01 · Legal & Policies
Privacy Policy
Last updated: August 30, 2026
1. Introduction
tonescript ("we", "our", "us") values your privacy. This Privacy Policy details how the tonescript Chrome Extension and Web Portal (tonescript.cc) collect, use, and protect your information when you interact with our platform.
2. Chrome Extension Permissions & Usage
The tonescript browser extension requests minimal permissions required to deliver synchronized phonetic subtitles:
- activeTab: Used strictly on active YouTube watch pages to detect the current video ID, page title, and embed the sidebar learning panel.
- storage: Used to persist user preferences (such as preferred phonetic notation style) and authentication tokens locally on your browser.
- Host Permissions: Used to communicate securely with our backend API (
api.tonescript.cc) and public open lyrics sources (https://lrclib.net).
3. Information We Collect
- Account Information: When you sign up, we receive your email address and profile identifiers via Clerk to manage your account and credit balance.
- Learning & Study Progress: Tracked song study counts, study streak dates, and bookmarked vocabulary lines are saved so you can review them in your dashboard.
- User-Contributed Lyrics: Text pasted into the manual untimed lyrics tool is stored to provide phonetic transcriptions across the community.
4. Third-Party Sub-processors & Service Providers
We do not sell your personal data. We partner with trusted service providers to operate our platform:
- Creem (Merchant of Record & Payments): Credit pack transactions and billing information are securely processed by Creem (creem.io). Creem acts as the Merchant of Record, ensuring PCI-DSS compliance and handling tax calculation. We do not store credit card numbers on our servers.
- Clerk (User Authentication): Manages user login sessions, social authentication, and security tokens.
- Google Gemini API (Phonetic Transcriptions): Server-to-server AI processing transforms lyric texts into intuitive phonetic spelling. No user identity or account data is shared with Google AI Studio.
- Sentry (Error Telemetry): Used for crash diagnostics. Sensitive payloads, authorization tokens, and personal text are redacted prior to sending.
5. Data Retention & User Rights
You retain the right to access, export, or delete your account data at any time. If you wish to delete your account, remove your saved vocabulary history, or request data export, please contact us.
6. Contact Us & Data Protection
If you have any questions about this Privacy Policy or wish to exercise your data privacy rights, please reach out to: