Privacy Policy
Overview
RubberDucky is a Chrome extension that helps you take AI-assisted notes while reading web pages and research papers. This policy explains what information we collect, how we use it, how long we keep it, and the choices you have.
Information we collect
Reading notes and annotations
When you use features such as Explain, highlights, region capture, Ask & review, project organization, sync, or voice tutor, we may process:
- Text you select on a page
- AI-generated summaries, explanations, and tags
- Page URL and title
- Project names and note metadata
- Annotations and highlights you save
Notes are stored locally in your browser. If you sign in with Google, notes and projects are also stored on our Cloudflare Worker backend (Cloudflare D1 database) so you can sync across devices.
Google account information
If you choose to sign in with Google, we receive your email address, display name, and Google profile identifier through OAuth scopes userinfo.email and userinfo.profile. We use this to create your account, enable cloud sync, and match one-time RubberDucky Pro payments to the correct account.
If you connect Google Docs export, additional Google permissions are requested only at that time to create or update documents you authorize.
Voice tutor audio
When you start a voice tutor session, audio from your microphone is sent to VAPI, our voice AI provider, for speech-to-text, tutoring responses, and text-to-speech playback. Session transcripts may be saved as notes. The microphone is not used at install time or in the background—only during an active session you start.
Payment information
RubberDucky Pro is a one-time unlock processed by Razorpay. We receive payment status, amount paid, Razorpay payment and order identifiers, and the email used at checkout. We do not receive or store your full card number, CVV, or bank credentials.
Information we do not collect
- We do not passively collect your browsing history.
- We do not read page content unless you explicitly trigger Explain, capture, voice tutor, or a related action.
- We do not sell your personal information.
- We do not use your data for third-party advertising or ad profiling.
How we use information
We use collected information only to:
- Provide AI explanations, note storage, project organization, and voice tutoring
- Sync your notes when you are signed in
- Verify billing entitlement after payment
- Operate, secure, and troubleshoot the service
- Meet legal obligations related to payments and account records
Third-party service providers
| Provider | Purpose |
|---|---|
| OAuth sign-in; optional Google Docs export | |
| Cloudflare | API hosting and database for signed-in users |
| Google Gemini | AI text explanations (via our backend) |
| VAPI | Voice tutoring and audio processing |
| Razorpay | One-time payment processing |
Each provider processes data under its own privacy policy when acting on our behalf.
Data retention
| Data type | Retention |
|---|---|
| Notes, projects, and annotations | Kept while your account is active until you delete them or request account deletion. Residual copies may persist briefly during sync or backup cycles. |
| Voice audio | Processed in real time during an active session. Transcripts saved as notes follow note retention above. |
| Google account metadata | Retained while your account exists. |
| Billing records | Retained while your account exists and as required for reconciliation, fraud prevention, and applicable law. |
| Local browser storage | Until you uninstall the extension or clear extension data in Chrome settings. |
Your choices
- Use without sign-in: Local note features may work without an account; cloud AI, sync, and voice tutor require sign-in (and payment when billing is enabled).
- Skip voice tutor: Do not start a voice session if you do not want microphone use.
- Delete content: Remove projects and notes from the side panel.
- Account deletion: Email shayna.vinoth2007@gmail.com to request deletion of your cloud account and associated notes.
Depending on your jurisdiction, you may have additional rights (access, correction, portability, objection). Contact us at the address below.
Security
Backend communication uses HTTPS. After Google sign-in, API requests use signed tokens. Razorpay webhooks are verified before updating entitlements. No method of transmission or storage is completely secure; we use industry-standard practices to protect your data.
Children
RubberDucky is not intended for users under 13. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact shayna.vinoth2007@gmail.com.
International transfers
Our backend runs on Cloudflare's global network. By using RubberDucky while signed in, your data may be processed in countries where our service providers operate.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will change when we do. Continued use after changes constitutes acceptance of the updated policy.