Privacy Policy

Last updated: May 29, 2026

This Privacy Policy explains how Your AI Translator by LicheeSight collects, uses, and protects information when you use the browser extension and user portal at youraitranslator.licheesight.com.

1. Information We Collect

  • Account information: email address and authentication identifiers.
  • Subscription and billing metadata processed through Dodo Payments.
  • Extension device-linking and license metadata needed for account access, device verification, and entitlement refresh.
  • Local extension activity records, such as usage totals and provider request history stored on your browser.
  • Optional page context, screenshots, images, files, or chat attachments that you choose to send to your selected AI provider.
  • Optional feedback you submit through support email or Featurebase.

2. Local Vault, API Keys, and On-Device Data

In BYOK mode, your provider API keys are stored locally inside the extension in an encrypted local vault. Those BYOK keys are not uploaded to or stored on our server as part of normal product operation.

The extension may also store local usage data such as estimated token counts, provider selections, and device-side settings to improve your experience. This local data is generally kept on your device unless you explicitly send feedback or use a feature that requires server interaction.

The extension can keep a local provider request history for transparency and troubleshooting. This history may include prompts, provider responses, errors, model/provider metadata, usage metadata, and attached context summaries. It is stored on your browser for up to 30 days or the latest 100 requests, whichever limit is reached first, and can be cleared from the extension settings.

Local token-usage records inside the extension are intended as device-side usage history. When the selected provider returns explicit usage metadata, the extension prefers those values. Otherwise it may store an estimate. These local records are not represented as the authoritative billing invoice for your external provider account.

If you enable cloud settings sync, the extension stores an encrypted settings package in your browser's sync storage. That encrypted package is protected by a passphrase you provide. The passphrase is stored only on the browsers where you choose to save it, and it is not sent to or retained by our server.

BYOK API keys remain in the local extension vault during normal runtime. If you enable encrypted cloud sync, the extension may also store a separate encrypted BYOK snapshot in browser sync storage so another browser signed into the same sync profile can restore those keys after you enter the passphrase locally.

3. Translation Data and Third-Party Providers

When you use BYOK mode, translation requests are sent to your selected AI provider using your own API key. Your use of third-party providers such as OpenAI, OpenRouter, Google, Anthropic, DeepL, xAI, Alibaba Cloud, DeepSeek, or a custom OpenAI-compatible provider you configure is also subject to the terms and privacy policies of those providers.

Translation and Writing Assistant requests may include the text you select, type, or ask the extension to process, the active prompt, target language, model selection, and optional surrounding context when context-based translation is enabled. These requests are sent directly from your browser to the selected provider endpoint.

Sidebar chat requests may include your typed message, page title, page host, selected page sections, selected text, uploaded or pasted files/images, and screenshots of a page section when you explicitly attach that context. Attached context is sent to your selected AI provider only when you submit the chat message.

If you configure a custom provider endpoint, the extension requests browser host access only for that endpoint's origin. Custom provider traffic is controlled by the endpoint you enter and the provider account/API key you supply.

We do not process billing for your direct BYOK provider usage. For product subscriptions, billing is handled separately through Dodo Payments.

The extension may periodically contact our backend to validate account status, refresh locally stored license entitlements, and maintain linked-device access. These refresh calls do not require your BYOK key.

4. Browser Permissions and Page Access

The browser extension requests access to webpages so it can detect selected text, hover targets, editable fields, word hints, and in-page translation UI on pages where you choose to use it. The extension does not continuously upload full webpages to LicheeSight. Page text is processed for translation only when you trigger a translation or Writing Assistant action.

If you use page-section chat attachments with screenshots, the extension may request optional access that allows Chrome to capture the visible tab. This permission is used only after you choose to attach a page section and grant the browser permission. If you deny it, the extension can still attach available text context without a screenshot.

Some extension resources are available to webpages only so the extension can render its own in-page UI consistently. Provider API host permissions are limited to supported provider domains, and custom provider host permissions are requested only after you enter a custom endpoint.

If an AI response includes formatted content, the extension removes unsupported or unsafe code before displaying it on the webpage. Some translation UI may be shown in an isolated browser layer to reduce interference from website styles.

5. How We Use Information

  • Authenticate users and link browser devices securely.
  • Provide subscription management and customer support.
  • Detect abuse, protect service integrity, and improve reliability.
  • Comply with legal obligations.

6. Data Sharing

We share data only with service providers required to operate the product (for example Supabase for auth/database, Dodo Payments for billing, and selected AI providers you choose to use). We do not sell personal information.

Information received from Chrome extension permissions or Google account APIs is used only to provide and improve the extension's user-facing translation, account, licensing, and support features. We do not use or transfer this information for advertising, resale, data brokerage, creditworthiness, or lending.

7. Data Retention and Security

We retain account and transaction data as long as needed to provide the service, meet legal requirements, and resolve disputes. We use industry-standard controls to secure data in transit and at rest.

For cloud settings sync, we provide client-side encryption tooling, but the practical security of the synced settings also depends on your browser profile security, local device security, and how you manage your passphrase. We do not receive the passphrase and cannot recover it for you. If you forget it, encrypted cloud settings may become unreadable.

Because cloud settings sync relies on browser-managed storage outside our direct custody, we disclaim responsibility for loss of access caused by forgotten passphrases, compromised browser accounts, insecure local devices, or unsupported third-party browser sync behavior.

8. Your Rights

You can request access, correction, or deletion of your personal data by contacting us. You may also stop using the service and remove the extension at any time.

9. Contact

For privacy requests, contact:[email protected]