Highlightly ("we", "our", or "us") operates highlightly.co (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to all users of the web app, Chrome extension, and WhatsApp bot.
Information We Collect
Account Information
When you create an account we collect:
- Email address — used to identify you and send transactional emails (magic-link sign-in, billing alerts).
- Name and profile picture — only if you sign in with Google and Google shares them with us.
We do not collect a password unless you explicitly set one in Settings → Profile.
Browser Extension Identifier
You can use the browser extension without an account. So that we can apply free-tier limits fairly before anyone signs in, the extension generates a random identifier when it is installed and stores it locally in your browser.
- It is a random value (a UUID). It is not derived from your device, browser fingerprint, IP address, or any personal information, and it does not identify you.
- It is sent to our API with each highlight request, alongside the YouTube video URL, so we can count usage against the free daily limit.
- We use it only for quota enforcement and abuse prevention — never for advertising, and we do not sell it or share it with third parties.
- If you later sign in, requests are attributed to your account instead.
- Removing the extension, or clearing its storage from your browser's extension settings, removes the identifier. A fresh one is generated on the next install.
Because this identifier accompanies the video URLs you submit, it forms a record of which videos have been summarised from a given extension install. That record is retained under the same terms as the usage data described below.
Video and Transcript Data
When you submit a YouTube URL:
- We retrieve the video's publicly available captions and run them through our transcription pipeline.
- The transcript is processed in memory by our AI model (Google Gemini) to select highlight segments.
- We cache the resulting highlight timestamps in our database to avoid re-processing the same video for other users. This cache entry contains only the video ID, highlight timestamps, and AI-generated chapter titles — not the full transcript text.
- We do not download the video or its audio, and we do not permanently store transcript text, audio, or video content.
Usage Data
We collect the following automatically to operate and improve the Service:
- Videos you watch (video ID, duration watched, timestamp reached, highlight mode used).
- Feature interactions (mode toggle, transcript downloads, note additions).
- Quota consumption (watches per day, per month).
If you accept cookies (see section 6), we send anonymised event data to PostHog for product analytics. You can opt out at any time via the cookie banner or Settings → Notifications.
Payment Information
Payments are handled by Razorpay. We never receive or store your full card number, CVV, or bank account details. We store only your Razorpay customer ID and subscription status.
WhatsApp Bot
If you use the WhatsApp bot:
- We receive your WhatsApp phone number and the message content you send us (the YouTube URL and any commands).
- We create an anonymous record linked to your number. If you later create a web account with the same number, the records are merged.
- We do not read or store any other messages in your WhatsApp conversation.
How We Use Your Information
We use the information we collect to:
- Provide the Service — process videos, return highlights, store your history and notes.
- Manage your account — authenticate you, send magic-link emails, handle billing.
- Improve the Service — analyse usage patterns to prioritise features and fix bugs.
- Enforce limits — track daily and monthly quota to apply the Free / Pro / Max tier rules.
- Communicate — send billing receipts, product updates (opt-in), and security alerts.
We do not use your data to train AI models, sell it to third parties, or show you advertising.
Data Storage and Retention
- Account data is stored in Supabase (PostgreSQL) hosted on AWS in the United States.
- Highlight cache entries are retained indefinitely unless the video is removed from YouTube, at which point they are purged automatically.
- Watch history and notes are kept until you delete them manually or delete your account.
- Payment records are retained for 7 years as required by applicable tax law (stored by Razorpay, not by us).
- Deleted accounts: when you trigger account deletion via Settings → Data → Delete account, your email, watch history, notes, and collections are permanently purged within 7 calendar days. Aggregate anonymised usage statistics (no personal identifiers) are retained.
Third-Party Services
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database and authentication | supabase.com/privacy |
| Razorpay | Payment processing | razorpay.com/privacy |
| PostHog | Product analytics (opt-in only) | posthog.com/privacy |
| Google Gemini | AI highlight selection | ai.google.dev/terms |
| Groq | Audio transcription | groq.com/privacy |
| Vercel | Web hosting | vercel.com/legal/privacy-policy |
| Twilio / Gupshup | WhatsApp message delivery | Per provider |
We require all sub-processors to maintain appropriate data-protection standards.
Your Rights and Choices
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — delete your account and all associated data via Settings → Data → Delete account.
- Portability — export all your data (watch history, notes, collections) as a ZIP file from Settings → Data → Export.
- Opt-out of analytics — decline the cookie banner or toggle off "Product analytics" in Settings → Notifications.
To exercise any right not covered by self-serve features, email support@highlightly.co for assistance.
EU/EEA users: you may lodge a complaint with your local supervisory authority.
Cookies and Local Storage
We use localStorage (not third-party cookies) to:
- Remember your playback mode preference (
Highlight/Full video). - Resume videos at your last-watched position (
yt_time_<videoId>). - Track whether you have seen the first-skip toast (once per device).
If you accept the cookie banner, we also set a first-party PostHog analytics cookie on highlightly.co to identify your browser session across page loads.
If you decline or are not in a jurisdiction that requires consent, no analytics cookies are set.
Changes to This Policy
We may update this policy as the Service evolves. When we make material changes we will email registered users at least 14 days in advance and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance.
Contact Us
Highlightly Privacy Team
Email: support@highlightly.co
Response time: within 2 business days.