01privacy policy
What this extension knows and what it never sends.
Reply AI has no server, no account and no analytics. It stores what it needs on your own machine and makes exactly one kind of outbound request: to OpenRouter, on your own API key, when you press Generate.
Last updated: 17 August 2026 · Applies to version 0.1.0 onward
What we collect about you
Nothing. There is no server to collect it with. The extension sends us no usage data, no error reports, no install ping and no identifier of any kind, and it has no way to know that you exist.
What is stored on your device
All of it lives in the browser's own extension storage and is readable only by this extension.
| What | Where | Why |
|---|---|---|
| OpenRouter API key | Local, on this device | Authenticates your generation requests. Sent only to openrouter.ai |
| Soul profile | Local, on this device | The description of your channel and voice that you wrote yourself |
| Preferences | Local, on this device | Chosen model, tone, creativity, context depth, who the reply speaks as |
| Model list | Local, on this device | A cached copy of OpenRouter's public catalogue, so the settings page opens fast |
| Video descriptions | Session, cleared when the browser closes | Avoids re-reading the same page for every reply on it |
| Daily reply counter | Synced storage | Enforces the free daily limit. See the note below |
The counter is the one item Chrome may copy off your device: it lives in synced extension storage, so if you are signed into Chrome with sync on, Chrome carries it to your Google account along with your other browser data. It holds today's date and a list of short one-way fingerprints of the comments already answered — 32-bit numbers that cannot be turned back into a comment, an author or a link. It exists so the day's count follows your profile instead of resetting on every new machine. Nothing else is synced: your API key and your soul profile stay on the device they were entered on.
What is sent when you press Generate
One HTTPS request to openrouter.ai/api/v1/chat/completions, containing only
what the model needs to write the reply:
- the text of the comment you are replying to, and its author's public display name;
- the comment that started the thread, when you reply inside one;
- the video's title, channel name and id — and, only at the deepest context setting, its description;
- your soul profile and the settings for this reply;
- anything you typed into the note field, and the earlier attempts when you regenerate;
- your API key, as the authorisation header;
- two headers naming the application, so the request is attributable in your own OpenRouter dashboard.
That request goes from your browser straight to OpenRouter and never passes through us. OpenRouter then routes it to whichever model provider you selected. Their handling of it is governed by your agreement with them — see OpenRouter's privacy policy, and the prompt-logging controls in your OpenRouter account settings, which you own and we cannot change.
Two things worth stating plainly. Nothing is sent unless you press a button — the extension does not read comment sections in the background, and it never posts a reply for you; inserting text into YouTube's reply box is the last thing it does, and pressing Reply is yours. And the comment text belongs to the person who wrote it, not to us: it reaches OpenRouter under your own account and no copy is kept anywhere else.
Signing in to OpenRouter
Connecting an account uses the browser's own identity API to open OpenRouter's consent page in a normal browser window. Your OpenRouter password is typed on their site and never reaches the extension; what comes back is an API key scoped to this extension, stored as described above. You can revoke it at any time at openrouter.ai/settings/keys, which instantly stops the extension from being able to generate anything.
Permissions, and why each one exists
| Permission | What it is for |
|---|---|
storage |
The table above. Without it there is nowhere to keep your key or your settings |
identity |
Opens OpenRouter's sign-in page and receives the key it issues |
openrouter.ai |
The single host the extension may contact. It is not broadened to all sites, and the extension cannot reach any other server |
www.youtube.comstudio.youtube.com |
The two pages the interface is drawn on — the button in a comment's toolbar and the panel that opens from it. Reading the page is how the comment gets into the panel |
The extension contains no remote code. Text a model returns is displayed and inserted as text; it is never executed.
The Pro link
Pro does not exist yet, and the button for it is a link to a page on this website. If you ticked features in settings before pressing it, they travel in the address bar — visible to you, in the URL — so the page can pre-tick the same boxes. That is a page you chose to open, not a report the extension filed: nothing is submitted from inside the extension, and if you type an email address it happens on the website, under the terms in the next section.
This website and the waitlist
These pages set no cookies and load no third-party scripts, fonts or images. If you submit the waitlist form, your address is stored in our own self-hosted mailing tool on a server we run, together with the features you voted for, your answer on price, anything you wrote in the free-text field, and which entry point sent you.
You will receive a confirmation email and are on the list only if you click the link in it. The address is used for one thing — telling you when Pro exists — and every email carries a one-click unsubscribe that deletes you from the list. It is never sold, rented or shared, and it is not used for any other mailing.
Deleting everything
Removing the extension removes its storage with it, including the synced counter. Settings also lets you clear the stored key on its own. To leave the waitlist, use the unsubscribe link in any email from us; to be certain nothing of yours remains, write to the address below and it will be deleted.
Changes
If what the extension stores or sends ever changes, this page changes in the same release and the date at the top moves. Material changes are also listed in the release notes on GitHub, so the history is public rather than a silent edit.
Contact
privacy@reply-ai.mikidev.app — for anything on this page, including a request to delete data.