free comic pages per day, or free-model requests in Page Assistant). To count it we store your account ID, the date and the count. These counters are deleted after 7 days.
4. Data sent when you use a feature
Nothing below is sent unless you actively invoke the feature. "Our servers" means our backend at api.vexai.pyktools.com and our own OCR/detection servers; the providers named in each row are described in §5.
| Feature you invoke | What is sent, and to whom | Retained |
|---|---|---|
| Web page translation and the selected-text popup | The text segments to translate go directly from your browser to Google Translate. For a single English word, that word is also sent to the free dictionary service dictionaryapi.dev. Nothing goes to our servers. | Not retained by us |
| Page Assistant (chat) | Your message, the conversation history, your local date, time and time zone (so answers about "today" are correct), and — only while the 📖 "Read page content" toggle is on — the current page's URL, title and extracted text; plus any screenshot or image you attach. The toggle starts off every time you open the panel and resets when you navigate to another page, so page content is never sent until you switch it on for that page. Sent to our servers, then to the AI provider of the model you selected. If you enable Web search, the search query the AI writes is sent to a web search provider. | Conversation stored so you can resume it; you can delete any conversation from Settings → Page Assistant → chat history. Auto-deleted 60 days after its last update. |
| Comic / image translation — Free mode | The image goes to our OCR server. The recognised text is then translated either directly from your browser by Google Translate or on our servers by an AI provider. | Image not stored. Recognised and translated text may be cached — see §9. |
| Comic / image translation — Smart mode | The image, plus source and target language, go to our servers and then to Alibaba Cloud's AI model, which reads and translates it. | Image not stored. Translated text may be cached — see §9. |
| Snip & translate (OCR) | In the default mode, text is recognised on your device and the recognised text is translated directly from your browser by Google Translate. Other modes send the selected screen region to our OCR server or to an AI provider. | Not retained |
| Advanced / document translation | The text or document you submitted, sent to our servers and an AI provider (basic mode translates directly from your browser with Google Translate). | Not retained |
| AI content detector | The text or image you submitted, sent to our servers. Detection uses models hosted on our own servers and/or an AI provider. Text not in English may first be translated directly from your browser by Google Translate. | Not retained |
| Safe link — "Check link with AI" | Only the single link URL you selected from the right-click menu. Our server then fetches that page itself, without any of your cookies or credentials, and analyses its content with an AI provider. We never receive the links you merely hover over, click, or visit. | Not retained |
| Writing assistant | Your prompt and the text you are working on, sent to our servers and an AI provider. | Not retained |
| News search / deep dive | Your search keywords and language. Our server queries news and web search providers and fetches the article pages it finds, then summarises them with an AI provider. | Search history stored. Auto-deleted after 90 days. |
| YouTube dubbing | The video ID and the subtitle text to translate and voice, sent to our servers; the translated lines are voiced by a text-to-speech provider (Google Cloud or Microsoft). If you choose the free voice, lines are sent directly from your browser to Google's text-to-speech service, or spoken by your device's own voices without any network request. | Generated audio is cached in server memory, not linked to your account, and cleared when the server restarts |
| Vibes (custom effects) | The effect you create: its name, settings, and either an image you upload or an image generated by Alibaba Cloud's AI model from the text prompt you write. | Stored until you delete the effect |
| Feedback form | Your message, the optional reply-to email you enter, and any screenshots you attach. Delivered to us by email (Gmail); not stored in our database. | Kept in our mailbox for as long as needed to handle it |
| Buying credits | Handled by Paddle (§5). We store the transaction record. | Purchase records kept 2 years (needed for refunds and disputes); other credit usage records auto-deleted after 90 days |
Retention above is enforced automatically by scheduled jobs in our database.
5. Third parties who process data for us
| Provider | Role | What they receive |
|---|---|---|
| Supabase | Database hosting | Account record, chat sessions, search history, credit transactions, custom effects |
| Alibaba Cloud (Qwen models) | Default AI provider for translation, comic reading, OCR assistance, detection, writing and image generation | The content of the specific request you made (text, image, page extract, prompt) |
| OpenRouter, and through it the maker of the model you pick — Google, Anthropic, OpenAI, DeepSeek, Xiaomi, MiniMax, NVIDIA, inclusionAI | AI answers in Page Assistant when you select one of these models | The conversation and any page content or image you chose to include |
| Sign-in; Google Translate; Cloud text-to-speech; Sheets/Docs API (§8); email delivery for feedback | OAuth identity check; text you translate; subtitle lines to voice; feedback messages | |
| Microsoft | Neural text-to-speech voices for YouTube dubbing | Subtitle lines to voice |
| Web search providers — Serper, Google Programmable Search, Tavily, DuckDuckGo | Web and news search for Page Assistant and News | The search query only — never your identity |
| dictionaryapi.dev | Dictionary definitions in the selection popup | The single English word you selected |
| Sentry | Error reporting on our servers (not in the extension) | Technical error details: error message, the feature involved, your account ID. Images, tokens, cookies and authorization headers are stripped before sending. |
| Paddle | Payment processing (Merchant of Record) | Your billing details, collected directly by Paddle. We never see or store your card number. |
Free model in Page Assistant. The optional "Free model" is served by providers that offer models at no cost through OpenRouter. Some of these providers may log prompts and use them to improve their models. Do not send personal or confidential content while the free model is selected; choose a paid model if this concerns you.
OCR for Free-mode comics and the AI-image detection models run on servers we operate ourselves; that content is not passed to a third party for those steps.
6. Why the extension needs each permission
| Permission | Why it is needed |
|---|---|
<all_urls> / activeTab / scripting | To read and translate the page you are currently on, and to draw the translation overlay and side panel. Content is read only when you invoke a feature. |
storage | To save your settings, notes, and sign-in session |
tabs | To know which tab a feature was invoked on, and to open the settings page |
contextMenus | The right-click "VexAI" submenu on selected text (Translate, Summarize, Explain, Reply), and — when Safe link check is enabled — the "Check link with AI" entry shown on links |
identity | Google sign-in |
cookies | Two narrow uses only: (a) when downloading an image that is protected against hotlinking, we re-attach the cookie you already have for that image's own site so the download succeeds; (b) we attach your youtube.com cookie when fetching YouTube subtitles. In both cases the cookie is sent only back to the site it belongs to. Cookies are never sent to VexAI or to any third party. |
offscreen | Runs the on-device OCR engine used by Snip & translate, which needs a worker in Manifest V3 |
declarativeNetRequestWithHostAccess | To set the correct Referer when fetching images from sites that block hotlinking |
Host access to translate.googleapis.com, www.googleapis.com, accounts.google.com | Google Translate requests made from your browser, Google sign-in, and the Google Sheets / Docs skills |
7. Google Sheets and Google Docs access
Signing in to VexAI asks only for your basic Google identity (openid, email, profile). Two further scopes exist, and they are requested separately and only at the moment you first open the Google Sheets or Google Docs skill — never during normal sign-in:
.../auth/spreadsheets— read and edit Google Sheets.../auth/documents— read and edit Google Docs
If you only use VexAI to translate and read, you are never asked to grant these at all.
We deliberately do not request any Google Drive scope. The extension cannot list, browse, or download files from your Drive — it can only act on the specific Sheet or Doc you have open at the time.
These scopes are used only by the Page Assistant's optional Google Sheets / Google Docs skills, and only when you have explicitly enabled that skill and are working on such a document. In that case:
- the relevant cell range or document content is sent to the AI model so it can answer or perform the edit you asked for;
- any edit is written directly from your browser to the Google API;
- we do not browse, list, index, or back up your Drive, and we do not store your Sheets or Docs content on our servers.
Every operation that writes to a Sheet or Doc shows a confirmation dialog first. That dialog lists the actual file ID, range and change taken straight from the request that is about to be sent — not just the AI's description of it — so you can check what will happen before allowing it.
VexAI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you never enable these skills, these scopes are never exercised. You can revoke access at any time from Settings → Page Assistant → Google Sheets & Docs connection → Revoke, or at myaccount.google.com/permissions. Signing out of the extension also revokes it automatically.
8. Shared caches
Image translations. To reduce cost and latency, translations of images are cached on our servers keyed by a hash of the image, and reused for anyone who later translates the identical image. The cache entry contains the extracted and translated text — it is not linked to your account or to any user identifier, and entries expire after 180 days. Pages you capture from the screen (rather than images loaded by the site) are never written to this cache.
Because the translated text of an image you process may be served to another user who processes the same image, do not use image translation on private or confidential images while this is enabled. You can turn it off: Settings → Comic → "Enable global translation cache". With it off, your translations are not written to the shared cache.
Dubbing audio. Voiced subtitle lines are cached in server memory keyed by a hash of the voice and text, so a popular video is only voiced once. The cache holds no user identifier and is cleared whenever the server restarts.
9. Features that never leave your device
These run entirely locally and make no network requests with your content:
- Gmail pre-send check — the confirmation dialog before you send an email. Your email content is analysed in the page and never transmitted.
- Safe-link check (automatic warning) — the warning shown when you click a link with a suspicious URL structure is computed entirely in the page. No link you hover, click, or visit is transmitted. The separate "Check link with AI" action is not local — see §4.
- Quick Notes — stored in
chrome.storage.localon your machine only. - On-device OCR in Snip & translate — the image is processed in your browser. The first time you use a language, the extension downloads that language's recognition data from
tessdata.projectnaptha.com; this download contains nothing about you or your image. - All extension settings and panel layout state.
10. Data stored on your own device
| Location | Contents |
|---|---|
chrome.storage.sync (synced by Chrome to your Google account) | Settings: languages, theme, enabled sites, translation mode |
chrome.storage.local (this device only) | Sign-in token and profile, a random installation ID (§3), quick notes, translation cache, panel state |
Uninstalling the extension removes both. Removing your server-side account requires a request — see §12.
11. Our website
The website at vexai.pyktools.com is a static site with no sign-in, cookies, analytics or tracking. It is hosted on GitHub Pages; like any web host, GitHub may log the IP address and browser details of visitors for security purposes, under GitHub's own privacy statement.
12. Your rights and choices
- Access / export — Settings → Account → Export data copies your local settings and data.
- Delete a conversation — Settings → Page Assistant → chat history, at any time.
- Delete your server-side data — email vexai.app@gmail.com from the address you signed up with. We will delete your account record, chat sessions, search history and custom effects, and confirm within 30 days. Purchase records are kept for the period in §4 where the law or payment disputes require it, and the hashed installation ID described in §3 is kept. (There is currently no self-service delete button; this is handled manually.)
- Delete local data — sign out, or uninstall the extension. Signing out keeps the installation ID (§3); uninstalling removes it.
- Withdraw Google access — see §7, or myaccount.google.com/permissions.
- Opt out of the shared image cache — see §8.
Depending on where you live you may have additional rights (access, rectification, erasure, portability, objection) under the GDPR or similar laws. Use the contact address above to exercise them.
13. Security
Traffic between the extension and our servers uses HTTPS. Access to your account data is protected by a signed session token, and database rows are isolated per user by row-level security. No system is perfectly secure; please report vulnerabilities to vexai.app@gmail.com.
14. Children
VexAI is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will remove it.
15. International transfers
Our infrastructure and AI providers operate in multiple regions, including outside your country of residence. By using the extension you understand your request content may be processed in those regions.
16. Changes to this policy
If we change how data is handled we will update this page and revise the "Last updated" date. Material changes will also be noted in the extension's release notes on the Chrome Web Store.
17. Contact
Questions, requests, or complaints: vexai.app@gmail.com