Legal
Privacy Policy
Last updated: September 6, 2026
What We Collect
When you use Summario, we collect the following:
- •YouTube video URLs you choose to summarize
- •Your account email (if you create an account)
- •Usage counts — how many summaries, chats, and digests you've used
- •Notes you write on videos in your library
- •Channel subscriptions you set up for daily digests
Chrome Extension
The Summario Chrome extension is a client-side companion to the Summario web app. This section describes the extension's specific data handling.
Permissions we use and why
- Storage: saves your preferences (theme, UI language, chat history for the open video) locally in your browser.
- Alarms: runs a periodic sync to refresh account state and a keep-alive alarm during long AI operations.
- Cookies: detects sign-in/sign-out events on app.summario.net so your auth state stays in sync. Used only for app.summario.net.
- Scripting: re-injects the Summario widget on YouTube after extension updates, so you don't need to hard-refresh.
- Active Tab: reads the current tab's URL only when you click the Summario popup, to identify the open YouTube video.
- Identity: enables “Sign in with Google” via the Chrome identity API. Used only when you click the sign-in button.
Data we access on YouTube
When you use Summario on a YouTube watch page, we access the currently-open video's URL, title, and transcript. We do not access or collect your browsing history, data from other tabs, or activity on any site other than youtube.com. We do not track your viewing behavior across YouTube videos.
How AI processing works
Your video content (transcript, title, and any questions you ask in chat) is processed by third-party AI services to generate summaries, takeaways, and chat responses. These AI providers are contractually bound not to retain or train on your data. We use multiple AI providers for redundancy and performance.
Local vs. server storage
Preferences (theme, language, chat history for the current video) are stored in chrome.storage.local on your device and never leave your browser. Your account information, subscription status, and saved video summaries are stored on our servers.
Cookie sync
The extension uses the cookies permission solely to detect when you log in or log out on app.summario.net. This keeps your authentication state in sync between the web app and the extension. We do not read cookies from any other site.
Deletion rights
You can delete your account at any time from the Settings page at app.summario.net/settings under Account → Danger Zone. Deletion is scheduled for 30 days after you confirm — during that grace period you can cancel any time by signing back in, and we'll send a confirmation email when you request deletion. After 30 days the account row and every record linked to it are permanently removed. Uninstalling the extension removes all local data immediately.
YouTube trademark
Summario is an independent product and is not affiliated with, endorsed by, or sponsored by YouTube or Google LLC. YouTube™ is a trademark of Google LLC. We access publicly visible YouTube page content via your browser; we do not use YouTube's Data API v3 for the summarization feature.
Highlights export (Notion & Obsidian)
Pro users can save text selections from YouTube videos as “highlights” and export them to Notion or Obsidian.
- Notion: when you connect Notion, you authorize Summario to write to a workspace you choose. Your Notion access token is stored on our servers and used only to push highlights you explicitly export. We do not read content from your Notion workspace outside of the pages we create. You can revoke access at any time from your Notion settings.
- Obsidian: uses a local URI scheme (obsidian://) to open your local Obsidian app with the highlight content. No data is sent to a third-party server; the URI is generated locally and opened in your browser.
Both export destinations are optional. If you do not connect Notion and do not use the Obsidian shortcut, no highlight data leaves Summario's servers.
What We Don't Store
- ✓Full video transcripts — these are processed to generate your summary, then deleted
- ✓Payment details — handled entirely by Stripe. We never see your card number.
- ✓Your YouTube watch history — we only know about videos you explicitly choose to summarize
Google User Data
Part of what Summario handles comes from your Google Account, through Google's own APIs. This section sets out exactly what we receive, what we do with it, and who it is shared, transferred or disclosed to.
What we receive from Google
- •Sign in with Google — your name, email address and profile picture. Used to create your Summario account, sign you in, and send you the digests and service emails you ask for.
- •Connecting YouTube (optional) — Summario requests Google's read-only YouTube permission. Read-only by definition: we cannot change, upload or delete anything in your YouTube account. Of everything that permission makes available, we read one thing — the list of channels you subscribe to — so we can offer those channels for import and follow them for you. We do not read your watch history, likes, comments, playlists or private videos, and no other part of your YouTube account is used by any Summario feature.
Who we share, transfer or disclose it to
Your YouTube subscription list is never sold, rented, traded, or shared with advertisers. It is not sent to our AI providers. It is not sent to any advertising or analytics platform, including Google Ads, Google Analytics and Meta, and it is never used to build advertising audiences or to profile you. The only parties that ever hold it are the ones named in the next paragraph, all acting on our instructions.
The only parties that hold it besides you and us are the infrastructure providers that host our servers and database. They process it solely to operate Summario on our behalf, under contract, and may not use it for their own purposes. We also send it back to Google's own APIs when you ask us to act on it. Beyond that, we disclose it only where the law compels us to, and we will tell you unless we are legally forbidden from doing so.
Your account email address is used separately, for advertising measurement — in an irreversibly hashed form, and only where you have consented. That is whichever address your account was created with, which for a Sign in with Google account is the address Google supplied. It is the only thing we receive from Google that is ever used this way: nothing read under the YouTube permission — your subscribed channel list included — is used for advertising, at any time, in any form. See Cookies below, which describes what is shared, with whom, and how to withdraw it.
Your name and profile picture are used only inside Summario — to show whose account is signed in, and to address the emails we send you. They are stored in our database and returned only to your own signed-in Summario sessions. Beyond you and us, they are held only by the infrastructure providers that run our servers, database and mail delivery on our behalf, under contract and on our instructions. They are never sold, never shared with advertisers or analytics platforms, and never sent to our AI providers: the advertising measurement described above carries a hashed email address and technical identifiers such as your IP address — never your name, and never your picture. What we store for the picture is the link Google supplies rather than a copy of the image, so it loads from Google's own servers when the app displays it.
Limited Use
Summario's use of data obtained under Google's read-only YouTube permission adheres to the Google API Services User Data Policy, including the Limited Use requirements. That data — your subscribed channel list — is used only to provide and improve the features you asked for, and never for advertising, audience building or profiling. We do not use any data obtained from Google's APIs to develop, improve or train generalised artificial intelligence or machine learning models.
Withdrawing access
You can revoke Summario's access to your Google Account at any time from your Google Account permissions page. Deleting your Summario account removes the stored access tokens and the channel list imported from YouTube, on the schedule described under Data Retention.
How We Protect Your Data
Sensitive data — the credentials that let Summario read your YouTube data, and the content of your account with us — is protected by the following measures:
- ✓Encrypted in transit — every connection between your browser, the Summario extension, our servers and Google is encrypted with TLS. We serve no part of Summario over an unencrypted connection.
- ✓YouTube access tokens encrypted at rest — the credentials that let Summario read your YouTube subscription list are encrypted with AES-256-GCM before they are written to our database. The production service refuses to start without its encryption key, so those tokens cannot be stored unencrypted.
- ✓Tokens never leave the server — they are never sent to your browser, to the Summario extension, or to any third party other than Google itself.
- ✓Least privilege — we request read-only access, only the narrowest scope the feature needs, and only at the moment you choose to connect YouTube.
- ✓Restricted human access — production systems and the database can be reached only by the small number of authorised team members who operate the service, and only for that purpose.
- ✓Encrypted backups — database backups are encrypted and kept for 30 days, then overwritten.
- ✓Payment details never reach us — card data is handled entirely by Stripe, a PCI-DSS compliant processor. We never see or store card numbers.
No system is perfectly secure, and we will not pretend otherwise. If you believe you have found a security problem in Summario, email us at [email protected] and we will look at it promptly.
Data Retention
We keep your data only for as long as you have an active Summario account, plus a short grace period after deletion to let you change your mind. Specific retention windows:
- •Account profile, summaries, highlights, chat history, and integrations — retained while your account is active. When you delete your account, every linked record is scheduled for permanent deletion 30 days later.
- •Usage logs (token counts, cost, request timestamps) — retained while your account is active for billing, abuse prevention, and product analytics. After account deletion these rows lose their user reference and are no longer linkable to you; aggregated rows may be kept indefinitely for service-wide reporting.
- •Transcripts — public YouTube captions cached at the video level, not the user level. Not deleted with your account because they are not personal data.
- •Backups — encrypted database backups are kept for 30 days. Data removed from the live database persists in backups for up to that window before being overwritten.
Deleting Your Account
You can delete your Summario account at any time:
- Sign in to app.summario.net.
- Open Settings → Account.
- Scroll to Danger Zone and click Delete account.
- Confirm with your password (or, if you signed in with Google or a magic link, by typing your email exactly).
After you confirm, your account enters a 30-day grace period:
- •All active sessions are revoked across web and mobile.
- •If you have a Pro subscription, it is scheduled to end at your current billing period — no further charges will be made.
- •A confirmation email is sent so you have a written record.
- •You can cancel any time during these 30 days by signing back in — Settings will show a banner with a “Cancel deletion” button.
After 30 days, our retention job permanently deletes your user record and every record linked to it (settings, subscriptions, summaries, highlights, notes, integrations, chat sessions and messages, digests, WhatsApp verifications, refresh tokens, API tokens, and sync logs). This deletion is irreversible — we cannot recover your data after the grace period ends.
Third-Party Services
Summario uses the following third-party services:
- •Stripe — payment processing. Subject to Stripe's privacy policy.
- •Twilio — WhatsApp digest delivery
- •Hosting and infrastructure providers — servers, database and content delivery
- •Third-party AI service providers — AI processing for summaries and chat. Transcripts are processed and not retained.
- •Google Analytics 4 & Google Tag Manager — website traffic and advertising-conversion analytics. To measure which ads and campaigns lead to installs and sign-ups, we send conversion events to Google both from your browser and from our servers. Subject to Google's privacy policy.
- •Meta (Facebook) — advertising measurement via the Meta Pixel and the Meta Conversions API. To measure which ads lead to installs, sign-ups and subscriptions, we share conversion events with Meta both from your browser and from our servers, including a hashed (irreversible) form of your email address and your IP address. Subject to Meta's privacy policy.
Cookies
We show a cookie consent banner and ask your permission before loading advertising or analytics cookies from third parties (such as Google Analytics via Google Tag Manager, or the Meta Pixel), and before sharing any data with advertising partners. Essential cookies (needed to keep you logged in) are always active.
Separately, if you arrive from an ad or a shared link, that link may carry campaign identifiers — for example a click ID or campaign name — which let us tell which campaign brought you to us. Where consent is required, we hold those identifiers only in your browser's memory while the banner is open: none of them are stored until you choose. If you accept, we save them in a first-party cookie for up to 90 days; if you decline, they are discarded, and any that were saved earlier are deleted. Where consent is not legally required, they are saved on arrival. The cookie is set by us and read only by us, and its contents are notshared with Meta, Google or anyone else unless you consent to advertising cookies. You can remove it at any time by clearing this site's data in your browser.
We share advertising and analytics data — including a hashed (irreversible) form of your email address and your IP address — with Meta and Google only after you have given consent. In regions where consent is not legally required, advertising and analytics are enabled by default and no banner is shown. If you are in one of those regions and would prefer we did not track you, use your browser's tracking protection or an ad blocker, or email us at [email protected] and we will delete what we hold about you. Where consent isrequired, you can withdraw it by clearing this site's data, which brings the banner back.
Your Rights
You can:
- •Request a copy of all data we hold on you
- •Request deletion of your account and all associated data
- •Export your notes and summaries at any time from the web app
Email us at [email protected] to exercise any of these rights.
GDPR (EU Users)
If you're an EU resident, you have the right to access, correct, and delete your personal data under GDPR. You can delete your account yourself from Settings → Account → Danger Zone at app.summario.net/settings; for data access (Art. 15) or correction (Art. 16) requests, email us at [email protected]and we'll respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority. EU residents can find their national DPA via the European Data Protection Board's directory at edpb.europa.eu/about-edpb/about-edpb/members_en.
Contact
Privacy questions, concerns, or requests: [email protected]
Summario is a service operated by Coinis DMCC. Coinis DMCC is the data controller responsible for your personal data.