Keyjot — Privacy Policy
Last updated: July 30, 2026
Keyjot ("Keyjot", "we", "us") is a Chrome extension that helps you draft replies inside any text field on the web. This policy explains what data the extension and its backend collect, why, who it is shared with, and the choices you have. Questions: beforesleep@beforesleep.app.
1. Summary
- We collect the minimum needed to sign you in, generate replies, process payments, and understand product usage.
- We never collect your browsing history and never transmit the content of pages you visit. The extension only reads text when you invoke it.
- We never sell your data or share it for advertising.
- Analytics are anonymous and can be turned off at any time.
- The text you ask the AI to work with is used to produce a reply and is not stored on our servers.
2. Information we collect
2.1 Account information (only if you sign in)
Signing in is optional and only required to use the cloud AI. When you sign in with Google we use the openid, email, and profile scopes and receive your email address (stored on our backend to identify your account and token balance) and your name and profile picture (stored locally in your browser only, never on our backend). We do not receive or store your Google password.
2.2 Content you submit for AI generation
When you generate a reply with the cloud AI, the extension sends our backend only what is needed to produce that reply: the message you are replying to (or text you selected), your one-line intent / key point, and your chosen tone, length, and language, plus an optional signer name. This content is forwarded to the AI provider (Google Gemini) in real time to generate the reply and is not persisted in our database (see §4). If you configure your own AI endpoint, this content goes directly from your browser to that endpoint and does not pass through our servers at all.
2.3 Usage analytics (anonymous, opt-out)
We collect anonymous, aggregated usage events (e.g. installed, command window opened, draft generated/inserted, checkout started), tied to a random device identifier — not your name or email. Event properties are limited to non-identifying, coarse values: extension version, OS family, interface and reply language, AI source, whether you are signed in, a bucketed token balance and template count, the tone used, and a coarse category of site (e.g. "gmail", "outlook", "other").
We deliberately never send as analytics: the content of any page, message, draft, key point, template body, or variable value; exact text lengths (only coarse buckets); URLs or hostnames; or your email or name. Your IP address is masked on our server and server-side geolocation is disabled. The only free-form text we receive is what you type into the in-product feedback form, submitted deliberately. Analytics are on by default and can be turned off under AI Settings → Privacy.
2.4 Payment information
Purchases are handled by our third-party payment processor, Polar (a merchant of record). Card and billing details are entered on the processor's checkout and handled by them — we never see or store your card number. After a successful payment we store the order id, the product purchased, the token amount, the paid amount, and your account id to credit your balance and prevent double-crediting.
2.5 Data stored locally in your browser
Your templates, settings, signer name, and session token are stored in your browser's local extension storage (chrome.storage.local) and stay on your device, except where a feature requires it (e.g. the session token is sent as a bearer credential to authenticate backend requests).
3. How we use information
To authenticate you and maintain your session; generate the AI replies you request; process purchases and maintain your token balance; operate, debug, and improve the product through anonymous analytics; and respond to feedback and support. We do not use your data for advertising and do not sell it.
4. Third parties and subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Google (Sign-In) | Authenticate you | Your Google email, basic profile |
| Google Gemini API | Generate the AI reply | The message/intent you submit, in real time (not stored by us) |
| Polar | Process payments | Payment and order details (card data handled by them, not us) |
| PostHog | Anonymous product analytics | The anonymous events described in §2.3 (IP masked) |
| Cloudflare | Host our backend | Requests to our backend transit Cloudflare's network |
Each provider processes data under its own privacy policy and terms. Content sent to Google Gemini is processed under Google's API terms.
5. Data retention
- Account email and token balance: kept while your account exists.
- AI generation content: not persisted in our database; transient only.
- Analytics events: retained by our analytics provider per its settings, in anonymous form.
- Payment records: retained as required for accounting and tax purposes.
6. Your choices and rights
Turn off analytics (AI Settings → Privacy); sign out (removes and revokes your session token); revoke Google access at myaccount.google.com/permissions; or email beforesleep@beforesleep.app to access or delete your data. Depending on where you live you may have additional rights (e.g. under GDPR or CCPA).
7. Data security
Sessions use opaque, randomly generated tokens. Payment card data never touches our servers. Analytics carry no message content and a masked IP. Backend access requires a valid session credential. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.
8. Children
Keyjot is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction) and we do not knowingly collect their data.
9. International transfers
Our providers may process data in countries other than yours (including the United States). Where required, we rely on the providers' safeguards for such transfers.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through an in-product notice.
Contact: beforesleep@beforesleep.app