Privacy Policy
Effective date: September 4, 2026
This Privacy Policy describes how AutoTopHat (the Chrome extension and its companion backend API) collects, uses, stores, and shares information when you use the service.
AutoTopHat’s single purpose is to automatically answer TopHat lecture questions for the signed-in student.
1. Who we are
AutoTopHat is provided by the publisher listed on the Chrome Web Store item page. The extension runs in your browser; the backend runs as a Cloudflare Worker and stores account data in Cloudflare KV.
2. Information we collect
Personally identifiable information
- Google account email address and Google account id (
sub), obtained when you sign in with Google - TopHat student user id (from TopHat lecture WebSocket traffic)
- Course id for the lecture you are attending
Authentication information
- Short-lived Google OAuth access tokens used to authenticate requests to our API
We do not collect or store your Google password.
Financial and payment information
- Subscription and billing status (for example plan, Stripe customer id, subscription id, current period end)
Card numbers and full payment details are processed by Stripe; we do not store credit card numbers.
Location
- IP address (from Cloudflare’s connecting IP), retained briefly to detect abuse (for example many IPs on one account)
User activity
- TopHat lecture question events observed over the lecture WebSocket while the extension is active on a matching lecture page (for example when a question appears and whether it was solved)
Website content
- Question text, answer choices, and question images (URL or image data) needed to generate an answer
Data stored only on your device
- Extension settings (for example whether auto-answer is armed)
- Session state (sign-in / plan status cache)
- Optional local WebSocket/event logs in IndexedDB when logging is enabled
Local logs stay on your device unless you export them yourself.
We do not collect health information, personal emails/texts/chats, or a general browsing history outside TopHat lecture pages the extension is designed to work with.
3. How we use information
We use the information above to:
- Sign you in and restrict access to allowed email domains (when configured)
- Bind one Google account to one TopHat student account (anti-abuse)
- Run the free trial and paid subscription entitlements and daily solve quotas
- Send question content to our server-side model provider to generate answers
- Cache answers briefly so repeated identical questions can be served efficiently
- Process checkout and subscription changes via Stripe
- Detect abuse and operate the service (including operator unbind of a mistaken account binding)
- Improve reliability using operational logs (for example solve success/failure codes)
4. How we share information
We share data only as needed to run the service:
| Recipient | Purpose |
|---|---|
Sign-in / token validation (openid, email scopes) |
|
| Stripe | Checkout, subscriptions, customer portal |
| Google Gemini (Generative Language API) | Generate answers from question text/images |
| Cloudflare | Host the API and store KV data / request infrastructure |
| TopHat | We submit answers back through your existing TopHat lecture WebSocket in the browser; we do not send your Google credentials to TopHat |
We do not sell your personal information. We do not share data with third parties for their advertising.
5. Retention
| Data | Typical retention |
|---|---|
| Student / binding / subscription records | Kept while needed to enforce trial, binding, and billing |
| Cached answers | About 24 hours |
| Daily quota counters | About 48 hours |
| IP addresses used for abuse checks | About 48 hours |
| Google token validation cache | Short-lived (hours) |
| Server operational logs | Per Cloudflare / operator log retention |
| On-device settings and IndexedDB logs | Until you clear extension data or clear logs in the UI |
6. Security
We use HTTPS for API traffic, keep model and payment secrets on the server (not in the extension), and limit API access to the published Chrome extension origin where applicable. No method of transmission or storage is 100% secure.
7. Your choices
- Sign out in the extension to clear the cached Google auth token from the extension.
- Manage subscription opens Stripe’s customer portal.
- Clear logs removes on-device IndexedDB event logs.
- Uninstalling the extension removes local extension storage; server-side account and billing records may remain as needed for abuse prevention and subscription records.
- To request unbinding of a Google account from a TopHat student id (for example you permanently changed Google accounts), contact us at the email below. Trial clock and plan state are preserved on the student record when an operator unbinds.
8. Children’s privacy
AutoTopHat is intended for students using TopHat in an educational setting. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
9. Changes
We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Continued use of AutoTopHat after an update means you accept the revised policy. Material changes will also be reflected in the Chrome Web Store privacy disclosures.
10. Chrome Web Store disclosures
This policy is intended to match the data types disclosed on the AutoTopHat Chrome Web Store listing, including personally identifiable information, authentication information, financial and payment information, location (IP address), user activity, and website content.
Contact Us
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact via email at edusoft2024@gmail.com