Privacy Policy
Last Updated: November 2025
1. Introduction
Hiwrite ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our Chrome browser extension, website, and related services (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Chrome Extension Data Collection
Our Chrome extension requires the following permissions and collects the following data:
- activeTab Permission: We access the active browser tab to enable highlighting functionality on web pages you visit. We only access tab content when you actively use the extension to create highlights.
- Host Permissions (<all_urls>): Our extension can run on all websites to allow you to highlight content on any webpage. We do not access or collect data from websites unless you actively use the highlighting feature.
- Page Content: When you create a highlight, we collect the selected text, the URL of the page where the highlight was created, and any notes or tags you add to the highlight.
- URLs: We collect URLs of web pages where you create highlights to associate highlights with their source pages.
2.2 Account Information
When you create an account, we collect:
- Authentication Data: If you sign in using Google OAuth or Microsoft Azure AD, we collect your name, email address, and profile picture from these providers.
- Account Data: We store your user ID, workspace ID, account status, and account creation/update timestamps.
2.3 User-Generated Content
We collect and store the following content you create:
- Highlights: Text selections, notes, tags, colors, and timestamps associated with your highlights.
- Documents: URLs and metadata of web pages where you create highlights.
- Chat Conversations: Messages you send to our AI assistant ("Thought Buddy") and AI responses.
- User Settings: Your color customization preferences, career information, and other settings.
2.4 Usage and Technical Data
We automatically collect:
- Information about how you interact with our Service (features used, timestamps, usage patterns)
- Subscription and billing information (if you upgrade to a paid plan)
- Cookies and similar tracking technologies for session management and authentication
3. How We Use Your Information
We use the collected information for the following purposes:
- To Provide Our Service: To enable highlighting, store your highlights, and provide AI-powered features like chat assistance.
- To Process Payments: To manage subscriptions, process payments, and handle billing through our payment processor.
- To Improve Our Service: To analyze usage patterns and improve our features and user experience.
- To Communicate: To send you service-related updates, account notifications, and respond to your inquiries.
- To Ensure Security: To protect against fraud, unauthorized access, and other security threats.
4. How We Store Your Information
Your information is stored in the following locations:
- Database (PostgreSQL): User accounts, highlights, notes, chat conversations, settings, and subscription information are stored in our secure database.
- Cloud Storage (S3/MinIO): Files and documents you upload are stored in secure cloud storage.
- Local Browser Storage: Some data may be temporarily stored in your browser's local storage for extension functionality.
All data is encrypted in transit using HTTPS and encrypted at rest using industry-standard encryption methods.
5. Sharing Your Information with Third Parties
We share your information with the following third-party service providers:
5.1 OpenAI
We use OpenAI's services (including GPT models and embeddings) to provide AI-powered features. When you use our AI chat feature, we send your chat messages and relevant highlights to OpenAI to generate responses. OpenAI's use of your data is governed by their privacy policy. We do not use your data to train OpenAI's models unless you explicitly opt-in to such use.
OpenAI Privacy Policy: https://openai.com/privacy
5.2 Stripe
We use Stripe to process payments for premium subscriptions. When you make a payment, we share your email address and billing information with Stripe. Payment card details are processed directly by Stripe and are not stored on our servers.
Stripe Privacy Policy: https://stripe.com/privacy
5.3 Google OAuth / Microsoft Azure AD
If you sign in using Google or Microsoft accounts, we receive your name, email address, and profile picture from these providers. We do not share your data back with Google or Microsoft beyond what is necessary for authentication.
Google Privacy Policy: https://policies.google.com/privacy
Microsoft Privacy Policy: https://privacy.microsoft.com/privacystatement
5.4 Other Sharing
We may also share your information:
- As required by law, court order, or legal process
- To protect our rights, property, or safety, or that of our users
- In connection with a business transfer (merger, acquisition, etc.)
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit (HTTPS/TLS) for all data transmission
- Encryption at rest for stored data
- Secure authentication and access controls
- Regular security audits and updates
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide you with our services. Specifically:
- Account data is retained while your account is active
- Highlights and user content are retained until you delete them or your account is deleted
- We may retain certain information after account deletion as required by law or for legitimate business purposes (e.g., fraud prevention)
You can request deletion of your account and data at any time by contacting us at [email protected]
8. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: You can access your personal information through your account settings or by contacting us
- Correction: You can update your account information and user settings at any time
- Deletion: You can delete individual highlights, notes, or your entire account and all associated data
- Export: You can request a copy of your data in a portable format
- Opt-Out: You can opt-out of marketing communications by unsubscribing from our emails
To exercise these rights, please contact us at [email protected]
9. Children's Privacy
Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at [email protected]
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using our Service, you consent to the transfer of your information to these countries.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Website: https://hiwrite.ai