Privacy Policy
Effective August 21, 2026
Quiz Genie AI turns a webpage you choose into a quiz, a tutoring session, or a deck of flashcards. It reads that page only when you ask it to.
Quiz Genie AI runs no server that receives your data. The extension sends page content directly to the AI provider you choose, authorized by your own credentials: an OpenAI API key, a ChatGPT Codex sign-in, or an OpenRouter account. Quiz Genie AI has no account of its own and never asks you to sign in to Google.
Data handled
- Active-tab context: After the user clicks the Quiz Genie toolbar icon, Chrome temporarily supplies that tab's URL and title so the extension can confirm that it is a supported HTTP(S) page. The capture holds a URL with credentials, query text, and fragments removed, the page title, and the capture time. This context remains temporary and is not used to build a browsing history.
- Page reading: After you choose Generate quiz, Start tutoring this page, or Make flashcards from this page and accept the notice shown in the panel, the extension reads the page you are on. The reading can include its text and layout, content shown to assistive technology, content inside frames from the same site, descriptions of media, one screenshot of the visible area, and images the page has already loaded. Depending on the page, that reading can contain personally identifiable, health, financial and payment, authentication, personal communication, location, or other information you or the site put there. The extension does not sort that information into categories; it handles all of it as part of the page you chose.
- Capture position: The extension reads the current scroll coordinates and listens for a scroll change during capture. It uses them only to confirm that the page structure and visible screenshot belong to the same view. It does not monitor later activity or use the position for analytics, advertising, or profiling.
- Temporary local analysis: To examine the page reading, the AI model may return a short piece of JavaScript. It runs only inside the isolated sandbox declared in the extension's manifest, and only against a fixed copy of that reading. It cannot reach the live page, extension APIs, your credentials, the network, or stored data. The reading, the screenshot, any such code, and the raw request history are discarded when the operation finishes or you cancel it.
- What the panel is holding: The questions, lessons, cards, your answers and ratings, and the supporting quotes and images behind them stay in the panel's memory while you work. Quiz, Tutor, and Flashcards each keep their own and do not pass it to one another. It is cleared when you end that mode, and when the side panel closes or reloads. It is never written to Chrome storage.
- Authentication information: OpenAI API keys and ChatGPT Codex OAuth credentials are stored only in the user's local Chrome profile, and each is sent only to OpenAI. Choosing OpenRouter runs Chrome's web authorization redirect, which asks for no Google account and returns a key issued by the user's own OpenRouter account; that key is stored the same way and sent only to OpenRouter.
- Local preferences and diagnostics: The selected AI connection, prompt preferences, disclosure version, and theme selection are stored in Chrome. The extension also keeps a size-limited diagnostic log in local Chrome storage so that a user can report a problem. It records event names and a fixed list of permitted metadata fields. It never records page content, prompts, model responses, credentials, or request headers, and it never leaves the device.
Chrome Web Store data categories
The Chrome Web Store counts local processing and direct transmission to the selected AI provider as data handling. It also treats a sensitive category as handled when that information appears inside the selected page, screenshot, or learner input. For this reason, the Store disclosure selects all nine available data categories:
- Personally identifiable information: A selected page or screenshot can contain a name, address, email address, username, account number, or other identifier.
- Health information: A selected page or screenshot can contain medical or health information.
- Financial and payment information: A selected page or screenshot can contain transactions, payment details, financial statements, or similar information. Quiz Genie AI itself takes no payment information.
- Authentication information: The extension handles the user's OpenAI API key, ChatGPT Codex credentials, or OpenRouter key. A selected page or screenshot can also contain authentication information.
- Personal communications: A selected page can contain email, chat, or social posts. Tutor also sends the learner's typed messages to the selected provider.
- Location: A selected page or screenshot can contain an address, region, IP address, map, or other location information. The extension does not use a device-location API.
- Web history: The extension handles the selected page URL, title, and capture time for the user-facing learning operation. It does not build or retain a list of visited pages.
- User activity: The extension handles the current scroll position and a scroll-change signal during capture. It does not log clicks, keystrokes, or later browsing activity.
- Website content: The extension handles selected-page text, structure, links, images, media descriptions, and a visible screenshot.
How data is used and shared
When you start a quiz, a tutoring session, or a deck, the extension sends the page reading to the AI provider you chose. A long page is sent in parts, in the order the page presents them. While the model works it may search the text it was given, run temporary JavaScript against it as described above, or look at an image from the page when the picture is needed to answer. Audio and video are never sent; only their descriptions are.
One quiz, session, or deck usually takes several requests. The extension asks the model to write the material, then asks it to check that material against the same page text before you see it, and repeats a step when a check fails. Later requests can also carry exact excerpts from the page, your answers, and the messages you type to the Tutor.
In OpenAI API-key and ChatGPT Codex modes, that content goes directly from the extension to OpenAI. In OpenRouter mode it goes directly from the extension to OpenRouter, which routes the request to the model it serves; OpenRouter's own privacy terms govern its handling, and the request is billed to the user's OpenRouter account.
No Quiz Genie AI server sits in that path. Quiz Genie AI does not receive, proxy, log, or store these requests, the page content inside them, the responses, or the credentials that authorize them.
The selected provider -- OpenAI, or OpenRouter when that connection is
chosen -- processes Quiz, Tutor, and Flashcards requests. Its handling
is governed by its own privacy terms. Requests set
store: false, which prevents later retrieval through the
provider's API but is not a promise of Zero Data Retention; the user's
OpenAI account controls and OpenAI's policies govern its processing.
Data is not sold, used for personalized advertising, or transferred for
unrelated purposes.
Retention and control
Everything Quiz Genie AI keeps is stored on the user's own device. There are no server-side records to retain, because there is no server.
Local data remains until the user removes credentials, clears extension data, or uninstalls the extension. Uninstalling removes all of it. Users can disconnect a connection, remove a saved key, clear what a mode is holding, or uninstall the extension at any time. Content already sent to a provider is governed by that provider's retention policy and controls.
Security and limited use
User data is transmitted over HTTPS. The extension has no persistent access to visited pages; Chrome grants temporary page access only after the user invokes the toolbar action. Direct modes request optional access limited to the OpenAI API, sign-in, and ChatGPT service origins, or the OpenRouter origin, and only when the user selects that connection. Quiz Genie AI's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
Contact
For privacy questions, email huangaustin496@gmail.com.