HUH? ← BACK TO LAUNCH

THE IMPORTANT STUFF // NO FINE-PRINT GAMES

PRIVACY
POLICY.

EFFECTIVE DATE: SEPTEMBER 17, 2026

01 INTRODUCTION

This policy explains how Huh? — Video Explainer (the “Extension”) collects, uses, shares, stores, and deletes information when you use its YouTube explanation features.

02 INFORMATION WE COLLECT

  • Account data: Your email address, user ID, and authentication session data when you create or use an account. Supabase provides authentication and account storage.
  • YouTube video data: When you click “Huh?” on a YouTube video, the Extension reads the current video ID and timestamp in your browser to identify the selected moment.
  • Transcript context: After you click “Huh?”, the Extension requests available English captions from YouTube through your browser connection. It selects surrounding transcript text, normally about 60 seconds before and 15 seconds after the selected moment, and sends only that selected context to our backend hosted on Render.
  • AI request data: The selected transcript text, including the confusing passage and its surrounding transcript context, is sent to the Google Gemini API with instructions for generating the explanation.
  • Usage data: We store daily explanation counts and related timestamps to enforce the beta allowance of 10 explanations per account per day.
  • Local settings: Obsidian vault preferences, authentication state, and a limited cache of recent explanations may be stored through Chrome storage on your device.
  • Technical and security data: Our backend processes the client IP address for rate limiting and may log timestamps, IP addresses, user or video identifiers, request outcomes, and error details for security, debugging, and service reliability.

We do not continuously monitor your browsing history, track you across websites, or collect YouTube data until you use an Extension feature.

03 HOW WE USE INFORMATION

We use this information only to:

  • Generate explanations and study material for the YouTube moment you select.
  • Authenticate accounts and maintain sessions.
  • Enforce daily beta and rate limits.
  • Save user-selected settings and recent results locally.
  • Prevent abuse, diagnose failures, and maintain the service.

We do not sell personal data or use it for personalized advertising, credit decisions, or unrelated profiling.

04 SERVICE PROVIDERS AND DATA SHARING

We share data only as needed to provide, secure, or maintain the Extension:

  • Render: Hosts our backend and processes API requests, the selected surrounding transcript context, generated results, and application logs.
  • Google Gemini API: Receives the selected transcript passage, surrounding transcript context, explanation level, and prompt instructions to generate an answer.
  • Supabase: Provides account authentication and stores account and daily usage records.
  • YouTube: The Extension requests captions for the video selected by the user through the YouTube page open in the browser.

Google’s treatment of Gemini API inputs and outputs depends on the applicable service tier and is governed by the Gemini API Terms.

We may also disclose information when required by law or when reasonably necessary to protect users, the Extension, or others from fraud, abuse, or security threats.

05 STORAGE AND SECURITY

User data is transmitted over HTTPS. Account and service data is stored in Supabase with access controls. Secrets used by the backend are not included in the Extension package.

The Extension processes the full caption response transiently in browser memory to select the nearby passage. The active Extension does not send the full transcript to our backend, and the backend does not store the selected transcript context in the application database.

Chrome storage remains on the user’s device or Chrome profile. Render service files are ephemeral and may be removed whenever the service restarts or redeploys.

No method of transmission or storage is completely secure. We use reasonable safeguards but cannot guarantee absolute security.

06 DATA RETENTION

  • Account data: Retained while the account is active. After a verified deletion request, we aim to delete the account and associated active records within 30 days.
  • Usage data: Daily counters are retained while the account is active to enforce the beta allowance and evaluate service reliability. They are deleted with the account within 30 days of a verified deletion request.
  • Server logs: Render currently retains application logs for up to 7 days on our Hobby plan. If our hosting plan changes, Render may retain them for up to 30 days.
  • Transcript data: Full captions are used transiently in browser memory. The selected surrounding context is processed transiently by Render and Gemini to generate the requested result; we do not intentionally retain it after the request completes, except where portions may appear temporarily in server or provider security/error logs under their stated retention practices.
  • Local data: Retained in Chrome storage until you clear the Extension’s data or uninstall it, subject to Chrome’s own synchronization behavior.

Supabase, Google, YouTube, and Render may retain data independently under their own policies and legal obligations.

The v1 beta does not offer paid checkout or collect payment information. If paid Pro access is introduced later, we will update this policy and the Extension's in-product disclosure before collecting payment-related data.

07 YOUR CHOICES AND DELETION REQUESTS

You can stop new collection by not using the Extension or by uninstalling it. You can clear locally stored data using Chrome’s extension or site-data controls.

To request account deletion, contact us from the email address associated with your account. We may ask you to verify ownership before deleting data.

08 CHROME WEB STORE LIMITED USE DISCLOSURE

Our use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

We use and transfer this information only to provide or improve the Extension’s disclosed, user-facing features and for permitted security, legal, and operational purposes.

We do not use or transfer this information for personalized advertising, unrelated profiling, or sale to data brokers. Humans do not read user data except with consent or where permitted for security, legal, or aggregated operations.

09 CHANGES TO THIS POLICY

We may update this policy when the Extension’s practices or service providers change. The effective date above identifies the latest version.

10 CONTACT

Questions and verified deletion requests can be sent to vidhanvyrs@gmail.com.