Data we collect
Account data
Sign-in identity, email address, display name, profile image, account tier, workspace settings, and authentication state through Firebase Authentication and Firestore.
Workspace and map data
Saved maps, topology content, publish state, comments, bookmarks, likes, forks, and related workspace metadata that you create or interact with.
YouTube page data
When you choose to analyze a YouTube page, the extension may read data from the active page such as title, URL, description, chapters, comments, playlist/channel context, available transcript/captions, and public metadata needed to generate learning summaries, Q&A, recommendations, or knowledge maps. If captions are unavailable, the summary fallback uses only page text such as the title, channel, description, chapters, and keywords; it does not upload or analyze video audio or frames.
Billing and support data
Payment-provider IDs, product/variant identifiers, entitlement status, support emails, and refund/cancellation metadata. Full card details are handled by the payment provider, not by Human Highlight.
Server-issued AI Credit transaction records and billing-support cases, including the message you submit, are retained for up to 180 days so charges, credits, refunds, and support decisions can be verified. Diagnostic AI-usage and error signals are retained for up to 30 days, so older investigations may have a transaction record without the shorter-lived diagnostic detail. Deleting your account triggers cleanup of these records.
Billing transactions, checkout attempts, payment events, refunds, disputes, and limited provider-verification records are retained for up to 180 days for reconciliation, fraud prevention, and dispute handling. Depending on the payment provider, these records may include a billing contact email and signed webhook data needed to prove what the provider sent. Human Highlight does not store full payment-card details.
Feedback reports and screenshots
A feedback report may include the title, description, environment details, and an optional screenshot you submit. Actionable reports may be copied to our GitHub issue tracker for engineering triage. Screenshots are kept for no more than 30 days; report content is kept for no more than 90 days, then the GitHub title/body and stored report are privacy-redacted. Deleting your account triggers the same cleanup immediately. Content-free retry/audit status may remain for up to 30 additional days.
Screenshots remain in controlled private storage. We do not copy their download URLs, access tokens, or Firebase user IDs to GitHub.
Diagnostic error reports
When the extension itself hits an unexpected error, it may send a diagnostic report while you are signed in: the error message, a stack trace naming extension files only, the extension version, your browser's user-agent string, your interface language, the kind of YouTube page (watch, Shorts, channel) but not which video or channel, and your account ID. URLs are shortened before sending so that they cannot identify a video or channel, and no page content, transcript, comment, or map data is included. Reports are rate-limited, used only to fix defects, and kept in error-monitoring logs for no more than 30 days. Signed-out use sends no reports.
YouTube connection diagnostics are a separate, optional setting, off by default. If you enable it while signed in, the extension sends counts grouped by request category, extension or page transport, and response status to Human Highlight through Google Cloud, at most once every five minutes. We use these counts to diagnose connection failures and rate limits. The counter payload excludes video/channel IDs, URLs, search text, titles, captions, page content, and raw error messages. Requests are authenticated; these are not anonymous requests. Counter logs are kept for no more than 30 days. Turning the setting off clears unsent counts and stops further collection and uploads; already submitted logs follow that retention period.
Browser video search counts. When the extension sends YouTube searches for your maps from your browser, the next upload includes how many of those requests were sent, answered, refused (403 or 429), failed in another way or got no answer, and how often sending paused as a result. These counts travel inside the map's signed-in upload. Our servers only add them to service-wide daily totals: they are not stored with your account, any video, search text or URL, and individual reports are not kept. Daily totals are kept for up to 13 months and are used to decide whether the extension should send more slowly.
How data is used
- To sign you in, maintain your workspace, and sync paid workspace features.
- To generate, cache, display, publish, moderate, and recommend knowledge maps.
- To enforce quotas, paid entitlements, AI Credits, and abuse controls.
- To provide support, troubleshoot errors, handle refunds, and respond to legal or abuse reports.
- To measure site reliability and basic product usage through analytics and error monitoring.
Important boundaries
| YouTube history | Human Highlight does not need your full YouTube watch history. The extension reads only the YouTube page you actively choose to analyze, and video summary/Q&A analysis starts only after a manual user action that can be reset from the extension Options page. |
|---|---|
| Raw transcripts | Available transcript/caption text is used to generate the video-learning output you requested. Raw transcripts are not used for advertising and are not intended to be permanently stored unless you explicitly save, export, publish, or share derived content. |
| Google APIs and Limited Use | Human Highlight's use and transfer of information received from Google APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements. Google API data is used only to provide or improve the user-facing learning, sign-in, sync, support, security, and entitlement features described in this policy. |
| Public maps | If you publish a map, that map and its public metadata may be visible to other portal visitors. Private workspace material remains private unless you publish or share it. |
| Children | KidMap family learning is managed by a parent, legal guardian, or authorized adult. Adults create and manage accounts, authorize child-device links, and handle purchases. A linked child's profile identifiers (such as display name, email, and avatar), KidMap progress, and recent learning activity may be shown to the authorizing adult. Children should not independently create paid accounts, purchase plans, or enter payment details. The Kids landing page does not initialize Google Analytics; limited first-party fatal-error diagnostics may still be reported for security and reliability. Adults can unlink a child device, delete account data in Settings, or contact us about access or deletion. |
Choices and contact
You can contact us to request help with account access, deletion, privacy questions, or legal concerns. Some records may be retained where needed for security, abuse prevention, billing records, dispute handling, or legal compliance.
Email contact@humanhighlight.co for account/privacy requests and legal@humanhighlight.co for legal notices.