隱私權政策/Privacy Policy
本頁為可公開存取的隱私權政策(靜態 HTML,不需登入、不需執行 JavaScript)。Markdown 原文見 GitHub。
我們收集什麼
本擴充功能沒有自有後端,不會把資料上傳到 SanHsien 的伺服器,也不販售使用者資料。
僅在你按下「摘要/翻譯/解釋/大綱」時,於本機讀取:
- 目前分頁的網址、標題
- 你選取的文字(翻譯/解釋)
- 頁面可見文字(摘要可在設定關閉;大綱預設附上)
上述內容只用來組成提示詞,寫入你自己的 ChatGPT 網頁輸入框。未按動作按鈕時,不會讀取或傳送頁面內容。
設定(網域、模板等)存在 chrome.storage.sync,並隨你的 Chrome 同步帳戶由 Google 處理同步。
我們如何使用
- 提示詞只在本機組成並寫入 ChatGPT 輸入框。
- 是否送出訊息由你在 ChatGPT 介面決定。
- 資料用途僅支援本產品單一功能:在側邊欄使用 ChatGPT,並依你的操作處理目前頁面/選取。
我們與誰分享
- 不會把頁面內容分享給 SanHsien 或本專案伺服器(沒有後端)。
- 寫入 ChatGPT 後,若你送出,內容由 OpenAI/ChatGPT 依其服務條款與隱私政策處理。本專案非 OpenAI 官方產品。
- Chrome 同步儲存由 Google 依 Chrome/Google 帳戶政策處理。
網路與安全相關行為
為了在 Chrome 側邊欄 iframe 載入 ChatGPT,擴充功能會用 declarativeNetRequest 移除 ChatGPT 網域回應中的 Content-Security-Policy 與 X-Frame-Options。這會削弱該網域的 clickjacking 防護。
主機權限包含 http://*/*、https://*/*,僅為在你點擊動作時以 scripting 讀取當前內容分頁;不常駐掃描所有分頁,也不追蹤瀏覽紀錄。
Chrome Web Store 使用者資料政策
本產品處理的資料僅用於上述單一用途。若有使用 Google API 或 Chrome 同步所收到的資訊,將遵守 Chrome Web Store User Data Policy,包含 Limited Use 要求。
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
聯絡
安全與隱私問題:sanhsien (at) gmail.com(標題加 [PRIVACY] 或 [SECURITY])。
Privacy Policy (English)
What we collect
This extension has no backend of its own. It does not upload data to SanHsien’s servers and does not sell user data.
Only when you click Summarize / Translate / Explain / Outline does it read locally:
- the current tab’s URL and title
- your selected text (for Translate / Explain)
- visible page text (optional for Summarize; included by default for Outline)
That text is used only to build a prompt and insert it into your own ChatGPT web input box. Page content is not read or sent until you click an action.
Settings (origin, templates, and similar) are stored in chrome.storage.sync and synced by Google with your Chrome profile.
How we use data
- Prompts are composed on-device and written into the ChatGPT input box.
- You decide whether to send the message in the ChatGPT UI.
- Data is used only to support the extension’s single purpose: ChatGPT in the Chrome side panel, acting on the current page / selection at your request.
Sharing
- Page content is not shared with SanHsien or any project server (there is none).
- After insert, if you send the prompt, OpenAI / ChatGPT processes it under their terms and privacy policy. This project is not an official OpenAI product.
- Chrome sync storage is handled by Google under Chrome / Google Account policies.
Network and security-related behavior
To load ChatGPT in a side-panel iframe, the extension uses declarativeNetRequest to strip Content-Security-Policy and X-Frame-Options from ChatGPT-domain responses. That weakens clickjacking protection for those domains.
Host permissions include http://*/* and https://*/* so that, when you click an action, scripting can read the active content tab. The extension does not scan all tabs in the background and does not keep a browsing history.
Chrome Web Store user data policy
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact
Privacy and security: sanhsien (at) gmail.com with subject [PRIVACY] or [SECURITY].