Privacy Policy — HaoSub Subtitle Translator

Effective date: August 15, 2026
Last updated: September 25, 2026

HaoSub Subtitle Translator (the “Extension”) adds machine-translated subtitles to YouTube videos. This policy explains what data the Extension handles, why it handles it, where it goes, how long it remains, and what choices you have.

The public version of this policy is available at https://axing499.github.io/HaoSubDoc/.

1. Data the Extension handles

The Extension handles only the data needed to provide and configure subtitle translation:

The Extension does not ship a developer API key. It does not intentionally collect names, email addresses, account credentials other than the optional user-supplied Baidu or DeepL keys, payment information, browsing history across sites, or the content of non-YouTube pages.

2. How and why data is used

Data is used only for the Extension’s single purpose: to display translated subtitles alongside, or instead of, YouTube captions, to remember the user’s subtitle preferences, and to provide optional English vocabulary highlighting and dictionary lookup. Learning mode is a Beta feature aimed mainly at English learners, especially Simplified Chinese speakers studying English; support for other languages is still in progress.

The developer does not sell or rent user data. The Extension has no advertising, behavioral profiling, analytics, telemetry, or developer-operated model-training pipeline. Data handled by the Extension is not used by the developer for advertising, analytics, creditworthiness or lending decisions, or training developer models.

3. Consent, defaults, and controls

Translation is off by default. The Extension does not begin translation merely because it is installed.

When no valid current-version local record exists, the Popup, Options page, and YouTube-player settings panel show a disclosure that subtitle text and the selected target language will be sent from the browser to the translation service the user selects: Google Translate by default, or Baidu Translate or DeepL if the user enters their own API keys and chooses that engine. The same disclosure states that, with learning mode and the online dictionary on, looking up a word may send that lemma to Free Dictionary API. The Enable translation button inside that disclosure is the only explicit confirmation: clicking it saves the record and enables translation. Until that confirmation exists, the separate Use HaoSub captions switches outside the disclosure stay disabled and cannot grant consent or turn translation on. After a valid record already exists, the disclosure does not appear again and those switches only toggle translation on or off without rewriting consent. Selecting Later saves enabled: false, does not create the record, and suppresses automatic first-use prompts so they do not return on every video. Manually opening settings after Later still shows the disclosure and keeps the external switches locked until the in-disclosure button is used. Turning YouTube CC on is not consent and cannot create the record or enable translation. Original-only display does not send subtitle text to a translation provider.

Google AI Studio is an optional engine. Selecting it shows a separate confirmation that subtitle text will be sent to Google AI Studio with the user’s own API key, and that aggregate mode may rotate among models the user checks. That confirmation is stored per provider. It does not replace or invalidate the current consent record, and an extension update does not ask for it again. The Extension also asks Chrome for optional permission to contact generativelanguage.googleapis.com at that moment. Until both that confirmation and the optional permission exist, the Extension does not send subtitle text to Google AI Studio.

SiliconFlow is a separate optional engine with the same rule. Selecting it shows its own confirmation, stored per provider, and asks Chrome for optional permission to contact api.siliconflow.cn and www.siliconflow.cn. The model price page is read only to label models whose listed input and output prices are zero. It does not increment the consent version and is not asked again on extension updates.

YouTube’s CC button controls caption activity for the current player session without changing the Extension’s saved translation preference. Turning CC off pauses Extension translation while preserving that preference. Turning CC on resumes Extension translation only when the saved preference is enabled and valid consent already exists; otherwise, only YouTube’s native captions are shown. CC actions never create consent or enable the saved translation preference. Turning CC or translation off never clears the local consent record.

The Background Service Worker sends translation requests only when both:

  1. a valid current-version local consent/enablement record exists; and
  2. the translation setting remains enabled.

Turning translation off stops new translation requests. Resetting settings restores default subtitle settings, including the default-off state. Stored Baidu and DeepL API keys are kept unless the user also chooses to remove them. Resetting currently does not delete the prior local consent record. Uninstalling the Extension stops its processing; Chrome normally removes extension-owned local and synced data according to Chrome’s uninstall and sync behavior.

4. Data sharing and third-party boundary

When translation is enabled and the valid current-version local record exists, the Extension sends:

directly from the browser to one selected provider over HTTPS:

HTTPS encrypts the request in transit between the browser and the service endpoint; endpoint operators and software with access to request URLs or bodies may still process or log it. A failure on one engine does not silently retry another engine. Character allowances and free-trial limits advertised by a provider are that provider’s offerings; this Extension does not supply them.

There is no developer-operated relay server: subtitle text and translations are not routed through a server controlled by the Extension developer. The selected provider is the third-party recipient and processes translation requests under that provider’s own terms and privacy practices. The developer does not control the provider’s retention, logging, security, or secondary use after data crosses this boundary. Users should review the applicable provider policies before enabling translation. Optional Baidu, DeepL, Google AI Studio, SiliconFlow, OpenRouter, and Groq keys are stored only in chrome.storage.local on this device. They can be read from the installed extension and are not encrypted with a user password.

If learning mode is on, the online dictionary is on, and a valid current-version local record exists, an English lemma may be sent over HTTPS to Free Dictionary API at https://freedictionaryapi.com/api/v1/entries/en/{word}. With Simplified Chinese as the subtitle target language and a packaged short definition present, that happens when the user requests English definitions or adds the word to the vocabulary book. With any other target language, tapping the word may send the lemma immediately. If the lemma is missing from the lookup table or the packaged glosses are empty, opening the card may send the request immediately. When the target is not Simplified Chinese or English, the request may include Wiktionary translations; the Extension keeps only that target language and discards the rest. A failure does not silently retry Google Translate, Baidu, or DeepL.

YouTube remains a separate third party. The Extension runs only on https://www.youtube.com/*, reads caption data made available to the current YouTube page/player, and may directly request valid YouTube timed-text resources over HTTPS. YouTube’s handling of video, account, and caption data is governed by YouTube/Google policies, not this policy. Free Dictionary API / Wiktionary is a separate third party for optional word lookups.

5. Storage, cache size, and retention

Synced settings

Extension settings are saved in chrome.storage.sync. Chrome may synchronize these settings through the user’s signed-in Chrome profile according to the user’s Chrome sync configuration and Google’s applicable policies. Subtitle text and translated text are not written to chrome.storage.sync by the translation cache.

Local consent/enablement record

The consent/enablement version and enablement timestamp are saved in chrome.storage.local, local to the Chrome profile rather than intentionally synchronized by the Extension. A separate settings-schema version marker is also stored locally. Optional Baidu App ID and Secret, optional DeepL API keys, and optional Baidu/DeepL monthly character-usage counters and caps, if present, are stored in the same local area and are never written to chrome.storage.sync. Usage records store counts and caps, not subtitle text. If the user adds words in learning mode, those vocabulary-book entries (definitions and up to four caption examples) are stored in the same local area, are not synced, and are not mixed with the translation cache. Trimmed dictionary lookups, if any, are stored in the same local area. These local records remain until extension-owned data is removed, such as through uninstall or browser/profile storage management. Resetting subtitle settings removes and recreates the settings-version marker. Stored Baidu and DeepL keys are deleted only if the user also chooses to remove them. Resetting does not currently remove the consent/enablement record and does not clear the vocabulary book. Monthly caps return to unlimited; used-character counts are kept.

Translation cache

The Background Service Worker keeps a two-layer translation cache. The source text is part of the cache key and the translated text is the value. Neither layer writes subtitle text or translations to chrome.storage.sync or chrome.storage.local. Learning-mode vocabulary entries are separate from this cache.

Layer 1 (memory): an in-memory least-recently-used cache of at most 1,000 entries, each expiring 30 minutes after insertion. This layer disappears when the service worker’s memory is discarded, the Extension is reloaded, or the Extension is uninstalled.

Session layer (current tab + video): always on. Entries live in chrome.storage.session for the current tab’s current YouTube watch video, at most 4,000 unique strings, with a 30-minute idle timeout. This layer is not written to disk. It is cleared when the tab is closed, when the user leaves /watch or switches videos, when the idle timeout elapses, when the browser session ends, or when the Extension is reloaded. It exists so refreshing the same video does not need a new translation request. If session storage is unavailable, translation continues using memory and the network.

Other transient processing

Current YouTube caption payloads and translation work may exist temporarily in page, content-script, or service-worker memory while a video is processed. The Extension does not provide a developer database or cloud account in which this data is retained.

6. Permissions and security

The Extension requests only:

Network endpoints are HTTPS. Stored settings and local consent/enablement records are restricted to trusted extension contexts when Chrome supports the relevant access-level API. The Extension uses packaged JavaScript and does not intentionally download or execute remote code. No method of transmission or storage is guaranteed to be completely secure, however.

7. Disclosure, transfer, and sale

The developer does not sell user data and does not disclose it to advertisers, data brokers, analytics providers, or developer-operated training systems. Data is transferred to the selected translation provider only to provide the user-requested translation, as described above. The developer does not use handled data for creditworthiness or lending decisions. Data may also be disclosed if required by applicable law; because the Extension has no developer relay or backend collection, the developer ordinarily does not possess subtitle requests sent directly to the selected provider.

8. Children and sensitive content

The Extension is a general-purpose subtitle utility and is not directed specifically to children. Subtitle text can reflect whatever a user chooses to watch and may contain personal or sensitive information. Users should not enable translation for content they do not want sent to Google Translate, Baidu Translate, or DeepL. If applicable law requires parental consent for a user, that consent should be obtained before using the translation feature.

9. International processing

Google, Baidu, or DeepL may process translation requests in countries other than the user’s country. Chrome sync may likewise process synchronized settings through Google infrastructure. Those transfers are governed by the selected provider’s applicable terms, privacy policies, and legal mechanisms. The Extension developer does not choose the provider’s processing locations.

10. Your choices and requests

Users can:

Because the developer does not operate an account system, relay server, analytics service, or user database for this Extension, the developer generally cannot identify or retrieve an individual user’s subtitle requests. Privacy questions or legally applicable requests may be sent to axing499@163.com.

11. Changes to this policy

This policy may change when the Extension’s features, providers, data practices, or legal obligations change. Material changes should be reflected by updating the “Last updated” date, publishing the revised policy, and updating in-product/store disclosures where required. The current implementation recognizes consent version 4. Adding Free Dictionary API as an optional recipient for learning-mode word taps is a material change: existing version 1–3 records are treated as not granted until the user confirms again inside the disclosure. A future material privacy change that alters what already-consented users send should increment that version so the existing gate treats the old record as not granted. Adding an optional provider that cannot receive subtitle text until a separate per-provider confirmation does not increment the version. Google AI Studio, SiliconFlow, OpenRouter, and Groq use that separate confirmation. If the user turns on backup translation, the same subtitle text is also sent to the selected backup engine so a translation can appear before the AI result arrives.

12. Contact

Privacy contact: axing499@163.com
Public privacy-policy URL: https://axing499.github.io/HaoSubDoc/