# HypeX - Web Assistant Privacy Policy **Effective date:** July 29, 2026 HypeX - Web Assistant ("HypeX", "we", "our", or "the extension") respects user privacy. This Privacy Policy explains what information is processed when users choose to use HypeX features, including member login, HX Token balance, PayOS top-up, AI chat, translation, summarization, explanation, rewrite, OCR, screenshot, image analysis, video analysis, and prompt generation. ## Single Purpose HypeX helps users understand and work with web content they choose. The extension provides user-requested assistance such as translation, summarization, explanation, rewriting, OCR, image-to-prompt, visual analysis, video analysis, and AI chat directly in the browser. HypeX accesses page content only when the user invokes a relevant feature. HypeX does not continuously collect page content in the background. ## Information We Process Depending on the feature used, HypeX may process the following categories of information: - **User-provided content:** Text typed by the user, selected text, prompts, uploaded files, screenshots, images, OCR text, and other content the user asks HypeX to process. - **Website content:** Page title, selected page text, limited page context, screenshots, images, video frames, and page content needed to complete a user-requested action. - **Web browsing activity:** Current page URL, sanitized URL, domain, or page title may be used when needed to provide context for a user-requested feature or to remember disabled domains locally. - **Account information:** When users sign in to HypeX Member, Supabase may store account, session, profile, balance, order, and usage records needed for authentication, HX Token balance, payment reconciliation, and AI usage accounting. - **Authentication information:** Supabase session tokens, refresh tokens, and user-entered provider API keys may be stored locally using Chrome extension storage. - **Payment information:** PayOS order metadata, checkout information, payment status, and top-up reconciliation data may be processed for HX Token purchases. - **Settings and preferences:** Extension settings, selected AI provider, language preferences, feature toggles, disabled domains, and local history/settings may be stored on the user's device. ## How We Use Information HypeX uses information only to provide, secure, and improve the features requested by the user, including: - authenticating HypeX Member accounts; - showing HX Token balance and usage history; - creating and reconciling PayOS top-up orders; - sending user-requested prompts, selected text, screenshots, images, OCR text, files, or page context to the selected AI provider; - saving local preferences and extension settings; - preventing abuse, troubleshooting errors, and complying with legal obligations. HypeX does not sell user data. HypeX does not use user data for advertising, creditworthiness, unrelated profiling, or resale. ## Permissions and Host Access HypeX requests only the permissions needed for its stated features: - `contextMenus`: Adds user-initiated right-click actions for selected text, images, OCR, translation, summarization, explanation, and analysis. - `storage`: Saves extension settings, selected provider, local preferences, session state, HX Token balance cache, and user-entered API keys on the user's device. - `scripting`: Runs extension scripts on the active page only when needed for user-requested features such as collecting selected text, showing the assistant panel, displaying translation results, or collecting limited page context. - `identity`: Supports optional HypeX Member sign-in. HypeX uses Chrome Identity APIs such as `chrome.identity.getRedirectURL()` and `chrome.identity.launchWebAuthFlow()` to complete Google sign-in through Supabase Auth. HypeX does not directly read the user's Chrome profile and does not use login data for ads, tracking, resale, or unrelated profiling. - `` host access: Allows HypeX to work on user-selected content across websites. Page content is accessed only when the user invokes a relevant feature. ## Data Sharing and Third-Party Services HypeX may transmit information to third-party services only when needed to provide a user-requested feature: - **Supabase:** Receives account, session, profile, balance, order, and usage records for HypeX Member features. - **PayOS:** Receives payment and order metadata needed to create, verify, and reconcile HX Token top-up transactions. - **AI providers:** Depending on the user's selected configuration, requests may be sent to services such as 302.ai, Google Gemini, OpenAI-compatible providers, MemeFast, or another provider configured by the user. These requests may include prompts, selected text, page context, OCR text, screenshots, uploaded files, images, or video frames needed to produce the requested output. HypeX shares data with these processors only to provide the requested feature, operate account and billing functionality, prevent abuse, provide support, comply with legal obligations, or protect the security of the service. ## Remote Code HypeX does not execute remote code as part of the Chrome extension package. Extension code is packaged with the extension. Network requests to AI providers, Supabase, PayOS, or other configured services are used to exchange data needed for user-requested features, not to download and execute remote extension code. ## Data Storage and Security Local settings, preferences, session tokens, and user-entered provider API keys may be stored using Chrome extension storage on the user's device. Server-side provider secrets, PayOS secrets, Supabase service-role keys, and HypeX provider credentials are not stored in the extension package. HypeX Member AI requests may go through Supabase Edge Functions so privileged server-side secrets remain outside the extension. Reasonable safeguards are used to protect account, payment, and usage data. ## Human Access to User Data HypeX does not allow humans to read user content except when required for user support, security, abuse investigation, legal compliance, or when the user explicitly provides the information for troubleshooting. ## Data Retention and Deletion Local extension settings and local state remain on the user's device until the user clears them, resets extension storage, or uninstalls the extension. Member account, balance, order, payment, and usage records may be retained as needed for account operation, payment reconciliation, fraud prevention, security, accounting, dispute handling, and legal compliance. Users may request deletion or support for account data by contacting `betafpt@gmail.com`. Some transaction, security, or legal records may need to be retained where required by law or legitimate business needs. ## HX Token HX Token is an internal prepaid usage unit for paid HypeX AI functionality. HX Token is not cash, not cryptocurrency, not transferable, and cannot be withdrawn. The extension shows package price and HX Token amount, not upstream provider budget or HypeX margin. ## Contact For privacy questions or deletion requests, contact the HypeX operator at `betafpt@gmail.com`.