Privacy Policy for BoardBuddy Chrome Extension
Last Updated: February 4, 2026
Introduction
BoardBuddy ("we," "our," or "us") operates the BoardBuddy Chrome Extension (the "Extension"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Extension.
Data Collection
User-Provided Information
- Email Address: Collected during activation for account verification and support purposes
- OpenAI API Key: Stored locally in your browser's Chrome storage (we do not have access to this)
- Activation Code: Used for extension activation and subscription verification
- Usage Preferences: Settings such as selected persona, theme preferences, and feature toggles
Automatically Collected Information
- Usage Statistics: Daily usage counts, feature usage patterns (stored locally and synced via Chrome storage)
- Extension Activity: Which features you use, when you use them (for analytics and usage limit enforcement)
- Technical Data: Extension version, browser version, error logs (for troubleshooting)
Data Sent to Third-Party Services
- OpenAI API: Question text and prompts are sent to OpenAI for AI analysis (when using your API key or our proxy)
- Supabase: Email, activation codes, and usage data are stored in our Supabase database
- Stripe: Payment information is processed by Stripe (we do not store payment details)
No Sale of Data
We do not sell, trade, or otherwise transfer your personal information to outside parties. This does not include trusted third parties who assist us in operating our extension, conducting our business, or servicing you, so long as those parties agree to keep this information confidential.
Data Usage
We use the collected information to:
- Provide Services: Enable extension functionality, AI analysis, and features
- Account Management: Verify activation, manage subscriptions, track usage limits
- Improve Services: Analyze usage patterns to improve features and fix bugs
- Support: Respond to support requests and troubleshoot issues
- Compliance: Comply with legal obligations and enforce our Terms of Service
Data Storage and Handling
We are committed to securing your data through industry-standard handling and storage practices.
Data Handling
All user data is handled securely via HTTPS encryption in transit. We strictly limit access to personal information to employees/contractors who need it to operate the service.
Data Storage
- Local Storage: Preferences, Anki deck IDs, and interface settings are stored
locally on your device using Chrome's
storage.localAPI. - Cloud Storage: User accounts and authentication tokens are securely stored in Supabase (hosted on AWS).
Security Measures
- HTTPS encryption for all data transmission
- Secure API key storage (local only, never transmitted to our servers)
- Regular security audits of our infrastructure
- Access controls and authentication for database access
Data Sharing
We strictly do not sell your personal data. We only share data with third-party service providers necessary to operate the extension, as detailed below.
Third-Party Service Providers
We adhere to the "Use of Data" policies of the following third-party services:
- Purpose: AI-powered question analysis
- Data Shared: Question text, prompts, and context (only when features are used)
- Privacy Policy: https://openai.com/privacy/
- Note: If you provide your own API key, data is sent directly to OpenAI (not through our servers)
Supabase
- Purpose: Backend database and API services
- Data Shared: Email, activation codes, usage statistics
- Privacy Policy: https://supabase.com/privacy
Stripe
- Purpose: Payment processing
- Data Shared: Payment information (we do not store this)
- Privacy Policy: https://stripe.com/privacy
AnkiConnect (Local)
- Purpose: Integration with Anki desktop application
- Data Shared: Card data (only if you use Anki features, stays local)
- Note: This is a local connection (127.0.0.1), no data leaves your computer
Your Rights and Choices
Access and Deletion
- You can view your stored data through the extension settings
- You can delete your account and data by contacting us at blake@ivytutoring.net
- You can uninstall the extension at any time (local data will be removed)
Data Portability
- You can export your settings and preferences
- Contact us for a copy of your stored data
Opt-Out Options
- You can disable usage tracking in extension settings
- You can use your own OpenAI API key (we won't track your API usage)
- You can uninstall the extension to stop all data collection
Children's Privacy
Our Extension is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Data Retention
- Account Data: Retained while your account is active, deleted upon account deletion request
- Usage Statistics: Retained for up to 2 years for analytics purposes
- Local Data: Stored until you uninstall the extension or clear Chrome storage
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. We ensure appropriate safeguards are in place.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on https://boardcompanion.com/privacy-policy
- Updating the "Last Updated" date
- Sending an email notification (for material changes)
Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email: blake@ivytutoring.net
- Website: https://boardcompanion.com
Compliance
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
By using BoardBuddy, you acknowledge that you have read and understood this Privacy Policy.