AutoTopHat Privacy Policy

Effective date: September 4, 2026

This Privacy Policy describes how AutoTopHat (the Chrome extension and its companion backend API) collects, uses, stores, and shares information when you use the service.

AutoTopHat’s single purpose is to automatically answer TopHat lecture questions for the signed-in student.

Contact: jhlam@wisc.edu

1. Who we are

AutoTopHat is provided by the publisher listed on the Chrome Web Store item page. The extension runs in your browser; the backend runs as a Cloudflare Worker and stores account data in Cloudflare KV.

2. Information we collect

Personally identifiable information

Authentication information

We do not collect or store your Google password.

Financial and payment information

Card numbers and full payment details are processed by Stripe; we do not store credit card numbers.

Location

User activity

Website content

Data stored only on your device

We do not collect health information, personal emails/texts/chats, or a general browsing history outside TopHat lecture pages the extension is designed to work with.

3. How we use information

4. How we share information

RecipientPurpose
GoogleSign-in / token validation (openid, email)
StripeCheckout, subscriptions, customer portal
Google GeminiGenerate answers from question text/images
CloudflareHost the API and store KV data
TopHatAnswers are submitted through your existing lecture WebSocket in the browser; we do not send your Google credentials to TopHat

We do not sell your personal information. We do not share data with third parties for their advertising.

5. Retention

DataTypical retention
Student / binding / subscription recordsWhile needed for trial, binding, and billing
Cached answersAbout 24 hours
Daily quota countersAbout 48 hours
IP addresses (abuse checks)About 48 hours
Google token validation cacheShort-lived (hours)
On-device settings and logsUntil you clear extension data or clear logs

6. Security

We use HTTPS for API traffic, keep model and payment secrets on the server (not in the extension), and limit API access to the published Chrome extension origin where applicable. No method of transmission or storage is 100% secure.

7. Your choices

8. Children’s privacy

AutoTopHat is intended for students using TopHat in an educational setting. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13.

9. Changes

We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Continued use after an update means you accept the revised policy. Material changes will also be reflected in the Chrome Web Store privacy disclosures.

10. Chrome Web Store disclosures

This policy is intended to match the data types disclosed on the AutoTopHat Chrome Web Store listing, including personally identifiable information, authentication information, financial and payment information, location (IP address), user activity, and website content.

This document describes product behavior; it is not legal advice.