Privacy Policy
Video Control Tools
Last updated: September 5, 2026
Video Control Tools is a browser extension and related activation/support service. This policy explains the data processed for authentication, licensing, support, payment matching, security, and operation of the service.
Data we process
- Google account email: obtained through Google OAuth and used to verify whether the account is authorized to use the extension.
- Google OAuth access token: sent securely to our Cloudflare Worker and Google's token verification service. The raw token is not stored in our D1 database.
- Telegram support data: Telegram user ID, chat ID, username and first name may be stored when you use the support/activation bot, together with activation requests and their status.
- Payment transaction metadata: when you choose paid activation, SePay may send transaction ID, receiving bank/account, amount, payment code, transfer content/description, reference code and transaction time. We use this only to match a bank transfer to an activation request and handle payment exceptions.
- Network information: Cloudflare may process request IP addresses for security, abuse prevention and rate limiting.
- Current page content: extension controls may inspect or modify relevant DOM elements on the active page. This page content is processed locally in your browser and is not sent to our server.
Information we do not request
We do not request or store online-banking passwords, OTP codes, card numbers, CVV codes, Google passwords, or Telegram passwords. Do not send passwords or authentication codes to the support bot.
Local storage
The extension temporarily stores an authorization result, the authorized email address, and a one-way fingerprint of the current access token in Chrome session storage for up to 15 minutes. The raw OAuth access token is not stored by the extension in Chrome storage.
Server-side storage
Cloudflare D1 may store authorized email addresses, Telegram support/session identifiers, activation orders, payment matching records, payment review records, and webhook transaction metadata required for audit, duplicate-payment protection, support, and activation. Browsing history and page content are not stored server-side.
How data is used
Data is used only to authenticate users, verify licenses, create and reconcile activation requests, prevent duplicate processing, provide support, investigate payment exceptions, and protect the service from abuse.
Sharing and service providers
We do not sell user data. Google processes OAuth verification; Cloudflare provides hosting, database and security services; Telegram provides the support bot/chat service; and SePay processes bank-transaction notifications used to match payments. Each provider may process technical data according to its own privacy terms.
Data retention
Session authorization data in the extension expires automatically. Server-side license, support, order and payment records may be retained for as long as reasonably necessary to provide access, resolve support/payment disputes, prevent duplicate processing, maintain audit history, and meet applicable legal or operational requirements. Records may be deleted when they are no longer needed.
Security
Requests use HTTPS. The service validates Google-issued tokens, restricts extension-origin API access, rate-limits license checks, verifies Telegram webhook secrets, verifies SePay HMAC-SHA256 signatures, validates payment amount/account/order state, uses parameterized database queries, and uses idempotency controls to avoid processing the same transaction more than once.
Your choices
You can disable or uninstall the extension at any time. You can stop using the Telegram bot. For questions about authorization, support records or payment records, contact the publisher through the support channel provided with Video Control.
Changes to this policy
We may update this policy when the service changes. Material changes will be reflected on this page before the related feature is made generally available.