The short version
Live Subtitles captures audio only from a browser tab you explicitly choose. Your browser sends that audio straight to the speech provider that produces the subtitles, over an encrypted connection, using a short-lived credential we issue for each session. The audio never passes through our servers, and neither do the subtitles — we could not retain them if we wanted to. We do not receive tab titles or the addresses you visit.
An account is required. We keep your sign-in identity, your balance, and a record of when each session ran and how long it lasted — nothing about what was said or what you were watching. Those session records are kept in identifiable form for 365 days after the session ends.
Data we process
| Data | Purpose | Storage |
|---|---|---|
| Account identifier, email, sign-in method, and the name or picture your sign-in provider supplies | Sign you in, operate the account, and keep one free starter allowance per person | Held by our identity and account services until you delete the account, subject to legal needs |
| Active-tab audio | Create subtitles and meter the time used | Sent from your browser directly to the speech provider while a session is active; it never reaches Live Subtitles servers |
| Transcript and translation text | Show live subtitles in your browser | Returned straight to your browser; not stored by us and unable to appear in our logs |
| Session identifier, start, end, time used, and status | Usage history, balance accuracy, and support | 365 days after the session ends |
| Credit grants and deductions, subscription state, and the references our payment provider needs to match a payment to your account | Purchases, balances, refunds, duplicate prevention, disputes, and legal obligations | As long as needed to operate the account and meet financial, fraud, tax, and legal requirements |
| Display preferences and sign-in state | Remember the interface and keep you signed in | Local Chrome extension storage |
Sanitized operational logs may contain timestamps, request IDs, error codes, and coarse service metrics. They must not contain audio, subtitle text, access tokens, payment-card details, tab titles, or URLs visited by the user.
Audio capture and subtitle content
Capture starts only after the user invokes Live Subtitles on the current tab with the toolbar action or keyboard shortcut. It ends when the user stops it, the tab closes or navigates, the available balance is exhausted, or the session terminates. The extension captures tab audio, not the microphone or camera.
A running session sends audio continuously, so silence inside it also uses time. Subtitles follow the tab: when playback stops, the extension stops sending audio and your time stops being used. Subtitle text stays in extension memory for live display only and is discarded when the session stops, the tab closes, or the browser restarts. There is no transcript to export, because none is kept.
Signing in
Sign-in is with Google, which may process authentication information under its own terms and privacy policy. Our service uses a short-lived identity token to tell which account is making a request; those tokens and the per-session subtitle credentials are never placed in URLs or application logs.
Google is the only sign-in method. No web page can pass a credential to the extension, and the extension accepts no messages from web pages at all.
Payments
Stripe provides hosted checkout, subscription management, payment methods, refunds, and the customer billing portal. Payment-card numbers are entered on Stripe-hosted pages and are not received or stored by Live Subtitles. We receive the identifiers and status events needed to associate a purchase with an account and adjust credit.
Service providers and international processing
Live Subtitles is operated with the help of a small number of providers, engaged under contracts that limit them to processing data on our instructions:
- an identity provider for Google sign-in;
- a cloud provider that hosts our service, account records, balances, and session records. It issues the short-lived credential your browser uses, but carries no audio and no subtitle text;
- Stripe for payments, subscriptions, checkout, and the billing portal;
- a speech provider, which receives audio directly from your browser and returns the transcription and translation. For abuse prevention we attach a one-way hash of your account identifier to each session as a stable safety identifier, without your email address or name.
These providers may process information in countries other than your own, under their terms and lawful transfer mechanisms. We will name the current providers on request through Support.
We do not sell personal information or use it for advertising, creditworthiness, or unrelated profiling.
Browser permissions
| Permission or access | Purpose |
|---|---|
| activeTab | Temporarily grants access to the one tab the user invokes |
| tabCapture | Reads audio from that selected tab while subtitles run |
| offscreen | Holds the audio capture outside the extension's suspendable background worker |
| scripting | Injects the subtitle overlay, and the playback watcher that pauses billing when you pause the video, on demand |
| storage | Saves local preferences, sign-in, and session UI state |
| identity | Supports user-initiated Google sign-in |
| alarms | Closes a session that has been left paused |
| Exact Live Subtitles service origins | Connects to the account, usage, billing, sign-in, and subtitle services |
There is no microphone or camera permission, broad <all_urls> host
access, or content script declared to run on every website. Executable extension code
is bundled in the published package.
Retention and account deletion
Identifiable session history is available for 365 days after a session ends. Expired rows are no longer returned while asynchronous storage cleanup completes.
Account deletion removes your sign-in identity and identifiable session history. Payment and ledger records that must be kept for accounting, fraud prevention, disputes, tax, or law may remain in minimized or anonymized form. Uninstalling the extension removes local data but does not by itself delete the cloud account; use the in-product deletion control or contact Support.
Two records deliberately outlive deletion, and neither identifies you. A one-way hash of the deleted account identifier is kept for 30 days, so that payment events still in flight cannot recreate the account. A one-way hash of your sign-in identity is kept for 12 months to record that the free starter allowance has been used, so that deleting and recreating an account does not issue it again; after 12 months a returning user is offered it once more. Neither record carries an email address, a name, or any session data, and neither can be reversed to recover the identity it came from.
Routine encrypted backups of the account database are retained for up to 35 days, so deleted data may persist in backup form for that period before ageing out. Backups are used only to restore the service after a failure.
Contact, children, and policy changes
Live Subtitles is not directed to children below the minimum age required to enter a contract or use the connected services in their country. A parent or guardian should contact us if they believe a child supplied personal information without consent.
Submit privacy and deletion requests through the Support page →. Material changes will be published here with an updated date and, where required, communicated through an appropriate product or account channel.