Product-Specific Privacy Notice
Vimeo Downloader - HD Video & Audio Save
Effective Date: April 15, 2026 | Last Updated: April 15, 2026
This notice supplements the main ReForge Extensions privacy policy and applies specifically to the browser extension Vimeo Downloader - HD Video & Audio Save.
Plain-Language Summary
- The extension stores settings, download history, counters, and encrypted login state locally in your browser using Chrome storage APIs.
- When you use the extension on Vimeo, it may access the current page URL, Vimeo player configuration data, media playlist data, and related metadata needed to detect and process downloadable media.
- If you create or use a paid account, we process account and subscription data such as email address, password, device ID, device fingerprint, auth token, plan, and subscription expiry.
- Payment card details are processed by Stripe. We do not store full payment card numbers in the extension or our own browser storage.
- Any data transmitted to our servers or service providers is encrypted via HTTPS/TLS.
- We do not sell, trade, or rent user personal information to others. The data is not used for credit-worthiness or for any lending purposes.
We do not sell, trade, or rent user personal information to others. The data is not used for credit-worthiness or for any lending purposes.
We do not use the data collected by this extension for advertising, data brokerage, or independent commercial resale.
1. Scope
This product-specific notice applies to the extension Vimeo Downloader - HD Video & Audio Save, its extension interface, its related support materials, and the related service endpoints used to provide login, subscription, payment, automatic login, configuration, and download support for this product.
The main policy at /privacy.html still applies unless this product-specific notice is more specific.
2. Data We Collect and Why
2.1 Local Extension Settings and History
- The extension may store settings and local records such as language preference, download directory, file naming settings, auto-split thresholds, download history, download count, install time, and local identifiers in Chrome storage APIs such as chrome.storage.local and related browser storage.
- This data is used to remember your preferences, support download features, maintain local history, and improve continuity between sessions.
2.2 Vimeo Page and Media Data Needed to Perform the Requested Feature
- When you use the extension on Vimeo, the extension may access the current page URL, Vimeo player configuration responses, video title, thumbnail, duration, selected quality, media playlist URLs, segment URLs, and similar page or media metadata.
- This data is used only to identify downloadable media, prepare the requested download, support audio/video merging or splitting, and populate local download history for the action you initiated.
2.3 Account, Authentication, and Subscription Data
- If you log in or subscribe, we may process your email address, password, device ID, device fingerprint, encrypted auth token, encrypted cached user data, plan type, subscription status, subscription expiry, and device authorization records.
- This data is used to authenticate you, verify subscription status, enforce device limits, restore login state, and enable paid features.
2.4 Payment and Billing Data
- If you start checkout or manage a subscription, we may process your email address, selected plan, device ID, Stripe checkout session ID, Stripe customer ID, Stripe subscription ID, and related billing status metadata.
- Stripe processes payment card information directly. We do not store full payment card numbers in the extension's local storage or in our own application storage.
2.5 Analytics, Operational Logging, and Troubleshooting Data
- The extension may send operational and analytics events including extension version, browser type, operating system, interface language, random local UUID, install time, download count, paid status, event category, event action, event tag, and the current active tab URL at the time of interaction.
- Related backend services may also log data such as email address, device ID, session ID, customer ID, subscription ID, login results, token verification results, request metadata, and error details for security, fraud prevention, operations, and troubleshooting.
2.6 Email and Support Communications
- If you receive transactional emails or contact support, we may process your email address, message content, attachments, and delivery metadata.
- For new paid accounts, a welcome email may contain your account credentials or related account setup information.
2.7 Data We Do Not Collect by Default
- We do not intentionally collect passwords from unrelated websites, payment card numbers from websites, private messages, or keystrokes from unrelated sites through this extension.
- We do not use extension data for credit-worthiness decisions, lending, data brokerage, or unrelated advertising.
3. Storage Location and Retention
3.1 Local Browser Storage
- Settings, download history, counters, encrypted login data, device identifiers, and similar extension state are stored locally in your browser using Chrome storage APIs.
- This local data is generally retained until you change it, log out, clear browser storage, or uninstall the extension. Local download history is also limited by the maximum history setting configured in the extension.
3.2 Temporary Processing Data
- Vimeo page data, playlist data, and media-processing data may be held temporarily in browser memory or temporary processing contexts while the requested action is being performed.
- This temporary processing data is intended to be discarded after the requested action or session ends, except to the extent that selected details are saved into local history or logs described in this notice.
3.3 Auth Tokens and Cached Account State
- The extension stores auth tokens and cached user data in encrypted local storage. JWT tokens are configured to expire after 7 days.
- Locally cached auth state remains until it expires, is replaced, you log out, you clear browser storage, or you uninstall the extension.
3.4 Server-Side Account and Subscription Records
- Account and subscription records stored in Cloudflare Workers KV may include email address, password hash, device records, subscription details, account creation time, and update history.
- We retain this account data as long as needed to provide the service, support account access, manage subscriptions, resolve disputes, comply with law, or until the account is deleted or operational cleanup occurs.
3.5 Short-Lived Tokens and Event Records
- Auto-login records are configured for up to 10 minutes.
- Processing locks are configured for about 60 seconds.
- Processed payment-session markers are configured for up to 24 hours.
- Login event records in Cloudflare KV are configured for up to 30 days.
- Signup event records in Cloudflare KV are configured for up to 1 year.
3.6 Provider Logs, Security Logs, and Analytics Logs
- Website and API request logs handled by Cloudflare may be retained for up to 30 days unless a longer period is reasonably necessary for abuse investigation, incident response, or legal compliance.
- Operational and analytics logs sent to Aliyun SLS or comparable observability systems are retained according to the retention settings configured for those providers and our operational needs.
3.7 Transmission Security
- Any data transmitted to our servers or service providers is encrypted via HTTPS/TLS.
4. Third-Party Service Providers
4.1 Cloudflare
- Purpose: API hosting, website delivery, DNS, TLS termination, caching, request handling, and security.
- Data involved: request metadata, account records in KV, login and event records, short-lived auto-login records, and related operational data.
4.2 Stripe
- Purpose: subscription checkout and billing management.
- Data involved: email address, selected plan, Stripe customer and subscription identifiers, payment status, and billing session metadata.
- Payment card details are processed by Stripe under Stripe's own privacy and security controls.
4.3 Resend or Comparable Email Providers
- Purpose: transactional email delivery such as welcome emails and credential or account notices.
- Data involved: recipient email address, message content, and delivery metadata.
4.4 Aliyun SLS
- Purpose: product analytics, operational monitoring, troubleshooting, and error investigation.
- Data involved: extension usage events, device or account-related metadata, current active tab URL at the time of logged actions, and backend operational logs.
4.5 Feishu or Comparable Internal Notification Providers
- Purpose: internal payment, incident, and operational notifications.
- Data involved: limited operational fields such as email address, plan, device ID, and error context when alerts are generated.
5. Sharing of Data
- We share data only with service providers and infrastructure providers needed to deliver the extension, process payments, send emails, maintain security, and support operations.
- We may disclose information when required by law or when reasonably necessary to protect rights, safety, security, or prevent abuse and fraud.
- We may transfer information as part of a merger, acquisition, financing, or sale of assets, subject to applicable law.
- Other than the limited cases listed in this notice, we do not share extension data with outside parties for their independent advertising or marketing purposes.
6. No Sale of Data and Limited Use
We do not sell, trade, or rent user personal information to others. The data is not used for credit-worthiness or for any lending purposes.
We do not license, rent, or provide extension data to data brokers, ad networks, or other third parties for their own commercial use.
We do not use data collected by this extension for unrelated advertising, data brokerage, or independent commercial profiling.
7. Permissions and Why They Are Used
- storage: to save settings, history, counters, and encrypted local auth state.
- downloads: to save media files requested by the user.
- tabs and webNavigation: to identify the active page, coordinate downloads, and support user-initiated actions.
- notifications: to display status messages such as successful login or similar product events.
- <all_urls> host access: to detect relevant Vimeo page/media data, support content scripts, and handle user-requested extension features.
8. Your Choices
- You can stop using the extension at any time by disabling or uninstalling it.
- You can remove locally stored extension data by clearing browser storage, logging out, deleting local history, or uninstalling the extension.
- You can decide whether to create a paid account or enter payment information through Stripe.
- You can contact us to request privacy or support assistance.
9. Contact
Questions, support requests, or privacy requests can be sent to [email protected].
Main privacy policy: /privacy.html