Privacy Policy
Chat Exporter — Chrome Extension
Last updated: March 2, 2026
Chat Exporter ("the Extension") is a Chrome Extension that exports
conversations from AI chat platforms (ChatGPT, Claude, Gemini, Grok,
Copilot, Perplexity, NotebookLM). This privacy policy comprehensively
describes what user data we collect, how we use it, how we store it, and
with whom we share it.
1. Data We Collect and How We Use It
1.1. Chat Content (processed locally only)
When you click Export, the Extension uses content scripts to read the
visible messages from the current chat page in your browser tab. This
data is processed entirely on your device to generate the export file.
-
Purpose: To convert chat messages into your chosen
export format (Markdown, PDF, Word, etc.).
-
Storage: Chat content is
never sent to our servers and is
never stored by the Extension. It is only held
temporarily in memory during the export process and then discarded.
-
Sharing: Chat content is not shared with us or any
third party. If you choose to export to Google Drive, the exported
file is uploaded directly from your browser to your own Google Drive
account.
1.2. Email Address (optional — only if you sign in)
If you choose to create an account for Premium features, we collect your
email address.
-
Purpose: Authentication (passwordless login via email
OTP code), linking your subscription status, and enforcing the
one-device-per-account policy.
-
Storage: Stored on our Supabase database (hosted on
AWS) for as long as your account is active.
-
Sharing: Shared with Supabase (authentication
provider) and Polar.sh (if you purchase a Premium plan, for payment
processing).
1.3. IP Address
Your IP address is collected automatically when the Extension
communicates with our server to check free daily export quota.
-
Purpose: To enforce the free daily export limit (5
exports per day) for users who are not signed in.
-
Storage: Stored on our Supabase database, associated
with a daily usage count. Records are limited to the current date
only.
-
Sharing: Shared with Supabase (database provider).
Not shared with any other party.
1.4. Device Identifier
A randomly generated UUID is created and stored in your browser's local
storage (chrome.storage.local) when you first use the
Extension.
-
Purpose: To enforce the one-device-per-account policy
for Premium users (only one device may be logged in per account at a
time).
-
Storage: Stored locally in your browser and on our
Supabase database (linked to your email if you sign in).
-
Sharing: Shared with Supabase (database provider).
Not shared with any other party.
1.5. Google Account Data (optional — only if you use Google Drive
export)
If you choose to export files to Google Drive, the Extension requests an
OAuth2 access token from your Google account via
chrome.identity API.
-
Purpose: To authenticate with Google Drive API and
upload your exported file to a folder named "Chat Exporter" in your
Google Drive.
-
Scope: The Extension requests only the
drive.file scope, which limits access to files created by
the Extension. The Extension cannot read, modify, or
delete any other files in your Google Drive.
-
Storage: The OAuth2 access token is cached
temporarily in
chrome.storage.local until it expires
(typically 1 hour). No Google account data (name, email, profile) is
collected or stored by us via this flow.
-
Sharing: The exported file content is sent directly
from your browser to Google Drive API. Our servers are
not involved in this transfer. No Google user data is
shared with any other party.
1.6. Browser Local Storage
The Extension stores the following data in
chrome.storage.local (on your device only):
- Authentication session tokens (for Supabase)
-
Google Drive OAuth2 access token (temporary, expires after ~1 hour)
- Export destination preference (Local or Google Drive)
- Daily quota cache (synced with server)
- Device ID (random UUID)
- OTP flow state (temporary, expires after 10 minutes)
This data is stored only on your device and is never
transmitted to our servers (except as described in the specific sections
above).
2. Summary Table
3. Data We Do NOT Collect
-
We do not collect, store, or transmit your chat
conversations to our servers.
-
We do not read, access, or modify any files in your
Google Drive other than files created by this Extension.
-
We do not track your browsing history or activity on
any website.
-
We do not collect your name, phone number, or
location.
-
We do not use cookies, analytics services,
advertising networks, or tracking scripts.
- We do not sell, rent, or trade any user data.
4. Data Sharing
We do not sell your data to any third party. User data
is shared only with the following service providers, strictly for the
operational purposes described in this policy:
-
Supabase (supabase.com) — Receives email address, IP
address, device ID, and usage count for authentication, database
storage, and quota tracking. Data hosted on AWS.
Supabase Privacy Policy.
-
Polar.sh (polar.sh) — Receives email address when you
purchase a Premium plan, for payment processing and subscription
management.
Polar Privacy Policy.
-
Google (google.com) — If you choose to export to
Google Drive, the exported file is uploaded directly from your browser
to Google's servers via Google Drive API. No other data is sent to
Google by us.
Google Privacy Policy.
No other parties receive your data. We do not share data with
advertisers, data brokers, or information resellers.
5. Data Retention
-
Free usage records (IP address + daily count):
Retained for the current day only. No historical free usage data is
kept.
-
Account data (email, subscription, device ID):
Retained for as long as your account is active. Deleted within 30 days
of a deletion request.
-
Google Drive token: Cached in your browser for up to
1 hour, then automatically expires. You can disconnect at any time via
the Extension interface.
-
Browser local storage: Retained until you uninstall
the Extension or clear your browser data.
6. Data Deletion
You can delete your data at any time:
-
Browser local data: Uninstall the Extension, or clear
your browser data from Chrome Settings.
-
Google Drive connection: Click "Disconnect" in the
Extension's export panel, or revoke access from your
Google Account permissions page.
-
Server-side account data: Contact us at
[email protected]
to request deletion of your email, subscription, device ID, and all
associated records. We will process your request within 30 days.
7. Google API Services Disclosure
The Extension's use and transfer of information received from Google
APIs adheres to the
Chrome Web Store User Data Policy, including the Limited Use requirements.
Specifically:
-
The Extension only uses Google Drive API data to upload export files
that you explicitly choose to save to Google Drive.
-
The Extension does not use Google API data for advertising,
tracking, or any purpose unrelated to the Extension's core
functionality.
-
The Extension does not allow humans to read your Google API data
unless you give affirmative consent, it is necessary for security
purposes, or it is required by law.
-
The Extension does not transfer Google API data to third parties.
8. Content Scripts Disclosure
The Extension injects content scripts into the following websites to
enable chat export functionality:
- chatgpt.com / chat.openai.com (ChatGPT)
- claude.ai (Claude)
- gemini.google.com (Gemini)
- grok.com / x.com/i/grok (Grok)
- copilot.microsoft.com (Copilot)
- perplexity.ai (Perplexity)
- notebooklm.google.com (NotebookLM)
These content scripts read the visible chat messages on the page
only when you click the Export button. The scripts do
not run in the background, do not modify page content, and do not
transmit any data to external servers.
9. Security
We take reasonable measures to protect your data:
-
All communication between the Extension and our servers uses HTTPS
encryption.
-
Authentication uses passwordless OTP (one-time password), so no
passwords are stored.
-
Google Drive authentication uses OAuth2 with the minimal required
scope (
drive.file).
-
Our database uses Row Level Security (RLS) to ensure users can only
access their own data.
10. Children's Privacy
The Extension is not directed to children under the age of 13. We do not
knowingly collect personal information from children under 13.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be
posted on this page with an updated "Last updated" date. Continued use
of the Extension after changes constitutes acceptance of the updated
policy.
12. Contact
If you have questions or concerns about this privacy policy or our data
practices, contact us at:
[email protected]