Privacy Policy
Last updated: September 27, 2026
In short: Eavesdrop has no servers and no accounts. It fetches YouTube comments from YouTube's official API using only the video ID, keeps your settings and saved comments in your own browser, and only talks to Lemon Squeezy if you activate a Pro license.
Eavesdrop is not affiliated with, endorsed by, or sponsored by YouTube, Google, or Lemon Squeezy.
YouTube API Services
Eavesdrop uses YouTube API Services to show comments. By using Eavesdrop you are also using YouTube's services, so the YouTube Terms of Service apply, and Google's handling of those requests is covered by the Google Privacy Policy.
Eavesdrop never accesses your Google or YouTube account: it does not ask you to sign in and does not use OAuth,
so there is no account access to revoke. To remove the data Eavesdrop keeps, uninstall the extension (this
deletes its settings, license and saved comments), or use “Clear all” in Eavesdrop's Settings to delete your
saved comments. The comment cache and the “seen” list live in YouTube's own site storage (see the caveat
below): cached comments are never used more than 30 days after they were fetched and are deleted the next time
Eavesdrop loads comments after that, and you can remove both right away by clearing your browser's site data for youtube.com.
What Eavesdrop reads
While you are on a YouTube video page, Eavesdrop reads that page's video ID from the URL, then fetches that
video's comments from YouTube's own public, official Data API v3
(commentThreads.list / comments.list on googleapis.com) to show them in a
floating panel over the video. It does not read anything from any other tab, site, watch history, or Google
account activity.
Eavesdrop's script loads on every youtube.com page, not only on video pages, because YouTube
switches between pages without a full reload and a script that only loaded on video pages would miss a video
you reached from the home page or search. On any page that is not a video (/watch), it does
nothing.
What Eavesdrop sends
-
To Google's YouTube Data API v3: requests for pages of comments and replies, sent to
googleapis.comusing an API key that belongs to Eavesdrop (not to you). That key identifies the application to Google for quota and abuse-prevention purposes; it is the same fixed value for every installation and is not derived from anything about you. Nothing is added to these requests beyond the video ID (to fetch that video's comments) and, when you expand a thread's replies, that comment's ID. - To Lemon Squeezy, only if you activate a Pro license: when you paste a license key in Settings and click “Activate”, Eavesdrop sends that key (plus a randomly generated, anonymous label for this browser install — not your name, email, or any account identifier) to Lemon Squeezy's license API to confirm the purchase. While Pro is active, Eavesdrop re-checks that same key at most once a day (only the key itself), so a refunded or revoked license stops unlocking Pro. If you never activate a license, Eavesdrop never contacts Lemon Squeezy.
- Nowhere else. Eavesdrop does not operate its own server, so there is nowhere else for data to go. Comment text is never sent anywhere beyond the request that fetched it.
What Eavesdrop stores, and where
All of the following stays on your own device, or syncs only through Chrome's own built-in sync if you have it turned on for your Chrome profile (Chrome operates that sync, not Eavesdrop):
- Your plan (Free or Pro) and, if you activated one, your Pro license key, so it can be shown back to you and re-validated. Chrome sync storage.
- Comments you saved — author, text, like count, the video's title, a link back to the comment, and any note or tags you add in Settings, only for comments you explicitly saved. Exporting them (Markdown, CSV or JSON) or sharing one as an image creates a file or clipboard image on your device; nothing is uploaded. Chrome local storage, capped at 200 saved comments.
- Your settings: language, appearance, auto-scroll speed, which panel features are on, and any mute words you typed. Chrome sync storage. Mute words are matched against comment text entirely on your device.
- A session-only log of the last 20 network requests (just the host and request type, e.g. “www.googleapis.com · commentThreads.list” — never content, comment text, or the API key). Cleared when the browser closes; it exists so you can verify from Settings that nothing unexpected happens.
- A few small device-local values: the panel's position, size and open/closed state, which comment IDs you've already seen per video (for “new since your last visit”), whether you've seen the first-use tips, and a local cache of recently viewed videos' comments so they load instantly (never used, and deleted, once 30 days have passed since they were fetched). None of this leaves your browser.
One technical caveat: to draw the panel inside YouTube's page, Eavesdrop hands your settings, mute words and the IDs of the comments you saved on the current video (never their text, and never those from other videos) to the part of the extension running inside that page, and keeps the comment cache and “seen” list in the page's own browser storage. YouTube's own page scripts could technically read them, the same way they can read anything else shown on that page. Eavesdrop itself never sends them anywhere.
Features that are currently inactive
Eavesdrop's code includes on-device comment translation and an on-device AI comment summary. Both are turned off and neither runs or sends anything today. If they are turned on in the future, they are designed to run entirely on your device through Chrome's built-in AI APIs, and this policy will be updated before that happens.
Eavesdrop is read-only with respect to your YouTube account: it cannot like, dislike, post or change anything on YouTube.
Future changes
A future version may route comment requests through a server we operate, so the YouTube API key is kept server-side. No such server exists today. This policy will be updated before any change like that ships, not after.
Contact
Questions about this policy or how Eavesdrop handles data: fixcelservice@gmail.com.