Skip to content
Portrait of Luffy LiuLuffy Liu
FanFan Cards GitHub ↗
中/EN

FanFan Cards · Privacy

Privacy Policy

Effective August 26, 2026 · Last updated August 27, 2026

ON THIS PAGE OverviewData processedThird-party transfersRetention and deletionSecurity and permissionsContact

Overview

FanFan Cards is a local-first Chrome extension. The developer does not operate a server that receives extension user data, does not use advertising, analytics, or tracking services, and does not sell user data.

The extension can use its built-in offline dictionary by default. Data is sent to a third party only when you configure an AI provider or turn on GitHub sync.

Data the extension processes

  • Website content and page information: when you actively select, explain, or translate content, the extension reads the selected text, the nearby sentence or paragraph, the page title, and the page URL. Paragraph and full-page translation read visible text on the current page.
  • FanFan mode and saved-word highlights: when you enable FanFan mode, the extension scans visible text on the current page and matches it against the word library stored in your browser. Matching and highlighting happen entirely on-device. Page content is not sent to an AI provider, the developer, or another third party.
  • YouTube captions: when you turn on bilingual captions in the YouTube player, the extension reads the current video's caption-track list and caption text. Caption requests are made from the page context to youtube.com, so they carry the browser's existing YouTube cookies in the same way as the page's own requests. The extension does not read, store, or transmit those cookies. A one-time validation parameter generated by the player is used only for the immediately following caption request; it is not retained or sent to the developer or another third party.
  • Learning data: saved words, explanations, source sentences and URLs, review history, learning activity, and user settings.
  • Authentication information: AI service API keys entered by the user and, if GitHub sync is enabled, a GitHub token entered by the user.

This data is stored by default in your own browser through chrome.storage.local. The developer cannot access this local data.

When data is sent to third parties

  1. After you choose and configure an AI provider, the selected text, required context, page title, and URL are sent directly over HTTPS to that provider (Anthropic, OpenAI, DeepSeek, Google Gemini, or an OpenAI-compatible endpoint you provide) to generate an explanation or translation. When you turn on bilingual YouTube captions, the current caption text and video title are sent in the same way to generate the translation. An API key is sent only to its corresponding provider.
  2. After you actively enable GitHub sync, word cards, source information, review history, and learning activity are sent to a repository in your own GitHub account. The GitHub token is sent only to the GitHub API.

The developer does not receive this data through a relay server. A third party's handling of the data is governed by the terms and privacy policy between you and that provider.

Data retention and deletion

Local data remains until you clear it in the extension, remove the extension's data, or uninstall the extension. You can export your cards at any time and can clear translation caches or all cards from the settings page.

Data synced to GitHub is governed by the settings and actions of your own GitHub repository and can be deleted by you on GitHub at any time.

Security and minimum permissions

The extension does not load or execute remote code. External requests use HTTPS; only a local development endpoint may use http://localhost. Access to a custom API endpoint is requested for that specific host only after you click “Test connection.”

The extension injects a script into the page context on youtube.com. It is used only to read public video and caption-track information from the player, record the one-time validation parameter described above, and make the same-origin caption request. The script cannot access extension APIs, does not read other page data, and does not communicate with a server operated by the developer.

The extension's use of information follows the Chrome Web Store User Data Policy, including its Limited Use requirements:

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Contact

For questions about this policy, email luffyliux@gmail.com or contact the developer through GitHub Issues ↗.

© 2026 Luffy LiuBack to FanFan Cards