Privacy Policy — Social Repurposer
Effective date: June 23, 2026 Last updated: June 23, 2026
This Privacy Policy explains what data the Social Repurposer Chrome extension and its backend collect, why, and what we do with it. It is written to satisfy the Chrome Web Store user-data disclosure requirements and applicable privacy laws (GDPR, CCPA/CPRA).
Operator: Social Repurposer. Contact: socialrepurposer@gmail.com
1. Short version
We do not sell your data.
We do not advertise to you.
We do not read your browsing history, your emails, your YouTube account, or any tabs other than YouTube watch pages — and on those pages we only read the URL and title.
We send the YouTube video URL you click "Repurpose Video" on to our backend, which forwards it to Google's Vertex AI (Gemini) to generate post drafts. We do not store the generated text.
We store (a) a random install ID and a per-month generation counter, (b) for paid users, the email address that ExtensionPay provides us so we can confirm your subscription.
Payments are handled entirely by ExtensionPay (ExtPay) + Stripe. We never see your card.
2. Data we collect
2.1 Data stored locally on your device
Stored in chrome.storage.local. This data never leaves your browser except as described below.
| Key | What it is | Why |
|---|---|---|
| `userId` | A random UUID generated on first install | Used as a per-install identifier for the monthly usage counter |
| `tone` | The tone preset you last selected | Remember your preference between sessions |
| `customInstructions` | The text you type in the custom-instructions box (Premium) | Reused on each generation |
| `latestResult` | The most recent generated post set, plus the video title and URL | Powers the "Restore last repurpose" card |
| `firstTipDismissed` | Boolean, whether you closed the first-time tip | Avoid showing it again |
2.2 Data sent to our backend
When you click Repurpose Video or open the side panel, the extension sends a request to our Firebase Cloud Function. Each request contains:
The YouTube video URL and video title (from the page you are viewing).
The selected tone ("professional", "casual", etc.).
Optional custom instructions (Premium users only, ≤250 characters).
Your install ID (random UUID).
For paid users, the email address from ExtPay, plus a "paid" claim used to look up your subscription.
We do not send: your browsing history, your name, your IP address (beyond what is automatically present in any HTTPS request), the page contents of any tab other than the video URL/title, your YouTube login state, or anything from other websites.
2.3 Data stored on our backend (Google Cloud / Firestore)
| Collection / doc | What it stores | How long |
|---|---|---|
| `usage/{userId}/months/{YYYY-MM}` | A counter (integer) and a "last used" timestamp | Until you uninstall + 13 months of inactivity, then purged |
| `paid_users/{email}` | Your email (lowercased), paid status (true/false), plan label, last ExtPay event type and timestamp | Until you cancel + 24 months, then purged |
We do not store the YouTube URLs you submit, the AI output, the video titles, or your custom instructions. They are passed through to Vertex AI and the response is returned to your browser; nothing is persisted on our side.
2.4 Data handled by third parties
Google Cloud Vertex AI (Gemini 2.5 Flash): receives the video URL, video title, tone, and (Premium) custom instructions to generate the post text. Google's data handling is governed by their Vertex AI data terms. Google states that customer prompts and responses sent to Vertex AI are not used to train Google's foundation models without explicit opt-in.
Firebase / Google Cloud Functions: runs our backend; receives the request and standard HTTPS metadata (IP, user-agent) per Google's security logging. Retention follows Google Cloud defaults.
Firestore: stores the usage counter and paid-user records described above.
ExtensionPay (ExtPay): handles subscription identity. Their service stores your email and subscription status. See ExtPay's privacy policy.
Stripe: processes your card. We never see your card. See Stripe's privacy policy.
2.5 Data we do NOT collect
We do not collect names, addresses, phone numbers, ages, demographics, or any social-network credentials.
We do not use cookies, web beacons, fingerprinting, analytics SDKs, advertising SDKs, or any tracking pixels.
We do not read or transmit the contents of any web page other than the YouTube video title and URL on https://www.youtube.com/watch?v=….
We do not access your microphone, camera, location, clipboard contents (except writing to it when you press Copy), or local files.
3. Why we collect it (legal basis)
| Purpose | Legal basis (GDPR) |
|---|---|
| Operating the Service (sending the URL to Vertex AI, returning text) | Contract — necessary to perform what you asked for |
| Enforcing the monthly cap (install ID + counter) | Legitimate interest — preventing abuse of a free product |
| Verifying paid status (email lookup) | Contract — your subscription |
| Fraud / abuse prevention | Legitimate interest |
| Complying with law (DMCA, court orders) | Legal obligation |
4. Sharing
We do not sell or rent personal data. We share data only with the service providers listed in §2.4 strictly to operate the Service, and we may disclose data if required by law (subpoena, court order, valid government request).
We will never share your data with advertisers, data brokers, or AI training pipelines outside the Vertex AI inference call.
5. Retention
Local data lives on your device until you uninstall the extension or clear extension storage from Chrome.
Usage counters are retained for the current calendar month and the previous 12 months for cap enforcement and abuse review, then deleted.
Paid-user records are retained while your subscription is active and for 24 months after cancellation for accounting and dispute purposes, then deleted.
Backend request logs (the standard Google Cloud Functions logs) are retained for up to 30 days for debugging and abuse prevention.
6. Security
All communication between the extension and our backend is over HTTPS/TLS.
Backend requests carry a shared-secret header to prevent random third parties from invoking the function.
Backend → Vertex AI uses Google's service-account identity (no API keys stored anywhere).
Payment data never touches our infrastructure.
Access to Firestore is restricted to the Cloud Function's service account.
No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and the appropriate regulators as required by law.
7. Your rights
Depending on where you live, you have some or all of the following rights:
Access — request a copy of the data we hold about you.
Correction — ask us to fix inaccurate data.
Deletion — ask us to delete your data. You can delete most data yourself by uninstalling the extension and cancelling your subscription. For server-side deletion of your paid-user record, contact us.
Portability — request your data in a machine-readable format.
Objection / restriction — object to or restrict processing based on legitimate interests.
Withdraw consent — where processing relies on consent.
Non-discrimination (California residents) — we will not deny service or charge differently for exercising your rights.
To exercise any of these, email socialrepurposer@gmail.com from the address tied to your subscription (or include your install ID for free users). We will respond within 30 days.
You also have the right to lodge a complaint with your local data-protection authority (EU/UK) or the California Privacy Protection Agency.
California (CCPA/CPRA) categories
The categories of personal information we collect, in California-statute terms: Identifiers (random install ID; email for paid users). Internet/network activity (a YouTube URL/title you submit each time you press the button). We do not sell or share personal information for cross-context behavioral advertising.
8. International transfers
Our backend is hosted in us-central1 (Iowa, USA). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. We rely on Google Cloud's Standard Contractual Clauses and supplementary safeguards for transfers from the EU/UK.
9. Children
The Service is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has used the Service, contact us and we will delete the data.
10. Chrome Web Store certification
Per the Chrome Web Store Developer Program Policies, we certify that:
We do not sell user data to third parties.
We do not use or transfer user data for purposes unrelated to the extension's single core function (repurposing YouTube videos into social-media posts).
We do not use or transfer user data to determine creditworthiness or for lending purposes.
11. Changes to this Policy
We may update this Policy. The "Last updated" date above will change and material changes will be announced in the extension. Continued use after an update constitutes acceptance.
12. Contact
Social Repurposer Email: socialrepurposer@gmail.com
For privacy or data-subject requests, please include "Privacy Request" in the subject line.