Privacy Policy
Last updated: March 3, 2026
WebDaddy ("we", "our", or "the Extension") is a Chrome browser extension that provides AI-powered study assistance, including text explanations, answers, source finding, and screenshot analysis. This Privacy Policy explains what data we collect, how we use it, how we store it, and your rights regarding that data.
Summary: We only collect data necessary to provide the service. We do not sell your data. Text you highlight is sent to our AI service for processing and is not stored permanently.
1. Data We Collect
| Data Type | Purpose | Stored Where |
|---|---|---|
| Email address | Account creation and authentication | Supabase (cloud database) |
| Selected text | Sent to AI for explanation/answer generation | Processed in transit; not stored permanently |
| Screenshots | Sent to AI for visual analysis when you use the screenshot feature | Processed in transit; not stored permanently |
| Device identifier | Randomly generated ID to enforce device limits per account | Chrome local storage & Supabase |
| Authentication tokens | Keep you logged in | Chrome local storage (on your device only) |
| Usage data | Track credit consumption and rate limiting | Supabase (cloud database) |
| Extension settings | Your preferences (e.g., quick actions toggle, hold duration) | Chrome local storage (on your device only) |
2. How We Use Your Data
- To provide the service: Selected text and screenshots are sent to our server, which forwards them to OpenAI's API to generate explanations, answers, or source suggestions. This content is processed in real time and is not stored on our servers after the response is delivered.
- To manage your account: Your email is used for authentication via Supabase Auth (Google OAuth or magic link). We track credit usage to enforce plan limits.
- To prevent abuse: Device IDs and rate limits are used to prevent excessive usage and multi-account abuse.
- To process payments: If you purchase credits or a subscription, payment is handled entirely by Stripe. We do not store credit card numbers or payment details.
3. Data Sharing
We share data only with the following third-party services, solely to provide the Extension's functionality:
- OpenAI: Selected text and screenshots are sent to OpenAI's API for AI processing. OpenAI's data usage policy applies. We use their API in a way that does not train their models on your data.
- Supabase: Provides authentication, database hosting, and serverless functions. Your email, device ID, and usage data are stored in Supabase.
- Stripe: Handles payment processing for subscriptions and credit purchases. We do not store payment information.
We do not sell, rent, or share your personal data with advertisers, data brokers, or any other third parties.
4. Data Storage and Security
- Local storage: Authentication tokens, device ID, and settings are stored in Chrome's local storage on your device. This data never leaves your browser except when making authenticated API requests.
- Cloud storage: Account data (email, usage, credits) is stored in Supabase's cloud database with row-level security (RLS) enabled, ensuring users can only access their own data.
- Encryption: All data transmitted between the Extension and our servers uses HTTPS/TLS encryption. Supabase database functions that modify user data run as SECURITY DEFINER with restricted search paths.
- Content processing: Text and images you send for AI processing are transmitted securely, used only to generate a response, and are not stored permanently on our servers.
5. Data Retention
- Account data: Retained as long as your account exists.
- Usage data: Daily usage records are retained for billing and analytics purposes.
- Selected text and screenshots: Not retained after the AI response is generated and delivered.
- Authentication tokens: Refreshed automatically and replaced; old tokens expire and are discarded.
6. Your Rights
You have the right to:
- Access your data: View your credit balance, usage, and account details through the extension popup.
- Delete your account: Contact us to request full account deletion, including all associated data.
- Opt out: You can uninstall the extension at any time to stop all data collection.
- Manage devices: Remove registered devices from your account through the extension popup.
7. Cookies and Tracking
The Extension does not use cookies, analytics trackers, or any form of cross-site tracking. We do not track your browsing history or the websites you visit. The Extension only activates when you explicitly select text or use a quick action.
8. Children's Privacy
WebDaddy is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Extension after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: noreply@webdaddy.ai
Website: webdaddy.ai
© 2026 NexProto INC. All rights reserved.