Privacy Policy
Last updated: August 21, 2026
At Cabina AI ("we", "our", or "us"), we prioritize your privacy. This Privacy Policy explains how our Chrome Extension and Services collect, use, store, share, and safeguard your information. By using Cabina AI, you agree to the practices described in this policy.
1. Data Minimization & BYOK Architecture
Cabina AI is designed around a strict Bring Your Own Key (BYOK) model. We do not process, store, or eavesdrop on your live meeting audio on our servers. Audio captured via browser APIs is streamed directly from your device to your configured AI provider (Google Gemini or OpenAI) using your personal API keys. No audio data passes through or is retained by Cabina AI servers.
2. Information We Collect
We collect only the minimum data necessary to provide and improve our services:
- Account Information: When you log in with Google OAuth, we receive and store your email address, display name, and Google user ID to manage your subscription and identify your account.
- Subscription & Payment Data: We process payment transactions through Lemon Squeezy (our Merchant of Record). We store your subscription status and license key. We do not store or have access to your credit card numbers, bank account details, or other financial information — these are handled entirely by Lemon Squeezy.
- Cloud Transcripts (Optional): If you enable cloud backup, meeting summaries and transcripts are stored on our servers linked to your user account for dashboard history and retrieval.
- User Preferences & Settings: Your configuration preferences (language pair, AI provider selection, UI settings) are stored locally in your browser using the Chrome Storage API.
- API Keys: Your personal AI provider API keys (Google Gemini, OpenAI) are stored locally in your browser's Chrome Storage and are never transmitted to or stored on our servers.
3. How We Use Your Data
We use the data we collect for the following purposes:
- Service Delivery: To authenticate your account, validate your subscription, and provide access to Cabina AI features.
- Subscription Management: To verify license status, manage trial periods, and process renewals through Lemon Squeezy.
- Cloud Transcript Storage: To save and display your meeting transcripts in the Cabina AI dashboard (only if you opt in to cloud backup).
- Product Improvement: Aggregated, anonymized usage data (such as feature usage counts) may be used to improve the product. No personal audio or transcript content is used for this purpose.
- Customer Support: To respond to your inquiries and resolve issues related to your account or subscription.
4. Chrome Extension Permissions
Cabina AI requests only the permissions necessary for its core functionality:
tabCapture: Captures the audio stream of the active Google Meet tab to enable real-time translation. Audio is streamed directly to your configured AI provider and is not sent to Cabina AI servers.offscreen: Creates an offscreen document to process captured audio streams in the background, as required by Chrome's Manifest V3 architecture.storage: Stores your preference settings, local API keys, and session data securely in your browser's local storage.identity: Enables Google OAuth sign-in to authenticate your account and manage your subscription.
Content scripts are injected into Google Meet pages (meet.google.com) to render the translation overlay sidebar. This is declared in the manifest and does not require additional permissions.
5. Data Storage & Security
- Local Storage: API keys, user preferences, and session data are stored locally in your browser using the Chrome Storage API. This data never leaves your device except when API keys are used to authenticate directly with your chosen AI provider.
- Server Storage: Account information (email, display name, user ID) and subscription status are stored on our backend servers hosted on Cloudflare Workers. Cloud transcripts (if enabled) are also stored on our servers.
- Security Measures: We use HTTPS encryption for all data in transit. Server-side data is protected by Cloudflare's infrastructure security. API keys stored locally benefit from Chrome's built-in storage isolation between extensions.
- Audio Data: Live meeting audio is streamed in real-time from your browser directly to your AI provider (Google Gemini or OpenAI). It is not stored, logged, or cached by Cabina AI at any point.
6. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. Your data may be shared with the following third parties only as necessary to provide our services:
- Google Gemini API (Google LLC): If you select Google Gemini as your AI provider, your meeting audio is streamed directly from your browser to Google's Gemini API using your personal API key. This data is subject to Google's API Terms of Service.
- OpenAI API (OpenAI, Inc.): If you select OpenAI as your AI provider, your meeting audio is streamed directly from your browser to OpenAI's API using your personal API key. This data is subject to OpenAI's Terms of Use.
- Lemon Squeezy (Lemon Squeezy, LLC): Processes all payment transactions as our Merchant of Record. They receive payment information you provide during checkout. This data is handled in compliance with PCI-DSS standards and is subject to Lemon Squeezy's Privacy Policy.
- Google OAuth (Google LLC): Used for authentication. Google provides us with your basic profile information (email, name, user ID) when you sign in. Subject to Google's Privacy Policy.
- Cloudflare (Cloudflare, Inc.): Our backend infrastructure provider. Server-side data is processed and stored using Cloudflare Workers. Subject to Cloudflare's Privacy Policy.
We do not share any user data with parties other than those listed above.
7. Data Retention
- Account Data: Your account information is retained for as long as your account is active. Upon account deletion request, your data will be deleted within 30 days.
- Cloud Transcripts: Stored transcripts are retained until you manually delete them from your dashboard or request account deletion.
- Local Data: Preferences and API keys stored in Chrome Storage persist until you uninstall the extension or clear browser data.
- Audio Data: Not retained — audio is streamed in real-time and never stored by Cabina AI.
8. Your Rights
You have the following rights regarding your data:
- Access: You can request a copy of the personal data we hold about you by contacting us.
- Deletion: You can request deletion of your account and all associated data by contacting us at the email below. We will process your request within 30 days.
- Correction: You can request corrections to inaccurate personal data.
- Opt-Out: You can disable cloud transcript backup at any time in the extension settings. You can revoke Google OAuth access from your Google Account settings.
- Data Portability: You can export your transcripts from the Cabina AI dashboard.
9. Children's Privacy
Cabina AI is not intended for use by children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information promptly.
10. International Data Transfers
Your data may be processed in countries other than your own, including the United States, where our infrastructure providers (Cloudflare, Lemon Squeezy) operate. By using Cabina AI, you consent to the transfer and processing of your data in these jurisdictions.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify users through the extension or via email. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of Cabina AI after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at dangvuongquang@gmail.com.