K-Echo 隐私政策
K-Echo 的单一用途是在 YouTube、Bilibili(B站)和 Douyin(抖音)视频页提供韩语字幕、双语逐句复读和学习笔记。本政策适用于 K-Echo Chrome 扩展、K-Echo 会员服务以及用户主动安装的 Windows 本地助手。
1. 我们处理的数据
- 邮箱和账号标识:用于注册、登录、邮箱验证、密码重置和显示账号状态。
- 密码、验证码和会话令牌:用于身份验证和账号安全。密码和会话令牌不会写入宿主视频页面、URL 或公开日志。
- 当前视频页和视频标识:包括受支持站点、当前页面 URL、视频 ID 和 B站分 P 标识,用于读取正确字幕、建立缓存键并避免串用其他视频数据。
- 字幕、翻译和临时音频段:用于显示或生成字幕、逐句复读、翻译和语音识别。识别完成后,共享服务端字幕缓存可能保存完整字幕分段和词级内容、语言、视频时长、语音服务商、模型和分段策略等元数据,但不保存原始音视频。
- 复读、收藏、学习痕迹和设置:用于提供学习记录和偏好,主要保存在浏览器本地。
- 学习笔记和 AI 对话:用于保存用户笔记,以及响应用户主动请求的翻译、解释或总结。
- 技术与安全信息:必要的请求时间、错误和安全审计信息,用于运行服务、防滥用、排错和保障账号安全。
- 设备与网络安全摘要:扩展生成的安装标识在服务端以带密钥的 HMAC-SHA-256 保存为安装标识摘要;请求 IP 在应用风控字段中先归一化为 IPv4 /24 或 IPv6 /64 网段,再以 HMAC-SHA-256 保存为 IP 网段摘要。它们用于会话安全、请求限速、防止重复领取免费额度和防滥用。
2. 数据的使用位置和保留
实时同传路径:浏览器免费同传路径不向 K-Echo 会员同传网关发送麦克风音频,由浏览器提供的语音识别和翻译能力处理;浏览器或其服务提供方可能依其自身政策处理数据。只有用户选择“自动”并明确同意云端音频处理后,K-Echo 才会启用会员路径:麦克风音频以临时 PCM 流发送到 K-Echo 会员同传网关,再转发给阿里云百炼的 Qwen 实时同传模型,用于生成韩语字幕和中文译文。K-Echo 网关不长期保存原始音频,也不把同传音频写入共享字幕缓存。
浏览器本地的字幕缓存、收藏、复读记录、学习笔记和设置会保留到用户删除相应内容、清除扩展数据或卸载扩展。账号和会员数据在账号有效期间及履行安全、争议处理或法律义务所必需的期间内保留。临时音频段只用于用户主动发起的字幕任务,并在上传确认、取消、退出、任务结束或卸载时按处理位置清理;临时对象存储的生命周期规则只作为异常兜底。
共享服务端字幕缓存用于让同一视频的后续字幕任务复用已经完成的识别结果。它保存视频身份摘要、语言、时长、完整字幕分段和词级内容以及语音服务商、模型、配置和分段策略元数据,目前没有自动过期或用户自助删除机制。清除扩展数据或卸载扩展不会删除该服务端缓存;用户可以通过联系邮箱提供视频信息并申请删除。
安装标识摘要会随会话、安全风险事件和免费额度防重复记录保存;IP 网段摘要会随安全风险事件保存。会话和风险事件带有到期时间,但免费额度账务或必要安全记录可能为防止重复领取、处理争议和履行安全义务继续保留摘要;并非所有此类记录目前都有自动物理删除机制。应用风控字段不保存原始安装标识或完整 IP,基础设施必要的访问日志仍按安全运营需要处理。
3. 数据共享和处理商
K-Echo 只在完成用户主动请求的功能时向必要处理商发送最少数据。可能使用的处理商包括:阿里云(托管、对象存储、邮件、人机验证以及启用时的通义千问 AI/ASR)、火山引擎/豆包(启用时的 ASR 或 AI)、腾讯云(启用时的 ASR)、讯飞(启用时的 ASR 或 AI),以及 DeepSeek、OpenAI 和 Google Gemini(仅在会员服务实际启用相应 AI 或 ASR 路径时处理必要内容)。YouTube、Bilibili 和 Douyin 是用户主动访问的视频来源站点。
会员同传由 K-Echo 后端及阿里云百炼处理实时音频、韩语识别结果和中文译文。运行日志只记录连接 ID、响应 ID、错误码、token 数、点数和延时等必要元数据,不记录字幕或译文正文、原始 PCM/base64、Bearer 令牌、一次性票据或 API Key。
K-Echo 不出售用户数据,不把数据提供给广告商,不用于个性化广告、无关的跨站跟踪、信用评估或与韩语字幕学习无关的分析。
4. 安全
跨公网传输使用 HTTPS。本地助手只监听本机回环地址并通过 Chrome Native Messaging 与扩展通信。我们限制凭据暴露,并仅允许完成用户可见功能所必需的访问。
5. 用户选择、账号和数据删除
用户可以在扩展中删除本地收藏和学习内容、清除扩展存储或卸载扩展。上述操作不会自动删除共享服务端字幕缓存或账号安全、账务记录。账号和数据删除、访问或更正申请可发送至下方公开联系邮箱;申请删除共享字幕缓存时请提供相应视频信息。处理请求前,我们可能要求验证账号或请求所有权。
6. 儿童隐私
K-Echo 面向一般韩语学习者,不以儿童为目标,也不会有意收集与产品学习功能无关的儿童个人数据。
7. 政策更新
当产品的数据处理发生实质变化时,我们会更新本页面和最后更新日期,并在需要时通过产品界面提供显著说明。
8. Chrome Web Store 有限使用承诺
K-Echo 对 Chrome 用户数据的使用仅限于提供或改进本政策所述、用户可见的韩语字幕学习功能,并遵守 Chrome Web Store 用户数据政策的 Limited Use 要求。
9. 联系我们
隐私咨询、账号和数据删除申请:gguaiTH@163.com
K-Echo Privacy Policy
K-Echo has one purpose: Korean subtitle replay and learning notes on YouTube, Bilibili, and Douyin video pages. This policy applies to the K-Echo Chrome extension, K-Echo member services, and the Windows Local Helper installed only at the user's request.
1. Data we handle
- Email and account identifiers: used for registration, sign-in, email verification, password reset, and account status.
- Passwords, verification codes, and session tokens: used for authentication and account security. Passwords and session tokens are not written into the host video page, URLs, or public logs.
- Current video page and video identifiers: including the supported site, current page URL, video ID, and Bilibili part identifier, used to load the correct subtitles, build cache keys, and prevent data from another video being reused.
- Subtitles, translations, and temporary audio segments: used to display or generate subtitles, replay sentences, translate text, and perform speech recognition. After recognition, a shared server subtitle cache may retain complete subtitle segments and word-level content, language, video duration, speech provider, model, and segmentation-policy metadata, but it does not retain original audio or video.
- Replay, favorites, learning activity, and settings: used for learning history and preferences and stored mainly in the browser.
- Learning notes and AI conversations: used to save notes and answer user-requested translation, explanation, or summarization.
- Technical and security information: necessary request timing, error, and security audit information used to operate the service, prevent abuse, troubleshoot, and protect accounts.
- Device and network security digests: the extension-generated installation identifier is stored by the server as a keyed HMAC-SHA-256 installation identifier digest. For application risk controls, an IP address is first reduced to an IPv4 /24 or IPv6 /64 prefix and then stored as an HMAC-SHA-256 IP-prefix digest. These digests support session security, rate limiting, duplicate-free-credit prevention, and abuse prevention.
2. Storage and retention
Live-translation paths: the free browser live-translation path does not send microphone audio to the K-Echo member live-translation gateway and instead uses speech-recognition and translation capabilities provided by the browser; the browser or its service provider may process data under its own policy. Only after the user selects Automatic and explicitly consents to cloud audio processing does K-Echo enable the member path: transient PCM audio is sent to the K-Echo member live-translation gateway and forwarded to Alibaba Cloud Model Studio's Qwen real-time translation model to produce Korean subtitles and Chinese translations. The K-Echo gateway does not retain the raw audio long term or add it to the shared subtitle cache.
Browser-local subtitle caches, favorites, replay history, notes, and settings remain until the user deletes them, clears extension data, or uninstalls the extension. Account and member data is retained while the account is active and as needed for security, dispute handling, or legal obligations. Temporary audio segments are used only for user-initiated subtitle jobs and are cleared at the relevant processing location after upload confirmation, cancellation, exit, job completion, or uninstall; object-storage lifecycle rules are an exceptional fallback.
The shared server subtitle cache lets later subtitle jobs for the same video reuse a completed recognition result. It stores a video-identity digest, language, duration, complete subtitle segments and word-level content, and speech-provider, model, configuration, and segmentation-policy metadata. It currently has no automatic expiry or user self-service deletion. Clearing extension data or uninstalling the extension does not delete this server cache; users may contact us with the video information to request removal.
The installation identifier digest is retained with session, security-risk, and duplicate-free-credit records; the IP-prefix digest is retained with security-risk records. Sessions and risk events carry expiry timestamps, while free-credit accounting or necessary security records may continue to retain digests to prevent duplicate grants, resolve disputes, and meet security obligations. Not all such records currently have automatic physical deletion. Application risk-control fields do not store the raw installation identifier or full IP address; necessary infrastructure access logs are handled for security operations.
3. Sharing and processors
K-Echo sends the minimum necessary data to a processor only when needed for a user-requested feature. Possible processors are Alibaba Cloud for hosting, object storage, email, CAPTCHA, and enabled Qwen AI/ASR; Volcengine/Doubao for enabled ASR or AI; Tencent Cloud for enabled ASR; iFlytek for enabled ASR or AI; and DeepSeek, OpenAI, or Google Gemini only when the corresponding member AI or ASR path is enabled. YouTube, Bilibili, and Douyin are video source sites visited by the user.
Member live translation is processed by the K-Echo backend and Alibaba Cloud Model Studio using transient audio, Korean recognition results, and Chinese translations. Operational logs contain only necessary metadata such as connection IDs, response IDs, error codes, token counts, credits, and latency. They do not record subtitle or translation text, raw PCM/base64, Bearer tokens, one-time tickets, or API keys.
We do not sell user data, provide it to advertisers, use it for personalized advertising, unrelated cross-site tracking, credit assessment, or analytics unrelated to Korean subtitle learning.
4. Security
Data sent over public networks uses HTTPS. The Local Helper listens only on the local loopback interface and communicates with the extension through Chrome Native Messaging. We limit credential exposure and access data only as needed for user-visible features.
5. User choices and Account and data deletion
Users can delete local favorites and learning content, clear extension storage, or uninstall the extension. These actions do not automatically delete the shared server subtitle cache or account-security and accounting records. Requests to access, correct, or delete an account and its data can be sent to the public contact address below; a shared-cache removal request should identify the relevant video. We may verify account or request ownership before completing a request.
6. Children's privacy
K-Echo is a general Korean-learning product, is not directed to children, and does not knowingly collect children's personal data unrelated to its learning features.
7. Policy changes
If product data practices materially change, we will update this page and its last-updated date and provide prominent in-product notice when required.
8. Chrome Web Store Limited Use
K-Echo uses Chrome user data only to provide or improve the user-visible Korean subtitle learning features described in this policy and complies with the Limited Use requirements of the Chrome Web Store User Data Policy.
9. Contact
Privacy, account, and data deletion requests: gguaiTH@163.com