Tubekeep — Privacy Policy
This policy covers the Tubekeep Chrome extension. The Deft Foundry account — signing in, buying, the newsletter — is covered separately by the site privacy policy. You do not need one for the library: everything this extension keeps, it keeps in your own browser. Where a feature of it does need you signed in, it is the one named under What leaves your device below.
What it collects
- The lists in your own YouTube account: for every channel you subscribe to its name, id, @handle, the address of its avatar and the description it published; your playlists and the video titles, ids and durations in them; what is in Watch Later; and what you have liked
- The folders you build and what you filed where
- How far a read or a batch has got, so either can be resumed — including the changes still queued to be made
- Which channels you have the notification bell set to, and at which setting
- How many items your batches have used against the free allowance — one number, kept in this browser, never sent anywhere, and carried inside your backup file so moving to another machine keeps its count
- The changes you make to your own library inside YouTube in this browser: adding or removing a video, liking one, renaming a list or changing who can see it, deleting or un-saving one, subscribing or unsubscribing, and changing a channel's notification setting. The ids in those requests are used to update the index and are not sent anywhere
- If you choose to sign in: your Deft Foundry name, email, the address of your avatar and which plan you are on, cached in the browser so the extension can show which account it is and whether a paid ceiling is lifted
What leaves your device
- Only if you use the AI subscription filing, and only for the batch in hand: it sends each channel's name, @handle and a short hint built from its description and a few titles you already saved from it — plus the names of folders you already have. When the last batch is done, one further call decides which of the folders it just built belong together under a parent, and sends only that: each folder's name, how many channels went into it and a few of their names, beside the folder names you already had
- No video id, no channel id, no folder id, no duration and no thumbnail — the server answers by position in the batch, and the mapping back to your library stays in the browser
- Channel avatars and video thumbnails are Google's own images, so your browser asks Google's image servers for them while a Tubekeep window is open. Which images those are says what is in your library, and it is the same request the YouTube page beside it is already making
- Only when you press play: the video id you clicked goes to a small page on deftfoundry.com, which exists for one reason — YouTube's embedded player refuses to run inside an extension page — and that page loads YouTube's own player for it. Your browser then talks to YouTube exactly as it would on the site: the video plays with its advertising, and the view counts. Nothing about the rest of your library is sent, and nothing is sent at all until you press play
- Reading your own lists and carrying out your batches happen inside your own signed-in YouTube tab, so YouTube sees those requests the way it sees you using the site. It has to be you: Watch Later, your playlists and your subscriptions do not exist to anyone else. Nothing of yours is sent to YouTube that it did not already have
- Opening one of your channels to see its videos is the exception, and it is the one request here that is deliberately NOT you: a channel's list of videos and the public profile page beside it are both public, so they are asked for anonymously — no cookies, no sign-in, no YouTube tab needed — which means YouTube cannot attach which channels you looked at to your account. All that leaves the browser is the channel's own id, and what comes back — how many subscribers and videos they have, when they joined, where they are, and the links they published — is shown to you and kept nowhere. The same anonymous route names a video you have just added on YouTube: one public request carrying only that video id, so the new row can show its title and channel before the next read
- One request to deftfoundry.com asks whether you are signed in, and carries nothing about your library. And when you press something here that opens one of our pages — sign in, pricing, help — the link says which extension you pressed it from, so we can tell whether people reach the site through an extension or find it on their own. If that visit is where you create an account, that one word is kept on the account; it says nothing about your library and nothing about where you were before
- Nothing else leaves at all. Searching, sorting, filing, clearing dead links, managing your lists and backing up happen entirely inside your browser, and no server of ours is involved in any of them
Who else sees it
- The AI subscription filing only: the batch above is passed by deftfoundry.com to the language model that suggests the folders. The API key is ours and lives on our server, never in the extension
- Google, for the thumbnails and avatars above, for the anonymous requests that list a channel's videos and read its public profile, and — from the moment you press play — for YouTube's own embedded player, which is subject to YouTube's terms and Google's privacy policy like any embedded video anywhere else. No analytics, no error reporting, no third-party SDK
The use of information described on this page complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Where it is kept, and for how long
Until you remove the extension or clear its storage. Uninstalling Chrome extensions deletes their storage with them. On our side, the AI subscription filing keeps only a count of how many channels it has filed for your account — never the names.
What it can reach, and why
- storage / unlimitedStorage
- Holds the index of your channels, playlists and queue in the browser. A few thousand videos is more than the default quota allows.
- alarms
- Wakes the extension about once a minute to read the next page of a list, to work through a queued batch of changes, or to carry on the AI subscription filing — so a long job survives the panel being closed. They are the extension's only timers.
- scripting
- Runs one function inside your own signed-in YouTube tab, both to read your own lists and to carry out the changes you asked for. YouTube's own pages are the only place those lists exist. Anything public — a channel's list of videos, and the public profile beside it — is read without it and without your session.
- sidePanel
- Opens a panel down the side of the browser for browsing and searching your library and opening what you pick on YouTube — without leaving the page you are on.
- webRequest
- Notices the changes you make to your own library inside YouTube itself — adding or removing a video, liking one, renaming a list or changing who can see it, deleting or un-saving one, subscribing or unsubscribing, and changing a channel's notification setting — so the local index stays in step without re-reading everything. It only watches youtube.com, only reads the address of those requests and the ids inside them, never reads a response, and never changes a request.
- youtube.com access
- The one site your library comes from, and the only place changes to it can be made. Also where a channel's public list of videos and its public profile page are fetched from when you open one — those requests carry no cookies and no account, and nothing they return is saved.
- deftfoundry.com access
- Reads whether you are signed in to Deft Foundry, and — if you use the AI subscription filing — sends that batch of names for the model to sort. Everything else works signed out; nothing about your library leaves for anything else.
Your choices
Removing the extension deletes everything it stored — Chrome discards an extension's storage with the extension. If you also have a Deft Foundry account, you can export or delete it from the account data page.
Questions
Write to [email protected]. Changes to this policy move the date at the top of this page.