Privacy Policy for BoardBuddy Chrome Extension
Last Updated: November 18, 2025
Introduction
BoardBuddy ("we," "our," or "us") operates the BoardBuddy Chrome Extension (the "Extension"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Extension.
Information We Collect
User-Provided Information
- Email Address: Collected during activation for account verification and support purposes
- OpenAI API Key: Stored locally in your browser's Chrome storage (we do not have access to this)
- Activation Code: Used for extension activation and subscription verification
- Usage Preferences: Settings such as selected persona, theme preferences, and feature toggles
Automatically Collected Information
- Usage Statistics: Daily usage counts, feature usage patterns (stored locally and synced via Chrome storage)
- Extension Activity: Which features you use, when you use them (for analytics and usage limit enforcement)
- Technical Data: Extension version, browser version, error logs (for troubleshooting)
Data Sent to Third-Party Services
- OpenAI API: Question text and prompts are sent to OpenAI for AI analysis (when using your API key or our proxy)
- Supabase: Email, activation codes, and usage data are stored in our Supabase database
- Stripe: Payment information is processed by Stripe (we do not store payment details)
How We Use Your Information
We use the collected information to:
- Provide Services: Enable extension functionality, AI analysis, and features
- Account Management: Verify activation, manage subscriptions, track usage limits
- Improve Services: Analyze usage patterns to improve features and fix bugs
- Support: Respond to support requests and troubleshoot issues
- Compliance: Comply with legal obligations and enforce our Terms of Service
Data Storage and Security
Local Storage
- API keys, preferences, and settings are stored locally in Chrome's sync storage
- This data is encrypted by Chrome and synced across your devices (if Chrome sync is enabled)
- We cannot access your locally stored API keys
Cloud Storage
- Email addresses and activation data are stored in Supabase (encrypted database)
- Usage statistics are stored in Supabase for subscription management
- All data is transmitted over HTTPS
Security Measures
- HTTPS encryption for all data transmission
- Secure API key storage (local only, never transmitted to our servers)
- Regular security audits of our infrastructure
- Access controls and authentication for database access
Third-Party Services
OpenAI
- Purpose: AI-powered question analysis
- Data Shared: Question text, prompts, and context (only when features are used)
- Privacy Policy: https://openai.com/privacy/
- Note: If you provide your own API key, data is sent directly to OpenAI (not through our servers)
Supabase
- Purpose: Backend database and API services
- Data Shared: Email, activation codes, usage statistics
- Privacy Policy: https://supabase.com/privacy
Stripe
- Purpose: Payment processing
- Data Shared: Payment information (we do not store this)
- Privacy Policy: https://stripe.com/privacy
AnkiConnect (Local)
- Purpose: Integration with Anki desktop application
- Data Shared: Card data (only if you use Anki features, stays local)
- Note: This is a local connection (127.0.0.1), no data leaves your computer
Your Rights and Choices
Access and Deletion
- You can view your stored data through the extension settings
- You can delete your account and data by contacting us at blake@ivytutoring.net
- You can uninstall the extension at any time (local data will be removed)
Data Portability
- You can export your settings and preferences
- Contact us for a copy of your stored data
Opt-Out Options
- You can disable usage tracking in extension settings
- You can use your own OpenAI API key (we won't track your API usage)
- You can uninstall the extension to stop all data collection
Children's Privacy
Our Extension is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Data Retention
- Account Data: Retained while your account is active, deleted upon account deletion request
- Usage Statistics: Retained for up to 2 years for analytics purposes
- Local Data: Stored until you uninstall the extension or clear Chrome storage
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. We ensure appropriate safeguards are in place.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on https://boardcompanion.com/privacy-policy
- Updating the "Last Updated" date
- Sending an email notification (for material changes)
Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email: blake@ivytutoring.net
- Website: https://boardcompanion.com
Compliance
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
By using BoardBuddy, you acknowledge that you have read and understood this Privacy Policy.