AI Video Tutor — Privacy Policy
Effective date: 2026-09-17 · 生效日期:2026-09-17
AI Video Tutor is a browser extension that acts as a one-on-one learning assistant beside the video you are watching. This policy explains what data the extension handles and how.
AI Video Tutor 是一款在浏览器里、陪伴你观看视频的一对一 AI 学习助教(浏览器扩展)。本政策说明该扩展如何处理数据。
1. No backend, no account, no telemetry
AI Video Tutor has no server of its own. There is no account system, no login, no analytics, no telemetry, no crash reporting, no advertising SDK, no third-party trackers, and no cookies. We (the developer) collect nothing and cannot see your usage.
2. What data is stored — and where
- Your API keys are stored only in the browser's
chrome.storage.local(on your device). They are never written to the page DOM, the console, or any server. - Subtitles, knowledge chunks, keyframes, conversation history, and learning notes are stored only in the browser's local IndexedDB (
AI_VIDEO_TUTOR_DB) on your device. - The page URL, video title, platform, duration and channel/uploader name are stored locally with the video record so the extension can recognise a video it has already indexed. The URL and the channel name are stored only — neither is ever transmitted anywhere.
- No full videos and no high-resolution screenshots are stored long-term.
All of the above stays on your device and is removed when you uninstall the extension or clear browser data.
3. Bring Your Own Key (BYOK) — third-party processing
The extension is BYOK: you provide your own API key for the AI model you choose. When you ask a question, the content involved is sent — by your explicit action — directly from your browser to the AI provider you configured. That content is your question, the video's title, platform and duration, the matching subtitles, the pages found by web search, and — for questions about the picture — a single frame of the current image. The video's URL is never sent. The provider is a third party and processes the data under its own privacy policy. Providers you can configure include:
- Google Gemini —
generativelanguage.googleapis.com - OpenAI —
api.openai.com - DeepSeek —
api.deepseek.com - Alibaba Cloud DashScope (Qwen) —
dashscope.aliyuncs.com - Dots API —
note3-prev-api.askdiandian.com - Any OpenAI-compatible endpoint or custom base URL you enter yourself
We do not proxy, store, or control these requests — it is a direct connection between your browser and the provider you own the key for. Apart from the optional web-search service described next, whichever provider you configure is the only third party that ever receives your learning data.
You can also configure an optional dedicated web-search service — Tavily (api.tavily.com) or Brave Search (api.search.brave.com). When you enable one and ask a question that needs checking against the web, your question text is sent to that service as a search query, and the results it returns are passed to your AI provider within the same request. That service receives the search query only: it never receives your subtitles, your video's URL or any captured frame. Enabling it is entirely optional, and leaving it off keeps the extension to the single AI provider listed above.
4. Other network requests
There is one more request pattern, and it only ever talks to the site you already have open. When you press Build knowledge index on a YouTube or Bilibili page whose own markup exposes no subtitles, the extension asks that platform for the captions it already has:
- YouTube — the watch page and the
timedtextcaption file it points to, onyoutube.com. - Bilibili — the public video and player APIs on
api.bilibili.com, then the caption file they name, served fromhdslb.com.
These requests carry no cookies and identify you only as an anonymous visitor to a page you already have open. They happen only when you ask for an index, and they are skipped entirely when you supplied your own subtitle file or the page exposed its own subtitle track. On any other site, no such request is made.
Beyond those, there are no other network requests. The extension contacts no server of ours: there is no update ping, no licence check, no font or asset CDN and no analytics endpoint, and it sends no usage data, error reports or diagnostics anywhere. The catalogue of known models ships inside the extension rather than being downloaded.
5. Permissions — why they are needed
storage— to save your settings and API keys locally.activeTab— to act on the tab you are viewing once you open the assistant, including capturing the video frame you ask about.sidePanel— to run the assistant as a side panel beside the video.host_permissions: <all_urls>— the content script that detects the<video>element and reads the page's subtitles is declared in the manifest and must run on whichever site you are watching, which can be any site. The same permission lets the extension reach the AI endpoint you configure, since that address is yours to choose.
The extension injects no scripts at runtime, does not hold the scripting or tabs permissions, and cannot read your browsing history.
6. Your control and data deletion
- You can delete all local data at any time by clearing the extension's data in browser settings, or by uninstalling the extension.
- You are never required to enter an API key; a Mock mode lets you try the UI without any key.
7. Children
The extension is not directed to children under 13 and does not knowingly collect personal information from them.
8. Contact
For privacy questions, open an issue at https://github.com/luvchippy/AI-Video-Tutor/issues.
1. 无后端、无账号、无遥测
AI Video Tutor 没有自己的服务器:没有账号系统、没有登录、没有分析统计、没有遥测、没有崩溃上报、没有广告 SDK、没有第三方追踪器、没有 Cookie。开发者不会收集、也无法看到你的使用情况。
2. 存储了什么数据、存在哪里
- 你的 API Key 只保存在浏览器的
chrome.storage.local(本机)。它不会被写入页面 DOM、控制台或任何服务器。 - 字幕、知识片段、关键帧、对话记录、学习笔记 只保存在浏览器本地的 IndexedDB(
AI_VIDEO_TUTOR_DB)。 - 页面 URL、视频标题、平台、时长与频道/UP 主名 会随视频记录存在本机,用于识别你已经建立过索引的视频。URL 与频道名仅存储,不会发送到任何地方。
- 不长期保存完整视频、不长期保存高清截图。
以上数据都留在你的设备上,卸载扩展或清除浏览器数据即被删除。
3. 自带 Key(BYOK)——第三方处理
本扩展采用 BYOK:你为自己选择的 AI 模型提供 API Key。当你提问时,相关的内容会因你的主动操作、由你的浏览器直接发送给你所配置的 AI 服务商。发送的内容是:你的问题、视频的标题/平台/时长、命中的字幕、联网搜索到的网页,以及——当问题涉及画面时——当前画面的一帧。视频 URL 不会发送。该服务商是第三方,按其自身的隐私政策处理数据。你可以配置的服务商包括:
- Google Gemini ——
generativelanguage.googleapis.com - OpenAI ——
api.openai.com - DeepSeek ——
api.deepseek.com - 阿里云百炼 DashScope(通义千问)——
dashscope.aliyuncs.com - Dots API ——
note3-prev-api.askdiandian.com - 你自己填写的任意 OpenAI-compatible 端点或自定义 Base URL
我们不会中转、存储或控制这些请求——这是你的浏览器与你自己持有 Key 的服务商之间的直连。除了下面说明的可选搜索服务,你所配置的那一家是唯一会收到你学习数据的第三方。
你还可以额外配置一个独立的联网搜索服务——Tavily(api.tavily.com)或 Brave Search(api.search.brave.com)。启用后,当你提出需要联网核实的问题时,你的问题文本会作为搜索词发送给该服务,它返回的结果会在同一次请求中一并交给你的 AI 服务商。该服务只收到搜索词,不会收到你的字幕、视频 URL 或截取的画面。这一项完全可选,不配置时扩展只联系上面列出的 AI 服务商。
4. 其他网络请求
还有一类请求,它只联系你已经打开的那个网站。当你在 YouTube 或 Bilibili 页面上点击「建立视频知识索引」、而页面本身没有暴露字幕时,扩展会向该平台索取它自己已有的字幕:
- YouTube —— 请求
youtube.com上的观看页,以及其中指向的timedtext字幕文件。 - Bilibili —— 请求
api.bilibili.com上的公开视频与播放器接口,再请求它们给出的字幕文件(由hdslb.com提供)。
这些请求不携带 Cookie,只会以匿名访客身份访问一个你本来就打开着的页面。它们仅在你主动建立索引时发出;如果你自己提供了字幕文件,或页面本身带有字幕轨,则完全不会发出。在其他站点上不会产生这类请求。
除此以外没有其他网络请求。本扩展不联系开发者的任何服务器:没有更新检查、没有授权校验、没有字体或素材 CDN、没有统计端点,也不会把使用数据、错误报告或诊断信息发往任何地方。已知模型清单随扩展一起打包,不需要下载。
5. 权限 —— 为什么需要
storage—— 在本地保存你的设置与 API Key。activeTab—— 在你打开助教后操作你正在看的标签页,包括截取你询问的视频画面。sidePanel—— 让助教以侧边栏形式固定在视频旁边。host_permissions: <all_urls>—— 检测<video>元素、读取页面字幕的 content script 在 manifest 中声明,需要在你观看的任意网站上运行,而这些网站无法预先限定。同一权限也让扩展能访问你自己配置的 AI 端点,因为那个地址由你决定。
本扩展不在运行时注入脚本,不持有 scripting 或 tabs 权限,也无法读取你的浏览记录。
6. 你的控制权与数据删除
- 你可以随时在浏览器设置中清除扩展数据,或卸载扩展,即可删除全部本地数据。
- 你永远不必输入 API Key;Mock 模式可让你在无 Key 的情况下体验界面。
7. 未成年人
本扩展不面向 13 岁以下儿童,也不会故意收集儿童的个人信息。
8. 联系方式
如有隐私相关问题,请在 https://github.com/luvchippy/AI-Video-Tutor/issues 提交 issue。