Product-specific privacy policy

Video Downloader & Stream Saver

Controller: ReForge Extensions
Chrome Web Store item ID: fncpbnalnkcndchoifjnikcoiominaho
Effective date: August 9, 2026 · Last updated: August 9, 2026

This policy explains what Video Downloader & Stream Saver processes, where that data is kept, when it is transmitted, and who receives it. It applies to the Chrome Web Store version of this extension.

Summary

  • When enabled, the extension detects compatible media on HTTP and HTTPS pages in browser tabs. It keeps discovered candidates, active tasks, and optional history primarily in Chrome storage on the device.
  • Media bytes are fetched from the source website or CDN and are processed in the browser before being saved through Chrome Downloads. They are not uploaded to ReForge or Alibaba Cloud as part of the download workflow.
  • The extension contacts ReForge for product configuration and sends installation, user-action, and optional review-feedback events to Alibaba Cloud Log Service. Those events do not include page URLs, media URLs, filenames, media bytes, or cookie values.
  • The current product configuration does not require an account. The bundled SDK also contains account and subscription functions for a future enabled version; their data handling is described below so this policy remains complete and specific.

Data the extension processes

The extension needs broad host access because compatible direct media, HLS playlists, DASH manifests, and CDNs cannot be listed in advance. It processes the following categories only to discover, display, preview, and save compatible media or to operate the extension service.

Data and source Purpose, location, and recipients
Page and media context
Active page and frame URLs, hostname, page title, favicon, media URLs, media type, duration, dimensions, size, poster or preview URL, playlist or manifest text, and media-response metadata.
Used to find and group media choices for the relevant tab. Candidate data is held in Chrome session storage for the current tab and is removed when the tab navigates or closes, or when the browser session ends. This category is not sent to ReForge or Alibaba Cloud. When a user requests a preview or download, the relevant URL is sent to the original website or CDN that hosts the media.
Media content and download output
Selected media files, stream segments, subtitle files, audio tracks, and temporary browser-side processing output.
Used to fulfill a user-requested preview, conversion, recording, or download. Stream assembly and FFmpeg WebAssembly processing run in browser memory or an offscreen extension document. Completed files are saved by Chrome to the user-selected Downloads location. ReForge and Alibaba Cloud do not receive these media bytes.
Cookies and functional request headers
A source website may require its existing browser session when media is fetched. The extension can process Cookie, Referer, Origin, Authorization, Accept, Content-Type, or custom X- headers from an observed media request. The special-site scanner can also use the current page's YouTube cookie string and visitor data when a server-controlled YouTube capability is explicitly enabled.
Used only to replay the source site's required request context to the same source site or CDN for a user-requested preview or download. The extension does not request the Chrome cookies permission or call the Chrome Cookies API. Cookie values are not written to extension local, session, or sync storage and are not sent to ReForge or Alibaba Cloud. Other functional headers can be retained in Chrome session storage for the current candidate or task; an in-memory replay cache is pruned after about 10 minutes. Temporary request-header rules are removed after a task finishes, fails, or is cancelled.
Preferences and site rules
Language, appearance, preview behavior, download folder, filename template, history settings, notification and context-menu choices, quality and concurrency preferences, and user-created hostname rules.
Used to remember how the extension should work. These settings are stored in Chrome Sync storage, so Chrome may synchronize them to the user's signed-in Chrome profile under Google's terms and settings. They remain until changed, reset, removed with the extension, or otherwise removed by Chrome Sync.
Local task, history, and statistics data
Task status, progress, speed, errors, selected file name, source and media URLs, page title, site, media facts, download IDs, completion time, aggregate success or failure counts, and review-prompt state.
Used to show active work, retry tasks, organize downloads, and offer an optional local history. Active tasks use Chrome session storage. History is stored locally only when enabled, retains 30 days by default, can be set from 1 to 365 days, is limited to 100 items, and can be cleared from the extension. The user can export that local history to a file. This data is not sent to ReForge or Alibaba Cloud.
Product configuration and operational events
Product ID, extension version, a random installation UUID, install time, browser family, operating-system family, language, event time, event name, and limited action attributes such as format, media kind, boolean setting changes, review count, or star rating. A voluntary low-rating reason can contain information the user types into it.
ReForge receives product-configuration requests through api.reforgeextensions.com. The extension sends the listed operational events to the ReForge Alibaba Cloud Log Service project. This supports configuration delivery, reliability analysis, product operations, and review prompts. Network services also necessarily receive standard connection information such as IP address and HTTP metadata. Automatic scanning, media discovery, progress updates, and history writes do not create custom operational events.
Account and subscription data if enabled in a future version
Email address, password or one-time email code, device ID, login token, account and subscription status, selected plan, and checkout or portal session details.
These functions are currently hidden because this product is configured as not requiring payment. If enabled and used, the extension sends the relevant data to ReForge to authenticate an account, provide a subscription, or open account management. Passwords are not written to extension storage. Card payment data is entered on Stripe-hosted checkout pages, not collected by this extension. When a signed-in account exists, its email and plan status can also be attached to an operational event for account support and subscription operations.

How data is collected and used

When the extension is enabled, its content scripts and media-request listeners inspect supported HTTP and HTTPS pages, including frames and media requests, to identify direct files and supported streams. The extension reads limited page elements, metadata, player responses, and network metadata that identify media. It does not use the Chrome browsing-history API, Chrome Cookies API, clipboard access, or form-field APIs.

We use the information described above to provide the requested extension functions, maintain settings and local history, keep downloads working with source-site request requirements, deliver product configuration, prevent duplicate tasks, troubleshoot reliability issues, and operate the optional account, subscription, and review features. We do not use extension user data for personalized advertising, retargeting, creditworthiness, or data-broker purposes.

The extension is not designed to collect passwords entered into websites, form values, private messages, unrelated browsing history, or payment card numbers. It does not sell media data, browser activity data, or account data.

Permissions and host access

  • storage: stores settings, enabled state, temporary task and candidate records, optional local history, statistics, and SDK state.
  • downloads: creates user-selected downloads, checks download status, opens completed files or their folder when requested, and exports local history.
  • webRequest: observes request URLs, response metadata, and functional headers so compatible media can be detected and source-site download requirements can be preserved.
  • declarativeNetRequest: installs temporary session-only request-header rules for a selected preview or download and removes them at task completion, failure, or cancellation.
  • offscreen: allows long-running browser-side stream fetching, AES-128 stream handling, and local FFmpeg WebAssembly processing outside the popup.
  • tabs: associates candidates with the correct page, reads the active tab's URL, title, and favicon, and supports returning to the source tab.
  • sidePanel, contextMenus, and notifications: provide the optional long-task interface, explicit right-click actions, and an optional completion notification. Notifications can include the completed filename.
  • Host access: <all_urls> is used because media and CDN hosts cannot be known in advance. The extension also has explicit access to the ReForge product API and Alibaba Cloud log endpoint. Host access is not used to sell browsing data or to run advertising.

Sharing and service providers

  • Source websites and CDNs: receive the relevant media and request-context data when the browser plays, previews, or downloads a source selected by the user. Their own privacy policies apply to those requests.
  • Google Chrome: provides extension storage, Sync storage when enabled in the user's Chrome profile, downloads, notifications, tab APIs, and Chrome Web Store review destinations.
  • ReForge product API: provides encrypted product configuration and, only if activated and used, account and subscription services.
  • Alibaba Cloud Log Service: receives the operational event categories described in this policy on behalf of ReForge.
  • Stripe: if a future paid version is activated and the user opens checkout, Stripe processes payment information on its hosted payment pages under its own privacy policy.

We share user data only with these service providers as needed to provide the extension, when the user directs a media request to a source website, to comply with law, or to protect the service. We do not rent, sell, or otherwise provide user data to data brokers or advertisers.

Retention, deletion, and user controls

  • Extension data: settings, history, and local SDK state can be removed by clearing the relevant extension data or uninstalling the extension. Active tab and task data uses Chrome session storage and ends with the browser session; the extension also removes tab records on navigation or tab close.
  • History: users can disable local history, choose its retention period, delete individual entries, clear all entries, or export a copy from Options.
  • Permissions: users can disable the extension or change site access in Chrome's extension settings. Logging cannot be separately disabled in the current version; removing the extension stops future extension events.
  • Service-side records: ReForge retains product API and operational-log records only for the period needed to operate, secure, and troubleshoot the service. Account and subscription records, if activated, may be retained while active and afterward as required for fraud prevention, tax, accounting, or legal obligations. Service-side retention settings are not controlled by the extension code; contact us to request the current applicable retention information or deletion review.

Security and Chrome Web Store Limited Use

The extension uses HTTPS for ReForge and Alibaba Cloud service requests. It keeps media processing in the browser and uses Chrome storage boundaries for extension state. No Internet transmission or device storage method is entirely risk-free, and source websites control the security of their own services.

We use Chrome extension user data only to provide or improve the user-facing functionality described in this policy. We do not transfer that data to others except as necessary to provide the service, comply with applicable law, or protect against security or fraud risks. We do not use it for personalized ads, credit decisions, insurance decisions, employment decisions, or data brokerage.

Children, changes, and contact

Video Downloader & Stream Saver is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided personal information through an enabled account or feedback feature, contact us so we can review and delete it where appropriate.

We may update this policy when the extension's permissions, processing, or service providers change. The updated version will be posted at this URL with a revised effective date before a materially changed version is submitted for review or released.

For privacy questions, requests to access or delete service-side data, or this policy, contact [email protected]. Please include the extension name and the email address used for any account or support request, if applicable.