Chrome Extension

隱私權政策
字幕通:雙語字幕與 AI 影片摘要

最後更新:2026 年 8 月 16 日 · 生效日:2026 年 8 月 16 日

一句話版本:這個擴充功能沒有伺服器。開發者收不到、也看不到你的任何資料。字幕文字只會直接送到你自己設定的 AI 供應商,而且只在你按下按鈕的當下。

1. 這份政策涵蓋什麼

本政策說明 Chrome 擴充功能「字幕通:雙語字幕與 AI 影片摘要」(以下稱「本擴充功能」)如何處理資料。安裝並使用本擴充功能即表示你了解並同意本政策。

2. 開發者不收集任何資料

本擴充功能沒有後端伺服器。開發者不經營任何接收使用者資料的服務,因此:

3. 哪些資料會離開你的電腦

只有在你主動點擊「翻譯」或「產生摘要」時,本擴充功能才會把下列內容送出:

資料送到哪裡用途
該部影片的原文字幕文字 你在設定頁指定的 AI 供應商:OpenAI、Anthropic(Claude),或你自行填寫的相容 API 網址 產生譯文或摘要
影片標題;若開啟「摘要帶入影片資訊」則另含頻道名稱、影片長度、發布日期、標籤與說明欄文字 提供上下文,讓譯文與摘要更準確
你的 API Key(放在 Authorization 標頭) 向該供應商驗證身分並計費
youtube.com 的字幕請求 YouTube 取得該部影片既有的字幕軌(與你手動開啟 CC 字幕是同一個介面)

沒有任何資料會送到開發者、開發者的伺服器或其他第三方。本擴充功能不會替你把資料送去你沒有指定的地方。

關於你的 API Key

API Key 儲存在你電腦的 chrome.storage.local,只有本擴充功能讀得到。它不會被送到開發者手上,也不會出現在網頁內容中:讀取與使用金鑰的程式只跑在 background service worker 裡,注入 YouTube 頁面的程式碼只會被告知「金鑰是否已設定」,拿不到金鑰本身。

4. 存在你電腦裡的資料

下列資料只存在本機,不會同步到雲端:

快取存在的唯一目的,是讓你重看同一部影片時不必再向供應商付一次錢。

你可以隨時清除:

5. 第三方服務

你送出的字幕內容會受到你所選供應商的政策約束,這部分不在開發者的控制範圍內。請自行參閱:

若你在設定頁填入自訂的 API Base URL,等於選擇把資料送往該服務,其資料處理方式請洽該服務提供者。Chrome 會在你儲存自訂網址時,另外詢問你是否授權連線到該網域。

6. 權限用途說明

權限為什麼需要
storage保存你的設定與本機快取
unlimitedStorage長片的字幕與摘要容易超過預設的 5 MB 配額,沒有這個權限快取會寫入失敗,導致重複扣款
https://www.youtube.com/*讀取影片的字幕軌,並在播放頁面上繪製字幕疊層與側邊面板
https://api.openai.com/*當你選擇 OpenAI 作為供應商時,送出翻譯/摘要請求
https://api.anthropic.com/*當你選擇 Claude 作為供應商時,送出翻譯/摘要請求
https://*/*(選用)僅在你自行填寫其他相容 API 網址時,由 Chrome 針對該網域個別詢問你授權;使用預設供應商者永遠不會被要求此權限

7. 資料保存與刪除

因為開發者不持有任何資料,也就沒有可供刪除的伺服器紀錄。所有資料的保存與刪除完全由你在自己的電腦上掌控(見第 4 節)。若要求刪除已送往 AI 供應商的資料,請直接聯絡該供應商。

8. 兒童隱私

本擴充功能並非針對 13 歲以下兒童設計,且不會刻意收集兒童的個人資料。使用本擴充功能需要自行申請 AI 供應商的 API 帳號,該類帳號通常本身即有年齡限制。

9. 資料安全

所有對外連線一律使用 HTTPS。API Key 僅存放於瀏覽器本機儲存空間,且限制在 background service worker 中使用,不注入網頁。由 AI 回傳的內容一律以純文字方式寫入畫面(不使用 innerHTML),避免模型輸出被當成程式碼執行。

10. 政策變更

本政策如有修改,會更新本頁最上方的「最後更新」日期。若變更涉及資料處理方式的實質調整,會一併在擴充功能的更新說明中標示。

11. 聯絡方式

有任何隱私相關問題,請來信:service@dimanyen.com

In one sentence: this extension has no server. The developer never receives or sees any of your data. Subtitle text goes directly to the AI provider you configured, and only at the moment you click a button.

1. Scope

This policy explains how the Chrome extension “字幕通:雙語字幕與 AI 影片摘要” / “Subtitle Buddy — Bilingual Subtitles & AI Video Summary” (the “Extension”) handles data. By installing and using the Extension you acknowledge this policy.

2. The developer collects nothing

The Extension has no backend server. The developer operates no service that receives user data. Accordingly, the Extension does not:

3. What leaves your computer

Only when you explicitly click “Translate” or “Generate summary” does the Extension transmit:

DataRecipientPurpose
The original caption text of the current video The AI provider you selected in the options page: OpenAI, Anthropic (Claude), or a custom OpenAI-compatible URL you entered yourself Produce the translation or summary
The video title; plus channel name, duration, publish date, tags and description text if “include video info in summary” is enabled Provide context so the output is accurate
Your API key (sent in the Authorization header) Authenticate and bill your own account with that provider
Caption requests to youtube.com YouTube Retrieve the video's existing caption track — the same endpoint used when you turn on CC manually

Nothing is sent to the developer, to the developer's servers, or to any other third party. The Extension never transmits your data to a destination you did not configure.

About your API key

The key is stored in chrome.storage.local on your machine and is readable only by this extension. It is never sent to the developer and is never exposed to web page content: only the background service worker reads and uses it, while the script injected into YouTube pages is told merely whether a key is configured, never the key itself.

4. Data stored on your device

The following is stored locally and is not synced to any cloud:

The cache exists for one reason only: so that re-watching a video does not charge your API account twice.

You can clear it at any time:

5. Third-party services

Content you submit is subject to the policies of the provider you chose, which is outside the developer's control:

If you enter a custom API base URL, you are choosing to send data to that service; consult its operator for its data practices. Chrome will separately prompt you to grant access to that origin when you save the custom URL.

6. Permission justification

PermissionWhy it is needed
storagePersist your settings and the local cache
unlimitedStorageCaptions and summaries for long videos can exceed the default 5 MB quota; without it, cache writes fail and you would be billed again for videos already processed
https://www.youtube.com/*Read the video's caption track and draw the subtitle overlay and side panel on the watch page
https://api.openai.com/*Send translation/summary requests when OpenAI is the selected provider
https://api.anthropic.com/*Send translation/summary requests when Claude is the selected provider
https://*/* (optional)Requested by Chrome for one specific origin only if you enter your own OpenAI-compatible endpoint; users on the default providers are never asked

7. Retention and deletion

Because the developer holds no data, there are no server-side records to delete. Retention and deletion are entirely under your control on your own device (see section 4). To request deletion of data already sent to an AI provider, contact that provider directly.

8. Children's privacy

The Extension is not directed at children under 13 and does not knowingly collect personal information from them. Using it requires your own API account with an AI provider, which typically carries its own age requirements.

9. Security

All outbound connections use HTTPS. The API key is confined to browser-local storage and to the background service worker; it is never injected into web pages. Model output is always rendered as plain text (innerHTML is never used), so returned content cannot be executed as code.

10. Changes to this policy

Material changes will be reflected in the “last updated” date at the top of this page and noted in the extension's release notes.

11. Contact

For privacy-related questions: service@dimanyen.com