Privacy
What Cherrypick keeps, sends, and deletes
Written from the extension’s code, version 0.1.0. The extension has no account and no Cherrypick server: it talks only to YouTube and to the evaluation provider, TypeSafe’s Jev.
At a glance
- Account
- None. There is no sign-in, and the extension uses no Cherrypick server.
- Where data lives
- In your Chrome profile: the extension’s local and session storage, and IndexedDB. Nothing uses Chrome sync.
- What leaves your browser
- Requests to YouTube for the videos you scroll past, sent without your cookies. With Live Jev selected, evaluation requests to TypeSafe, with your token.
- Your token
- Kept in extension storage, which is not encrypted. By default it is held in memory and cleared when the browser closes.
- This website
- No analytics and no cookies. Its server logs are described in section 6.
Stored in your browser
Everything is local to your Chrome profile. Cherrypick encrypts nothing itself, and Chrome’s extension storage is not an encrypted vault.
| Data | Where | Kept until | Cleared by |
|---|---|---|---|
| Profiles | Extension local storage | You delete them | Delete, Delete profiles |
| Active profile choice | Extension local storage | You change or delete it | Delete profiles |
| Consent record (the time you accepted) | Extension local storage | No control removes it | None |
| Session: a copy of the active profile, the threshold, every video seen this session (ID, title, channel, duration), attempts used and the allowance | Extension local storage | You start a new session | New session |
| Chosen provider | Extension local storage | You change it | None |
| Provider token (default) | Extension session storage, in memory | The browser closes | Remove token |
| Provider token (Remember on this device) | Extension local storage, on disk, unencrypted | You remove it | Remove token |
| Provider diagnostics for the last 50 requests: video ID, start time, latency, HTTP status, outcome, a short error note written by the extension, token usage, model, question and evidence-unit counts, and citation counts. No token, request body or caption text | Extension session storage | The browser closes | None |
| Evaluation results: video ID, title, channel, duration, verdicts and answers, the cited caption lines, token usage | IndexedDB | 24 hours, at most 100 results, 20 MB in total | Clear history |
| Cached captions, video metadata and pasted transcripts | IndexedDB | 24 hours, 20 MB in total | Clear cached captions |
Results and captions share one 20 MB cap; beyond it, or beyond 100 results, the least recently used are removed first. No control removes the consent record or the provider choice, and the video titles and channels in the session record go only when you start a new session.
Sent over the network
Every request the extension makes. It may contact only www.youtube.com and api.typesafe.ai.
www.youtube.com· YouTube
- Purpose
- Set up a YouTube client session: once per background worker lifetime, and again on the next video after an acquisition fails (other than a caption download error)
- Sent
- Nothing beyond the address
- Credentials
- None. Cookies are omitted, and any cookie, authorization or X-Goog header is stripped.
- Purpose
- Get a video’s details and caption track list
- Sent
- One video ID, with the YouTube client context: client name and version, interface language and region, your time zone and UTC offset, the visitor ID YouTube issued at session setup, and generic device and browser fields set by the library (not read from your browser). Chrome adds the current YouTube page as the referrer.
- Credentials
- None. Cookies are omitted.
- Purpose
- Download that video’s timed captions
- Sent
- The caption address YouTube returned, checked to be on www.youtube.com
- Credentials
- None. Cookies are omitted, and any cookie, authorization or X-Goog header is stripped.
Only for videos you scrolled past, while a session is running and the tab is in the foreground, one video at a time. This happens with either provider, including Fixtures.
api.typesafe.ai· TypeSafe (Jev), the evaluation provider
May be charged to your account- Purpose
- Evaluate one video against your profile
- Sent
- The video’s title, channel, description and duration; its caption text split into evidence units, or your pasted transcript; your goal, viewer context and instructions, with each criterion and question.
- Credentials
- Your token, in the Authorization header. No cookies.
Only with Live Jev selected, a token saved, consent given, and the session running and under its limit, after the attempt is counted. The Fixtures provider never calls it.
Nothing else. The extension sends no analytics or telemetry. The watch page, the Skip button, threshold changes and cached results send nothing.
Your provider token
You choose how long Chrome keeps it. It is entered on the extension’s settings page, and no extension message ever returns it.
This browser session
Default- Held in memory, in Chrome’s session storage
- Cleared when the browser closes, and when the extension is reloaded or updated
Remember on this device
- Written unencrypted to the extension’s local storage, on disk
- Kept until you remove it
- Anyone with access to your Chrome profile or disk, or malware running as you, could read it
Either way, only the extension’s background reads it, to send it to api.typesafe.ai. It is never synced, exported or logged. The YouTube page’s content script cannot read extension storage.
Deleting your data
On the extension’s settings page, except New session, which is in the side panel. Each control is independent.
Remove token
Clears: Your token, from both session and local storage.
Keeps: Results, captions, profiles, session.
Clear history
Clears: All evaluation results. Recommendations and Skip buttons that depend on them disappear at once.
Keeps: Cached captions, profiles, token, session usage.
Clear cached captions
Clears: Cached captions, metadata and pasted transcripts.
Keeps: Results, profiles, token, session usage.
Delete
Clears: One profile. If it was active, the session’s copy of it is cleared and analysis pauses.
Keeps: Results already cached for it (unused until they expire or you clear history), captions, token.
Delete profiles
Clears: All profiles and the active profile choice.
Keeps: Results, captions, token.
New session
Clears: The list of videos seen. The allowance resets to 20.
Keeps: Results and captions.
Results and cached captions also expire on their own after 24 hours. Provider diagnostics have no button; they go when the browser closes.
This website
- Analytics
- None. This site sets no cookies, stores nothing in your browser, and loads no third-party scripts, fonts or trackers.
- Server logs
- This site and the extension ZIP are served by the operator’s own web server, on Server providerto be supplied. For each request, its access log records your IP address, the time, the page or file requested, the response status and size, and your browser’s user agent. For requests the server cannot complete, its error log records your IP address, the time, the request, the host name and the referring page. Kept for Container logs rotate at 10 MB per file, with up to 5 files retained; no maximum retention period is configured.
- Downloads
- Downloading the ZIP is an ordinary request to the same server, logged the same way. No sign-in, no form.
Operator and contact
- Operated by
- eupthere
- Address
- Postal addressto be supplied
- Privacy contact
- [email protected]