Bỏ qua đến nội dung chính
Tony HoangKết nối

Tony Hoang · KDSPY AI

Privacy Policy

Effective October 11, 2026

This policy applies to the KDSPY AI Chrome extension, published by Tony Hoang, and its account and license services. It explains what information is handled when you sign in and research Amazon books.

1. Information we handle

  • Google account: your email address, display name and Google account identifier, using the openid, email and profile scopes. Google handles your password; the extension does not receive it.
  • Account and license: a session token, signed license, plan, randomly generated device identifier, device label, extension version and account/device activity needed to provide access and enforce license limits.
  • Book research, stored locally: Amazon pages you request, book titles, authors, identifiers, prices, BSR, reviews, covers, estimated sales and revenue, analysis history and settings.
  • Support: information you choose to send when contacting us. Please do not send passwords, session tokens or payment credentials.

2. How information is used

Google account and device information is sent over HTTPS to our account service at api-edu.ainexus.vn to sign you in, issue and check your license, manage devices and provide Free or paid Pro access. Session and license information is also stored in the extension on your device.

Amazon book content and analysis results are processed and stored locally in Chrome. They are not uploaded to our account service. The extension does not collect browsing history from unrelated websites or use advertising or behavioral analytics SDKs.

3. Amazon session and optional integrations

The extension fetches Amazon pages using your own Amazon session. To obtain regional prices, it may set the session’s Deliver to ZIP code, initially 10001. You can change or disable this in Settings. It does not edit your saved Amazon addresses or collect your physical location.

If you enable the Pro MCP integration, the extension communicates with a bridge on your own computer at 127.0.0.1. Your MCP client can request book analyses and receive results. If you use an external AI service through that client, data you choose to share with it is governed by that service’s privacy practices.

Book covers are loaded from Amazon. Opening a book link or using a Google search or Lens action sends the selected URL, query or cover URL to that destination.

4. Sharing and payments

We do not sell personal information or use it for advertising, creditworthiness or lending decisions. Information is shared only as needed to deliver sign-in, hosting, account communications and payments, or to meet legal obligations. Service providers include Google for sign-in, Cloudflare for hosting and SePay for payments on the external checkout page.

Pro purchases take place outside the Chrome Web Store. The extension receives plan and license status; it does not receive your bank password or card credentials. Information you provide on checkout pages is processed by the checkout service and its payment provider.

5. Storage, security and retention

Account-service traffic uses HTTPS. Local extension storage holds account sessions, signed licenses and research history. Protect your Chrome profile and computer, as anyone with access to them may be able to access locally stored information.

Research history remains on your device until you delete it, clear extension data or uninstall the extension. Account and license records are retained to provide the service and handle support; you may request deletion. Transaction records may need to be retained for accounting, fraud prevention or legal obligations. Signing out removes the local sign-in session but does not by itself delete server-side account records.

6. Your choices and deletion requests

You can sign out, manage registered devices, delete analysis history and uninstall the extension. You can also revoke Google access through your Google Account.

To request access, correction or deletion of account information, email hoanghd218@gmail.com and state that your request concerns KDSPY AI. We may ask you to verify account ownership before disclosing or deleting account information. Do not include authentication tokens or passwords.

7. Google API Limited Use

KDSPY AI’s use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Google account information is used only for the user-facing sign-in, account and license features described here. It is not used for advertising. Human access is limited to your consent, necessary security investigations or legal obligations.

8. Changes and contact

Updates will be posted on this page with a revised effective date. Questions and privacy requests can be sent through the KDSPY AI support page.