01privacy policy
What this extension knows and what it never sends.
Reply AI has no account, no analytics and nothing that tracks you. It stores what it needs on your own machine, and every reply goes straight to OpenRouter on your own API key. One service of ours exists, and it is contacted at most twice in the life of an install — for a free trial key, and to turn a supporter code into a licence — never with a word of anyone’s comment, and only when you press something.
last updated: 18 august 2026 · applies to version 1.0.0 onward
What we collect about you
No usage data, no error reports, no install ping and no profile. Nothing you write, and nothing anyone else wrote, ever reaches us.
There are two exceptions, each of which happens at most once and only when you press something. If you press Try it free, the extension sends a random number it generated for itself and receives an OpenRouter key with a few cents on it. We record that number, the time, and whether a key was issued — enough to give one trial per install and to answer you if it fails. It is tied to no account, no email and no address. Take your own key instead and this never happens at all.
The second is activating a supporter licence, which sends the code and nothing else. It is described further down. Neither request carries an identifier of you, and after them the extension never contacts us again.
What is stored on your device
All of it lives in the browser’s own extension storage and is readable only by this extension.
| what | where | why |
|---|---|---|
| OpenRouter API key | Local, on this device | Authenticates your generation requests. Sent only to openrouter.ai |
| Soul profile | Local, on this device | The description of your channel and voice that you wrote yourself |
| Preferences | Local, on this device | Chosen model, tone, creativity, context depth, who the reply speaks as, whether the coffee card may appear |
| Model list | Local, on this device | A cached copy of OpenRouter's public catalogue, so the settings page opens fast |
| Video descriptions | Session, cleared when the browser closes | Avoids re-reading the same page for every reply on it |
| Reply counter | Synced storage | Counts what you have written, and remembers whether you have answered the question about a review. It gates nothing — see the note below |
| Install id | Local, on this device | A random number this copy of the extension gives itself, used once to ask for a free trial key. Only created if you take the trial |
| Supporter licence | Synced storage | The signed licence a code turns into, if you were given one. It names what was bought and when it expires, and nobody at all |
The counter is the one item Chrome may copy off your device: it lives in synced extension storage, so if you are signed into Chrome with sync on, Chrome carries it to your Google account along with your other browser data. It holds today’s date, two totals, and a short list of one-way fingerprints of the comments most recently answered — 32-bit numbers that cannot be turned back into a comment, an author or a link. It exists so the count follows your profile instead of resetting on every new machine, and so the extension can say thank you once every twenty replies. It restricts nothing: there is no daily limit and nothing is refused when the number gets large. A supporter licence rides the same storage for the same reason, and names nobody. Nothing else is synced — your API key stays on the device it was entered on, the trial's included, and so does your soul profile.
What is sent when you press Generate
One HTTPS request to openrouter.ai/api/v1/chat/completions, containing only what the model needs to write the reply:
- the text of the comment you are replying to, and its author’s public display name;
- the comment that started the thread, when you reply inside one;
- the video’s title, channel name and id — and, only at the deepest context setting, its description;
- your soul profile and the settings for this reply;
- anything you typed into the note field, and the earlier attempts when you regenerate;
- your API key, as the authorisation header;
- two headers naming the application, so the request is attributable in your own OpenRouter dashboard.
That request goes from your browser straight to OpenRouter and never passes through us. OpenRouter then routes it to whichever model provider you selected. Their handling of it is governed by your agreement with them — see OpenRouter’s privacy policy, and the prompt-logging controls in your OpenRouter account settings, which you own and we cannot change.
Two things worth stating plainly. Nothing is sent unless you press a button — the extension does not read comment sections in the background, and it never posts a reply for you; inserting text into YouTube’s reply box is the last thing it does, and pressing Reply is yours. And the comment text belongs to the person who wrote it, not to us: it reaches OpenRouter under your own account and no copy is kept anywhere else.
Signing in to OpenRouter
Connecting an account uses the browser’s own identity API to open OpenRouter’s consent page in a normal browser window. Your OpenRouter password is typed on their site and never reaches the extension; what comes back is an API key scoped to this extension, stored as described above. You can revoke it at any time at openrouter.ai/settings/keys, which instantly stops the extension from being able to generate anything.
Permissions, and why each one exists
| permission | what it is for |
|---|---|
| storage | The table above. Without it there is nowhere to keep your key or your settings |
| identity | Opens OpenRouter's sign-in page and receives the key it issues |
| openrouter.ai | Where every reply is generated. Your key goes here and nowhere else |
| api.mikidev.app | Ours, contacted at most twice in the life of an install and only if you ask it to: once for a free trial key, once to turn a supporter code into a licence. Replies never go through it |
| www.youtube.com · studio.youtube.com | The two pages the interface is drawn on — the button in a comment’s toolbar and the panel that opens from it. Reading the page is how the comment gets into the panel |
The extension contains no remote code. Text a model returns is displayed and inserted as text; it is never executed.
The links out of the extension
A handful of buttons lead to a web page rather than doing something in the extension: the Pro waitlist, the review, bug-report and contact links in the block that asks how it is going, and Buy Me a Coffee. All of them are ordinary links you press.
The Pro link carries the features you ticked in settings, in the address bar, visible to you, so the waitlist page can pre-tick the same boxes. The rest carry nothing at all — no identifier, no counter, no reply text, and not the star you pressed, which is never stored and never leaves the panel it was drawn in. None of them is a report the extension filed: nothing is submitted from inside it, and if you type an email address it happens on the website, under the terms in the next section.
Buy Me a Coffee is a third-party site with its own privacy policy. Their button is redrawn locally rather than embedded, so nothing of theirs runs or loads until you click it.
This website and the waitlist
These pages set no cookies and load no third-party scripts, fonts or images. If you submit the waitlist form, your address is stored in our own self-hosted mailing tool on a server we run, together with the features you voted for, your answer on price, anything you wrote in the free-text field, and which entry point sent you.
The contact form is a different thing and is stored differently: what you write there, the address to reply to and the name if you gave one are turned into an email to the address below and nothing else. It is not added to any list, there is no mailing to unsubscribe from, and the only record that persists is that email in an inbox — for as long as the conversation is worth keeping, and deleted on request.
You will receive a confirmation email and are on the list only if you click the link in it. The address is used for one thing — telling you when Pro exists — and every email carries a one-click unsubscribe that deletes you from the list. It is never sold, rented or shared, and it is not used for any other mailing.
Activating a licence code
Codes are given away rather than sold — in giveaways and by hand — so there is no purchase here and no payment of yours that we see. If you buy a coffee, that happens entirely at Buy Me a Coffee, under their privacy policy, and nothing about it reaches this extension or changes how it behaves.
Activating sends the code and nothing else: no email, no account, no identifier of your machine. What comes back is a signed licence saying what kind of code it was and when it expires, stored in Chrome's synced storage so it reaches your other machines. There is nothing in it that identifies you, we never learn which install activated which code, and after that moment the extension never contacts us about the licence again.
Deleting everything
Removing the extension removes its storage with it, including the synced counter. Settings also lets you clear the stored key on its own. If you took the trial, the random number that asked for it stays in our record of trials issued — write to the address below and it will be deleted, along with the trial key it names. To leave the waitlist, use the unsubscribe link in any email from us; to be certain nothing of yours remains, write to the same address.
Changes
If what the extension stores or sends ever changes, this page changes in the same release and the date at the top moves. Material changes are also listed in the release notes on GitHub, so the history is public rather than a silent edit.
Contact
privacy@mikidev.app — for anything on this page, including a request to delete data. The address is printed rather than linked on purpose: it has to work from a machine with no mail client configured, and from a screenshot. There is also a form, which reaches the same inbox.
