← Back to Home

Privacy Policy

Effective: 4 October 2026 | Version: 7.0.1

Summary

1. What We Collect

Nothing in this section is collected "always". Account information is kept while you have an account. Usage analytics is collected while its switch is on, and it is on by default. The rest is stored only when you use the feature that needs it.

1.1 Account Information (When You Have an Account)

You create an account on our website, vcpeai.aoneahsan.com, with Google sign-in. The extension has no Google sign-in of its own and asks for no identity permission. It connects to your website account: press "Connect to your account", a tab opens on the website, both show the same short code, and you press "Connect this browser" there. This works the same on Chrome, Edge and Firefox.

Data Why Where it is kept
Email address To identify your account and to answer you Supabase
Name Shown in the extension and on the website Supabase
Profile photo (the address of the photo, which Google gives us at sign-up) Shown in the extension and on the website Supabase
Google account id (stored on the profile when the account is created) To tie the account to the Google account you signed in with Supabase
The browsers you connected (see 1.3) So you can see where your account is connected Supabase
When you joined and when you were last active Account upkeep Supabase

We do not receive your Google password. "Sign out" in the extension disconnects that browser only. Your account and its data stay until you delete them.

1.2 Location Data

Data How it is collected When
Timezone and browser language Read from your browser Always read in the browser
Country, region and city Your browser sends your IP address to ipapi.co, which answers with an approximate location Only while Usage analytics is on, and at most once a day
A location you type in Settings → Privacy & Data → Your Location Only if you enter one

The IP lookup goes from your browser straight to ipapi.co. We receive the country, region and city it returns, and we do not store the IP address.

The country, city and timezone are saved to your profile only while Usage analytics is on and an account is connected. A location you type in replaces the detected one there, under the same condition. The region stays in your browser.

Turn Usage analytics off and the IP lookup does not run.

1.3 Device Information

Data Why When
Browser (Chrome, Edge or Firefox), operating system (Windows, macOS or Linux) and extension version Compatibility, fixing problems, support Sent with each usage event while Usage analytics is on
For a connected browser: a device name (for example "Chrome on Linux"), the browser, the operating system, the extension version and when it was last seen So you can see where your account is connected Kept while that browser is connected to an account

The extension also keeps a fuller record in your browser for the Privacy & Data tab and for your export: browser version, screen size and language.

1.4 Usage Analytics (On by Default, One Switch)

Settings → Privacy & Data has a switch named Usage analytics. It is on by default, and it works the same with and without an account.

While it is on:

Data Example Who it covers
Usage events: the event name, the hostname of the site, your browser, your operating system, the extension version, a random session id, and your account when one is connected "speed changed" on "youtube.com", Chrome, 16.0.0 Everyone, with or without an account
Which sites you used the extension on, counted by site name "youtube.com", 12 times A connected account
Which features you used, counted "loop", "screenshot" A connected account
Which speeds you used, counted 1.5x, 2x A connected account
An approximate location (see 1.2) Country and city Saved to the profile of a connected account

An event carries the site's hostname. It does not carry the address or the title of the video you were watching.

While it is off, no usage event is recorded or sent, no site, feature or speed is counted, and the location lookup does not run. Anything waiting to be sent is discarded when you turn it off.

On Firefox, the browser asks for two optional data permissions. Usage events are sent only if you allow "technical and interaction data". Page content (a screenshot you upload, a transcript you save, captions for an AI run) is sent only after you allow "website content".

We use this to see which sites and features people use, and to decide what to fix first.

1.5 Data You Save or Sync

Without an account, your settings, keyboard shortcuts, filter presets, per-video and per-playlist speeds and playback positions are stored in your browser, and they stay there.

With a connected account, the following is stored on our servers, each item only when you save it:

Data Stored when
Settings and keyboard shortcuts Cloud sync is on
Notes you write on a video You save a note
Watch-later items You add a video to the list
Screenshots You choose a cloud action for screenshots in Settings (Upload to Cloud, or Cloud + Clipboard)
Extracted video details You use the feature that extracts them
Transcripts You save one to your account
Flashcards, learning paths and collections You create them on our website
Messages, feature requests and issue reports you send us You send one

A note, a watch-later item, a screenshot, extracted details and a saved transcript are each stored with the title and address of the video they belong to. That is the only way those features can show you the video again.

We keep no record of the videos you watch.

Screenshots are stored as files in FilesHub. Everything else on this list is stored in Supabase.

Export/Import Settings writes a JSON file to your device and reads it back in your browser. We do not receive that file.

Picture-in-Picture on scroll and auto-skip work inside the page and store nothing. A skip can be counted as a usage event while Usage analytics is on.

1.6 Microphone Access (Screen Recorder)

The Screen Recorder can record your microphone along with the screen, and only if you choose that when you start a recording. Your browser shows its own permission prompt, and you can deny or revoke access at any point.

Feature Accesses What happens to the data
Screen Recorder Microphone (optional) Recorded in your browser and saved to your device. It is not uploaded to us.

1.7 AI Features (Optional — Off Until You Use Them)

Video Controls Plus includes optional AI features: summarizing a video from its captions, and writing help on LinkedIn. They do nothing until you start them. When you use one, only the specific text it needs is sent to the AI provider you choose — a video's caption/transcript text for a summary, or the text you are drafting for writing help.

What you choose Where your text goes
The shared allowance (needs a connected account, 3 runs a day) To our server, which passes it to OpenAI on our key and returns the answer
Your own OpenAI or Anthropic key Straight from your browser to the provider you chose. It does not pass through us.
A local model It stays on your device.

We do not store the text of an AI request or its answer. For the shared allowance we keep a count of the runs you used that day, and nothing else. A key you add is stored in your browser and is not sent to us. Your own key or a local model needs no account.

2. Switches in Settings → Privacy & Data

These are the four switches on that tab, with what each one does today.

2.1 Usage Analytics and Error Tracking

Switch Default What it controls
Usage analytics On Everything in 1.4, and the IP location lookup in 1.2. The events go to our own database in Supabase, and to no analytics company.
Third-Party Error Tracking On Crash and error reports sent to Sentry. Off, the extension sends none.
Settings Sync On Whether a connected account stores your settings on our servers. It does nothing without an account.

The extension loads no Firebase Analytics, no Microsoft Clarity and no Amplitude. Those exist on our website only, and there they are off until you turn them on (see 5.5).

2.2 Marketing Communications

This switch is off by default, and it controls one thing. Turned on, the extension may show an occasional browser notification about new features or another product of ours. Left off, it shows none.

We send no marketing email, whatever this switch is set to. The email we do send is listed in 4.3.

2.3 In-App Promotional Content

Video Controls Plus may display promotional content within the extension interface. This content is designed to inform you about other products and services from Zaions that may be useful to you. This promotional content:

Note: Browser notifications about new features or other products are shown only when "Marketing Communications" is on. Promotional cards inside the extension are shown either way, and you can dismiss each one.

3. Information We Do NOT Collect

4. How We Use Your Information

4.1 To run the product

4.2 To improve it, while the switches are on

4.3 Email we send

We send three kinds of email, and each one follows something you did:

We send no marketing email.

5. Third-Party Services

These are the companies and services that handle your data, what each one handles, and when it is contacted.

5.1 Supabase: database and sign-in

Your account, everything in 1.5 except stored files, and the usage events in 1.4. Sign-in runs through Supabase with Google as the only provider.
Privacy policy: supabase.com/privacy

5.2 Google: sign-in and website hosting

Google signs you in and gives us your email, name, photo and Google account id. Firebase Hosting, a Google service, serves our website.
Privacy policy: policies.google.com/privacy

5.3 FilesHub: stored files and email

Screenshots and other files you upload are stored in FilesHub. FilesHub also delivers the email in 4.3, so it handles your email address and name for those messages.

5.4 Sentry: error reports

In the extension, error reports go to Sentry while "Third-Party Error Tracking" is on, with your account id when one is connected. Off, none are sent.

On the website, error reports and visit replays are sent to Sentry only after you turn on "Third-party Analytics" under "Privacy preferences" in the website's footer. A replay masks all text and everything you type, and it blocks images and video.
Privacy policy: sentry.io/privacy

5.5 Website analytics

This section is about vcpeai.aoneahsan.com only. The extension loads none of these tools.

Our own page-view count is first-party. It is stored in our database in Supabase and goes to no other company.

Third-party tools are off by default. They start only if you turn on "Third-party Analytics" under "Privacy preferences" in the website's footer:

Tool What it does Also contacts
Firebase Analytics Counts page views and events
Amplitude Event analytics sr-client-cfg.amplitude.com
Microsoft Clarity Session recordings and heatmaps c.bing.com
Sentry Error reports, with a masked visit replay (see 5.4)

A "Privacy preferences" link in the website's footer reopens these choices at any time.
Privacy policies: firebase.google.com/support/privacy · amplitude.com/privacy · privacy.microsoft.com/privacystatement

5.6 ipapi.co: approximate location

While Usage analytics is on, your browser sends your IP address to ipapi.co at most once a day and receives a country, region and city. We do not store the IP address.

5.7 OneSignal: website push notifications

The website loads OneSignal only after you turn on "Push Notifications" under "Privacy preferences" in the website's footer. It is off by default.

5.8 AI providers: OpenAI and Anthropic

Used only when you start an AI feature (see 1.7). On the shared allowance, our server passes your text to OpenAI. With your own key, your browser sends it straight to OpenAI or Anthropic, whichever you chose. A local model sends nothing off your device.
OpenAI: openai.com/policies/privacy-policy · Anthropic: anthropic.com/legal/privacy

5.9 Services a feature contacts, only while that feature is on

Each of these is contacted by your browser, not by our servers, and only when you use the feature named.

Service Contacted when What is sent
sponsor.ajay.app (SponsorBlock) SponsorBlock is on The id of the YouTube video and the segment categories you chose to skip
api.mymemory.translated.net (MyMemory) Netflix subtitle translation or dual subtitles is on The subtitle text to translate and the language pair
www.omdbapi.com (OMDb) Netflix ratings, with your own OMDb key The title, and your key
video.google.com/timedtext (Google) An AI summary fetches a video's captions and the page offers no caption track The id of the video

6. Data Retention

Data How long it is kept
Account information and everything in 1.5 Until you delete it, or delete your account
Stored files (screenshots) Until you delete the file, or delete your account
Usage events (1.4) 90 days. After that only daily counts remain, and a daily count holds no account and no session id.
Site, feature and speed counts on a connected account Until you delete your account
Data in your browser (settings, presets, speeds, positions) Until you reset settings, clear browser data or remove the extension
Exported files On your device. We do not have them.
Sentry, Firebase Analytics, Clarity, Amplitude As each service's own policy states

Deleting your account also deletes the usage events that carry your account id. Events recorded while no account was connected are not linked to you, and they expire after 90 days.

6.1 Data created before version 16.0.0 (transition, October 2026)

Until version 16.0.0 your account data was kept in Google Firestore. From 16.0.0 it is kept in Supabase. We are moving the existing data across.

While the move is under way, data created before 16.0.0 is still held in Firestore, and an account that existed before 16.0.0 starts empty in the new version until its data has been moved. Once the copy is confirmed in the new database, we delete the old data from Firestore.

Deleting your account in 16.0.0 removes it from the new database at once. The older Firestore copy is removed when the move finishes. If you want it removed sooner, write to the address in "Contact Us".

We will remove this paragraph when the move is finished.

7. Your Rights and Controls

8. GDPR Compliance (European Users)

If you are in the European Economic Area (EEA), you have additional rights:

Legal Basis for Processing:

9. CCPA Compliance (California Users)

California residents have the right to know what personal information we collect, request deletion, opt out of sale (we do not sell data), and non-discrimination for exercising rights.

10. Children's Privacy

Video Controls Plus is not directed at children under 13. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time, and the date at the top shows the latest change.

12. Contact Us

If you have questions about this Privacy Policy or your data:

Email: aoneahsan@gmail.com
Website: vcpeai.aoneahsan.com
Data Deletion: Request data deletion
Project: Video Controls Plus

13. Consent

By using Video Controls Plus you accept this Privacy Policy and our Terms of Service.

In the extension, usage analytics and error tracking are on by default, and you can turn each one off at any time in Settings → Privacy & Data. Marketing Communications is off by default. On the website, third-party tools and push notifications are off until you turn them on.

By creating an account on our website with Google sign-in, and connecting the extension to it, you also agree that we store your account information and the data you save or sync, as described in 1.1 and 1.5.


© 2026 Video Controls Plus | Home | Terms of Service | Contact