Privacy Policy
Last updated: December 7, 2024
1. Introduction
Retrove Inc. ("Retrove," "we," "our," or "us"), the company behind Gloss, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension and related services.
By using Gloss, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address when you create an account or sign in
- Payment Information: Processed securely through Stripe; we do not store credit card details
- Preferences: Your profession, learning goals, and display settings
2.2 Information Collected Automatically
- Video Metadata: YouTube video IDs, titles, and durations of videos you analyze
- Usage Data: Number of videos analyzed, tokens used, and feature usage
- Technical Data: Browser type, extension version, and error logs
2.3 Information We Do NOT Collect
- Your complete YouTube browsing history
- Video content or audio from videos you watch
- Personal data from other browser tabs or activities
3. How We Use Your Information
We use the collected information to:
- Provide and maintain the Gloss service
- Generate AI-powered definitions for videos you analyze
- Process payments and manage subscriptions
- Improve and personalize your experience
- Send important service updates (not marketing emails)
- Monitor usage to prevent abuse and enforce usage limits
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), UK, and Switzerland, we process your personal data based on the following legal grounds:
4.1 Contract Performance
We process data necessary to provide the Gloss service you requested:
- Account authentication and management
- Processing subscription payments via Stripe
- Generating AI-powered video definitions
- Enforcing usage quotas based on your plan
4.2 Legitimate Interests
We process certain data based on our legitimate business interests, balanced against your privacy rights:
- Preventing fraud and abuse of our service
- Improving and personalizing the user experience
- Debugging errors and maintaining service quality
- Sending important service-related communications
4.3 Consent
We rely on your consent for optional data processing:
- Collecting your profession, learning goals, and preferences (for personalized analysis)
- Sending these preferences to Google Gemini AI for customized definitions
You can withdraw consent at any time by clearing these fields in your preferences or contacting us.
4.4 Legal Obligation
We may process data to comply with legal requirements, such as tax record retention for subscription payments (7 years).
5. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Firebase (authentication, database), Stripe (payments), Google Cloud (Gemini AI)
- Legal Requirements: When required by law or to protect our rights
We do NOT sell, rent, or trade your personal information to third parties.
5.1 AI Processing & Automated Decision-Making
Gloss uses artificial intelligence (Google Gemini API) to automatically generate definitions and glossaries from YouTube video content. This is a core feature of our service.
What Data is Processed by AI:
- Video content: YouTube video URL, title, description, and captions/transcripts
- Your preferences (if provided): Profession, learning goals, known topics, and custom instructions
What Data is NOT Processed by AI:
- Your email address or account identity
- Payment or billing information
- Your previous analysis results or browsing history
How AI Processing Works:
When you analyze a video, our servers send the video information to Google's Gemini API, which returns a list of terms with definitions. The AI does not make decisions that significantly affect you legally or similarly. It only generates educational content.
Your Rights Regarding AI Processing:
- You can choose not to provide optional preferences (profession, goals) — the AI will still work with basic video content only
- You can delete any analysis at any time
- You can request human review of how the AI processed your data by contacting us
AI-generated definitions are provided for educational purposes only and may not always be accurate. Google's Gemini API is subject to Google's Gemini API Terms and Google Privacy Policy.
6. Data Security
We implement appropriate technical and organizational security measures to protect your data, including encryption in transit (HTTPS) and at rest, secure authentication through Firebase, and regular security reviews. However, no method of transmission over the Internet is 100% secure.
6.1 Data Location
Your data is stored on Firebase servers in the United States (us-central1 region). For users in the European Economic Area (EEA), we rely on Google's Data Processing Terms and Standard Contractual Clauses (SCCs) as the legal basis for international data transfers, in compliance with GDPR.
7. Data Retention
We retain your data according to these periods:
- Account data: Until you request deletion
- Video analyses: Until you delete them or request account deletion
- Usage counters: Reset monthly on the 1st of each month
- Subscription data: While your subscription is active, plus 7 years for tax records
To request deletion of your account and all associated data, email us at thomas@retrove.net. We will process deletion requests within 30 days.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request data portability
To exercise these rights, contact us at thomas@retrove.net.
Right to Lodge a Complaint
If you are in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data in accordance with applicable law.
A list of EEA data protection authorities is available at: European Data Protection Board Members
For UK residents, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.
9. Browser Extension Permissions
Gloss is a Chrome browser extension that requires certain permissions to function. Here is what each permission does and why we need it:
- tabs: Allows us to detect when you navigate to a YouTube video so we can offer to analyze it. We only read the URL of YouTube tabs — we cannot see your browsing history or other tabs.
- storage: Allows us to save your preferences (like display settings and notification preferences) locally in your browser. This data syncs across your Chrome browsers if you're signed into Chrome.
- identity: Allows you to sign in with your Google account using secure OAuth authentication. We only receive your email address — not your Google password.
- contextMenus: Allows us to add a right-click menu option to quickly toggle analysis on/off.
- Host permissions (youtube.com): Allows us to display the glossary overlay on YouTube video pages and detect video playback position.
We do NOT request permissions that would allow us to read data from other websites, access your browsing history, or monitor your activity outside of YouTube.
10. Children's Privacy
Gloss is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal data, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date. Your continued use of Gloss after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: thomas@retrove.net