Chính sách quyền riêng tư — Tab Cộng Đồng AI
Tài liệu này mô tả chính xác dữ liệu mà tiện ích Tab Cộng Đồng AI thu thập, dùng vào việc gì, lưu ở đâu và chia sẻ với những bên nào. Chúng tôi không bán, không chia sẻ cho mục đích quảng cáo và không dùng dữ liệu của bạn để huấn luyện mô hình.
1. Dữ liệu tiện ích thu thập và lưu trên máy bạn
Các dữ liệu sau được lưu bằng chrome.storage.local ngay trong hồ sơ Chrome của bạn:
- Gemini API key do bạn tự nhập.
- Cài đặt: ngôn ngữ, chủ đề/niche, loại nội dung, định dạng YouTube được phép, link website, giờ chạy lịch.
- Hồ sơ kênh: tên kênh, mô tả, tiêu đề video công khai mà bạn chủ động cho quét.
- Bài tham khảo: nội dung các bài Tab Cộng đồng công khai trên kênh bạn chọn quét.
- Lịch sử bài (tối đa 60 bài gần nhất) và số liệu KPI.
- Mã thiết bị (device ID): một chuỗi ngẫu nhiên do tiện ích tự sinh trong lần chạy đầu tiên
(
crypto.randomUUID()). Chuỗi này không chứa thông tin phần cứng, không chứa thông tin cá nhân và không dùng để nhận diện bạn trên bất kỳ website nào. - Tên và email bạn tự nhập ở bước đăng ký sử dụng.
- Thông tin giấy phép: mã kích hoạt hoặc token, gói sử dụng (plan), trạng thái và hạn dùng, thời điểm kiểm tra gần nhất.
Gỡ tiện ích khỏi Chrome sẽ xoá toàn bộ nhóm dữ liệu này khỏi máy bạn.
2. Mục đích sử dụng dữ liệu
- Sinh nội dung bài đăng: chủ đề, hồ sơ kênh và bài tham khảo được dùng làm ngữ cảnh cho yêu cầu gửi tới Google Gemini, để bài mới bám đúng ngành và văn phong kênh của bạn.
- Sinh ảnh minh hoạ cho bài dạng Image và Image poll.
- Chống trùng lặp và thống kê: lịch sử bài và KPI được dùng ngay tại máy để tránh lặp ý cũ và hiển thị số liệu cho bạn.
- Cấp và kiểm tra quyền sử dụng: tên, email và mã thiết bị được dùng để cấp giấy phép và xác định thiết bị nào đang được phép chạy.
- Chạy lịch và thông báo: giờ hẹn được dùng để chuẩn bị bài đúng thời điểm và báo cho bạn.
Chúng tôi không dùng dữ liệu vào bất kỳ mục đích nào khác ngoài các mục đích liệt kê ở trên.
3. Dữ liệu gửi tới bên thứ ba
| Bên nhận | Dữ liệu được gửi | Mục đích |
|---|---|---|
Google Gemini APIgenerativelanguage.googleapis.com |
API key của bạn; chủ đề/niche; hồ sơ kênh; nội dung bài tham khảo; nội dung bài vừa sinh (khi gợi ý bình luận); link website của bạn (khi bạn bật chèn link) | Sinh nội dung bài đăng, gợi ý bình luận và câu kêu gọi. Chạy trên hạn mức của chính API key bạn cung cấp. |
Pollinationsimage.pollinations.ai |
Câu mô tả ảnh, được ghép từ: nội dung lựa chọn trong poll, câu hỏi của poll, chủ đề/niche kênh của bạn và phong cách ảnh. Câu mô tả này nằm trong đường dẫn URL của yêu cầu nên bên nhận có thể ghi lại. Không gửi kèm API key, tên, email hay mã thiết bị. | Sinh ảnh minh hoạ miễn phí cho bài dạng Image và Image poll. |
Máy chủ cấp phép của nhà phát triểnscript.google.com,
script.googleusercontent.com (Google Apps Script) |
Tên và email bạn tự nhập khi đăng ký; mã thiết bị ngẫu nhiên; mã kích hoạt (nếu bạn nhập); phiên bản tiện ích; thời điểm gọi | Cấp và kiểm tra quyền sử dụng. Đây là dữ liệu định danh cá nhân duy nhất mà nhà phát triển nhận được. Xem thêm mục 4. |
YouTube / Googleyoutube.com, i.ytimg.com, docs.google.com |
Không gửi dữ liệu mới nào của bạn. Tiện ích chỉ đọc trang công khai và thao tác trong phiên đăng nhập
YouTube sẵn có trên trình duyệt của bạn. Riêng yêu cầu tải ảnh thumbnail từ i.ytimg.com
được gửi ở chế độ không kèm cookie. |
Đọc bài Cộng đồng công khai của kênh, lấy ảnh thumbnail video, chọn video qua Google Picker, điền nội dung vào ô soạn bài. |
Ngoài bốn bên trên, tiện ích không gửi dữ liệu tới bất kỳ máy chủ nào khác.
4. Kết nối định kỳ tới máy chủ cấp phép
Sau khi bạn đăng ký, tiện ích tự động kiểm tra lại trạng thái giấy phép với máy chủ cấp phép tối đa 12 giờ một lần. Mỗi lần kiểm tra gửi đi: mã thiết bị, email đã đăng ký, phiên bản tiện ích và thời điểm gọi. Việc này diễn ra nền, không cần thao tác của bạn.
- Nếu mất mạng, tiện ích vẫn chạy trong tối đa 7 ngày kể từ lần kiểm tra thành công gần nhất.
- Nếu bạn kích hoạt bằng mã kích hoạt ngoại tuyến (mã bắt đầu bằng
TCD.), tiện ích xác minh chữ ký ngay tại máy và không gọi máy chủ — trường hợp này không có dữ liệu nào được gửi đi.
5. Gemini API key của bạn
API key chỉ được lưu cục bộ và chỉ được gửi trực tiếp tới máy chủ Google Gemini để thực hiện yêu cầu sinh nội dung của bạn. Nhà phát triển không nhận, không ghi nhật ký và không có cách nào đọc được key này. Bạn có thể xoá key bất cứ lúc nào trong trang Cài đặt của tiện ích, hoặc thu hồi key tại Google AI Studio.
6. Bảo mật dữ liệu
- Mọi kết nối ra ngoài đều dùng HTTPS.
- Dữ liệu cục bộ nằm trong
chrome.storage.local— chỉ tiện ích này đọc được, và không đồng bộ lên tài khoản Google của bạn (tiện ích không dùngchrome.storage.sync). - Thông tin đăng ký được lưu trong một bảng tính Google Sheet riêng của nhà phát triển, chỉ tài khoản Google của nhà phát triển truy cập được.
- Nhà phát triển không vận hành máy chủ nào khác và không sao chép dữ liệu của bạn sang nơi nào khác.
7. Lưu trữ và xoá dữ liệu
- Dữ liệu cục bộ: tồn tại đến khi bạn xoá trong Cài đặt hoặc gỡ tiện ích khỏi Chrome.
- Thông tin đăng ký (tên, email, mã thiết bị, phiên bản, thời điểm kiểm tra): lưu trong Google Sheet của nhà phát triển, giữ trong thời gian tài khoản còn hoạt động.
- Yêu cầu xoá: gửi email tới địa chỉ ở mục 13 kèm email bạn đã đăng ký. Chúng tôi xoá bản ghi trong vòng 30 ngày và xác nhận lại cho bạn.
8. Những gì tiện ích KHÔNG làm
- Không đọc, không lưu và không gửi đi mật khẩu, cookie đăng nhập hay token phiên của bạn. Khi đọc trang kênh, tiện ích chỉ dùng phiên đăng nhập YouTube sẵn có trên trình duyệt của bạn, giống như khi bạn tự mở trang đó.
- Không thu thập lịch sử duyệt web. Tiện ích chỉ đọc nội dung trên các trang
youtube.commà bạn chủ động mở hoặc chỉ định. - Không chạy mã tải từ xa (remote code). Toàn bộ mã nằm trong gói tiện ích đã được Chrome Web Store xét duyệt.
- Không có quảng cáo, không gắn mã theo dõi (analytics/tracking) của bên thứ ba.
- Không bán, cho thuê hoặc chuyển nhượng dữ liệu người dùng cho bất kỳ bên nào.
- Không dùng dữ liệu người dùng để đánh giá tín nhiệm tín dụng hay cho vay.
9. Các quyền tiện ích yêu cầu và lý do
Tiện ích chỉ xin đúng những quyền cần cho chức năng mô tả ở trên. Không quyền nào được dùng để thu thập dữ liệu ngoài phạm vi mục 1.
| Quyền | Dùng để làm gì |
|---|---|
storage | Lưu cài đặt, API key, hồ sơ kênh, lịch sử bài và thông tin giấy phép ngay trên máy bạn. Không dữ liệu nào rời thiết bị vì quyền này. |
alarms | Chạy lịch chuẩn bị bài theo giờ bạn đặt và chạy bù khi lỡ lịch. |
scripting | Chèn nội dung vào ô soạn bài Tab Cộng đồng và đọc bài công khai trên kênh của bạn. Chỉ chạy trên youtube.com. |
notifications | Báo cho bạn khi bài theo lịch đã chuẩn bị xong hoặc khi có lỗi. |
tabs | Xác định đúng thẻ youtube.com đang mở để thao tác. Tiện ích không đọc, không lưu và không gửi đi lịch sử duyệt web hay danh sách thẻ của bạn. |
https://*.youtube.com/* | Đọc bài Cộng đồng công khai của kênh bạn chọn và điền nội dung vào ô soạn bài. |
https://i.ytimg.com/* | Tải ảnh thumbnail video của kênh (gửi ở chế độ không kèm cookie). |
https://docs.google.com/* | Hiển thị Google Picker để bạn chọn video kênh khi đăng bài dạng Video. |
https://generativelanguage.googleapis.com/* | Gọi Google Gemini API bằng API key của chính bạn để sinh nội dung. |
https://image.pollinations.ai/* | Sinh ảnh minh hoạ miễn phí cho bài dạng Image và Image poll. |
https://script.google.com/*https://script.googleusercontent.com/* | Kết nối tới máy chủ cấp phép của nhà phát triển để đăng ký và kiểm tra quyền sử dụng (xem mục 3 và mục 4). |
10. Cam kết Sử dụng có giới hạn (Limited Use)
Việc thu thập, sử dụng và chuyển giao dữ liệu người dùng của tiện ích tuân thủ Chính sách Sử dụng có giới hạn (Limited Use) của Chrome Web Store và Chính sách chương trình dành cho nhà phát triển của Chrome Web Store. Cụ thể: dữ liệu người dùng chỉ được dùng để cung cấp và cải thiện đúng những chức năng mà người dùng nhìn thấy; không bán cho bên thứ ba; không dùng hay chuyển giao cho mục đích quảng cáo, tiếp thị lại hoặc đánh giá tín nhiệm tín dụng; không dùng để huấn luyện mô hình AI của nhà phát triển; và không để con người đọc dữ liệu của bạn, trừ khi bạn cho phép rõ ràng, hoặc để phục vụ mục đích bảo mật/tuân thủ pháp luật khi bị bắt buộc.
11. Trẻ em
Tiện ích dành cho nhà sáng tạo nội dung quản lý kênh YouTube và không hướng tới người dưới 13 tuổi. Chúng tôi không cố ý thu thập dữ liệu của trẻ em.
12. Thay đổi chính sách
Khi có thay đổi ảnh hưởng tới cách xử lý dữ liệu, chúng tôi sẽ cập nhật trang này và đổi ngày ở đầu tài liệu. Việc tiếp tục sử dụng tiện ích sau khi cập nhật đồng nghĩa với việc bạn chấp nhận nội dung mới.
13. Liên hệ
Nhà phát triển: DG Media Holding
Email: hoangvant77internet@gmail.com
Privacy Policy — Tab Cộng Đồng AI
This document describes exactly what data the Tab Cộng Đồng AI extension collects, what it is used for, where it is stored, and which parties it is shared with. We do not sell user data, do not share it for advertising purposes, and do not use it to train models.
1. Data the extension collects and stores on your device
The following is stored via chrome.storage.local inside your own Chrome profile:
- Your Gemini API key, entered by you.
- Settings: language, channel niche/topics, content types, enabled YouTube formats, website link, schedule time.
- Channel profile: channel name, description, and public video titles that you choose to scan.
- Reference posts: the text of public Community posts on the channel you choose to scan.
- Post history (up to the 60 most recent posts) and KPI figures.
- Device ID: a random string generated by the extension on first run (
crypto.randomUUID()). It contains no hardware information, no personal information, and is not used to identify you on any website. - Name and email address that you enter during registration.
- Licence information: activation code or token, plan, status and expiry date, last check timestamp.
Removing the extension from Chrome deletes all of this data from your device.
2. How the data is used
- Generating post content: topics, channel profile and reference posts are sent to Google Gemini as context, so that new posts match your channel's niche and writing style.
- Generating illustration images for Image and Image poll posts.
- Duplicate avoidance and statistics: post history and KPI figures are used locally on your device to avoid repeating previous ideas and to display statistics to you.
- Granting and verifying licences: name, email and device ID are used to issue a licence and determine which device is allowed to run the extension.
- Scheduling and notifications: your chosen time is used to prepare posts on schedule and notify you.
We do not use the data for any purpose other than those listed above.
3. Data shared with third parties
| Recipient | Data sent | Purpose |
|---|---|---|
Google Gemini APIgenerativelanguage.googleapis.com |
Your API key; channel niche/topics; channel profile; reference post text; the text of the post just generated (when suggesting comments); your website link (when you enable link insertion) | Generating post content, comment suggestions and calls to action. Runs on the quota of the API key you supply yourself. |
Pollinationsimage.pollinations.ai |
An image description assembled from: the poll option text, the poll question, your channel niche/topics, and the image style. This description is part of the request URL, so the recipient may log it. Your API key, name, email and device ID are not sent. | Generating free illustration images for Image and Image poll posts. |
Developer's licensing serverscript.google.com,
script.googleusercontent.com (Google Apps Script) |
The name and email you enter at registration; the random device ID; the activation code (if you enter one); the extension version; the request timestamp | Issuing and verifying usage rights. This is the only personally identifiable data the developer receives. See section 4. |
YouTube / Googleyoutube.com, i.ytimg.com, docs.google.com |
No new data about you is sent. The extension only reads public pages and acts within the YouTube session
already signed in on your browser. Thumbnail requests to i.ytimg.com are sent without cookies. |
Reading the channel's public Community posts, fetching video thumbnails, selecting a video through Google Picker, and filling content into the composer box. |
Apart from these four parties, the extension sends data to no other server.
4. Periodic connection to the licensing server
After you register, the extension automatically re-checks its licence status with the licensing server at most once every 12 hours. Each check sends: the device ID, the registered email address, the extension version and the request timestamp. This happens in the background and requires no action from you.
- If your connection drops, the extension keeps working for up to 7 days from the last successful check.
- If you activate with an offline activation code (a code starting with
TCD.), the extension verifies the signature locally and does not contact the server — in that case no data is sent at all.
5. Your Gemini API key
Your API key is stored locally only and is sent directly to Google's Gemini servers solely to fulfil your own generation requests. The developer does not receive, log, or have any way to read this key. You can delete the key at any time on the extension's Settings page, or revoke it at Google AI Studio.
6. Data security
- All outbound connections use HTTPS.
- Local data lives in
chrome.storage.local— readable only by this extension, and never synced to your Google account (the extension does not usechrome.storage.sync). - Registration records are stored in a private Google Sheet accessible only to the developer's Google account.
- The developer operates no other server and does not copy your data anywhere else.
7. Data retention and deletion
- Local data: retained until you clear it in Settings or remove the extension from Chrome.
- Registration records (name, email, device ID, version, check timestamps): stored in the developer's Google Sheet and retained while the account remains active.
- Deletion requests: email the address in section 13 from, or quoting, your registered email address. We delete the record within 30 days and confirm back to you.
8. What the extension does NOT do
- It does not read, store or transmit your passwords, login cookies or session tokens. When reading channel pages it merely relies on the YouTube session already signed in on your browser, exactly as if you opened the page yourself.
- It does not collect browsing history. It only reads content on
youtube.compages that you actively open or specify. - It does not execute remote code. All code ships inside the package reviewed by the Chrome Web Store.
- It contains no advertising and no third-party analytics or tracking code.
- It does not sell, rent or transfer user data to any party.
- It does not use user data to determine creditworthiness or for lending purposes.
9. Permissions the extension requests, and why
The extension requests only the permissions its described features need. No permission is used to collect data beyond what is listed in section 1.
| Permission | Why it is needed |
|---|---|
storage | Store your settings, API key, channel profile, post history and licence information on your own device. No data leaves the device because of this permission. |
alarms | Run the scheduled post preparation at the time you set, and catch up on a missed schedule. |
scripting | Insert content into the Community post composer and read public posts on your channel. Runs on youtube.com only. |
notifications | Tell you when a scheduled post is ready or when an error occurs. |
tabs | Identify the correct open youtube.com tab to act on. The extension does not read, store or transmit your browsing history or your list of tabs. |
https://*.youtube.com/* | Read the public Community posts of the channel you select and fill the post composer. |
https://i.ytimg.com/* | Fetch your channel's video thumbnails (requested without cookies). |
https://docs.google.com/* | Show the Google Picker so you can choose one of your channel videos for a Video post. |
https://generativelanguage.googleapis.com/* | Call the Google Gemini API with your own API key to generate content. |
https://image.pollinations.ai/* | Generate free illustration images for Image and Image poll posts. |
https://script.google.com/*https://script.googleusercontent.com/* | Contact the developer's licensing server to register and verify your right to use the extension (see sections 3 and 4). |
10. Limited Use compliance
The extension's collection, use and transfer of user data complies with the Chrome Web Store Limited Use policy and the Chrome Web Store Developer Program Policies. Specifically: user data is used only to provide and improve the user-facing features described above; it is never sold to third parties; never used or transferred for advertising, retargeting or creditworthiness purposes; never used to train the developer's AI models; and never read by humans unless you give explicit permission, or it is required for security or to comply with applicable law.
11. Children
The extension is intended for content creators managing YouTube channels and is not directed at people under 13. We do not knowingly collect data from children.
12. Changes to this policy
If a change affects how data is handled, we will update this page and change the date at the top of the document. Continuing to use the extension after an update constitutes acceptance of the new terms.
13. Contact
Developer: DG Media Holding
Email: hoangvant77internet@gmail.com