◆ Legal · Chrome Extension

TubeLeader Extension Privacy Policy

A focused disclosure for the TubeLeader browser extension: what it reads, what it stores on your device, what it sends to our server, and the choices you have. Read it together with our main Privacy Policy and Extension Terms of Use.

This Extension Privacy Policy explains how the TubeLeader browser extension (the “extension”) for Google Chrome and other Chromium-based browsers handles information. It supplements, and should be read with, the main TubeLeader Privacy Policy. Where a topic (such as your website account, payments, or your general privacy rights) is covered fully in the main policy, this notice summarizes it and points you there.

1. Overview

The extension adds creator-research information to supported YouTube pages — badges, panels, scores, estimates and AI-assisted observations built from public YouTube data. It is designed to work on youtube.com and to communicate with the TubeLeader service at tubeleader.com. It is not designed to observe your general web browsing, and it does not run its research features on unrelated websites. Most of what it shows is computed from information already visible on the YouTube page you are on; a smaller set of features asks our server to compute a result, and those are described below.

2. Single purpose and limited use

The extension has a single purpose: to display creator-research information on supported YouTube pages. Consistent with the Chrome Web Store’s Limited Use requirements, the information the extension handles is used only to provide the features you request, to sign you in and enforce your plan and usage limits, and to keep the service secure and reliable. We do not sell your data, do not rent or trade it, do not use it for advertising or ad targeting, and do not use it to build profiles for purposes unrelated to the features you use. We do not transfer your data to third parties except the service providers needed to deliver these features, or where the law requires it.

3. Where the extension runs

The extension’s content scripts run on youtube.com pages to render its interface, and a small script runs on tubeleader.com to complete secure sign-in and to keep your login state in sync between the website and the extension. Its background service worker communicates with tubeleader.com for login, plan entitlements, status configuration and the server-backed features you request. The extension requests host access only for youtube.com and tubeleader.com; it is not granted access to your activity on other websites.

4. Account and authentication data

To use features that require sign-in, you log in through the dedicated TubeLeader Extension sign-in/connect page on tubeleader.com. After you sign in, the extension stores a login token and related user and plan state on your device, and periodically refreshes your entitlements so features and limits stay current. The extension also generates a random installation identifier; our server stores a one-way hash of it — used for login security, plan enforcement and installation status — rather than any hardware fingerprint. You can sign out at any time, which clears the local token; logging out on the website also signals the extension to clear its local session.

5. Local device storage

The extension uses Chrome extension storage on your device to hold: your login token and user/plan state; your consent choice; the random installation identifier; your feature toggles and interface preferences; the master on/off state; and local caches of research results and some research history so features load quickly without repeating network requests. The unlimitedStorage permission allows these local caches to exceed the small default quota. This local data stays on your device unless a feature specifically sends a request to our server, as described below. You can clear it at any time (see “Your controls”).

6. YouTube page information the extension reads

To render its interface, the extension reads public information already present on the supported YouTube page you are viewing, such as channel and video identifiers, titles, view counts, subscriber counts, publish dates, durations, descriptions, links and visible search-result fields. It can also read your browser’s YouTube API context that the page itself exposes, to request the same public data the page would. This reading happens locally in your browser to build the on-page interface; it is not, by itself, sent to our server. The extension does not access private YouTube Studio analytics, and it does not read information that is not part of the public YouTube page.

7. Information sent to the TubeLeader server

Some features are computed on our server so that the underlying methodology and models are not shipped in the extension. When you use one of these features, the extension sends the public fields required for that specific request:

  • Login, status and entitlements — your login token and installation identifier hash accompany requests that check your plan, usage allowances and service status configuration.
  • AI channel analysis — the public channel details and a sample of public video fields (titles, view counts, lengths, dates) needed for the analysis, plus prompt context, are sent to our server, which requests the analysis from the configured AI provider.
  • Revenue estimates — the public category, country and view figures needed to compute a revenue range.
  • Sponsorship analysis and channel analytics — the public channel/video fields those features require.
  • Monetization signals — for the monetized check, the extension fetches the public YouTube watch/channel page and sends its HTML to our server for signal matching; the matching patterns live only on the server.
  • Usage counting — a feature key is sent so daily free-use and plan limits can be enforced.

These requests carry the public research fields needed for the result, associated with your account for plan enforcement.

8. AI-assisted analysis

When you request an AI-assisted feature, the public fields and prompt context for that request are processed by the AI provider configured by TubeLeader (for example, OpenAI) solely to return the requested analysis. Please do not include secrets, credentials, private account data or sensitive personal information in content submitted for AI analysis. AI outputs are estimates and observations for research, not verified private facts.

9. Consent-based extension presence

Only after you affirmatively agree on the dedicated TubeLeader Extension sign-in/connect page do we record, against your signed-in account, limited operational information about the installation: that it is active, its extension version and enabled/disabled state, and daily feature-key totals of success, failure, quota-denial and entitlement-denial for server-backed features. Authorized administrators can view these operational records to provide support, maintain security, enforce plans and improve product reliability.

We collect this limited presence information for four narrow reasons: to provide support (for example, to see whether your installation is active and on a current version when you report a problem), to maintain security (to detect abnormal patterns that suggest abuse of a token or endpoint), to enforce plans fairly (to apply your daily free-use and plan limits consistently), and to improve product reliability (to see, in aggregate, which server-backed features are succeeding or failing so we can fix them). It is a small, operational signal about how the software is performing on your account — not a record of your browsing.

Presence reporting is deliberately limited. It does not include YouTube page URLs, page titles, the videos you watch, your YouTube search terms, referrers, page clicks, mouse or keyboard activity, scroll activity, battery level, ad-blocker status, screen resolution, device model, or your general browsing history. This limited reporting is required while the installation remains connected. If you decline the notice, your website account remains available, but the extension will not receive a token and its signed-in features will not connect. Any optional compatibility diagnostics remain separately optional and off unless you choose them.

10. What the extension does not collect

For clarity, the extension does not read your passwords or payment details; does not collect your browsing history on non-YouTube sites; does not track your mouse movements, keystrokes, scrolling or clicks for analytics; does not capture screenshots of your screen; does not collect precise location, contacts, files, or device sensors; and does not sell or share your information for advertising. It reads only the public YouTube page content needed for its interface, plus the account and operational data described above.

11. Permissions and why they are needed

  • storage — saves your login token, settings, consent choice, installation identifier and interface state on your device.
  • unlimitedStorage — lets local research caches exceed the small default quota so features load quickly and the browser does not evict them prematurely.
  • alarms — schedules lightweight background tasks such as periodic entitlement and status refreshes using the correct browser mechanism for a service worker.
  • Host access to youtube.com — required for the on-page interface: reading public page fields and injecting badges, tabs and panels on supported YouTube pages.
  • Host access to tubeleader.com — required for secure login handoff, entitlement and status requests, and the server-backed features you request.

We request only the permissions needed for these functions and do not request access to unrelated websites.

12. Service providers and sharing

Information handled by the extension is shared only with the providers needed to deliver its features — our hosting provider, the configured AI provider for AI-assisted analysis, and, for account purchases made on the website, our payment processors — or where the law requires it. Public YouTube data is obtained from Google/YouTube under their terms. We do not sell your data and do not share it for advertising. Our providers act on our instructions and are required to protect information consistent with this notice and applicable law. See the main Privacy Policy for the full provider and international-transfer details.

13. Data retention and deletion

Local extension data remains on your device until you remove it — by logging out, clearing extension storage, or uninstalling the extension — or until the browser evicts caches. On our server, the latest installation state is stored while the extension remains connected; your consent history and the daily aggregate feature outcomes are retained for up to 12 months for operational, security, plan-enforcement and product-reliability purposes, unless a longer period is legally required. You can request deletion of your account and associated server-side data by contacting support; some records may need to be retained where required by law or to resolve disputes.

14. Children

The extension is intended for a general, professional creator-research audience and is not directed to children under 13 (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children below that age through the extension.

15. Security

We use reasonable safeguards to protect information handled by the extension, including encrypted transport, hashed identifiers and access controls. No extension or internet service can guarantee absolute security. Protect your account and browser profile with a strong, unique password and any available additional verification, and tell us promptly if you suspect unauthorized access.

16. Your controls and rights

You can turn the extension’s interface on or off from its popup, toggle individual features, sign out to clear your local token, clear extension storage from your browser’s extension settings, or uninstall the extension entirely. You can also manage your account and connection from the website. Your broader privacy rights — including access, correction, deletion, portability and objection, and US-state and EEA/UK-specific rights — are described in the main Privacy Policy, and you can exercise them by contacting support@tubeleader.com.

17. Categories of data the extension handles, and why

For transparency, the categories of information the extension handles, where they live and why, are:

  • Authentication and account state — your login token and user/plan state, stored on your device to keep you signed in and apply your plan; and a one-way hash of a random installation identifier, stored on our server for login security, plan enforcement and installation status.
  • Local preferences and caches — your feature toggles, master on/off state, interface state, consent choice and cached public research results, stored on your device so features load quickly and reliably.
  • Public YouTube page fields — identifiers, titles, view and subscriber counts, dates, durations, descriptions, links and visible search-result fields, read locally in your browser to build the on-page interface, and sent to our server only for the specific server-backed request you make.
  • Operational presence data — after your consent, the installation’s active state, extension version, enabled/disabled state and daily aggregate feature-outcome counts, stored on our server to provide support, maintain security, enforce plans and improve reliability.

The extension does not intentionally collect special categories of sensitive personal data (such as health, precise location, biometric or government-identifier data).

If you are in the European Economic Area or the United Kingdom, we process information handled by the extension on the following legal bases: performance of a contract (to provide the signed-in features you request and enforce your plan); legitimate interests (to keep the service secure, prevent abuse and improve reliability, balanced against your rights and freedoms); consent (for extension presence reporting and any optional diagnostics, which you provide on the connect page and can withdraw by disconnecting the extension); and legal obligation (to meet security, tax and other legal requirements). Withdrawing consent does not affect processing already carried out before the withdrawal.

19. International data transfers

The providers that support the extension may process information in countries other than your own, including where our hosting and the configured AI provider operate. Where required by law, we rely on an appropriate legal transfer mechanism — such as the European Commission’s Standard Contractual Clauses or an equivalent safeguard — together with appropriate contractual protections. Further detail on transfers and providers is in the main Privacy Policy.

20. No advertising or cross-site tracking

The extension does not include advertising SDKs, does not set advertising cookies, and does not track your activity across websites. It does not build an advertising profile about you, and it does not share your data with advertising networks. Because the extension performs no cross-site or advertising tracking, there is nothing to opt out of for advertising within the extension itself; any advertising we run to promote TubeLeader happens on third-party ad platforms and is described in the main Privacy Policy. Some browsers send a “Do Not Track” signal; because there is no common industry standard and the extension does no cross-site tracking, no special handling is required.

21. Third-party services the extension relies on

The extension relies on a small number of third parties, each processing only the information needed for its function under its own terms: Google / YouTube, to obtain public YouTube data (governed by the YouTube Terms of Service and the Google Privacy Policy); our hosting provider, to run the TubeLeader server; the configured AI provider (for example, OpenAI), to return AI-assisted analysis; and, for account purchases made on the website, our payment processors. You can review and revoke third-party access to your Google/YouTube account at myaccount.google.com/permissions.

22. Chrome Web Store data disclosures

In the Chrome Web Store listing, we disclose the categories of data the extension handles and certify that our use complies with the Chrome Web Store Developer Program Policies, including the Limited Use requirements. In summary: the extension handles authentication information, website activity limited to the supported YouTube and TubeLeader pages needed for its features, and consent-based operational usage data; it uses this data only to provide and secure the features you request and to enforce your plan; it does not sell the data, does not use or transfer it for personalized advertising, and does not use or transfer it to determine creditworthiness or for lending purposes. This page is the human-readable privacy policy referenced from that Store listing.

The extension’s signed-in and presence features begin only after you affirmatively agree on the dedicated TubeLeader Extension sign-in/connect page — consent is not bundled into installation, and the extension does not connect until you choose to. Your consent choice is stored so you are not asked repeatedly, and it is tied to the current version of this notice; if we make a material change that requires fresh agreement, you will be asked to review and agree again before signed-in features continue. You can withdraw consent at any time by signing out or disconnecting the extension, which stops presence reporting and clears your local token. Declining or withdrawing consent does not affect your ability to use your TubeLeader website account; it only means the extension’s signed-in, server-backed features will not run.

24. Data minimization by design

The extension is built to send as little as possible off your device. Wherever a result can be produced from the public information already on the page, it is computed locally in your browser and nothing is sent to our server. Only when you use a specific server-backed feature are the public fields required for that one request transmitted. Presence reporting is limited to aggregate operational counts and installation state — not a log of the pages you visit or the videos you watch. The installation identifier is stored on our server only as a one-way hash, never as a hardware fingerprint. These choices are intended to keep your data footprint small while still allowing the features to work reliably.

25. Changes to this notice

We may update this Extension Privacy Policy to reflect changes to the extension, our practices or the law. Material changes will update the “Last updated” date above and, where required, the Chrome Web Store disclosure. Your continued use of the extension after an update takes effect means you accept the revised notice.

26. Contact

Questions or requests about this notice can be sent to support@tubeleader.com or through our Contact page. Please include enough non-sensitive account context to locate your record, and never send your password or full payment-card details.