Vidlore

Privacy Policy

Last Updated: September 27, 2026

1. Introduction

Vidlore: Course Notes & AI Tutor (“Vidlore”, “we”, “our”, or “the Extension”), formerly “Udemy Study Assistant & Note Formatter”, is a Chrome extension that helps you study Udemy™ courses you are already enrolled in. This Privacy Policy explains what information the Extension handles, where it goes, and how you control it.

Vidlore is an independent product. It is not affiliated with, endorsed by, or sponsored by Udemy, Inc.

2. Our Principle: Local by Default, Only What You Choose

The Extension does not collect course content while you browse. Nothing is read from a course until you click Extract on it. Everything you extract stays in your browser unless you use a feature that explicitly needs a server, as described below.

3. Data Stored Only on Your Device

The following data is stored in your browser’s own storage (IndexedDB and chrome.storage.local) on your device. We do not have access to it:

A few preferences (such as theme, output language, and the telemetry setting) are stored in chrome.storage.sync, which Chrome may sync across browsers signed in to your Google account.

4. Data That Leaves Your Device

WhenSent toWhat is sent
You extract a courseUdemy (udemy.com, udemycdn.com)Requests made through your existing Udemy session to read course structure, captions, and your notes. We never receive your Udemy credentials.
You sign inSupabase (our authentication provider)Your email address and basic Google profile (name) to create your account and verify your plan.
You use a cloud AI feature (summary, quiz, lecture chat) on the Vidlore AI serviceVidlore AI GatewayOnly the lecture text and question needed for that request, plus your signed account token. The request is forwarded to a third-party AI model provider to generate the answer.
You build the semantic search index (Pro)Hugging FaceA one-time download of the embedding model files. No course content or search query is sent.
Anonymous usage analytics (on by default, can be turned off)Vidlore AI Gateway, then PostHog (EU)A random installation ID, the extension version, and feature events such as “page viewed”, “transcript downloaded”, or “signed in”, sometimes with a course ID or export format. No transcript text, notes, or search queries.
An error occursSupabaseThe error message, stack trace, extension version, the page URL, and your account ID if you are signed in. Used only to fix bugs.
You submit a support requestSupabaseYour account ID, email, the message you write, and the extension version.
You uninstall the ExtensionVidlore AI GatewayYour random installation ID and extension version, so we can count uninstalls and show an optional feedback page.
You buy a planGumroadPayment is handled entirely by Gumroad. We receive purchase confirmation, your email, and order identifiers, never your card details.

5. What the AI Gateway Keeps

The Vidlore AI Gateway does not store your course library, transcripts, prompts, or AI responses. For each AI request it records only:

6. What We Do Not Do

7. Third-Party Services

8. Your Choices

9. Security

Your sign-in token is stored in the extension’s isolated storage (chrome.storage.local), never in a web page’s storage. Plan entitlement is verified with a cryptographically signed token inside the Extension’s background worker. All communication with our servers uses HTTPS.

10. Children

The Extension is not directed to children under 13, and we do not knowingly collect their personal information.

11. Changes to This Policy

We may update this policy when the Extension changes. The “Last Updated” date above shows the latest revision. Material changes will be announced in the Extension’s release notes.

12. Contact Us

Developer: Thang Le Email: hi@thangle.dev