Privacy Policy
This translation is provided for reference only. The Simplified Chinese version prevails.
Last updated: 2026-08-30
What We Collect
- Screenshots: screenshots you explicitly select are sent to our server for AI translation. They are used only for that single request and are discarded immediately after translation — never stored.
- Account information: your email address at sign-up/login, plus basic profile data returned by Google sign-in (email, Google user ID). Passwords are stored as salted PBKDF2 hashes; we cannot see plaintext.
- Anonymous identifiers: the website and extension each generate a separate random ID for first-party measurement of visits, install-link clicks, registration, translation, and purchase flows. They are not linked across the Chrome Web Store.
- Usage and conversion events: only fixed event types, timestamps, and daily translation counts. We do not include page addresses, images, source or translated text, user input, email, or payment details, and we do not use third-party advertising trackers.
What We Don't Collect
- No browsing history and no tracking of pages you visit
- No storage of your screenshots, source text, or translations
- We never see your card details (payments are processed by Creem)
Third-Party Services
- AI model services (SiliconFlow / Google Gemini): screenshots are sent to the currently enabled model provider at translation time, used only for that single inference.
- Creem: subscription payments and invoicing.
- Google: authentication for Google one-click sign-in.
- Cloudflare: server and database hosting.
Retention & Deletion
Account data (email and subscription status) is retained while your account is active. Raw first-party product analytics events are automatically deleted after 90 days. Contact us any time to delete your account and all associated data.
Extension Permissions
- activeTab and scripting: used only to capture the current tab when you click translate.
- storage: stores your settings and sign-in state (locally).
- identity: used for Google one-click sign-in.
- optional host_permissions (per-site grant): the content script is injected on a site only after you explicitly enable it for that site in the extension popup; it powers region selection and the translation overlay. Nothing is injected on sites you haven't authorized, and no other data is collected.
Contact
For privacy questions or deletion requests, contact: support@heehoo.org