Privacy Policy
Last Updated: September 24, 2026
1. Introduction
Welcome to We Don't Say That. We built this application to provide families with safer, filterable YouTube and Amazon Prime Video viewing. This policy explains the limited account, contribution, and technical data used to provide those features. We do not sell personal data.
2. Data Collection & Usage
Local and Browser Storage: Website watch history and website custom-word settings are stored in your browser. Extension preferences and optional Always mute / Never mute lists use Chrome extension storage and may sync through your Chrome profile when browser sync is enabled. They do not sync to your WDST account or the website player. For YouTube personalization, the extension sends those lists securely to WDST with the filter request. WDST processes them for that request without adding the lists or resulting personalized timings to the shared community archive. Prime Video applies the lists locally without sending them to WDST. You can edit or clear the lists in the extension's My word rules settings.
Playback and Website Content: To provide filtering, the extension reads supported-site URLs and video identifiers, titles, captions, and video-player state such as current time, pause, seek, and playback changes. A YouTube video identifier and the selected filter profile are sent to WDST to request a filter. Ordinary Prime Video filtering processes caption text in memory and discards it; the optional context-review pilot below is a separately consented exception. Edition identifiers and titles are used to locate matching community filters. The extension does not collect browsing on unrelated sites.
Optional AI Language Context Review: This limited pilot is off by default and restricted to approved test accounts. If you explicitly enable it in extension settings, short caption excerpts around sacred-name occurrences are sent to WDST and OpenAI to distinguish proper uses from misuse. A separate additional choice includes screw/suck word families and phrases to distinguish literal construction or suction from misuse. Existing sacred-name-only permission does not enable this broader review automatically. Consent is kept in this browser profile, not Chrome Sync. OpenAI receives the excerpt, candidate word or phrase and position, but not your WDST account identifier, account credentials, personal word lists, video or audio. WDST verifies your account and keeps hashed, account-scoped decision-cache and abuse-budget records. Decisions, not caption excerpts, are cached for up to 12 hours; budget records expire after two days. Excerpts and raw provider responses are not stored in WDST application logs or the community archive. This does not change the existing YouTube caption cache. OpenAI API data is not used for model training by default. Requests disable response storage, but OpenAI abuse-monitoring logs may retain submitted content for up to 30 days; this is not zero retention. Turning the option off stops future requests and removes active AI exceptions, but cannot recall requests already sent. See OpenAI API data controls.
YouTube Caption Retrieval: When a YouTube filter is not already cached, the WDST service requests the public caption track for the submitted video identifier from YouTube. WDST may route that public caption request through Decodo or IPRoyal proxy infrastructure to improve reliability. The resulting YouTube caption data may be cached in Upstash Redis for up to 12 hours so repeated requests do not require another retrieval. These providers do not receive your WDST session credential as part of the caption request.
Authentication Data: If you create an account, we use Clerk to manage your identity and session. WDST uses the authenticated account identifier and first name for access control, subscription display, contribution deduplication, abuse review, and community scan credits. Temporary extension credentials and the displayed first name are held in Chrome's memory-backed session storage and cleared when the browser session ends or the extension is reloaded, disabled, or updated. Version 1.3.5 and later also remove credential copies left in local or synchronized extension storage by earlier versions.
Community Contributions: When you choose manual or automatic sharing, WDST receives the contributed title, platform and edition-specific asset ID, duration, language categories or detected terms, mute timestamps, coverage information, ruleset version, and—for Prime Video—a transcript-free caption fingerprint, cue count, and caption duration. A verified modesty contribution also includes objective scene labels, severity, confidence, and start/end timestamps. Private notes, screenshots, and video frames are not submitted. The contributor account identifier is retained with timing submissions so one account cannot falsely count as multiple independent confirmations. Prime caption text, the complete transcript, and the Amazon account identity are not submitted.
Basic-Plan Access & Rate Limiting: To provide the Basic plan and protect the service against abuse, WDST records a daily, platform-specific set of supported content identifiers already admitted for the current account. Basic allows up to 20 distinct YouTube video IDs and 1 distinct Prime title or episode ID per day; revisiting the same identifier does not count again. For signed-out use, the server derives a one-way value from the request IP address so it can apply the same daily limit without retaining the raw IP address in the usage key. These access records expire automatically and are not used for advertising or unrelated browsing profiles.
Operational Logs: We retain limited diagnostics to operate and protect filtering. New extension reports contain bounded, sanitized error/stack text, source, extension version and allowlisted technical fields; arbitrary captions, page URLs, account data and personal word-list context are discarded. Error rate limits use a secret-keyed request-IP fingerprint. New daily extension-error and caption-failure buckets hold at most 500 and 200 records and expire 30 days after their last write. Caption failures may include the requested public YouTube ID and safe proxy-tier failure codes. Aggregate attempt, duration and AI token counts have the same daily/30-day retention, without caption excerpts, raw model replies or account identifiers. Earlier diagnostic records remain separately preserved for investigation and reviewed cleanup. Hosting and rate-limit providers process request metadata under their own retention policies. We do not use extension data for personalized advertising.
Support and Word Reports: A submitted word report can contain your issue, platform, extension version, selected preset and a playback timestamp you can correct, plus a bounded excerpt of public YouTube captions near that time. We retain up to 500 reports and private resolution notes/build information, with up to 1,000 resolution-audit entries, to investigate issues without overwriting the original reports. Contact support for deletion requests.
Retention: Basic-plan access keys expire after the applicable UTC day, and temporary YouTube caption caches expire after no more than 12 hours. Local extension settings remain until you change them or uninstall the extension. Verified community filters and contribution records may be retained to keep shared filters accurate and prevent duplicate confirmations; account-linked records can be removed through the deletion process described below.
Optional sacred-name exceptions for trusted content
“Allow sacred names on trusted content” (previously called sermon mode) is an optional YouTube feature that is off by default. It applies to human-approved channels and videos detected as likely sermons, not every religious video. WDST uses public video/channel information and English captions already retrieved for filtering to identify likely sermons. Canonical channel IDs, names, titles, descriptions and caption-language metadata may be cached for up to 12 hours. This feature does not itself send data to OpenAI; a separately enabled AI review may still run. The preference stays in this browser, not Chrome Sync.
A separate sharing choice allows signed-in viewers to suggest detected channels to WDST's private admin queue. A suggestion contains only the public channel ID/name, one example video ID/title, detection reasons, status, revision and dates—not the viewer's identity, captions or personal word lists. WDST still authenticates scan requests. The queue holds up to 1,000 channel records; decisions are retained to honor approvals and revocations, with up to 2,000 audit entries containing the reviewing administrator's ID, notes and dates. Contact support to request removal of a channel record. Turning sharing off stops future suggestions but cannot recall ones already sent.
Only human review can approve a lasting channel allowance. Automatic detection alone applies to one video. Trusted-content exceptions are not a clean-content certification: ordinary sacred names, even misuse, may be heard. Other selected language and personal word rules still apply.
3. Chrome Extension Disclosure
The We Don't Say That Chrome extension requires specific host permissions for supported YouTube and wedontsaythat.net pages. Amazon, Prime Video, and Prime caption-delivery access is optional.
These permissions are used to interact with supported video players, acquire the caption timing needed to build filters locally, retrieve community mute and modesty-scene data, and authenticate contributions. The extension may read Clerk's __session cookie from wedontsaythat.net when account verification or an authenticated contribution is required; it does not forward other website cookies. It does not read or submit an Amazon account cookie, payment information, or browsing on unrelated sites.
Amazon, Prime Video, and Prime caption-delivery access is optional and requested only when a user enables Prime support. The extension's packaged Prime scripts are removed if that access is revoked. The extension does not download or execute remote code.
4. Chrome Web Store Limited Use
The use of information received from Google and Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide or improve the family video-filtering features described here, operate and secure those features, and comply with applicable law. It is not sold, used for personalized advertising, transferred to data brokers, or used to determine creditworthiness. Humans do not read user data except with specific user consent, for security or legal reasons, or after aggregation and anonymization for internal operations.
5. Children's Privacy (COPPA Compliance)
Protecting the privacy of young children is our highest priority. We do not knowingly collect or solicit personally identifiable information from anyone under the age of 13. If you believe a child has provided us with personal data, please contact us immediately for removal.
6. User Rights & Data Deletion
You have the right to access, correct, or delete any personal information associated with your account. You can manage your account and request full data deletion at any time via your Account Profile or by contacting us.
7. Third-Party Services
WDST uses a limited set of service providers only to deliver, secure, and support the filtering service:
- Clerk provides account authentication, session verification, and subscription status. Payment-card details are handled by Clerk's billing infrastructure and are not read by the extension.
- Vercel hosts the WDST website and APIs, provides aggregate website analytics, and processes ordinary request metadata and operational logs.
- Upstash Redis / Vercel KV stores access-limit records, filter and contribution data, rate-limit and diagnostic records, and the temporary YouTube caption cache described above.
- Google / YouTube supplies public video metadata and caption resources for the requested YouTube identifier. By using YouTube you are also bound by the Google Privacy Policy and YouTube Terms of Service.
- Decodo and IPRoyal provide network proxy infrastructure used only to retrieve public YouTube metadata and caption resources when direct retrieval is unavailable.
- Google Chrome Sync may synchronize non-secret extension preferences through your Google account if Chrome Sync is enabled. WDST does not place authentication credentials in synchronized storage.
- Resend delivers limited operational alerts and support email; it is not sent routine extension viewing history.
- OpenAI processes limited caption excerpts around sacred names and, with additional permission, screw/suck word families only for the separately opted-in context-review pilot described above.
Website Advertising: We use Google AdSense on the public WDST website, not inside the Chrome extension. Extension data is not supplied to AdSense or used for advertising. Third-party website vendors, including Google, may use cookies to serve ads based on prior website visits. You may opt out of personalized website advertising through Google's Ads Settings.
Extension Trial and Complimentary Access Records
Where the account-based extension trial is offered, we retain your account identifier and the first successful filtered-playback timestamp to calculate the trial end date and prevent it restarting on reinstall. Complimentary early-supporter grants record account eligibility, grant date, and access start and expiration dates. These account records remain while the account exists and are removed through account deletion. Your browser may remember when you dismiss an account-specific gift notice. Trial enforcement does not require a payment card or create a subscription.
To preserve existing users’ free Basic access, the extension sends a randomly generated installation identifier and, when Chrome reports an update, its previous extension version. WDST stores eligibility and returns an installation-specific Basic access proof, kept in that browser rather than Chrome Sync. This record does not contain browsing history, captions, payment details, or an Amazon identity. If you connect a WDST account, eligibility can be linked to that account so it survives reinstalling. We retain eligibility records for as long as needed to honor this access; contact support to request removal. Uninstalling removes the local proof, not the server record.
Playback access checks send the platform, title identifier, and a temporary playback identifier to WDST. Signed playback confirmations allow an already-started video to finish after trial expiration. The extension keeps these confirmations in browser-session storage and removes the tab record when the tab closes; it does not add them to a permanent viewing-history list. No movie images or audio are sent for trial verification.
8. Contact Information
For any questions regarding this Privacy Policy or your data, please reach out to us at:
privacy@wedontsaythat.net