Privacy Policy

Last updated: September 27, 2026

In short: Eavesdrop has no servers and no accounts. It fetches YouTube comments from YouTube's official API using only the video ID, keeps your settings and saved comments in your own browser, and only talks to Lemon Squeezy if you activate a Pro license.

Eavesdrop is not affiliated with, endorsed by, or sponsored by YouTube, Google, or Lemon Squeezy.

YouTube API Services

Eavesdrop uses YouTube API Services to show comments. By using Eavesdrop you are also using YouTube's services, so the YouTube Terms of Service apply, and Google's handling of those requests is covered by the Google Privacy Policy.

Eavesdrop never accesses your Google or YouTube account: it does not ask you to sign in and does not use OAuth, so there is no account access to revoke. To remove the data Eavesdrop keeps, uninstall the extension (this deletes its settings, license and saved comments), or use “Clear all” in Eavesdrop's Settings to delete your saved comments. The comment cache and the “seen” list live in YouTube's own site storage (see the caveat below): cached comments are never used more than 30 days after they were fetched and are deleted the next time Eavesdrop loads comments after that, and you can remove both right away by clearing your browser's site data for youtube.com.

What Eavesdrop reads

While you are on a YouTube video page, Eavesdrop reads that page's video ID from the URL, then fetches that video's comments from YouTube's own public, official Data API v3 (commentThreads.list / comments.list on googleapis.com) to show them in a floating panel over the video. It does not read anything from any other tab, site, watch history, or Google account activity.

Eavesdrop's script loads on every youtube.com page, not only on video pages, because YouTube switches between pages without a full reload and a script that only loaded on video pages would miss a video you reached from the home page or search. On any page that is not a video (/watch), it does nothing.

What Eavesdrop sends

What Eavesdrop stores, and where

All of the following stays on your own device, or syncs only through Chrome's own built-in sync if you have it turned on for your Chrome profile (Chrome operates that sync, not Eavesdrop):

One technical caveat: to draw the panel inside YouTube's page, Eavesdrop hands your settings, mute words and the IDs of the comments you saved on the current video (never their text, and never those from other videos) to the part of the extension running inside that page, and keeps the comment cache and “seen” list in the page's own browser storage. YouTube's own page scripts could technically read them, the same way they can read anything else shown on that page. Eavesdrop itself never sends them anywhere.

Features that are currently inactive

Eavesdrop's code includes on-device comment translation and an on-device AI comment summary. Both are turned off and neither runs or sends anything today. If they are turned on in the future, they are designed to run entirely on your device through Chrome's built-in AI APIs, and this policy will be updated before that happens.

Eavesdrop is read-only with respect to your YouTube account: it cannot like, dislike, post or change anything on YouTube.

Future changes

A future version may route comment requests through a server we operate, so the YouTube API key is kept server-side. No such server exists today. This policy will be updated before any change like that ships, not after.

Contact

Questions about this policy or how Eavesdrop handles data: fixcelservice@gmail.com.