1. Introduction
This Privacy Policy describes how Sumbox ("we," "our," or "us") collects, uses, and protects your information
when you use our browser extension ("Extension"). We are committed to protecting your privacy and being
transparent about our data practices.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — Used for account identification, authentication, and communication
- Authentication data — Securely managed through Supabase (our authentication provider)
If you sign in with Google, we receive your email address and basic profile information from Google.
2.2 Content You Process
When you use the summarization feature, we temporarily process:
- YouTube video transcripts/captions — Extracted from videos you choose to summarize
- Article text content — Extracted from web pages you choose to summarize
- Page URLs and titles — Used to identify content and display in your history
Important: This content is sent to our summarization service (via
Make.com webhooks) solely to generate summaries. We do not permanently store the original content on our
servers.
2.3 Subscription Information
Payment processing is handled by Polar.sh. We receive:
- Subscription status (active, cancelled, expired)
- Subscription dates
- Polar customer ID
We do NOT receive or store your payment card details.
2.4 Locally Stored Data
The following data is stored locally in your browser (not on our servers):
- Summary history — Your past summaries, stored per user account
- User preferences — Language settings, dark mode preference
- Authentication session — To keep you logged in
3. How We Use Your Information
We use your information to:
- Provide and operate the summarization service
- Authenticate your account and manage your subscription
- Store your summary history locally for your convenience
- Improve and optimize the Extension
- Communicate important updates about the service
4. Information Sharing
4.1 Service Providers
We share your information only with the following service providers:
- Supabase — Authentication and user database
- Make.com — Webhook processing for summarization
- Polar.sh — Subscription and payment processing
- Google Gemini (via API) — AI model used to generate summaries. Content is sent for
processing and is not permanently stored by us. Google's data handling is subject to their own privacy
policies.
4.2 Legal Requirements
We may disclose information if required by law or to protect our rights, safety, or property.
We do NOT:
- Sell your personal information
- Share your data with advertisers
- Use your content for AI training purposes
5. Data Security
We implement appropriate security measures including:
- Secure HTTPS connections for all data transmission
- Authentication via industry-standard OAuth 2.0
- Encrypted storage of credentials via Supabase
- Local browser storage for sensitive history data
6. Data Retention
- Account data — Retained while your account is active; deleted upon account deletion request
- Summary history — Stored locally in your browser; you can clear it anytime
- Processed content — Not permanently stored; used only for real-time summarization
7. Your Rights and Choices
You have the right to:
- Access your account information
- Delete your account and associated data
- Clear your local summary history at any time
- Export your summaries using the download feature
- Opt-out by uninstalling the Extension
To exercise these rights, contact us at contact@sumbox.app.
8. Browser Permissions
The Extension requires certain browser permissions:
| Permission |
Purpose |
activeTab |
Access current tab when you click Summarize |
tabs |
Get URL and title of current page |
storage |
Save your preferences and history locally |
scripting |
Extract article content from web pages |
identity |
Enable Google Sign-In authentication |
sidePanel |
Display the Extension interface |
<all_urls> |
Extract content from any article you want to summarize |
Note: We only access page content when you explicitly click the
Summarize button. We do not passively collect browsing data.
9. Children's Privacy
The Extension is not intended for children under 13 years of age. We do not knowingly collect personal
information from children under 13.
10. International Users
Your information may be processed in countries other than your own. By using the Extension, you consent to the
transfer of information to countries that may have different data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Updating the "Last Updated" date
- Displaying a notice in the Extension
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: contact@sumbox.app