Legal

Privacy Policy

Last updated: August 31, 2026

Overview

Curxor (hereinafter "we") is a browser extension and related services that helps developers extract context from webpage elements and hand it to AI for processing. This policy explains how we collect, use, share, and protect your information.

By using our services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.

Information We Collect

Account information: when you sign in with GitHub, Google, or Gitee, we receive the email address, display name, and avatar within the authorized scope. We do not store your third-party account password, and we never post anything to your account.

Payment information: the order number, payment amount, and payment channel generated at the time of subscription. We do not store complete payment credentials; payments are processed directly by third-party payment providers.

Local processing (not collected): element selection, source-code parsing, and context assembly all happen on your device. Selected elements and source code are never uploaded to our servers. Information is only sent to the AI service you have authorized when you actively hand the context to that AI tool, in accordance with your configuration.

Device and sessions: browser type, IP address, and sign-in session records (session tokens are stored as salted hashes), used for security auditing and troubleshooting.

How We Use Information

Provide core services: authenticate your session, sync plan benefits and prompt templates, and enable the extension's local features. Element context extraction, multi-selection, batch description, and AI collaboration are all performed on your device and are never uploaded to our servers (see "Local processing (not collected)").

Process subscriptions, payments, refunds, and the delivery of plan benefits.

Detect abnormal logins, fraudulent activity, and activity that violates our Terms of Service, and keep the platform secure.

Information Sharing and Third Parties

AI services: context for the elements you select is sent, according to your configuration, to the AI service you authorize (such as the model or IDE you connect). We do not use your context to train our models; how the AI service you choose processes your context is governed by that service's privacy policy and terms of use.

Payment providers: order and refund information is shared with third-party payment providers to complete transactions.

OAuth providers: when you choose to sign in with GitHub, Google, or Gitee, we only receive information within the authorized scope (such as your email and display name), and we never post anything to your account.

We do not sell your personal information. Except in the circumstances described above or as required by law, we do not share your data with third parties.

Data Security

Passwords and session tokens are stored as irreversible hashes, and we cannot see your plaintext password or tokens.

Our service backend employs multiple layers of security protection: network isolation, authentication, runtime boundaries, data encryption, and audit logs.

Despite the reasonable security measures we take, no method of transmission over the Internet can guarantee 100% security.

Cookie and Local Storage

We use local storage and Cookie (retained for up to 30 days) to maintain your signed-in state and to save preferences (such as the collapsed state of the sidebar and default prompt templates).

We do not use third-party advertising Cookie or tracking pixels.

Data Retention

Account information is retained while you use our services. After your account is deleted, we will remove or anonymize your personal data within 30 days, except where retention is required by law.

Payment and audit records are retained for a longer period in accordance with financial and compliance requirements (typically no less than 5 years), and are no longer linked to your identity.

Your Rights

You can export a copy of your data, update your information, unlink GitHub / Google / Gitee OAuth authorization, or delete your account from the settings page; after deletion, your personal data will be removed or anonymized.

If you need assistance, please contact us through the contact details below.

Minors

Our services are intended for adults and are not directed at minors. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such data, please contact us to have it removed.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through announcements on our website or by email; if a change involves a new purpose or method of data processing, we will seek your consent separately. Continuing to use the services after such changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have any questions about privacy, please email us at [email protected], and we will respond within a reasonable period.