Privacy Policy
This Privacy Policy explains how we collect, use, and protect your personal information when you use our YouTube Parental Control Chrome Extension and website.
Last Updated: May 15, 2025
1. Information We Collect
When you use our YouTube Parental Control Chrome Extension and associated services, we may collect the following information:
- Account Information:
- Email address: Collected via OAuth (e.g., Google Sign-In) when you create an account or sign in. We use this to identify your account and communicate with you.
- Extension Usage Data:
- User Settings and Preferences: We store your configured settings for the extension, such as age range, content filters (blacklisted/whitelisted channels, flagged words), overlay preferences, and parental control configurations. This data is necessary to apply your desired parental controls.
- YouTube Video Interaction (Optional, based on features used): To provide content analysis and blocking, our extension processes information about YouTube videos you or users under your control attempt to view. This includes video metadata (title, description) and transcript content when available.
- Subscription Status: If you subscribe to a paid plan, we maintain a record of your subscription status (e.g., active, canceled, plan tier) to manage your access to premium features.
We do not collect or store any financial or credit card information directly. All payment processing is handled securely by our third-party payment processor, Stripe. Please refer to Stripe's Privacy Policy for more information on their data handling practices.
2. Chrome Extension Permissions
Our Chrome Extension requires specific permissions to deliver its features. We are committed to requesting only the permissions necessary for the extension to function correctly and transparently. Below is a detailed explanation of each permission and why it is needed:
identity
andidentity.email
:- Purpose: To authenticate you and access your email address for account management.
- Usage: These permissions allow the extension to use Chrome's identity API to facilitate OAuth 2.0 sign-in with providers like Google. This enables you to securely log into the extension. The
identity.email
permission specifically allows us to retrieve your email address, which serves as a unique identifier for your account, for communication, and to personalize your service experience. We do not access any other personal data from your Google account beyond what is necessary for authentication and email retrieval.
storage
:- Purpose: To store your extension settings, user preferences, and session information locally in your browser and sync essential settings across your devices.
- Usage: The extension uses Chrome's storage API (
chrome.storage.local
andchrome.storage.sync
) to save data such as your configured age range, lists of blacklisted/whitelisted channels, flagged words, parental control configurations, UI preferences, and authentication tokens (to keep you logged in).chrome.storage.sync
is used for settings that you would want to persist across different Chrome browsers where you are logged in, whilechrome.storage.local
is used for data specific to a single browser instance or for caching. This ensures your settings are remembered and applied consistently.
tabs
:- Purpose: To manage browser tabs for navigation, payment processing, and inter-component communication within the extension.
- Usage: The extension uses this permission to:
- Open new tabs to direct you to important pages, such as the extension's options page, our website for account-related actions (e.g., email-based login/signup), or the Stripe checkout page for managing subscriptions.
- Manage these tabs, for example, by monitoring the Stripe checkout tab for payment completion and then closing it.
- Facilitate communication between different parts of the extension, such as sending messages from the background script to content scripts that operate on YouTube pages.
cookies
:- Purpose: To manage cookies for specific domains, primarily to ensure a clean, secure, and reliable authentication experience with third-party OAuth providers (like Google or GitHub).
- Usage: The extension may use
chrome.cookies.getAll
andchrome.cookies.remove
to clear cookies associated with authentication provider domains before initiating new OAuth sign-in flows. This helps prevent conflicts with existing sessions or cached credentials, ensuring that you are prompted for the correct account or can sign in freshly. This is particularly useful for ensuring a smooth sign-in process if you use multiple accounts with an OAuth provider.
scripting
:- Purpose: To execute scripts in the context of web pages, specifically on YouTube, enabling the extension to interact with and modify page content as required for its parental control features.
- Usage: This is a core permission for our extension. It allows us to run our content scripts on YouTube pages. These scripts are responsible for:
- Analyzing video content (transcripts, metadata).
- Identifying elements on the page (e.g., video players, transcript buttons).
- Observing page navigations to apply controls to newly loaded videos.
- Implementing the video blocking or content overlay mechanisms based on your configured settings.
- Host Permissions (
*://*.youtube.com/*
,https://accounts.google.com/*
):- Purpose: To allow the extension to operate on specific websites.
- Usage:
*://*.youtube.com/*
: This permission is crucial for the extension to access and interact with all parts of the YouTube website. It's necessary for our content scripts to run, analyze video content, block videos, and display informational overlays as per your settings.https://accounts.google.com/*
: This permission is required to facilitate the Google OAuth authentication flow, allowing you to securely sign in to the extension using your Google account.
We are committed to using these permissions responsibly and only for the purposes stated. We do not use these permissions to track your browsing history across unrelated websites or to collect data beyond what is necessary for the extension's functionality.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the YouTube Parental Control Chrome Extension and our services.
- Authenticate your account and manage your access using Supabase as our backend provider.
- Analyze YouTube video transcripts and metadata to determine content suitability based on your configured settings.
- Apply your chosen parental control settings, including blocking or allowing videos and channels.
- Manage your subscription and provide access to relevant plan features.
- Communicate with you, including sending service-related notifications, updates, and responding to your support inquiries.
- Improve our services by understanding usage patterns and user feedback (on an aggregated and anonymized basis where possible).
- Ensure the security and integrity of our services.
4. Data Sharing and Disclosure
We do not sell your personal information to third parties. We may share your information only in the following limited circumstances:
- Service Providers: We may share information with third-party service providers who perform services on our behalf, such as:
- Supabase: For backend services, including database storage, authentication, and user management.
- Stripe: For secure payment processing for subscriptions. We do not store your full payment card details.
- Cloud hosting providers for our backend infrastructure.
- Legal Requirements: We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent fraud, act in urgent circumstances to protect the personal safety of users of the Service, or protect against legal liability.
- Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be sold or transferred as part of such a transaction as permitted by law and/or contract.
5. Data Security
We take the security of your data seriously and implement reasonable administrative, technical, and physical security measures to protect your personal information from unauthorized access, use, alteration, and disclosure. These measures include encryption, access controls, and secure development practices.
However, please note that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our services. We may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. You can request deletion of your account and associated data as described in the "Your Rights" section.
7. Your Rights and Choices
You have certain rights regarding your personal information, subject to local data protection laws. These may include the right to:
- Access the personal information we hold about you.
- Correct any inaccurate personal information we have about you.
- Delete your personal information.
- Object to or restrict the processing of your personal information.
- Data portability (receive your data in a structured, commonly used, and machine-readable format).
You can typically manage your extension settings directly within the extension. If you wish to exercise any of these rights, or delete your account, please contact us at parental.controls.extension@gmail.com. We will respond to your request within a reasonable timeframe.
8. Children's Privacy
Our service is designed to be used by parents or guardians to manage YouTube content for children. We do not knowingly collect personal information directly from children under the age of 13 (or the relevant age of consent in your jurisdiction) without parental consent. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us, and we will take steps to delete such information.
9. International Data Transfers
Your information, including personal data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including personal data, to the United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes, we will notify you by posting the updated policy on our website and updating the "Last Updated" date at the top of this policy. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
11. Contact Us
If you have any questions, concerns, or comments about this Privacy Policy or our data practices, please contact us at:
Email: parental.controls.extension@gmail.com