剪藏 / CLIPKEY · 生效日期:2026-08-30
隐私政策
适用于 Chrome 扩展「剪藏」及网页预览。产品没有我们运营的账号服务器,也不把剪藏明文送到我们的机器上。
剪藏的开发者不运营用于存放你剪藏内容的云端。扩展把数据写在你这台电脑上,或在你明确登录后写入你自己的 Google 账号。
本机存储
- 剪藏(标题、网址、正文、压缩截图、模型返回的关键点)存在
chrome.storage.local。 - 你填写的 AI Base URL、模型名、API Key 也存在本机。
- Web 预览使用浏览器
localStorage,行为相同。
卸载扩展或清除站点数据会删除对应的本机副本。
你自己提供的 AI 接口
「提炼关键点」只会把当前这一条的文字、图片,以及(若有视频链接)从 YouTube / B 站 / Vimeo 页面解析出的标题、简介、字幕发到你在设置里填写的 OpenAI 兼容地址。解析视频页面时,扩展会访问对应站点并可能下载官方封面;没有封面时,可能向同一接口的生图地址请求一张配图(会标明「生成图」)。不会把视频文件上传给你的模型。
- 请求头带上你自己的 API Key。
- 我们不会代你调用、也不会保存 Key 到我们的服务器(我们没有这样的服务器)。
- 没有 Key、Key 无效或网络失败时,界面只显示错误,不会编造关键点。
- 对方平台如何处理请求,以该平台的隐私政策为准。
Google 登录与 Drive
- 扩展使用
chrome.identity;网页预览使用 Google Identity Services。 - 申请的作用域是 Drive applicationDataFolder 以及读取邮箱,用来显示「已登录谁」和把剪藏同步到隐藏的应用数据文件夹。
- 同步内容包括剪藏元数据和压缩后的 JPEG。
- 退出登录会先尝试把本机剪藏同步到 Drive 应用数据。成功后可以选择只清除本机登录态(默认,剪藏留在这台电脑),或同时删除本机剪藏和截图。设置与 API Key 会保留。无论哪种选择,都不会删除 Google 里的应用数据。同步失败时不会清空本机剪藏。
- 未配置 OAuth 客户端时,登录按钮仍可点击,但只会提示「缺 OAuth 配置」,不会伪造登录状态。
网页访问
保存选区、保存本页、截取当前屏幕时,扩展只会在你主动点按钮后读取当前标签。截图时侧栏保持打开。只有你在截图菜单里明确选择「整页」时,才会按溢出方向滚动页面并拼接多张可见区域截图(有宽高上限)。不会注入常驻内容脚本。
调用你填写的模型地址时,可能向该主机发起网络请求;首次使用可能弹出可选的网站访问权限。
我们不做的事
- 不建立邮箱/密码账号体系
- 不把剪藏或 API Key 上传到剪藏自己的服务器
- 不出售数据
- 不做跨站广告追踪
离线备份
你可以导出 zip(JSON + 图片)并在另一台设备导入。导出文件在你选定的位置,由你保管。
联系
问题或隐私相关请求请发邮件至 ybl20200126@gmail.com。
CLIPKEY · Effective August 30, 2026
Privacy Policy
This policy applies to the CLIPKEY Chrome extension and its web preview. We do not operate an account server, and CLIPKEY does not send your clips in plain text to a server owned by us.
CLIPKEY stores data on your device or, only after you explicitly sign in, in the app data area of your own Google account. The developer does not operate a cloud service that stores your clips.
Local storage
- Clips—including titles, URLs, text, compressed screenshots, and model-generated key points—are stored in
chrome.storage.local. - Your AI base URL, model name, and API key are also stored locally.
- The web preview uses browser
localStoragewith equivalent behavior.
Uninstalling the extension or clearing its site data removes the corresponding local copy.
Your AI endpoint
“Extract key points” sends only the current clip's text and images to the OpenAI-compatible endpoint you configure. For YouTube, Bilibili, or Vimeo links, CLIPKEY may first read the page title, description, available transcript, and official thumbnail. It does not upload the video file. If no thumbnail is available, it may request a clearly labeled generated image from the same configured endpoint.
- Requests include the API key that you provide.
- We neither call the service on your behalf nor store your key on our servers; we do not operate such a server.
- If a key is missing or invalid, or the network fails, CLIPKEY displays an error and does not fabricate key points.
- The provider's own privacy policy governs how it handles your request.
Google sign-in and Drive
- The extension uses
chrome.identity; the web preview uses Google Identity Services. - Requested scopes cover Drive's applicationDataFolder and your email address, used to show the signed-in account and sync clips to its hidden app data folder.
- Synced content includes clip metadata and compressed JPEG images.
- Signing out first attempts to sync local clips. You can then keep local clips (the default) or delete local clips and screenshots. Settings and the API key remain. Neither choice deletes Google app data, and a failed sync never clears local clips.
- If OAuth is not configured, CLIPKEY reports the missing configuration and never simulates a signed-in state.
Page access
CLIPKEY reads the current tab only after you explicitly save a selection or page, or request a screenshot. Full-page capture scrolls and stitches visible regions only when you choose “Full page,” with size limits. CLIPKEY does not inject a persistent content script.
The first request to your configured model host may trigger an optional site-access permission prompt.
What we do not do
- No email/password account system
- No upload of clips or API keys to a CLIPKEY-owned server
- No sale of data
- No cross-site advertising tracking
Offline backup
You can export a zip archive containing JSON and images, then import it on another device. You choose and control the exported file's location.
Contact
For questions or privacy requests, email ybl20200126@gmail.com.