Highlightly
/Privacy Policy
PrivacyTerms

Privacy Policy

Last updated: 2026-09-07

Plain-English Summary

We use your email only to create your account. We process YouTube transcripts temporarily on our servers to generate highlights — we do not store video content. We never sell your data. Your account data lives in Supabase (hosted in the US). Payments go through Razorpay (we never see your card number). Our browser extension generates a random per-install identifier so we can apply free-tier limits before you sign in. You can delete your account and all your data at any time from Settings.

Highlightly ("we", "our", or "us") operates highlightly.co (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to all users of the web app, Chrome extension, and WhatsApp bot.

Information We Collect

Account Information

When you create an account we collect:

  • Email address — used to identify you and send transactional emails (magic-link sign-in, billing alerts).
  • Name and profile picture — only if you sign in with Google and Google shares them with us.

We do not collect a password unless you explicitly set one in Settings → Profile.

Browser Extension Identifier

You can use the browser extension without an account. So that we can apply free-tier limits fairly before anyone signs in, the extension generates a random identifier when it is installed and stores it locally in your browser.

  • It is a random value (a UUID). It is not derived from your device, browser fingerprint, IP address, or any personal information, and it does not identify you.
  • It is sent to our API with each highlight request, alongside the YouTube video URL, so we can count usage against the free daily limit.
  • We use it only for quota enforcement and abuse prevention — never for advertising, and we do not sell it or share it with third parties.
  • If you later sign in, requests are attributed to your account instead.
  • Removing the extension, or clearing its storage from your browser's extension settings, removes the identifier. A fresh one is generated on the next install.

Because this identifier accompanies the video URLs you submit, it forms a record of which videos have been summarised from a given extension install. That record is retained under the same terms as the usage data described below.

Video and Transcript Data

When you submit a YouTube URL:

  • We retrieve the video's publicly available captions and run them through our transcription pipeline.
  • The transcript is processed in memory by our AI model (Google Gemini) to select highlight segments.
  • We cache the resulting highlight timestamps in our database to avoid re-processing the same video for other users. This cache entry contains only the video ID, highlight timestamps, and AI-generated chapter titles — not the full transcript text.
  • We do not download the video or its audio, and we do not permanently store transcript text, audio, or video content.

Usage Data

We collect the following automatically to operate and improve the Service:

  • Videos you watch (video ID, duration watched, timestamp reached, highlight mode used).
  • Feature interactions (mode toggle, transcript downloads, note additions).
  • Quota consumption (watches per day, per month).

If you accept cookies (see section 6), we send anonymised event data to PostHog for product analytics. You can opt out at any time via the cookie banner or Settings → Notifications.

Payment Information

Payments are handled by Razorpay. We never receive or store your full card number, CVV, or bank account details. We store only your Razorpay customer ID and subscription status.

WhatsApp Bot

If you use the WhatsApp bot:

  • We receive your WhatsApp phone number and the message content you send us (the YouTube URL and any commands).
  • We create an anonymous record linked to your number. If you later create a web account with the same number, the records are merged.
  • We do not read or store any other messages in your WhatsApp conversation.

How We Use Your Information

We use the information we collect to:

  • Provide the Service — process videos, return highlights, store your history and notes.
  • Manage your account — authenticate you, send magic-link emails, handle billing.
  • Improve the Service — analyse usage patterns to prioritise features and fix bugs.
  • Enforce limits — track daily and monthly quota to apply the Free / Pro / Max tier rules.
  • Communicate — send billing receipts, product updates (opt-in), and security alerts.

We do not use your data to train AI models, sell it to third parties, or show you advertising.

Data Storage and Retention

  • Account data is stored in Supabase (PostgreSQL) hosted on AWS in the United States.
  • Highlight cache entries are retained indefinitely unless the video is removed from YouTube, at which point they are purged automatically.
  • Watch history and notes are kept until you delete them manually or delete your account.
  • Payment records are retained for 7 years as required by applicable tax law (stored by Razorpay, not by us).
  • Deleted accounts: when you trigger account deletion via Settings → Data → Delete account, your email, watch history, notes, and collections are permanently purged within 7 calendar days. Aggregate anonymised usage statistics (no personal identifiers) are retained.

Third-Party Services

ServicePurposePrivacy policy
SupabaseDatabase and authenticationsupabase.com/privacy
RazorpayPayment processingrazorpay.com/privacy
PostHogProduct analytics (opt-in only)posthog.com/privacy
Google GeminiAI highlight selectionai.google.dev/terms
GroqAudio transcriptiongroq.com/privacy
VercelWeb hostingvercel.com/legal/privacy-policy
Twilio / GupshupWhatsApp message deliveryPer provider

We require all sub-processors to maintain appropriate data-protection standards.

Your Rights and Choices

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate data.
  • Deletion — delete your account and all associated data via Settings → Data → Delete account.
  • Portability — export all your data (watch history, notes, collections) as a ZIP file from Settings → Data → Export.
  • Opt-out of analytics — decline the cookie banner or toggle off "Product analytics" in Settings → Notifications.

To exercise any right not covered by self-serve features, email support@highlightly.co for assistance.

EU/EEA users: you may lodge a complaint with your local supervisory authority.

Cookies and Local Storage

We use localStorage (not third-party cookies) to:

  • Remember your playback mode preference (Highlight / Full video).
  • Resume videos at your last-watched position (yt_time_<videoId>).
  • Track whether you have seen the first-skip toast (once per device).

If you accept the cookie banner, we also set a first-party PostHog analytics cookie on highlightly.co to identify your browser session across page loads.

If you decline or are not in a jurisdiction that requires consent, no analytics cookies are set.

Changes to This Policy

We may update this policy as the Service evolves. When we make material changes we will email registered users at least 14 days in advance and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance.

Contact Us

Highlightly Privacy Team

Email: support@highlightly.co

Response time: within 2 business days.