Privacy Policy
MaruComprehension Chrome Extension · Version 1.7.4 · Last updated: August 23, 2026
Short version: MaruComprehension has no server. The developer receives no data from you of any kind, and has no way to. Everything the extension stores lives on your own device in chrome.storage.local. Data leaves your device only to reach a service you chose and configured yourself — MaruMori, Jisho, YouTube's public caption endpoint, an AI provider you supply your own API key for, or your own Google Drive — and only for the feature you triggered. No analytics, no tracking, no advertising, no data selling, no third-party data brokers.
1. Who is responsible for your data
MaruComprehension is built and published by an independent individual developer ("the developer", "we"). It is a personal, non-commercial project.
There is no company, no backend server, and no staff. The developer operates no database, no logging infrastructure, and no account system, and therefore never receives, stores, or has any technical means of accessing your data. Where this policy says data is "sent", it is always sent directly from your own browser to a third-party service you have chosen to connect, never by way of any system the developer controls.
For any privacy question, or to exercise the rights described in section 11, contact marucomprehension@gmail.com.
2. What this extension does
MaruComprehension is an unofficial fan app that connects to your MaruMori account to fetch your learned vocabulary and kanji. It uses that data to:
- Color-highlight subtitles and transcripts on Comprehensible Japanese / Natural Japanese, Nihongo-Jikan, YouTube, Netflix, Crunchyroll, Plex, NHK News Web Easy, and any additional site you explicitly allow — known words in one color, unknown in another
- On BookWalker's web reader, color and explain a passage you have highlighted yourself. BookWalker draws its pages as images, not text, so the extension cannot and does not read the page: the only text it ever sees is the sentence BookWalker itself puts on screen in its own marker dialog when you make a selection. That text is tokenized on your device, colored against your vocabulary, given hover cards, and listed word by word with readings and meanings from the local dictionary. If you never highlight anything, this does nothing at all, and nothing is sent anywhere unless you press one of the two optional AI buttons described in section 6
- Let you paste or upload any Japanese text on the extension's own Transcribe Text page for the same colorized, hoverable, scored breakdown, independent of any site
- Calculate a comprehension score for each video based on how many subtitle words you already know
- Show hover cards with reading, definitions, and known/unknown status when you hover over any Japanese word in a subtitle or transcript
- Display a word sidebar listing all unknown words in the current video with JLPT level indicators
- Read a MaruMori grammar lesson aloud, using the speech voices your browser already has. Only the lesson’s own explanation text is read; example sentences are played using MaruMori’s own recordings instead. Nothing happens until you press a speaker button, and no API key is involved. Where the spoken text goes depends on the voice you choose — see the speech row in section 6.
- Show your current MaruMori SRS review level as a small badge while you do reviews on marumori.io, with an extra warning for items about to graduate, and keep a local record of your review sessions (items, accuracy, points, and a kanji/vocab/grammar split) for the review-stats screens. This reads the review page's own on-screen text to know which word or kanji is showing, and compares it against your already-cached MaruMori data; nothing is sent anywhere
- Save a watch history and an unknown word frequency list so you can track progress over time
- Let you mark words as Known directly from a hover card, stored separately from MaruMori
- Automatically track immersion time spent watching Japanese video, with a daily/streak view and a breakdown by source, plus a manual "add time" entry for sources it can't detect (e.g. a book)
- Run an optional focus timer for study sessions, which can add its duration to your immersion time and play a sound or show an on-screen notice when it finishes
- Add a right-click menu item to search any selected word or phrase on MaruMori's dictionary
- Optionally translate a video's subtitles using an AI provider you choose and supply your own API key for, showing the translation under each subtitle line and in the transcript sidebar — either the whole video at once, or just the line you are looking at
- Ask that same provider for help with a specific word or phrase: what a word with no dictionary entry means in the line it appears in, or an explanation of the grammar in the phrase currently on screen
- In the local player, transcribe a video's Japanese audio when you have no subtitle file for it — the audio is read out of the file you opened, on your device, and sent to Google Gemini (the only supported provider that accepts audio) to be written down
- Save that transcript as a .srt file on your device, so the same video never needs transcribing twice. The file is written by your browser's normal download; nothing is uploaded anywhere
- Let you export or import all extension data as a single file, to move your setup to another device
- Let you optionally back up your data to your own Google Drive, and sync it back down on another device, using a Google sign-in you control
3. What data the extension handles
The categories below use the same names as the Chrome Web Store's data-disclosure categories, so they can be read directly against this item's declared data usage.
Authentication information
- MaruMori API token — pasted by you to connect your MaruMori account. Used only to authenticate requests to MaruMori's own public API.
- AI provider API keys — only if you paste one. Stored per provider, so keys for Google Gemini, DeepSeek, OpenAI, and Anthropic are kept separately, alongside which provider you have selected. Each key is sent only to the provider it belongs to.
- Custom AI endpoints you add — only if you add one. For each, the name you gave it, the base URL you entered, the model id, and its API key if the server needs one (a self-hosted server usually does not, and the field may be left empty). Stored on your device exactly like the keys above, and each is used only to call the address you entered.
- Google OAuth access token — only if you turn on Google Drive backup. Issued by Google to Chrome's
identity API and held by the browser. The extension never sees, handles, or stores your Google password.
Website content
- Subtitle and transcript text from the video page you are viewing, so words can be segmented, looked up, and colored.
- Page text on marumori.io review screens — the word or kanji currently under review, read to display your SRS level badge.
- Video titles, taken from the page's own title — the same text shown in your browser tab.
- Text you paste or upload yourself on the Transcribe Text page.
- Audio from a local video file you open in the extension's own player, and only when you press "Transcribe".
User activity
- Watch history — titles, URLs, comprehension scores, and watch counts for Japanese videos you have watched on supported sites. This covers only pages where the extension is active; it is never a record of your general browsing, and the extension cannot see pages it has no permission for.
- Unknown word frequency — words that appeared as unknown across your watched videos, with occurrence counts.
- Immersion tracking data — daily watch-time totals, a per-source breakdown (YouTube, CIJ, Nihongo-Jikan, local player, etc.), a recent session log, per-video watched seconds, and any manual time entries you add.
- MaruMori review statistics — a local history of your review sessions on marumori.io: date, item count, accuracy, points, streaks, and the kanji/vocab/grammar split.
- Manually known words — words you have marked as Known from hover cards, stored separately from MaruMori.
Cached reference data and settings
- Vocab and kanji lists — downloaded from your MaruMori account and cached locally so scoring works without repeated API calls.
- Translation cache — the Japanese lines you have translated and their translations, kept per language so the same line is never sent for translation twice.
- AI assist cache — the word and grammar explanations you have asked for, kept per language alongside the phrase each was asked about, so the same question is never sent twice. Capped at the 400 most recent.
- Settings and preferences — subtitle style, hover toggle, badge visibility, focus timer duration and sound preferences, the list of extra sites you have allowed, and other UI preferences.
Never collected, in any circumstance: personally identifiable information (name, address, email, age, ID numbers); health information; financial and payment information; personal communications (email, messages, chats); location or IP-based geolocation; general web browsing history; keystroke logging; form contents on any site; passwords of any kind. The extension contains no analytics SDK, no crash reporter, no advertising or marketing network, no fingerprinting, and no tracking pixels of any kind, and it does not build any advertising or behavioural profile.
4. How this data is used
Every piece of data above is used for one purpose only: to deliver the language-learning feature you asked for, on your own device. Specifically:
- Vocabulary and kanji data is compared against on-screen Japanese text to decide which words to color as known or unknown, and to calculate your comprehension score.
- Credentials are used solely to authenticate to the service that issued them.
- History, frequency, immersion, and review data is used solely to draw your own progress screens inside the extension.
- Caches exist solely to avoid repeating a network request you have already paid for or waited on.
Your data is never used to build a profile, to train any machine-learning model of ours (we operate none), for advertising or marketing, for creditworthiness or lending purposes, or for any purpose unrelated to the single purpose of the extension.
5. Where data is stored
- On your device. All data is stored locally using
chrome.storage.local, in your own browser profile. It is not stored on any server operated by the developer, because no such server exists.
- In your own Google Drive, only if you switch on the optional backup described in section 7.
- In a file you save yourself, only if you use the export feature. If you do, that file contains a copy of your data including your MaruMori API token and any AI provider API keys. It stays on your device unless you move it. Treat it like a password: importing it elsewhere restores full access to everything it contains.
The extension does not use chrome.storage.sync, so nothing is silently replicated through your Chrome profile to other machines.
6. Data sent off your device
The extension contacts only the services below. In every case the request is made directly by your own browser to that service; nothing is proxied through, copied to, or observable by the developer.
| Destination | What is sent | When |
MaruMori API
public-api.marumori.io |
Your MaruMori API token, to retrieve your own vocab and kanji lists. |
When you connect your account or manually refresh. |
YouTube
youtube.com |
The video ID of the video currently open, to fetch its public Japanese caption track. No account credentials are sent. |
When you open a YouTube video with the extension active. |
Jisho dictionary
jisho.org |
Only the single word being hovered, to fetch its definition. |
When you hover a word and no local definition exists. |
MaruMori website
marumori.io |
Nothing beyond a normal page navigation — a new tab is opened at a dictionary URL. |
When you use "Search on MaruMori" or click a hover-card dictionary link. |
Google sign-in & Drive
accounts.google.com, www.googleapis.com |
Your Google OAuth token and the backup file described in section 7. |
Only if you connect Drive backup, and only on "Save", "Sync", or an auto-save interval you switched on yourself. |
Your browser’s speech engine Chrome’s Google 日本語 and Google US English are online voices supplied by Google; local voices (Kyoko, Samantha, and the rest of your system’s) synthesise on your device and send nothing. |
The lesson text being read aloud, and nothing else. This is handled by the browser itself through its standard speech API — the extension makes no network request of its own for it. |
Only while you are having a MaruMori grammar lesson read aloud, and only if the selected voice is an online one. Choosing a local voice in the read-aloud dropdown keeps it entirely on your device. |
AI provider you selected
generativelanguage.googleapis.com (Google Gemini), api.deepseek.com (DeepSeek), api.openai.com (OpenAI), api.anthropic.com (Anthropic) — or any OpenAI-compatible endpoint you add yourself in Settings → API, in which case the address is the one you entered and nothing is sent to it until you have granted this extension access to that host. |
Your own API key for that provider, plus the specific content listed below. |
Only if you have saved a key, and only when you press an AI button. |
What each AI action sends
Requests go only to the one provider you have selected — including a custom endpoint of your own — authenticated with the API key you supplied for it (a self-hosted endpoint may need none). The AI buttons are "Translate" in the subtitle settings panel, "AI Translate phrase" in the subtitle bar's ⋮ menu, "AI Assist" on a hover card, "AI Grammar" in the This Phrase tab, and "Translate" and "Grammar" in BookWalker's marker dialog.
- Translate — the Japanese subtitle lines of the video you are watching (every line for the whole-video button, or just the one line for "AI Translate phrase").
- AI Assist — the word you clicked (with its dictionary form and reading), the subtitle line it appears in, at most one subtitle line either side, and the video title.
- AI Grammar — the subtitle line shown in This Phrase, at most one subtitle line either side, and the video title.
- Translate and Grammar in BookWalker (one button each) — only the single passage you highlighted, exactly as BookWalker displayed it in its own marker dialog, plus the book title from the page's title bar. There are no neighbouring lines to send, because the extension has no access to the rest of the page. Neither button does anything until you press it: highlighting a passage on its own never contacts a provider, and the word list shown beside it is produced entirely on your device.
- Transcribe audio (local player only) — the audio track of the video file you opened, converted to 16 kHz mono and sent in pieces of about a minute. Audio only: the picture is never sent, and no filename, title, or other detail goes with it. This action requires Google Gemini, the only supported provider that accepts audio; if another provider is selected, the extension refuses rather than sending the audio elsewhere.
Nothing else is included: no MaruMori data, no vocabulary lists, no watch or review history, no account identifiers, no browsing history. Video titles are taken from the page's own title, the same text shown in your browser tab. Anything already answered on this device is served from the local cache and is not sent a second time. AI features are entirely optional and inert until you add a key.
Your relationship with the AI provider is your own. You are that provider's customer, not ours; usage is billed to your account with them, and their handling of what you send is governed by their privacy policy and terms, not this one. If you added an endpoint of your own, that relationship is with whoever operates it — which may be no one but you, if it runs on your own machine. Please review them: Google, DeepSeek, OpenAI, Anthropic.
No analytics service, crash reporter, advertising network, content delivery tracker, or any other third-party server is contacted. If you have allowed the extension on a self-hosted media server on your own network (e.g. Plex or Jellyfin), it is contacted the same way any page you open in your browser would be — the extension never reaches out to it on its own.
7. Google Drive backup (optional, off by default)
You may choose to connect a Google account to back up your data. This feature is disabled by default and does nothing until you sign in yourself.
- Sign-in uses Chrome's built-in
identity API — no password is ever seen or handled by this extension.
- Data is written to a single JSON file in your Google Drive's appDataFolder — a hidden, per-app storage space Google creates for each app you authorize. It does not appear in your regular Drive file list, and no other app can read it.
- The extension requests only the
drive.appdata scope. It cannot see, create, or modify any other file in your Drive.
- What is backed up: your MaruMori API token, any AI provider API keys and your selected provider, any custom AI endpoints you added (name, base URL, model id and key), vocab/kanji cache, manually-known words, immersion time (daily and per-site totals plus the recent session log), per-video watched seconds, and watch/word history. It does not include the per-source-per-day breakdown used for the stats chart, or the translation cache — those stay local-only, to keep the backup file small. (The translation cache is carried over only by the local export/import file.)
- "Save" uploads your current local data to that file, overwriting what was there. "Sync" downloads it and merges it into this device — historical data (immersion time, watch/word history, known words) is added to what is already here rather than replacing it, so using this on a second device will not erase either device's progress.
- Automatic backup: a separate opt-in switch, off by default, re-runs exactly the same upload as the "Save" button on an interval you choose. It only ever runs after you have connected Drive and switched it on, it writes to the same private appDataFolder file, and it sends nothing that a manual "Save" would not. Switching it off stops it immediately.
- You can revoke access at any time from your Google Account permissions page, which also deletes the backup file.
MaruComprehension's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data sharing and disclosure
The developer receives no user data and therefore discloses none. Beyond that:
- Your data is never sold, rented, licensed, or traded to anyone, under any circumstances.
- Your data is never shared with advertisers, data brokers, analytics vendors, marketing partners, or any other third party.
- The only parties that ever receive anything are the services listed in section 6 — MaruMori, Jisho, YouTube, your chosen AI provider, and your own Google Drive — each of which receives only the minimum described there, only when you trigger the feature, and only because you connected it.
- There is no transfer of data on any change of ownership, merger, or acquisition, because there is no data holding to transfer.
- The developer cannot disclose your data in response to a legal request, subpoena, or law-enforcement demand, as the developer holds none of it.
9. Limited Use certification
MaruComprehension's use of information received from any source complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, the extension:
- uses data only to provide or improve the single, user-facing purpose described in section 2;
- does not transfer data to third parties except as strictly necessary to provide that purpose at your request, as itemised in section 6;
- does not use or transfer data for serving advertisements of any kind, including personalized, retargeted, or interest-based advertising;
- does not use or transfer data to determine creditworthiness or for lending purposes;
- does not sell data to anyone;
- allows no human to read your data, other than yourself — no developer, contractor, or employee has any access path to it.
10. Data retention and deletion
Because all data is stored locally, you control retention entirely. Nothing expires on a schedule set by us, and nothing is retained anywhere after you remove it.
- Local data is kept on your device until you delete it. The AI assist cache is additionally capped at the 400 most recent entries, with older entries dropped automatically.
- Clearing specific data: watch history, word data, review statistics, and immersion tracking data can each be cleared at any time from within the extension.
- Removing credentials: deleting your MaruMori token or an AI API key from the extension's settings removes it from storage immediately.
- Deleting everything: removing the extension from Chrome deletes all locally stored data permanently. Chrome discards the extension's entire
chrome.storage.local area on uninstall.
- Deleting the Drive backup: revoke the extension at your Google Account permissions page; Google deletes the appDataFolder contents for a revoked app. You may also press "Save" after clearing local data to overwrite the file's contents first.
- Exported files are outside the extension's control once written; delete them yourself as you would any other file.
Data already sent to a third-party service at your request (for example, a subtitle line sent to an AI provider) is retained according to that service's own policy, and must be deleted through them. The extension has no ability to recall it.
11. Your rights
Depending on where you live, you may have rights of access, portability, rectification, and erasure over your personal data. Because the developer holds no copy of your data, these rights are exercised directly and immediately by you:
- Access and portability — the export feature writes your complete data set to a JSON file you keep.
- Rectification — all stored values are editable or clearable from the extension's own screens.
- Erasure — see section 10; uninstalling deletes everything.
- Objection and withdrawal of consent — every feature that sends data anywhere is opt-in and individually switchable; turning one off stops it at once.
If you have a question these steps do not answer, contact marucomprehension@gmail.com.
12. Security
- All external requests use HTTPS.
- Credentials are stored in
chrome.storage.local, which is sandboxed to the extension and unreadable by web pages or other extensions.
- The extension has no remote-code execution: it loads no scripts from any server, and all code shipped is contained in the reviewed package.
- The main residual risk is the export file, which contains credentials in plain text by design so it can be imported elsewhere. Store it accordingly.
13. Permissions explained
- storage — saves your API token, vocabulary cache, watch history, review statistics, immersion tracking data, and preferences locally on your device
- activeTab — reads the current tab's URL so the popup can show the correct comprehension score for the page you are on
- scripting — injects the subtitle coloring and hover card logic into supported video pages; fetches YouTube caption files from within the page context (required because YouTube rejects requests from extension origins); and shows the focus timer's sound/on-screen effect on the page you're viewing when a session ends
- alarms — keeps the focus timer counting down accurately in the background while the popup is closed, and drives the optional Drive auto-save interval if you switch it on
- notifications — shows a system notification when the focus timer finishes, if an on-page effect couldn't be shown
- contextMenus — adds the "Search on MaruMori" item to the right-click menu
- identity — lets you optionally sign in with your own Google account for the Drive backup feature in section 7. Requested only when you connect Drive; never used automatically or for any other purpose
- Host permissions — limited to the sites the extension supports: Comprehensible Japanese / Natural Japanese (
cijapanese.com, nijapanese.com), Nihongo-Jikan (nihongo-jikan.com), YouTube, Netflix, Crunchyroll, Plex (app.plex.tv), BookWalker's reader (viewer.bookwalker.jp), NHK News Web Easy, MaruMori (site and API), Jisho, and the four built-in AI provider endpoints, which are contacted only if you set up a key and press an AI button
- Optional host permission (
*://*/*) — two controls in the popup can each grant access to one additional address of your choice, neither of which can be known in advance and so neither of which can be listed above: "Allow this page", for self-hosted media servers such as Plex or Jellyfin, and "Save endpoint" in Settings → API, for a custom AI endpoint you add. This permission is declared as optional and is never granted at install time: Chrome grants nothing until you click "Allow this page" on a specific site, each address must be approved individually, and each can be revoked the same way at any time. Addresses you have not approved remain completely inaccessible to the extension. Data from an approved site is handled exactly as described in section 3 — read on your device to color words, never transmitted anywhere; an approved AI endpoint is a destination rather than a source, and receives only what section 6 describes, only when you press an AI button
14. Children's privacy
This extension is not directed at children under 13 and does not knowingly collect data from them. As no data reaches the developer, no such data could be collected inadvertently.
15. Changes to this policy
If this policy changes materially, the "Last updated" date above will be revised, and the change will be reflected in this page before the corresponding extension version is published. Continued use of the extension after a change constitutes acceptance of the updated policy.
16. Contact
Questions, concerns, or privacy requests: marucomprehension@gmail.com.
Disclaimer
MaruComprehension is an independent, unofficial fan app created by a MaruMori user. It is not affiliated with, endorsed by, or in any way associated with MaruMori.io, Comprehensible Japanese, Natural Japanese, or Nihongo-Jikan. All trademarks and brand names belong to their respective owners.