Privacy Policy

AI OverMind — Chrome Extension

Effective: February 8, 2026 Last Updated: February 8, 2026
TL;DR — The Short Version
Table of Contents
1. Overview 2. Information We Collect 3. Information We Do NOT Collect 4. How We Use Your Information 5. Local Data Processing 6. Content Script Behavior on AI Sites 7. Chrome Permissions Explained 8. Data Sharing 9. Third-Party Services 10. Cookies & Tracking Technologies 11. Data Storage & Security 12. Data Retention & Deletion 13. Your Rights 14. European Users (GDPR) 15. California Users (CCPA/CPRA) 16. Do Not Track & Global Privacy Control 17. Data Breach Notification 18. Children’s Privacy 19. Chrome Web Store Compliance 20. Changes to This Policy 21. Contact Us

1. Overview

AI OverMind (“the Extension”, “we”, “our”, “us”) is a Chrome browser extension developed by CelkiHub that helps users manage AI prompts, profiles, and workflows across supported AI platforms including ChatGPT, Claude, Gemini, Copilot, Grok, and Poe.

This Privacy Policy explains how we collect, use, store, and protect information when you use our Extension. We are committed to protecting your privacy and being transparent about our practices.

By using AI OverMind, you agree to the practices described in this policy. If you do not agree with this policy, please uninstall the extension.

2. Information We Collect

We collect the minimum amount of information necessary to provide our services. Here is a complete overview:

Data TypeWhatPurposeWhen
Account infoEmail, display name, profile picture URL, Google IDAuthentication & account managementWhen you sign in with Google
SubscriptionStripe customer ID, subscription status, plan, billing periodManage Pro subscriptionWhen you subscribe to Pro
Usage countsNumber of actions per day (anonymous count only)Enforce free-tier limitsEach time a feature is used
TechnicalExtension version, randomly generated installation ID, last activity timestampVersion compatibility, supportOn each API call

2.1 Account Information (Signed-in Users Only)

If you choose to sign in with Google, we receive and store your email address, display name, profile picture URL, and a unique Google account identifier. This information is used solely for authentication and account management. Signing in is optional — you can use AI OverMind without an account.

2.2 Subscription & Payment Information

If you subscribe to AI OverMind Pro, payment processing is handled entirely by Stripe. We never collect, store, or have access to your credit card numbers, bank account details, or any other financial credentials. We only store a Stripe customer reference ID, your subscription status, and billing period.

2.3 Usage Metrics

We track aggregate, non-identifiable usage counts (e.g., number of prompts used per day) solely to enforce free-tier usage limits. We do not track the content of your prompts, conversations, or interactions.

2.4 Technical Information

We collect your extension version number, a randomly generated installation identifier (not linked to any personal data), and a timestamp of your last activity. This helps us ensure compatibility and provide support.

3. Information We Do NOT Collect

We want to be absolutely clear about what we never collect, access, or transmit:

4. How We Use Your Information

The limited data we collect is used exclusively for:

We do not use your data for advertising, profiling, automated decision-making, or any purpose other than those listed above.

5. Local Data Processing

The core functionality of AI OverMind operates entirely on your device:

No prompt content, AI conversation data, or profile configuration ever leaves your device or is transmitted to our servers.

Your creative work — prompts, profiles, and flows — belongs to you and stays on your machine.

6. Content Script Behavior on AI Sites

AI OverMind injects a content script into supported AI chat sites (ChatGPT, Claude, Gemini, Copilot, Grok, and Poe) to provide its features. We want to be fully transparent about what this script does and does not do:

What the content script DOES

What the content script does NOT do

The only network requests the content script makes are to our backend API for: checking your subscription status and counting usage toward free-tier limits. These requests contain only your installation ID and authentication token — never any conversation content.

7. Chrome Permissions Explained

AI OverMind requests only the permissions strictly necessary for its functionality:

PermissionWhy It Is Needed
storageStore your prompts, profiles, flows, settings, and usage counters locally on your device
activeTabInsert selected prompts and profiles into the currently active AI chat tab when you trigger /// or //
identityEnable optional “Sign in with Google” for account features and subscription management
sidePanelDisplay the AI OverMind panel alongside AI chat sites for quick access
Host permissions
(chatgpt.com, claude.ai, gemini.google.com, copilot.microsoft.com)
Inject the content script that enables the /// menu, // profile switch, floating dock, and flow execution on supported AI platforms

We do not request broad permissions such as tabs, webRequest, history, bookmarks, or <all_urls>. We follow the principle of least privilege.

8. Data Sharing

We share your data only with the service providers strictly necessary to operate AI OverMind:

ProviderData SharedPurpose
Google (Firebase/Firestore)Account data, subscription statusSecure data storage
StripeEmail (for payment receipts)Payment processing
Google OAuthOAuth token (browser-to-Google only)Sign-in authentication

We do not:

9. Third-Party Services

We integrate with the following third-party services, each with their own privacy policies:

9.1 Google OAuth

Used for optional sign-in. We request only the openid, email, and profile scopes — the minimum required for authentication. See Google’s Privacy Policy.

9.2 Stripe

Used for subscription payments and billing. Stripe is PCI DSS Level 1 certified — the highest level of payment security certification. We never receive or store your card details. See Stripe’s Privacy Policy.

9.3 Google Cloud Platform (Firestore)

Our backend API runs on Google Cloud Functions and stores account data in Google Cloud Firestore. It processes only the account and subscription data described in Section 2. Data is encrypted at rest and in transit. See Google Cloud Privacy Notice.

10. Cookies & Tracking Technologies

AI OverMind does not use cookies, tracking pixels, web beacons, fingerprinting, or any third-party analytics SDKs.

For local data persistence, AI OverMind uses Chrome’s chrome.storage.local API — this is a sandboxed extension storage mechanism that is not a cookie and is not accessible to websites or other extensions.

The AI platforms where AI OverMind’s content scripts run (ChatGPT, Claude, Gemini, etc.) have their own cookie policies. AI OverMind does not interact with, read, modify, or access any cookies set by these platforms.

11. Data Storage & Security

We take the security of your data seriously. Here is how your data is protected:

Server-Side (Account Data)

Client-Side (Local Data)

12. Data Retention & Deletion

How Long We Keep Your Data

Data TypeRetention PeriodDeletion Trigger
Account dataUntil you request deletionAccount deletion request
Subscription dataUntil subscription ends + 90 daysAuto-deleted after retention period
Usage countsReset daily; aggregates kept 12 monthsAuto-deleted after retention period
Local data (prompts, profiles, flows)Until you delete or uninstallUnder your full control

How to Delete Your Data

Upon receiving a deletion request, we will acknowledge it within 10 business days and complete the deletion within 30 days, confirming by email.

13. Your Rights

Regardless of where you are located, you have the following rights:

To exercise any of these rights, email us at support-overmind@celkihub.com. We will acknowledge your request within 10 business days and respond substantively within 30 days (GDPR) or 45 days (CCPA). If additional time is needed for complex requests, we will notify you within the initial response period.

14. European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).

Legal Basis for Processing

Processing ActivityLegal Basis
Google sign-in (name, email)Consent — you actively choose to sign in
Subscription managementContract performance — necessary to fulfill your Pro subscription
Usage countingLegitimate interest — enforcing fair usage of free tier
Version checkingLegitimate interest — ensuring extension compatibility and security

Automated Decision-Making

AI OverMind does not engage in automated individual decision-making or profiling as defined in GDPR Article 22. Your subscription tier is determined solely by your chosen plan and payment status, not by automated profiling of your behavior or personal characteristics.

Your Additional GDPR Rights

International Data Transfers

Your account data is processed in the United States via Google Cloud Platform. Google provides appropriate safeguards for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission. Stripe also provides SCCs for payment data processing.

15. California Users (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Your California Rights

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. No opt-out is necessary because we never engage in these practices.

To make a privacy request, email support-overmind@celkihub.com. We will verify your identity and respond within 45 days as required by law.

16. Do Not Track & Global Privacy Control

AI OverMind does not track users across third-party websites and therefore does not respond to Do Not Track (DNT) browser signals, as there is no tracking to disable.

AI OverMind recognizes and respects Global Privacy Control (GPC) signals as required by applicable law. Since AI OverMind does not sell or share personal information for advertising or cross-context behavioral advertising purposes, GPC signals do not require any changes to our data processing.

17. Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will:

18. Children’s Privacy

AI OverMind is not intended for use by children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information within 30 days. If you believe a child has provided us with their data, please contact us immediately.

19. Chrome Web Store Compliance

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Specifically, AI OverMind commits to the following:

Chrome Web Store Data Disclosures

In accordance with Chrome Web Store requirements, here is what we certify:

CWS Data CategoryCollected?
Personally identifiable informationYes — email, name (via Google sign-in only)
Authentication informationYes — OAuth tokens (managed locally by Chrome)
Financial and payment informationNo — handled externally by Stripe
Health informationNo
Web browsing activityNo
Website contentNo
Personal communicationsNo
LocationNo
User activityAnonymous action counts only (for usage limits)

20. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

We encourage you to review this policy periodically. Continued use of the Extension after changes constitutes acceptance of the updated policy.

21. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your data, or our privacy practices, please contact us:

We acknowledge all privacy inquiries within 10 business days and fulfill data requests within 30 days (GDPR) or 45 days (CCPA).