1. Introduction
Vidlore: Course Notes & AI Tutor (“Vidlore”, “we”, “our”, or “the Extension”), formerly “Udemy Study Assistant & Note Formatter”, is a Chrome extension that helps you study Udemy™ courses you are already enrolled in. This Privacy Policy explains what information the Extension handles, where it goes, and how you control it.
Vidlore is an independent product. It is not affiliated with, endorsed by, or sponsored by Udemy, Inc.
2. Our Principle: Local by Default, Only What You Choose
The Extension does not collect course content while you browse. Nothing is read from a course until you click Extract on it. Everything you extract stays in your browser unless you use a feature that explicitly needs a server, as described below.
3. Data Stored Only on Your Device
The following data is stored in your browser’s own storage (IndexedDB and
chrome.storage.local) on your device. We do not have access to it:
- Course structure, lecture transcripts, and captions you extract.
- Notes you write or import from Udemy.
- AI summaries, quiz sessions, quiz results, and chat history.
- Semantic search embeddings and the search index. Embeddings are computed on your device, so your search queries never leave your machine.
- Your settings.
A few preferences (such as theme, output language, and the telemetry setting) are
stored in chrome.storage.sync, which Chrome may sync across browsers signed in to
your Google account.
4. Data That Leaves Your Device
| When | Sent to | What is sent |
|---|---|---|
| You extract a course | Udemy (udemy.com, udemycdn.com) | Requests made through your existing Udemy session to read course structure, captions, and your notes. We never receive your Udemy credentials. |
| You sign in | Supabase (our authentication provider) | Your email address and basic Google profile (name) to create your account and verify your plan. |
| You use a cloud AI feature (summary, quiz, lecture chat) on the Vidlore AI service | Vidlore AI Gateway | Only the lecture text and question needed for that request, plus your signed account token. The request is forwarded to a third-party AI model provider to generate the answer. |
| You build the semantic search index (Pro) | Hugging Face | A one-time download of the embedding model files. No course content or search query is sent. |
| Anonymous usage analytics (on by default, can be turned off) | Vidlore AI Gateway, then PostHog (EU) | A random installation ID, the extension version, and feature events such as “page viewed”, “transcript downloaded”, or “signed in”, sometimes with a course ID or export format. No transcript text, notes, or search queries. |
| An error occurs | Supabase | The error message, stack trace, extension version, the page URL, and your account ID if you are signed in. Used only to fix bugs. |
| You submit a support request | Supabase | Your account ID, email, the message you write, and the extension version. |
| You uninstall the Extension | Vidlore AI Gateway | Your random installation ID and extension version, so we can count uninstalls and show an optional feedback page. |
| You buy a plan | Gumroad | Payment is handled entirely by Gumroad. We receive purchase confirmation, your email, and order identifiers, never your card details. |
5. What the AI Gateway Keeps
The Vidlore AI Gateway does not store your course library, transcripts, prompts, or AI responses. For each AI request it records only:
- Your account ID, the feature used, the AI provider and model.
- Token counts and cost, used to enforce your quota and show your usage.
- Error messages when a request fails.
6. What We Do Not Do
- We do not sell, rent, or trade your personal information.
- We do not use your data for advertising. Usage analytics are used only to understand how features are used and to improve the Extension.
- We do not track your browsing history or activity outside Udemy lecture pages.
- We do not download course videos or bypass Udemy access controls.
- We do not keep a server-side copy of your course library.
7. Third-Party Services
- Udemy: the platform whose content you are studying.
- Supabase: authentication, plan verification, support, and error logs.
- AI model providers: generate AI responses for requests sent through the Vidlore AI Gateway.
- Hugging Face: hosts the embedding model used for on-device semantic search.
- PostHog: anonymous product analytics, hosted in the EU.
- Gumroad: payments. See Gumroad’s Privacy Policy for payment data.
8. Your Choices
- Turn off analytics: Settings → Privacy → Telemetry.
- Stay fully local: extraction, reading transcripts, and transcript export work without signing in. Pro search also runs entirely on your device; only the cloud AI features (summary, quiz, lecture chat) send content to our servers.
- Delete local data: use “Clear History” or delete a course from the Library. Uninstalling the Extension removes all local data.
- Delete your account: email us at the address below and we will delete your account, support tickets, error logs, and usage records linked to it, except purchase records we must keep for tax and accounting.
9. Security
Your sign-in token is stored in the extension’s isolated storage
(chrome.storage.local), never in a web page’s storage. Plan entitlement is verified
with a cryptographically signed token inside the Extension’s background worker. All
communication with our servers uses HTTPS.
10. Children
The Extension is not directed to children under 13, and we do not knowingly collect their personal information.
11. Changes to This Policy
We may update this policy when the Extension changes. The “Last Updated” date above shows the latest revision. Material changes will be announced in the Extension’s release notes.
12. Contact Us
Developer: Thang Le Email: hi@thangle.dev