1. Who We Are
StoryClover is a Chrome browser extension developed and operated as an independent project. The extension is currently in Beta and accessible via the Chrome Web Store.
For questions about this policy, contact us at: storyclover.support@gmail.com
If you have not received a response within 7 business days, you may escalate to Chrome Web Store Support.
2. Data We Collect
2.1 Authentication Data (Google OAuth)
When you sign in, Google provides us with your:
- Google account user ID (a persistent numeric identifier)
- Display name
- Profile picture URL
- Email address (used as your account identifier)
This data is obtained through Google's OAuth 2.0 identity flow. We do not receive your Google password. This data is stored securely in our backend database to maintain your account and session.
2.2 Webpage Content (On Explicit Request Only)
When you click "Generate" inside the extension, the visible text content of the current webpage is extracted and sent to our backend API. This content is used exclusively to generate the output you requested (story, analysis, summary, or Q&A answer).
We do not collect webpage content passively, in the background, or without your explicit action.
2.3 Generated Content
We store the AI-generated outputs (stories, analyses, summaries, and chat messages) in our database so you can revisit them within the extension. This is required for the feature to function.
2.5 Usage Quota Metadata
We track your generation count per content type (Story / Interactive / Summary / Socratic) to enforce Beta plan limits. This counter is stored per user account.
2.6 Analytics & Performance Telemetry
To measure performance and diagnose runtime errors, the extension collects operational event logs (such as generation triggers or error events). This telemetry includes:
- Event name (e.g., generation initiated, error encountered)
- Page URL associated with the generation request
- Anonymized browser session ID (randomly generated UUID)
- Client-side timestamp
This data is used solely to maintain, secure, and debug extension functionality.
2.7 User Feedback & Support Inputs
When you submit feedback or contact support through the extension, we collect your rating, helpfulness choices, feedback comments, page URL, and optional follow-up consent indicator.
2.8 Data We Do NOT Collect
- Passive web browsing activity or unvisited site histories
- Keystrokes, form inputs, or passwords on external sites
- Clipboard contents
- Cookies or web storage from third-party sites
- Financial or payment card information
- Precise physical location data
3. How We Use Your Data
We use your data exclusively for the following purposes:
- Authenticating your identity via Google OAuth and maintaining your session (JWT tokens)
- Generating AI-powered content from the webpage text you explicitly submit
- Storing and retrieving your previously generated content within the extension
- Enforcing your Beta plan usage quotas
- Diagnosing runtime errors and maintaining extension stability
- Responding to support requests you initiate
3.1 Single Purpose Statement
StoryClover operates under a strict single purpose: providing an interactive AI reading companion inside the Chrome Side Panel to transform webpage content into stories, interactive analyses, summaries, and socratic learning dialogues. All data collected is strictly necessary to support this single purpose.
3.2 Prohibition on Human Reading of Data
In strict compliance with the Chrome Web Store User Data Policy, our employees and personnel never read your personal user data or webpage content. Automated systems process your requests programmatically. Human access is strictly limited to the following exceptions:
- You provide explicit consent for technical support troubleshooting (e.g., investigating an error you reported)
- It is necessary for security purposes (e.g., investigating abuse or system attacks)
- To comply with applicable law or a binding court order
- The data is fully aggregated and anonymized for internal system performance reporting
3.3 Advertising & Model Training Restrictions
We do not use your data for:
- Targeted, personalized, re-targeted, or interest-based advertising
- Training or fine-tuning public AI models on your personal content
- Profiling, market research, or analytics unrelated to extension performance
- Selling or renting user data to third-party data brokers or ad networks
4. Data Sharing & Third Parties
4.1 AI Processing (Google Gemini)
Webpage content you submit for generation is sent to Google's Gemini API for LLM processing. This transfer is necessary to provide the core functionality. Google's use of this data is governed by their Gemini API Terms of Service and Google Privacy Policy.
4.2 Google OAuth
Authentication is handled through Google's OAuth 2.0 service. We receive only the user profile information you authorize during sign-in.
4.3 LLM Execution Tracing (LangSmith)
To monitor and debug multi-step AI orchestration pipelines (LangGraph), backend API calls generate internal execution trace IDs (run IDs). These execution logs contain non-identifying graph execution metadata used strictly by our engineering team to fix generation failures.
4.4 No Other Third-Party Sharing
We do not share, sell, transfer, or disclose your data to any other third party, except:
- When legally required by applicable law or court order
- To protect the security and integrity of the service (e.g., investigating abuse)
- As part of a merger, acquisition, or sale of assets, in which case users will be notified
5. Data Storage & Security
5.1 Storage Location
User account data, generated content, and usage metadata are stored in our backend database hosted on a secured server. JWT session tokens are stored locally in Chrome Extension Storage (chrome.storage.local) on your device.
5.2 Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Generated content (stories, analyses, summaries, chats): Retained until you delete them or delete your account.
- Usage quota counters: Reset monthly. Deleted when your account is deleted.
- JWT tokens: Expire automatically (short-lived). Invalidated on sign-out.
5.3 Security Measures
- All data transmission between the extension and our backend occurs over HTTPS (TLS-encrypted)
- Backend API endpoints are authenticated with short-lived JWT tokens
- Google OAuth tokens are never stored server-side beyond the authentication handshake
- Database access is restricted to backend application processes only
5.4 Data Breach Notification
In the event of a data breach affecting your personal data, we will notify affected users via email within 72 hours of discovery, in accordance with applicable data protection requirements.
6. Chrome Extension Permissions
StoryClover requests the following permissions in its manifest.json:
"storage"
Used to persist your authentication JWT token and session state locally in Chrome Extension Storage. This allows the extension to remain signed in across browser sessions without you having to re-authenticate every time.
"identity"
Used to initiate the Google OAuth 2.0 sign-in flow. This permission allows the extension to launch the Google sign-in dialog within Chrome's identity framework. No other authentication data is accessed.
We do not request tabs, history, bookmarks, webNavigation, cookies, or any other permission beyond what is necessary for core functionality.
7. Your Rights & Controls
You have the following rights over your data:
Access
You can view your generated content directly within the extension at any time.
Deletion
You can request deletion of your account and all associated data by emailing storyclover.support@gmail.com with the subject line "Delete My Account". We will process your request within 14 days.
Revoke Authorization
You can revoke StoryClover's access to your Google account at any time via Google Account Permissions. This will sign you out of the extension immediately.
Uninstall
Uninstalling the extension from Chrome immediately removes all locally stored data (JWT tokens, cached session state). Server-side data will be deleted upon a deletion request.
Opt-Out of Data Collection
Because authentication and webpage text extraction are core to providing the service, opting out of data collection is equivalent to not using the extension. We do not have optional analytics or marketing tracking to opt out of separately.
8. Children's Privacy
StoryClover is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately at storyclover.support@gmail.com and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy as the product evolves. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify active users via the extension interface or email for significant changes
Continued use of StoryClover after changes are posted constitutes acceptance of the revised policy. If you disagree with the updated terms, you may uninstall the extension and request data deletion.
10. Contact Us
For any privacy-related questions, data access requests, or concerns about this policy:
This policy applies to the StoryClover Chrome Extension and its associated backend service at storyclover.cloud.
© 2026 StoryClover AI. All rights reserved.