Privacy Policy

Last updated: 5/15/2026

Dockbox is a product and service operated by ARK MARKETING LLC, a United States limited liability company ("we," "our," or "us"). We build a Chrome extension and related services that combine AI chat, note-taking, YouTube summaries, and more. Where we refer to "Dockbox" in this policy, we mean our product, website, and offerings unless the context requires otherwise. We are committed to respecting your privacy and keeping secure the information we obtain from or about you. This Privacy Policy describes our practices with respect to personal data that we collect from or about you, and how we use it when you use our website (including dockbox.net), Chrome extension, accounts, billing, and online features (collectively, the "Services").

Language notice: This document is provided in English. Translations may be provided for convenience. In the event of any inconsistency, the English version will govern, except to the extent prohibited by applicable mandatory local law.

Quick privacy summary

We collect account information (such as your email and sign-in details), billing information for paid plans through Stripe, and limited operational usage metrics needed to run plan limits and prevent abuse. Your notes, chat history, and YouTube summaries are stored locally on your device (IndexedDB), and we do not keep server-side copies of that local content. We use your data to provide the product, process payments, secure the service, and comply with legal obligations. You can request access, correction, deletion, or portability of applicable account data through our contact page, and you can remove local extension data by clearing browser data or uninstalling the extension.

Storage at a glance: Your notes, chat history, and YouTube summaries are stored only on your device (IndexedDB)—we do not keep copies on our servers. AI features, authentication, and billing inherently use the network as described below.


Chrome Web Store: Limited use of user data

The Dockbox Chrome extension may handle personal or sensitive user data only as described in this Privacy Policy. Our practices comply with the Chrome Web Store Developer Program Policies and the Limited Use requirements. In particular:

  • We use such data only to provide or improve Dockbox's single, user-facing purpose—the sidebar experience described on our Chrome Web Store listing (notes, AI chat, YouTube summarization, and related account and billing features visible in the product).
  • We do not sell personal or sensitive user data and do not use or transfer it to serve personalized, re-targeted, or interest-based advertising.
  • We transfer data to others only where necessary to operate the Services (for example, the providers identified elsewhere in this policy), to comply with law, for security or abuse prevention, as part of a permitted business transfer, or with your consent—consistent with Limited Use allowed transfer rules.
  • We do not allow humans to read user content except in limited circumstances (for example, with your consent for support, where required for security or legal compliance, or when data is aggregated and anonymized for internal operations).

Alignment with the Chrome Web Store listing: Personal and sensitive data we handle is collected and used for the same user-facing features we describe on the Chrome Web Store and inside Dockbox—not for unrelated or undisclosed purposes.

No public disclosure of authentication or payment secrets: We do not publish or publicly disclose authentication secrets, full payment card numbers, or similar credentials in public areas of our Services, store listings, or other open channels. Payment and sign-in use secure flows operated by us or our processors (for example, Stripe, Google sign-in, Supabase sessions), consistent with Chrome Web Store requirements.

Browsing context vs. browsing history: We do not collect your general web browsing history for advertising or unrelated analytics. Features that need information about the current page or video (for example, YouTube summarization when you start a summary from the video you are watching) use that context only to power user-initiated actions described in the extension's interface—not for behavioral ad targeting or background tracking.

Chrome extension permissions we request and why:

  • sidePanel: to open and manage Dockbox in Chrome's side panel (the extension's primary interface).
  • identity: to support Google OAuth sign-in through Chrome's identity flow.
  • tabs: to read the active tab's URL/title/favicon only when needed for user-triggered features (for example, YouTube summarization), and to open user-requested external pages (such as pricing or account pages). We do not use this permission to track browsing history.

If anything in this section conflicts with a newer Chrome Web Store requirement, we will update this policy to match.


1. Personal data we collect

We collect personal data relating to you ("Personal Data") as follows.

Personal data you provide

  • Account information: When you create an account, we collect information associated with your account, such as your email address, authentication credentials (including through Google sign-in), and profile information we receive from Google (for example, name and profile picture), as applicable.
  • Billing information: If you subscribe to a paid plan, payment and subscription data is processed by Stripe. Payment card numbers are processed by Stripe; we do not store full card numbers on our own servers.

Personal data we receive from your use of the Services

  • Chat, notes, and YouTube summaries: Chat conversations, notes, and summaries you create are stored locally in your browser (IndexedDB). We do not store that content on our servers.
  • YouTube summarization: To generate summaries, our backend may obtain transcripts through Supadata. Requests may include video URLs or identifiers required for transcript retrieval.
  • Account usage (metered features): When you are signed in and use AI features or other metered functionality, we record usage tied to your account—such as approximate token counts, request counts, and related totals—so we can enforce plan limits, prevent abuse, and show usage in your account. This is operational service data, not marketing analytics.
  • Content sent to AI providers: When you use AI features, we send the minimum necessary content to third-party AI inference services we use—including xAI (Grok), DeepSeek, Mistral, and Groq—over the network. In the product, chat and the writing assistant are offered as modes (we do not expose third-party model names as user-facing choices there). YouTube summarization does not display those provider names either.

Technical and log data

We collect information that your browser or extension environment sends or that we generate in operating the Services, such as browser type and version, extension version and update information, and error logs and performance data as needed to run and secure the Services.

Website analytics (landing page only)

When you visit dockbox.net, we use:

  • Google Search Console to understand how users find our website (for example, search queries, page views, referral sources). See Google's Privacy Policy.
  • Vercel Web Analytics and Vercel Speed Insights (our site is hosted on Vercel) for aggregated traffic and real-user performance (for example, page views, navigation, Core Web Vitals). See Vercel's Privacy Policy.

The Chrome extension does not load these website analytics tools. Operational usage metrics for metered features are described under Account usage above.

Cookies and similar technologies

We use cookies and similar technologies as needed for the Services, including:

  • Essential cookies for authentication and basic functionality (for example, Supabase session cookies).
  • Session and persistent cookies where applicable for your browser experience on our website.
  • Local storage in the extension's browser context to save your chat history, notes, and settings locally on your device.

We do not use third-party marketing or advertising analytics products (for example, Google Analytics) inside the Chrome extension to track your browsing for ads. You can control cookies through your browser settings; disabling certain cookies may affect functionality.


2. How we use personal data

We use Personal Data for the following purposes:

  • To provide, operate, and maintain the Services—including chat, AI responses, note-taking, YouTube summarization, and authentication.
  • To meter and administer plans—including enforcing limits, preventing abuse, and displaying usage using operational metrics (such as token and request counts).
  • To bill and manage subscriptions—through Stripe and our account systems.
  • To communicate with you—including responding to inquiries submitted through our contact page.
  • To improve and develop the Services—including understanding how the landing page performs (see Website analytics above).
  • To protect security and integrity—including detecting abuse, fraud, and unauthorized access.
  • To comply with legal obligations and protect the rights, safety, and property of Dockbox, our users, and others.

We do not use your personal conversations to train AI models on our systems without your explicit consent.


3. Disclosure of personal data

We do not sell, trade, or rent your personal information. We may disclose Personal Data in the following circumstances:

  • Vendors and service providers: We disclose Personal Data to trusted providers who perform services on our behalf, including Supabase (authentication and related backend data), Stripe (payments), Supadata (YouTube transcript retrieval for summarization), Vercel (hosting and, for our marketing website only, Web Analytics and Speed Insights), and AI inference providers we use (xAI/Grok, DeepSeek, Mistral, Groq), depending on the feature and how we route requests on our backend. Those providers process data under their own terms and privacy policies.
  • Legal and safety: We may disclose Personal Data if we believe in good faith that disclosure is appropriate to comply with law, regulation, legal process, or governmental requests; to enforce our terms and policies; to protect the security or integrity of the Services; or to protect the rights, property, or safety of Dockbox, our users, or others.
  • Business transfers: If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Personal Data may be disclosed in diligence and transferred as part of that transaction, subject to standard confidentiality arrangements.
  • With your consent: Where you direct us or consent to disclosure for a specific purpose.

4. Retention

We retain Personal Data for as long as necessary to provide the Services and for legitimate business and legal purposes:

  • Account data is generally retained while your account is active.
  • Local data (chat, notes, summaries on your device) remains until you delete it or remove the extension.
  • Local data may persist after sign-out until you clear it or uninstall the extension.
  • Payment-related records may be retained as required for accounting, tax, and legal compliance.
  • Logs and technical data are typically retained for a limited period (for example, on the order of 90 days) unless a longer period is needed for security incidents, legal compliance, or dispute resolution.

5. Data controls

Depending on the Service, you may have controls such as:

  • Account and data requests: You may request access, correction, deletion, or portability as described in Your rights below. We may need to verify your identity before fulfilling certain requests.
  • Marketing: You may opt out of marketing communications using the choices in those messages, if applicable.
  • Cookies: You can manage cookies through your browser settings where applicable to our website.

6. Your rights

Depending on where you live, you may have statutory rights in relation to your Personal Data, such as the right to access, rectify, delete, restrict processing, data portability, and object to certain processing, and the right to withdraw consent where processing is based on consent.

To exercise rights that apply to you, contact us through our contact page. We will respond within a reasonable time and within any deadline required by law (including the timeframe for California residents described in Section 9).

If you are in the European Economic Area or the United Kingdom

If you are located in the EEA or UK, you have rights under the GDPR and, where applicable, the UK GDPR, including those listed above. Legal bases for processing may include contract (providing the Services), legitimate interests (for example, security and product improvement, balanced against your rights), and consent where required.

You may lodge a complaint with your local data protection authority.

International transfers

Data that stays only on your device is not transferred internationally by Dockbox in the sense of cloud processing by us. When you use online features—sign-in, billing, or AI requests—information may be processed in the United States or other countries where our service providers operate. Where required, we use appropriate safeguards (such as standard contractual clauses) for international transfers.


7. Children

Our Services are not directed to children under 13, and we do not knowingly collect Personal Data from children under 13. If you are a parent or guardian and believe a child under 13 has provided Personal Data to Dockbox, please contact us through our contact page. We will investigate and, where appropriate, delete that information.

You must be at least 13 to use the Services. If you are under 18, you represent that you have your parent's or guardian's permission to use the Services.


8. Security; data breach response

We implement technical, administrative, and organizational measures designed to protect Personal Data. Data is protected in transit (for example, TLS / HTTPS) when it communicates with our APIs, consistent with Chrome Web Store expectations for sensitive data. Where Personal Data is stored with cloud providers (for example, authentication records via Supabase or payment records via Stripe), we rely on those providers' industry-standard encryption and access controls. Local data in the extension relies on your browser and OS protections. No method of transmission or storage is completely secure.

Storage overview: Your chat, notes, summaries, and settings are stored on your device using IndexedDB—we do not upload that content to our servers. We use Supabase for authentication and Stripe for payments.

If we become aware of a breach that may affect your Personal Data, we will investigate, take appropriate steps, and notify affected users and authorities as required by applicable law (for example, within 72 hours of becoming aware, where the GDPR so requires). Content that exists only on your device is not exposed by a breach of our servers.


9. Additional U.S. state disclosures (including California)

If you are a California resident, you have rights under the CCPA and CPRA, including:

  • Right to know about the personal information we collect, use, and disclose.
  • Right to delete personal information, subject to exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell your personal information and do not share it for cross-context behavioral advertising as described in the CPRA.
  • Right to limit the use of sensitive personal information where that right applies.
  • Non-discrimination for exercising your privacy rights.

Sensitive personal information (CPRA): We do not collect or use the categories of sensitive personal information defined by the CPRA (for example, government identifiers, precise geolocation, or health information) for the purpose of inferring characteristics about you. If our practices change, we will update this Privacy Policy.

Other U.S. state privacy laws may grant similar rights depending on where you live. You may exercise rights by contacting us through our contact page. For California, we will generally respond within 45 days (or as required by applicable law).


10. Do Not Track

Some browsers offer a Do Not Track (DNT) signal. There is no consistent industry standard for how to respond to DNT. We do not currently respond to DNT signals. We collect data as described in this Privacy Policy to operate the Services.


11. Third-party links

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. Their terms and privacy policies apply when you leave our Services.


12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the Last updated date. If changes are material, we will take additional steps as required by applicable law. Continued use of the Services after the effective date of changes constitutes your acceptance of the updated policy where permitted by law.


13. Data controller

ARK MARKETING LLC is the data controller for the Personal Data described in this Privacy Policy when you use our Services. We operate the Dockbox Services from the United States.

If applicable law requires our registered business address or other company details, we will provide that information in response to a request submitted through our contact page, or we may publish it on our website when available.


14. How to contact us

If you have questions about this Privacy Policy or our data practices, please use our contact page.