本页同时发布中英文两版,内容一致;如有歧义以中文版为准。
Published in both Chinese and English; in case of ambiguity, the Chinese version prevails.
本扩展对用户数据的处理符合 Chrome Web Store 用户数据政策(Chrome Web Store User Data Policy)中的 Limited Use 要求:
本扩展没有服务器、没有账号体系、没有任何统计或遥测。开发者不接收、不存储、无法访问你的任何数据。你的课程、笔记、截图、字幕与转写文本全部保存在你自己的电脑上。
唯一会离开你设备的数据,是你在设置里自行填写并授权的大模型端点——只有当你主动点击生成时才发送,接收方是你自己指定的服务。
以下数据全部存储在浏览器为扩展分配的本地数据库(IndexedDB,库名 kedaibiao)中,扩展卸载时由浏览器一并清除:
| 数据 | 内容 | 存放位置与用途 |
|---|---|---|
| 课程 | 课程标题、平台标识、页面地址 | 本地数据库;用于把笔记归到同一门课 |
| 笔记 | 你输入的文字、时间戳、收藏标记 | 本地数据库;截图笔记携带截图引用 |
| 截图 | 你主动截取的视频画面(含标注后的图片) | 本地数据库;以图片数据形式保存 |
| 字幕 | 从课程页取得的字幕文本 | 仅在你的浏览器内使用(检索、跟随高亮、点击回跳),不写入数据库、不上传 |
| 转写 | 本地语音识别生成的带时间戳文本 | 本地数据库;供检索、回跳、生成章节与导出 |
| 章节 | 由规则或 AI 生成的大纲与摘要 | 本地数据库 |
| 设置 | 快捷键、主题、语言、截图质量、导出偏好、AI 端点配置(含 API Token) | 本地数据库;Token 仅存本机(见第 7 节) |
另有少量临时状态:
browser.storage.session:只存活于本次浏览器会话的界面状态(例如「刚截图后应聚焦哪条笔记」),关闭浏览器即消失;localStorage 条目:记录本地转写的标点恢复开关;kedaibiao-asr)中,可在设置页删除。以上数据都不会上传到任何开发者控制的服务器,也没有云同步(扩展不使用 storage.sync)。
| 权限 | 用途 |
|---|---|
activeTab | 在你点击图标/右键菜单/快捷键后,对当前这一个标签页执行截图、读取视频与字幕信息、注入页面脚本。未主动操作过的页面无法访问。 |
scripting | 同上,向已授权标签页按需注入扩展自带的内容脚本(支撑「任意含 HTML5 video 的网页」通用模式),不做批量注入。 |
tabs | 识别当前课程、在已打开的标签页之间定位并切换课程页、监听标签切换与地址变化以更新侧栏上下文。不读取浏览历史。 |
tabCapture | 课程拿不到视频直链时,捕获当前标签页正在播放的音频用于本地语音识别。音频仅在本机实时识别,不保存、不上传,且仍正常回放给你(不会被静音)。 |
offscreen | 提供不随侧栏关闭而终止的本地转写运行环境。 |
sidePanel | 扩展主界面(与视频并排显示);不打开时不显示任何内容。 |
storage | 保存上述临时界面状态。 |
contextMenus | 提供一个右键菜单项,用于在页面上激活扩展。 |
declarativeNetRequestWithHostAccess | 仅为智慧树(zhihuishu.com)代取本页课程已加载的字幕/视频数据补上 Referer 头,规则限定只作用于扩展自身发出的请求(tabIds: [-1]),不影响页面与其他网站。 |
主机权限:
*://*.zhihuishu.com/*(必需):仅用于智慧树平台的字幕与视频源接口代取(该接口校验 Referer 且无 CORS 头)。<all_urls>(可选,默认不授予):仅在下面两种由你主动点击触发的场景下申请,不触发则不授予:
内容脚本运行的站点:bilibili.com(视频页)、icourse163.org、xuetangx.com、youtube.com(watch 页)、zhihuishu.com。在部分平台,扩展会在页面自身的运行环境中接管该页面的 fetch / XMLHttpRequest,只读取与字幕地址匹配的响应内容(即该页面自己已经请求过的字幕),用于生成字幕时间轴;不修改页面数据、不改变页面行为、不影响页面与其他站点的任何请求。
.onnx 权重与 tokens.txt 词表)在首次使用时从 Hugging Face 官方源(huggingface.co,不可达时回退镜像 hf-mirror.com)下载并缓存于本机。下载的是纯数据文件,不含任何可执行代码;下载过程只发生一次,之后完全离线可用,下载源不会因此获得你的课程或笔记内容。tabCapture 捕获当前标签页正在播放的音频,同样只在本机实时识别,不保存、不上传。baseUrl)、模型名与密钥(apiToken)并保存。Authorization 请求头随上述请求发往你自己填写的地址,不会发送给开发者或任何其他方。websiteContent 同意;Chrome / Edge 无此机制,仅在你保存配置时由浏览器弹出该域名的访问授权提示。不填写地址、未获授权时,扩展不会发起任何此类请求。http://,则该次传输的安全性由你选择的服务决定,建议使用 HTTPS。eval、new Function 或任何动态引入远程脚本的写法;CSP 仅额外允许 'wasm-unsafe-eval',用于编译包内的 .wasm。运行期唯一的下载是识别模型的数据文件,不含可执行逻辑。本扩展是面向网课学习者的通用笔记工具,不面向儿童设计,也不会有意收集儿童的个人信息(事实上不收集任何人的个人信息)。
若本政策发生实质性变更(例如新增需要外传数据的功能),我们会在本页面更新并修改顶部「最近更新」日期;涉及数据外传的新功能,会在扩展内以显式授权的方式征得你的同意后才会启用。
对本政策或数据处理方式有疑问,请联系:xxj@xzynet.com
This extension handles user data in compliance with the Chrome Web Store User Data Policy, including the Limited Use requirements:
This extension has no server, no accounts and no analytics or telemetry. The developer never receives, stores or has access to any of your data. Your courses, notes, screenshots, subtitles and transcripts stay on your own computer.
The only data that can leave your device is what you send to an AI endpoint that you configure and authorise yourself — and only when you explicitly click to generate. The recipient is the service you chose.
Everything below is stored in the browser's local extension database (IndexedDB, database name kedaibiao) and is removed by the browser when you uninstall the extension:
| Data | Contents | Where it lives and what it is for |
|---|---|---|
| Courses | Course title, platform identifier, page URL | Local database; used to group notes under one course |
| Notes | Text you type, timestamps, bookmarks | Local database; screenshot notes reference an image |
| Screenshots | Video frames you captured, including annotated ones | Local database; stored as image data |
| Subtitles | Subtitle text obtained from the course page | In your browser only (search, follow-playback highlighting, click-to-seek); never written to the database and never uploaded |
| Transcripts | Timestamped text produced by on-device speech recognition | Local database; used for search, seek-back, chapter generation and export |
| Chapters | Outlines and summaries produced by rules or by AI | Local database |
| Settings | Shortcuts, theme, language, screenshot quality, export preferences, AI endpoint configuration (including the API token) | Local database; the token is stored locally only (see Section 7) |
A small amount of transient state also exists:
browser.storage.session: UI state that lives only for the current browser session (for example "which note should receive focus after a screenshot"); it disappears when the browser closes;localStorage entry recording the punctuation-restoration toggle for local transcription;kedaibiao-asr), which can be deleted from the settings page.None of this is uploaded to any server controlled by the developer, and there is no cloud sync (the extension does not use storage.sync).
| Permission | Purpose |
|---|---|
activeTab | After you click the icon, a context menu item or a shortcut, perform a single action on that one tab: capture a frame, read video/subtitle state, inject the page script. Pages you have not acted on are not accessible. |
scripting | Injects the extension's own content script on demand into an authorised tab (generic support for any page with an HTML5 video element). No bulk injection. |
tabs | Identifies the current course, locates and switches to an already-open tab for a course, and listens to tab/URL changes to refresh the side panel context. Browsing history is not read. |
tabCapture | When a course's video file cannot be resolved to a direct URL, captures the audio the current tab is playing for on-device recognition. Audio is recognised locally in real time, never saved, never uploaded, and still played back to you (it is not muted). |
offscreen | Provides a transcription environment that keeps running when the side panel is closed. |
sidePanel | The extension's main interface, shown next to the video; nothing is displayed when it is closed. |
storage | Stores the transient UI state described above. |
contextMenus | Provides one right-click menu item to activate the extension on a page. |
declarativeNetRequestWithHostAccess | Only sets the Referer header when fetching, on your behalf, the subtitle/video data that the Zhihuishu (zhihuishu.com) course page has already loaded. Rules are restricted to requests the extension itself makes (tabIds: [-1]) and never affect pages or other sites. |
Host permissions:
*://*.zhihuishu.com/* (required): used only to fetch Zhihuishu's subtitle and video-source endpoints, which validate Referer and send no CORS headers.<all_urls> (optional, not granted by default): requested only in the two situations below, each triggered by your own click; if you never trigger them, it is never granted:
Sites where content scripts run: bilibili.com (video pages), icourse163.org, xuetangx.com, youtube.com (watch pages) and zhihuishu.com. On some platforms the extension takes over the page's own fetch / XMLHttpRequest only to read responses whose URL matches a subtitle endpoint — that is, subtitles the page has already requested itself — in order to build the subtitle timeline. It does not modify page data, does not change page behaviour, and does not affect any request made by the page or by other sites.
.onnx weights and tokens.txt vocabulary) is downloaded once, on first use, from the official Hugging Face source (huggingface.co, falling back to the mirror hf-mirror.com) and cached on your device. These are data files only — no executable code. After that the feature works fully offline, and the download source never receives your courses or notes.tabCapture is used instead to capture the audio the current tab is playing — again recognised locally in real time, never saved and never uploaded.baseUrl), model name and key (apiToken) and save them.Authorization header of the requests described above, to the address you entered; it is never sent to the developer or to anyone else.websiteContent consent when the user clicks; Chrome and Edge have no such mechanism, so the only prompt is the browser's own host-permission dialog when you save your configuration. If you configure no endpoint, or consent is not granted, the extension makes no such request.http://, the security of that transfer is determined by the service you chose; HTTPS is recommended.eval, no new Function and no dynamic import of remote scripts; the CSP merely adds 'wasm-unsafe-eval' so the bundled .wasm can be compiled. The only runtime download is the recognition model's data files, which contain no executable logic.This extension is a general note-taking tool for online-course learners. It is not directed at children and does not knowingly collect personal information from children — in fact, it collects no personal information from anyone.
If this policy changes materially (for example, if a new feature would transmit data off your device), we will update this page and the "last updated" date above. Any new feature that transmits data will be enabled only after you explicitly authorise it inside the extension.
Questions about this policy or about how data is handled: xxj@xzynet.com