Privacy Policy
Effective: September 24, 2026 · Operator: ZHIWEN SHI · Contact: support@quizpilot.link
This policy explains what data the QuizPilot browser extension, its website and its API (together, "the Service") process, why, who receives it, and what you can do about it. If this English version and the Chinese version differ, the Chinese version prevails.
1. Data we process
1.1 Page content, only when you invoke the extension
- The extension reads the current tab only when you click its button, use the context menu or press its shortcut. It does not read the pages you browse in the background.
- It reads the text of the questions and options on the page, and a little of the surrounding instructions.
- When the page text is incomplete or a question contains an image, the extension takes a screenshot of that question's area. Screenshots are compressed before upload; when you select an area, only that area is captured.
- We do not read anything else you type on the page. Forms with a password field are skipped entirely.
1.2 Credits account data
- Email address: to sign you in and send login codes. If you sign in with Google, we also store your Google account identifier.
- Credit balance and ledger: top-ups, bonuses, charges, clawbacks.
- Preventing repeat sign-up bonuses: when an account is created we keep a keyed hash (which cannot be turned back into the original) of the network address (IP) and of the extension's install ID, to limit new-account credits per network and per device.
- Usage records: for each request, the time, the site's domain, the model used, the number of questions, tokens and credits charged. We do not store questions, answers or screenshots.
- Payment information: handled by Stripe. We keep only the order ID, amount and status; we never see or store card details.
1.3 Data stored on your device
The extension's settings, the model API keys you enter in Free mode, and your Credits
sign-in tokens are stored locally in your browser (chrome.storage.local) and
are not uploaded to our servers.
1.4 Debug logs you send to support
The debug log is off by default and stays in your browser. Only when you click "Send log" on the settings page is it emailed to support through our server. It contains the address of the page with the problem, the questions, options and answers read, the processing steps, and the description and reply email you enter (both optional). It never contains API keys. We use it only to investigate the problem and improve site support. Our server records just the time, the log size and a keyed hash of your network address, to limit how often logs can be sent.
2. Who receives data
- Credits mode: question text and screenshots go to our server, which forwards them to model providers, currently TypeSafe (the Jev model) and multimodal models through OpenRouter. We do not keep the questions, screenshots or answers.
- Free mode: question text and screenshots go directly from your browser to the model provider you configured, not through our servers. That provider's own privacy policy applies.
- Stripe: payment processing.
- Resend: sending login code emails and the debug logs you choose to send.
- Cloudflare: hosting our servers and database.
We do not sell your personal data, and we do not use it for advertising or to train our own models.
3. Retention
- Account, credit ledger and payment records: kept while your account exists, and for as long as financial and tax law requires afterwards.
- Usage records: kept for 12 months.
- Login codes: expire after 10 minutes and are deleted once used.
- Sign-in sessions: at most 30 days; they end immediately when you sign out.
- Debug logs you send to support: deleted once the issue is resolved, and kept at most 12 months; the records used for rate limiting are kept for 30 days.
4. Your rights
Contact support@quizpilot.link to access, export, correct or delete your account data. Unused credits of a deleted account are handled as set out in the Terms of Service. Uninstalling the extension clears all data it stored in your browser.
5. Security
All traffic uses HTTPS. Sign-in tokens are stored on our server only as hashes. The platform's model API keys are kept as encrypted secrets on the server and are never sent to the extension.
6. Children
Users under 18 should use the Service with a parent's or guardian's consent and guidance.
7. Changes
We will announce material changes to this policy in advance on the website and in the extension.