Privacy policy
Effective September 2, 2026 · Talking Heads tester release
This policy describes how Talking Heads, including its Chrome extension and hosted service, handles information. Contact the Talking Heads publisher at talking-heads@coffeeboy.cafe.
Information we process and why
- Google account: Google sign-in supplies a verified email address, display name, and account identifier. We use a derived identifier, account profile, and login sessions to authenticate you, enforce allowances, and associate test subscriptions. We do not request access to Gmail, Drive, or your Google password.
- Video context: the extension reads the current video's ID, title, creator, available English captions, and playback position/state. Relevant video context is sent to our service and OpenAI to produce suggested questions and grounded answers, and to support player controls. Suggested questions may be generated automatically when a video opens while you are signed in.
- Conversation content: your questions, recent chat context, generated answers, and voice transcriptions are processed to provide the conversation. Questions may contain personal information you choose to share; avoid sensitive information.
- Voice audio: when you start voice and grant microphone permission, microphone audio is sent through our service to OpenAI for transcription and responses. Audio may include background sound and silence. Ending the voice session stops capture. Text chat does not require the microphone.
- Usage and test billing: we retain usage reservations and debits, request identifiers, account status, and Stripe customer/subscription/event identifiers to enforce monthly limits and reconcile test subscriptions. Stripe hosts checkout and receives billing information you enter. The service does not receive full payment card numbers. During this release, use test payment information only.
- Security and AI audit trail: we keep per-account login and voice-session events, model and provider request/session identifiers, provider-reported token counts and available cache/audio/reasoning breakdowns, estimated costs, streamed audio duration, failures, quota denials, and administrative actions. This metadata helps authorized administrators monitor usage, investigate abuse, suspend access, and revoke sessions. Audit records do not include prompts, answers, captions, raw audio, passwords, or authentication tokens.
- Technical information: hosting providers process network information such as IP addresses and request metadata to deliver and protect the service. We use IP addresses for login rate limiting. Application error logs contain request IDs, paths, and status codes, not intentionally logged chat bodies, microphone recordings, credentials, or provider payloads.
Local storage and server processing
Your chat archive is kept in Chrome's local extension storage, not in a server-side chat-history database. Recent chat context is nevertheless transmitted when needed for an AI request. Local storage also holds your login token; preference settings such as speaking speed and floating references may sync through Chrome if browser sync is enabled. Local archives and login tokens do not use Chrome sync.
Cloudflare hosts our API and account/usage records. OpenAI processes video context, questions, conversation context, and audio to supply AI features. Google provides sign-in. Stripe provides sandbox checkout and subscription management. These services may process information outside your country under their own privacy and security terms.
Our application does not maintain a server-side archive of chat conversations or raw voice recordings. OpenAI and infrastructure providers can retain data under their applicable service policies; local-only chat history is not a promise of zero provider retention. See OpenAI, Cloudflare, Google, and Stripe.
Retention and your choices
Local chat archives remain until cleared or the extension's local data is removed. The trash button clears the active tab's video conversation; other tabs and saved copies may remain. Removing the extension's local storage removes all its local archives. Signing out revokes the current login session but does not delete local chats or the server account. Extension login sessions expire after 30 days. The administrator website uses necessary secure, HTTP-only cookies for its 10-minute sign-in flow and separate eight-hour admin session; it does not use advertising cookies.
The service caches up to 40 sets of generated video questions per account. They stop being reused after seven days, and expired entries are removed on later cache writes; they may remain stored longer if the account is inactive. Account profiles, usage ledgers, security audit trails, and subscription records currently have no automatic age-based deletion schedule. They are retained for account operation, abuse prevention, and reconciliation.
Email talking-heads@coffeeboy.cafe to request access to or deletion of account information. We may need to verify account ownership and retain limited records where required for security, disputes, or legal obligations. Clearing browser history or a video chat does not delete server account or provider records. You can revoke microphone access through Chrome and revoke Google access through your Google account.
Limited use and security
We do not sell personal data, use it for advertising, or transfer it for creditworthiness or lending decisions. We use and disclose it to provide the described features, protect the service, and comply with law. We do not use conversations to build our own model-training dataset. Access is limited to service providers and authorized operation/support needs, or disclosures required by law. Data is sent over encrypted connections; provider API keys remain on the server.
Talking Heads' use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Updates and contact
We will update this page as the product or data practices change. For privacy questions, contact talking-heads@coffeeboy.cafe.