Privacy Policy

Last updated: July 27, 2026

1. Information We Collect

Expand is an AI research companion that generates research briefs from publicly visible article previews. We collect only the information needed to provide this service.

Article URLs and previews

When you use Expand, we receive the article URL you submit. Our backend fetches the publicly visible preview of that article — the same text any visitor can see without subscribing or logging in. We do not access, decrypt, or circumvent any paywalled or subscriber-only content.

Account information

If you create an account, we collect your email address and a hashed password (or use Google OAuth for sign-in). We do not store passwords in plain text. Email verification codes are generated using cryptographically secure random values.

Usage data

We track the number of articles you expand per month to enforce your plan's quota. We also log request timestamps and IP addresses for rate limiting and abuse prevention. These logs are retained for 30 days.

Chrome extension permissions

The Expand Chrome extension requests permission to read the active tab's URL and page content. This is used solely to detect article previews and extract publicly visible text. The extension does not modify page content except to inject the AI-generated research brief below the existing preview.

2. How We Use Information

We use the information we collect for the following purposes:

  • Generate research briefs — Article previews are sent to our AI pipeline to produce cited expansions.
  • Search the web — We generate search queries from the preview and query third-party search APIs for relevant context.
  • Quota enforcement — We count article expansions against your plan limit.
  • Authentication — Email and password are used to verify your identity and manage your subscription.
  • Rate limiting — IP addresses are used to prevent abuse of our API endpoints.
  • Email communication — We send verification codes, password resets, and subscription receipts.

3. Third-Party Services

Expand relies on several third-party services to function. Each has its own privacy policy and data handling practices.

Stripe

We use Stripe for payment processing. When you subscribe to a paid plan, your payment information (credit card details) is collected and processed directly by Stripe. We do not store your full card number or CVV. Stripe's privacy policy applies: stripe.com/privacy.

Resend

We use Resend to send transactional emails (verification codes, password resets, receipts). Your email address is shared with Resend solely for the purpose of delivering these messages. Resend's privacy policy: resend.com/legal/privacy-policy.

DeepSeek / OpenAI-compatible AI providers

Article previews and search results are sent to an AI model (via an OpenAI-compatible API, currently DeepSeek) to generate the research expansion. The AI provider may process this data according to their own privacy policy. We do not send any personally identifiable information to the AI model beyond what is in the article preview itself.

Tavily, Exa, Bocha

We use Tavily, Exa, and Bocha for web search. Generated search queries (derived from the article preview) are sent to these services. They may log queries and results per their respective privacy policies. We do not send personal data in search queries.

Cloudflare

Our backend runs on Cloudflare Workers. Cloudflare processes all traffic to our API and may collect IP addresses, request metadata, and logs for security and performance purposes. Cloudflare's privacy policy: cloudflare.com/privacy.

4. Data Storage

All data is stored and processed server-side via Cloudflare Workers and Cloudflare D1 (SQLite database).

What we store

  • Email address and bcrypt-hashed password (for registered users)
  • Google OAuth ID (for Google sign-in users)
  • Refresh token hashes (for session management)
  • Subscription tier and article usage count
  • Article URL, preview text, and generated research brief (cached for 7 days)
  • Request logs (IP, timestamp, endpoint) for 30 days

What we do not store

  • Payment card details (handled by Stripe)
  • Browser history beyond the specific article URLs you expand
  • Passwords in plain text
  • Content from paywalled articles

AI processing happens server-side. Article previews are sent to our Cloudflare Workers backend, where search queries are generated, web search is performed, and the AI model produces the research brief. No AI processing occurs in your browser or on your device.

5. Cookies and Browser Storage

The Expand web app and Chrome extension use the following storage mechanisms:

  • Authentication cookies — A JWT access token and refresh token are stored in httpOnly cookies for session management. These are essential for authentication and expire after 15 minutes (access token) or 30 days (refresh token).
  • Chrome extension storage — The extension stores your settings (API key, model name, output language, debug mode) in chrome.storage.local. This data never leaves your device except when sent to our API for processing.
  • Local cache — Expanded article results are cached locally in the extension for quick re-access. This cache is stored on your device and can be cleared from the Options page.

We do not use tracking cookies, advertising cookies, or third-party analytics scripts.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Update your email address or other account details.
  • Deletion — Request deletion of your account and associated data. Contact us at support@380747.xyz.
  • Portability — Export your expanded article history from the Options page.
  • Objection — Opt out of non-essential communications.

To exercise any of these rights, email us at support@380747.xyz. We will respond within 30 days.

Expand complies with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) in the collection, use, and retention of personal data.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the service.

  • Account data: retained until you delete your account.
  • Article cache: retained for 7 days, then automatically purged.
  • Request logs: retained for 30 days, then automatically deleted.
  • Email verification codes: expire after 10 minutes.

8. Security

We take reasonable measures to protect your data:

  • All API traffic is encrypted via HTTPS/TLS 1.3.
  • Passwords are hashed with bcrypt before storage.
  • Refresh tokens are stored as SHA-256 hashes, never in plain text.
  • Rate limiting prevents brute-force attacks on authentication endpoints.
  • AI-generated content is HTML-escaped before rendering to prevent XSS.
  • Cloudflare's DDoS protection and WAF filter malicious traffic.

9. Children's Privacy

Expand is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us at support@380747.xyz and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Significant changes will be communicated via email to registered users.

11. Data Usage Compliance

In compliance with Chrome Web Store Developer Program Policies, Expand makes the following commitments:

  • No sale or unauthorized transfer of user data — We do not sell, trade, or otherwise transfer your personal data to third parties for purposes unrelated to the operation of the Expand service. Data is shared with third-party service providers (Stripe for payments, Resend for email, Cloudflare for hosting) solely to deliver the service you have requested.
  • Purpose-limited data use — All user data we collect is used exclusively to provide the Expand AI research companion service: authenticating users, tracking quota usage, generating AI summaries, processing payments, and sending verification emails. We do not use or transfer user data for purposes unrelated to the extension's single purpose.
  • No use for credit or lending — We do not use or transfer user data to determine creditworthiness, facilitate loans, or for any lending-related purposes.

12. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: support@380747.xyz
Domain: expand.380747.xyz
Backend: expand-api.380747.xyz