Privacy Policy

Hashtag Generator, Chrome extension ID bopeefhgkapafjbcagclialhcompnhdl.
Last updated: 23 September 2026. Effective: 23 September 2026.

This policy describes what the Hashtag Generator browser extension ("the extension", "we") collects, how that data is handled, where it is stored, how long it is kept, and who it is shared with. It applies to the extension and to the backend service it talks to. It does not apply to other products, or to any website you visit while the extension is installed.

1. What data the extension handles

1.1 Content you choose to submit

The extension only sends something when you act. Nothing is sent in the background, on a timer, or when you merely open a page. The content you can submit is:

A screenshot or a page image is a picture of whatever was on your screen at that moment. If it happens to contain personal information, that information is part of the image and is sent with it. Please do not submit images or text containing sensitive personal data.

1.2 Your settings

Two preferences are stored: the output language for generated titles and hashtags, and your preferred copy format. They are kept by the browser using the Chrome storage API. If you are signed into Chrome with sync enabled, Chrome itself may sync them to your other devices under your Google account; that copy is handled by Google under your own Chrome settings, and we never receive it.

1.3 Temporary result data on your device

When you pick an image on a page, the result is written to local browser storage so the side panel can display it, and the extension deletes that entry as soon as the panel has read it. Nothing else is cached. Uninstalling the extension removes all of its local storage.

1.4 Technical data at our backend

Our backend is a single Google Cloud Function. For each request it records an operational log entry containing: which AI model was used, whether the request was an image or text request, the size of the image in bytes, how long the request took, and, if something failed, the error status and message. The image itself, the text you typed and the generated result are never written to these logs.

In addition, the Google Cloud platform keeps standard request logs for the service, which include the IP address the request came from, the user agent, the timestamp and the HTTP status. We do not use these for analytics or profiling; they exist to operate and secure the service.

1.5 What we do not collect

2. How the data is handled

The path a request takes is short and has no other stops:

We use the data solely to produce the titles and hashtags you asked for, and to keep the service working and secure. We do not use it to train any model of our own, to build a profile of you, or for advertising.

3. Storage and retention

Data Where it lives How long
Language and copy-format settings Your browser (Chrome storage; synced by Chrome if you enabled sync) Until you change them or uninstall the extension
Temporary result of a page-image selection Your browser (local storage) Deleted as soon as the side panel displays it
Submitted images and text Our server's memory, in transit only Discarded when the response is returned; never stored by us
Operational logs (model, request type, image size, duration, errors) Google Cloud Logging, United States 30 days, then deleted automatically
Platform request logs (IP address, user agent, timestamp, status) Google Cloud Logging, United States 30 days, then deleted automatically

4. Who the data is shared with

We share data with exactly two categories of recipient, and we sell it to no one.

4.1 Google, as our service provider

4.2 Recipients you choose yourself

The side panel contains links to a rating form and the Chrome Web Store listing, and uninstalling the extension opens a feedback form. These are Google Forms and the Chrome Web Store. They only ever receive anything if you choose to open them and type something in; whatever you enter there goes to Google and to us as the form owner. Submitting them is entirely optional and the extension works the same either way.

4.3 Legal disclosure

We may disclose information if we are legally required to, or where it is necessary to establish or defend a legal claim, or to address fraud or abuse of the service. Because we do not store the content you submit, there is normally nothing of that kind for us to disclose.

5. Limited use disclosure

The use of information received from Google APIs by this extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, data obtained through the extension is used only to provide and improve the extension's single user-facing feature — generating titles and hashtags — and is never transferred for advertising, credit assessment, or any purpose unrelated to that feature; is never sold; and is never read by a human except with your explicit consent, to resolve a specific support request you raised, or where required by law.

6. Permissions and why each one is needed

Permission Why the extension needs it
storage To remember your output language and copy format, and to pass a result to the side panel.
activeTab To capture the visible area of the current tab when you press Full Screenshot.
scripting To load the helper script that lets you click an image on the page when you press Select Image on Page.
sidePanel To show the extension's interface in the browser side panel.
Access to all websites Because you can use the extension on any page you happen to be on, and the image you pick can be hosted on any domain. The extension cannot know in advance which sites those will be, so it cannot request a narrower list.

A small helper script is present on the pages you open so it can react the moment you start picking an image. Until you press Select Image on Page, it does nothing: it does not read the page, does not inspect its text or forms, and does not send anything anywhere.

7. Security

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your choices and rights

If you are in the European Economic Area or the United Kingdom, our legal basis for processing what you submit is the performance of the service you requested, and our legitimate interest in keeping that service running and secure for the operational logs. You also have the right to lodge a complaint with your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against anyone who exercises their rights.

9. International transfers

The backend runs in the United States (Google Cloud region us-central1), and Google may process requests to the Gemini API in other countries. If you use the extension from outside the United States, what you submit is transferred there for processing.

10. Children

The extension is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided personal information through the extension, write to us and we will act on it.

11. Changes to this policy

If this policy changes, the updated version will be published at this address with a new "last updated" date. Material changes will also be reflected in the extension's Chrome Web Store listing. Continuing to use the extension after a change means you accept the updated policy.

12. Contact

Questions about this policy, or about data handled by the extension: support@pictorai.app.