Privacy Policy
Effective date: 2026-07-20. Last updated: 2026-08-26.
This Privacy Policy explains how Youtube video summarizer ("we", "us") collects, uses, discloses, and protects information when you use our Chrome extension, the website at https://ytsummarizer.pro, and related services (together, the "Service"). We designed this policy to comply with theChrome Web Store User Data Policy, theGoogle API Services User Data Policy(including its Limited Use requirements), and the EU General Data Protection Regulation (GDPR) where it applies.
1. Who we are
Youtube video summarizer is provided by Stanmash Ltd, a private company limited by shares registered in England and Wales, United Kingdom under company number 17337841, with its registered office at Stoney Works, 8 Stoney Lane, London SE19 3BD, United Kingdom. Stanmash Ltd is the data controller for the personal data described in this policy. If you have any question about this policy or want to exercise a right described below, contact us at [email protected].
2. What we collect and why
We collect only what is necessary to run the Service. We do not sell personal information and we do not use it for advertising.
2.1 Data you provide
- Google account information (email address, Google account ID, display name). Collected only if you choose to sign in with Google to unlock the Pro plan. Used strictly to authenticate you and to identify your subscription.
- Video content you process. When you request an AI summary, the extension sends the transcript text — or the video ID our backend needs to fetch the captions itself — so the request can be processed by the AI provider.
- Feedback you send us. If you use the feedback form or the uninstall survey we receive the category you picked, the message you typed, and — only if you choose to fill it in — an email address so we can reply. We also attach the extension version, your country code, and your browser's user-agent string, which help us reproduce bugs. Nothing here requires an account, and we never link it to your Google account.
2.2 Data collected automatically
- Abuse-prevention identifiers. When you call our backend we temporarily store a hashed fingerprint derived from your plan tier and a truncated form of your IP address (a /16 IPv4 or /48 IPv6 prefix, not the full address). We use it exclusively to enforce quotas and rate limits and to detect automated abuse. It is not used to identify you personally or to build a marketing profile.
- Basic request metadata (timestamp, HTTP status, error type, response latency). Kept only in short-lived operational logs to keep the Service reliable and secure.
- Product and error analytics. We record which features are used and, importantly, when something fails — for example that a summary could not be generated, which step it failed at, and a short technical error code. Each event carries a random identifier generated on your device (not your Google ID, not your email, not your IP address), the extension version, and categorical fields such as the error code and whether you were signed in. Some events also carry the YouTube video ID — the public eleven-character code from the address bar, the same one anybody sharing that link would pass on. We include it so a refusal can be checked afterwards: having told someone their video has no subtitles, we need to be able to open it and see whether that was true. Crash reports may include a stack trace from our own code. When you press Upgrade in the extension and it opens our website, that same random identifier travels with the link, so the steps before and after the jump count as one visit rather than two strangers; it stays a random identifier on the website too, and still tells us nothing about who you are.
These events never contain video transcripts, video titles, the text of your summaries, your chat messages, or anything you typed. Without them a bug that breaks summaries for a whole group of users is invisible to us until somebody writes a review, which is why we treat this as necessary to keep the Service working rather than as marketing analytics.
2.3 Data stored locally in your browser
The extension stores your preferences (theme, copy format, autoOpen flag) and, if you sign in, your session token, in Chrome's storage.local. This data never leaves your device unless you sync it via Chrome yourself.
Your summary history is stored locally too, and only locally. Each summary you generate is kept on the device that made it — in the extension'sstorage.local (up to 200 summaries, 30 days) or, on this website, in your browser's localStorage (up to 50 summaries, 30 days). We do not keep a copy on our servers, which also means we cannot restore it for you. Clearing your browser data, uninstalling the extension, or using a different browser or device leaves you with an empty history, and the extension and the website each keep their own separate list even when you are signed in to the same account. You can delete individual entries or the whole history at any time from the History panel.
2.4 What we do NOT collect
- Your browsing history outside YouTube.
- The content of other tabs, forms, or pages.
- Keystrokes, mouse movements, screenshots, or any form of behavioural surveillance.
- Google account data beyond the profile fields listed above. We never request access to Gmail, Drive, Calendar, Contacts, or any other Google service.
3. Limited Use of Google user data
Our use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- use Google user data only to provide or improve user-facing features that are prominent in the Service (authentication and Pro entitlement);
- do not transfer Google user data to third parties except as necessary to provide the Service, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users;
- do not use Google user data to serve advertisements;
- do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data is aggregated and used for internal operations in accordance with the applicable privacy notices;
- do not sell Google user data.
4. How we use your data
We use the information above only for the following purposes:
- to deliver the AI summary you requested;
- to authenticate you and to keep track of whether you are on the Free or Pro plan;
- to enforce free-tier quotas and to prevent fraud, abuse, and denial-of-service attacks;
- to operate and maintain the Service (debugging, uptime, security);
- to reply to messages you send us;
- to comply with a legal obligation.
5. Legal bases (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your data on the following legal bases:
- Contract — to provide the Service you requested (Article 6(1)(b) GDPR).
- Legitimate interests — to keep the Service secure, prevent abuse, and maintain a working product, which includes the product and error analytics described in section 2.2 (Article 6(1)(f) GDPR). Those events are tied to a random per-install identifier rather than to you, and are used only to find and fix faults.
- Consent — for the waitlist email (Article 6(1)(a) GDPR). You may withdraw consent at any time.
- Legal obligation — where the law requires us to keep records or respond to lawful requests (Article 6(1)(c) GDPR).
6. Sharing and third parties
We share data only with the service providers ("sub-processors") we need to run the Service. Each of them is bound by their own privacy commitments:
- Google (Gemini API) — receives the transcript text needed to generate the summary. See theGoogle Privacy Policyand theGemini API terms. Gemini API data is not used by Google to train its models when accessed via a paid tier.
- Google (Sign-In) — used to authenticate you.
- Supadata — receives the URL of the YouTube video you asked about, and returns that video's caption text, when our servers cannot fetch the captions from YouTube directly. It receives no account details.
- Cloudflare, Inc. — hosts our backend Worker, KV storage, and static site. Processes traffic to keep the Service secure and reachable.
- Paddle (Paddle.com Market Ltd) — our payment provider and Merchant of Record. Processes payments and handles billing, taxes, and refunds for paid plans. We never see or store your full card number.
- PostHog (PostHog, Inc.) — receives the product and error analytics described in section 2.2. Data is processed on PostHog's EU infrastructure. No account identifiers and no email addresses are sent, and no video content — the public video ID may be included, never the transcript, the title, or the summary.
- Telegram (Telegram FZ-LLC) — feedback and uninstall-survey messages are delivered to a private chat we own, so a small team can read and act on them. The same chat receives two kinds of automated notification: fault notifications, which contain the error's technical title and counts only, and billing notifications, which tell us when a payment, cancellation, or refund happens. A billing notification contains the billing email address you gave Paddle, the amount, and Paddle's own reference ids — never your card details, and never anything about the videos you use the Service on.
We do not sell your personal information and we do not share it with data brokers, ad networks, or social networks.
7. International transfers
Our sub-processors process data in the United States and other countries. Where required, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism.
8. Data retention
- Transcripts and summaries. Held in memory only for the time needed to answer your request. We do not store them after the response is returned.
- Quota counters and abuse-prevention hashes. Automatically expire after 30 days.
- Operational logs. Retained for up to 30 days for troubleshooting, then deleted.
- Product and error analytics. Retained by our analytics provider for as long as the fault they describe is worth tracking, and in any case no longer than 12 months.
- Account records (email, Google ID, subscription status). Retained while your account exists and for up to 12 months after deletion to satisfy tax and accounting obligations.
- Feedback messages. Kept in our private Telegram chat for as long as the issue or idea they describe is still open. Ask us at [email protected] and we will delete yours.
- Billing notifications. The message that tells us a payment, cancellation, or refund happened stays in the same private chat for up to 12 months, alongside the account records it refers to. Ask us at [email protected] and we will delete yours.
9. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, California CCPA/CPRA, and similar laws), you have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate;
- delete your data ("right to be forgotten");
- object to or restrict our processing;
- receive a portable copy of your data;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local supervisory authority.
To exercise any of these rights, email[email protected]. We answer within 30 days. You may also revoke our access to your Google account at any time viaGoogle Account Permissions.
10. Security
All traffic to our backend is encrypted with TLS. Secrets and API keys live in Cloudflare Worker secrets, never in the extension bundle. The extension mounts its UI in a Shadow DOM to isolate it from YouTube's page scripts and other extensions. No security control is perfect; if you discover a vulnerability, please report it to[email protected].
11. Children
The Service is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced on this page with a new "Effective date" and, where required, by email or an in-app notice. Continued use of the Service after a change means you accept the updated policy.
13. Contact
For privacy questions, data-subject requests, or security reports, write to[email protected].
Youtube video summarizer is not affiliated with, endorsed by, or sponsored by YouTube, LLC or Google LLC. YouTube is a trademark of Google LLC.