Effective Date: September 18, 2025

Last Updated: September 18, 2025

Application: Videos We Love Chrome Extension

1. Introduction

Welcome to Videos We Love, a Chrome extension that helps you discover other YouTube users with similar viewing habits. This Privacy Policy explains how we collect, use, protect, and handle your personal information when you use our Chrome extension and related services.

By installing and using Videos We Love, you explicitly consent to the data collection practices described in this policy.This consent is obtained during the account creation process and is required for the extension to function.

2. Information We Collect

2.1 YouTube Viewing Data

  • Video IDs: Unique identifiers of YouTube videos you watch
  • Channel IDs: Identifiers of YouTube channels whose content you view
  • Video Titles: Titles of YouTube videos you watch (used for display purposes and similarity matching)
  • Keywords/Tags: Video keywords and tags when available from YouTube (used to enhance similarity calculations)
  • Watch Frequency: How many times you've watched specific videos
  • Timestamps: When you watched specific videos
  • Category Information: Video categories when available from YouTube

2.2 Account Information

  • Google Account Data: Name, email address, and profile picture from your Google account (obtained through OAuth)
  • User ID: Unique identifier created for your account
  • Email Storage: Email addresses are stored unencrypted to enable account lookup and authentication

2.3 Optional Profile Information

  • Biography: Personal description you choose to provide (encrypted at rest)
  • Contact Information: Social media links or other contact details you choose to share (encrypted at rest)

2.4 Technical Information

  • Extension Usage: Basic usage statistics for performance optimization
  • Error Logs: Technical information to help us fix bugs and improve functionality

3. How We Use Your Information

3.1 Core Functionality

Your YouTube viewing data is used exclusively for the primary purpose of Videos We Love:

  • Similarity Matching: Comparing your viewing patterns with other users to calculate similarity scores
  • User Discovery: Showing you users who watch similar content to yours
  • Statistics Display: Providing you with insights about your viewing habits and connections

3.2 Service Operation

  • Account Management: Creating and maintaining your user account
  • Authentication: Verifying your identity through Google OAuth
  • Communication: Enabling connections between users with similar interests

3.3 What We DON'T Do

  • ❌ We do NOT sell your data to third parties
  • ❌ We do NOT use your data for advertising
  • ❌ We do NOT share your viewing data with YouTube or Google
  • ❌ We do NOT track your browsing outside of YouTube
  • ❌ We do NOT access your private YouTube data (likes, subscriptions, etc.)

4. Data Protection and Security

4.1 Encryption

  • At Rest: Personal information (bio, contact info, name, profile image, Google ID) is encrypted using AES-256-CTR encryption with HKDF key derivation
  • In Transit: All data transmission occurs over HTTPS connections with TLS encryption
  • Key Management: Encryption keys are securely managed and rotated regularly

4.2 Access Controls

  • Authentication Required: All API access requires valid authentication tokens
  • Principle of Least Privilege: Users can only access their own data and public profiles of others
  • Rate Limiting: API endpoints are protected against abuse with rate limiting

4.3 Infrastructure Security

  • Secure Headers: HSTS, CSP, and other security headers are implemented
  • Regular Updates: Dependencies and security patches are applied promptly
  • Monitoring: Automated monitoring for suspicious activity and security threats

5. Data Sharing and Third Parties

5.1 No Data Sales

We never sell, rent, or trade your personal information to third parties for any purpose.

5.2 Service Providers

We use the following trusted service providers who may process your data:

  • Supabase: Database hosting and backend services (data is encrypted)
  • Google OAuth: Authentication service (standard OAuth flow)
  • Vercel/Netlify: Web hosting services (for the web interface)

5.3 Legal Requirements

We may disclose your information only if required by law, such as:

  • Valid court orders or legal process
  • Government agency requests with proper legal authority
  • Protection against fraud or security threats

6. Your Rights and Controls

6.1 Data Access

  • Profile Access: View all your collected data through your profile page
  • Statistics: Access your viewing statistics and similarity scores
  • Export: Request a copy of your data in a portable format

6.2 Data Control

  • Profile Editing: Update or remove your bio and contact information at any time
  • Privacy Settings: Control what information is visible to other users
  • Data Correction: Request correction of inaccurate information

6.3 Data Deletion

  • Account Deletion: Permanently delete your account and all associated data
  • Right to be Forgotten: Complete removal from our systems within 30 days
  • Partial Deletion: Remove specific data while keeping your account active

6.4 Consent Withdrawal

  • Extension Removal: Uninstalling the extension immediately stops all data collection
  • Account Deactivation: Temporarily disable your account while preserving data
  • Consent Revocation: Contact us to revoke consent and delete your data

7. Data Retention

7.1 Active Accounts

We retain your data as long as your account remains active and you continue using the extension.

7.2 Inactive Accounts

  • 12 Months: Accounts inactive for 12 months receive an email notification
  • 18 Months: Data is automatically deleted after 18 months of inactivity
  • Notification: 30-day advance notice before automatic deletion

7.3 Legal Requirements

In rare cases, we may retain certain data longer if required by law or for legitimate business purposes (e.g., fraud prevention, security incidents).

8. International Data Transfers

Your data may be processed and stored in countries other than your own. We ensure adequate protection through:

  • Encryption: All data is encrypted both at rest and in transit
  • Secure Providers: We only use reputable cloud providers with strong security measures
  • Privacy Standards: Adherence to GDPR and other international privacy standards

9. Children's Privacy

Videos We Love is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will promptly delete such information.

Users between 13-18 should obtain parental consent before using the extension.

10. Chrome Web Store Compliance

This extension complies with Chrome Web Store Developer Program Policies:

  • Limited Use: User data is only used for the explicitly stated functionality
  • Secure Transmission: All data is transmitted over HTTPS
  • User Control: Users maintain control over their data and can delete it at any time
  • Transparency: Clear disclosure of what data is collected and how it's used
  • Prominent Disclosure: Data collection practices are clearly explained during onboarding

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes:

  • Notification: Users will be notified via email and/or extension notification
  • Consent: Continued use after notification constitutes acceptance of changes
  • Opt-out: Users can delete their account if they disagree with changes
  • Version History: Previous versions of this policy are available upon request

12. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email

kojjyan.official@gmail.com

Response time: Within 5 business days

Data Protection Requests

kojjyan.official@gmail.com

For data inquiries (deleting account already deletes all data).

Response Commitment: We will respond to all privacy-related inquiries within 30 days, and data deletion requests within 5 business days.