WordThief 隐私政策 / Privacy Policy

中文

1. 政策摘要

WordThief 是一个本地优先的英语阅读语境采集工具。无需 WordThief 账号即可进行基础采集、保存、查看、发音和导出;完整使用 AI 语境释义、翻译和情景联想功能,需要您配置自己的模型 API Key。飞书同步也需要另行配置并主动开启。

WordThief 维护者不运营用于接收用户词库、阅读内容或 API Key 的服务器,不出售用户数据,不投放个性化广告,也不自动上传诊断或使用行为数据。

只有当您主动配置并使用以下可选能力时,扩展才会把相应数据直接发送给您选择的第三方:

  1. 自备模型服务(BYOK),用于生成语境释义、句子翻译或情景联想;
  2. 您自己的飞书多维表格,用于备份和跨设备同步。

2. WordThief 处理的数据

2.1 阅读与采集数据

当您在网页中主动选中文本并执行采集时,WordThief 会处理并保存在 Chrome 扩展本地存储中的数据可能包括:

扩展需要在网页中运行内容脚本,以便在您选中文本时显示采集按钮并取得所选内容、来源标题和 URL。WordThief 不会为了广告、画像或分析而持续记录浏览历史;未触发采集的普通浏览活动不会被发送给 WordThief 维护者。

2.2 配置与凭据

根据您使用的可选功能,WordThief 可能在 Chrome 扩展本地存储中保存:

这些凭据不会发送给 WordThief 维护者,但会在您主动调用相应服务时直接发送给该服务用于身份验证。凭据保存在本机 Chrome 扩展存储中,当前没有额外的应用层加密;请不要在共享设备上使用不受信任的凭据。

2.3 诊断数据

WordThief 提供用户主动开启的问题诊断功能。诊断可能包含功能步骤、时间、成功/失败状态、错误信息、环境元数据,以及您主动填写的问题描述和预期结果。

3. 数据存储与保留

采集数据、翻译结果、配置、凭据和同步队列默认存储在 chrome.storage.local 中,也就是当前浏览器配置文件的扩展本地存储。

WordThief 当前没有账号体系,因此不会把不同设备上的本地数据自动关联到维护者控制的用户档案。

4. 可选的模型服务(BYOK)

WordThief 不提供、代理或转售模型调用服务。您可以自行添加兼容的模型服务,例如 Gemini、豆包、Kimi、DeepSeek、混元、Ollama 或自定义 OpenAI 兼容接口。

当您首次向某个远程模型主机发送请求时,扩展会在产品界面中显示接收主机、用途和可能发送的数据范围,并要求您明确确认。切换到新的远程主机时需要重新确认。本机回环地址上的模型属于本机处理,不触发远程外发确认。

根据您触发的功能,发送给模型服务的数据可能包括:

WordThief 维护者不会收到这些模型请求。模型提供商如何保留和处理数据由您与该提供商之间的条款和隐私政策决定,请在配置前自行查阅。

5. 可选的飞书同步

飞书同步默认关闭。只有在您自行配置飞书应用、完成连接和权限检测、阅读产品内的数据范围说明并明确启用后,WordThief 才会开始同步或创建定时补同步任务。

为了获取访问令牌和读写您指定的多维表格,App ID、App Secret、App Token、Table ID 和临时访问令牌会直接发送到飞书开放平台接口。同步记录可能包含:

数据存放在您控制或授权的飞书多维表格中。WordThief 维护者不会获得该表格的访问权限,除非您另行主动授权或分享。飞书如何处理数据由飞书的条款、隐私政策和您的组织设置决定。

6. 音标与发音

Chrome Web Store 版本随扩展提供本地音标词典,查询本地词典不需要上传单词。点击发音时使用浏览器或操作系统提供的语音能力;WordThief 不会把发音内容发送到维护者服务器。浏览器或操作系统是否使用在线语音服务取决于您的设备、语音包和平台设置,请参阅相应平台政策。

7. 数据共享、出售与人工访问

除以下情况外,WordThief 不会传输或共享用户数据:

WordThief 不出售用户数据,不将用户数据用于个性化广告、信用评估或数据经纪。维护者不会人工阅读您的阅读内容,除非您为获得支持而明确选择并发送特定内容。

8. 安全措施与限制

9. 您的选择与控制

您可以:

删除本地数据不会自动删除已经发送到模型提供商或飞书的数据。对于第三方持有的数据,请使用该服务提供的删除和管理能力。

10. 儿童隐私

WordThief 不是专门面向儿童设计的服务,维护者不会故意通过本扩展收集儿童的个人身份信息。如果您代表未成年人使用本扩展,请根据所在地法律和第三方服务规则提供必要的监护与同意。

11. 政策更新

功能或数据处理方式发生变化时,本政策会同步更新日期和内容。若变化会引入新的数据处理方式,WordThief 会在商店页面或产品界面中提供相应说明,并在需要时重新取得同意。

12. Chrome Web Store Limited Use 声明

WordThief 对从 Chrome 和相关 API 获得的信息的使用将遵守 Chrome Web Store 用户数据政策,包括 Limited Use 要求。所有用户数据只用于提供或改进已明确披露的单一用途及相关安全、维护和可靠性需要。

13. 联系我们

如对本政策、数据处理或删除方式有疑问,请使用 WordThief 飞书反馈表单 联系我们。请勿提交 API Key、Token、App Secret、完整阅读原文、完整 URL、飞书凭据或未检查的诊断报告。

English

1. Summary

WordThief is a local-first contextual English-reading capture tool. Basic capture, local storage, review, pronunciation, and export do not require a WordThief account. Full AI meanings, translation, and visual-hint features require you to configure your own model API key. Feishu synchronization also requires separate setup and explicit enablement.

The WordThief maintainer does not operate a server that receives users' vocabulary libraries, reading content, or API keys. WordThief does not sell user data, serve personalized advertising, or automatically upload diagnostics or usage analytics.

Data is sent directly to a third party only when you configure and use an optional feature: (a) your chosen model provider for contextual translation or visual hints, or (b) your own Feishu Bitable for backup and cross-device synchronization.

2. Data handled by WordThief

When you actively select and capture content, WordThief may store the following in Chrome extension local storage:

The content script runs on webpages so it can show the capture control and obtain the selected content, page title, and URL after your action. WordThief does not continuously collect browsing history for advertising, profiling, or analytics, and ordinary browsing that does not trigger capture is not sent to the maintainer.

Depending on the optional features you configure, local settings may include model API URLs, model names, API keys, custom authentication headers, Feishu App ID, App Secret, App Token, Table ID, temporary access tokens, preferences, consent records, mappings, and retry queues. These credentials are stored in chrome.storage.local without additional application-layer encryption. They are not sent to the WordThief maintainer.

3. Optional model providers (BYOK)

WordThief does not provide, proxy, or resell model services. You may configure services such as Gemini, Doubao, Kimi, DeepSeek, Hunyuan, Ollama, or a custom OpenAI-compatible endpoint.

Before the first request to a remote model host, WordThief displays the recipient host, purpose, and possible data scope and asks for affirmative consent. A different remote host requires separate consent. Depending on the feature, requests may include selected words, sentences, contextual text, prompts, and credentials required by that provider. Requests go directly from the extension to the provider; the WordThief maintainer does not receive them. The provider's own terms and privacy policy govern its processing and retention.

4. Optional Feishu synchronization

Feishu synchronization is off by default. It starts only after you configure your Feishu app, complete connection and permission checks, review the in-product disclosure, and explicitly enable synchronization.

Credentials are sent directly to Feishu Open Platform to obtain access tokens and access the Bitable you specify. Synchronized records may include local record identifiers, words, sentences, meanings, translations, parts of speech, IPA, visual hints, the source page title and full URL, timestamps, and deletion status. The data is stored in the Feishu Bitable you control or authorize. The WordThief maintainer does not receive access unless you separately grant or share it.

5. Diagnostics, storage, and retention

Diagnostics are off by default, generated locally only after you start and stop a recording, and never uploaded automatically. A report may include feature steps, timestamps, success/failure states, errors, environment metadata, and text you enter. Review it before sharing and do not include API keys, tokens, App Secrets, full reading content, full URLs, Feishu credentials, or other sensitive data.

Local data remains until you delete it, clear extension data, or uninstall the extension. Stopping Feishu synchronization does not delete local data or remote Feishu records. The separate clear-credentials action removes locally stored Feishu credentials and related local synchronization state, but does not delete remote records. You control exported files and their retention.

6. Speech and local IPA

The Chrome Web Store build includes a local IPA lexicon. Pronunciation uses speech capabilities supplied by the browser or operating system; WordThief does not send speech content to a maintainer-operated server. Whether the platform uses an online speech service depends on the device and platform settings.

7. Sharing, security, and your controls

WordThief does not sell user data or use it for personalized advertising, credit assessment, or data brokerage. Data is transferred only as needed for a feature you actively use, as required by law or security needs, or when you export and share it yourself. The maintainer does not read your content unless you explicitly provide specific content for support.

Remote non-loopback endpoints must use HTTPS; local loopback services may use HTTP. Credentials are not included in learning CSV exports. No storage or network system can guarantee absolute security, so protect your device, browser profile, and third-party credentials.

You may use local-only features, export or delete local data, disable Feishu synchronization, clear Feishu credentials and local sync state, modify or remove model configurations, or uninstall WordThief. Deleting local data does not automatically delete data already handled by a model provider or stored in Feishu; use the third party's controls for that data.

8. Children, changes, and Limited Use

WordThief is not directed specifically to children. If you use it on behalf of a minor, provide supervision and consent required by applicable law and third-party service rules.

This policy will be updated when features or data practices change. New data practices will also be disclosed in the store listing or product interface, and fresh consent will be requested when required.

WordThief's use of information received from Chrome and related APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve the clearly disclosed single purpose and related security, maintenance, and reliability needs.

9. Contact

Contact us through the WordThief Feishu feedback form. Do not submit API keys, tokens, App Secrets, full reading content, full URLs, Feishu credentials, or unreviewed diagnostic reports.