Last updated: July 28, 2026
Scope and operator
This policy applies to ctcextensions.com, the CTC Extensions account dashboard, support channels, and CTC Extensions browser products. CTC Extensions operates these services. Product-specific disclosures and Chrome Web Store listings supplement this policy for the relevant extension.
Information we collect
We may process account identity and contact details, authentication records, workspace membership and settings, subscription and transaction references, plan entitlements, quota usage, support messages, consent records, and security or error diagnostics needed to operate the service.
When you visit our services, our infrastructure may process technical request information such as IP address, browser and device type, requested page, timestamps, and security signals. We do not sell personal information or use it for cross-context behavioral advertising.
How we use information
We use information to provide and secure accounts, deliver extension entitlements, enforce quotas, process support requests, maintain service reliability, prevent abuse, communicate service or billing updates, and comply with legal obligations. We do not use extension content for advertising or credit decisions.
Local-first extension data
FormRunner spreadsheet rows, field mappings, form values, and run history; Shopee product and review datasets; AI China Sourcing Extractor: 1688, Taobao, Tmall – CTC China Source product captures, Discover crawl jobs and datasets, temporary image-search blobs, reviews, projects, calculations, price history, and message drafts; Google Maps lead datasets; screenshot captures; and workflow recordings are stored locally in the browser unless a product clearly presents a sync, upload, or AI action. Local exports begin only after a user action.
You control local retention through product settings where available. You can delete local records, clear extension storage, or uninstall an extension. Uninstalling may delete local data that has not been exported.
Explicit sharing and AI actions
AI Full Page Screenshot – CTC Snap keeps captures local unless you create a share link. Pressing Create plan sends the signed-in user's request text, full active-tab URL/title, selected capture mode, output format, device preset, and available feature names through CTC to the configured AI provider. Screenshot pixels and automatically read page/form content are not included; anything the user types or pastes into the request is included. Planning input has a 15-minute job TTL and is cleared after planning, cancellation, or failure; the encrypted reviewable plan is cleared on completion/cancellation or scheduled cleanup after its 24-hour expiry. Creating a share link separately uploads only the selected image and limited metadata to CTC-managed storage. The shared asset and link expire after 24 hours unless revoked sooner.
AI Workflow Recorder: SOP & Guide – CTC Steps keeps recordings and screenshots local by default. Pressing Create plan sends the signed-in user's request text, full active-tab URL/title, feature capabilities, selected session/step identifiers and versions, and bounded recording state through CTC to the configured AI provider; recorded step text and screenshots are not sent at this stage. Pressing Run on a confirmed transformation sends the scoped SOP manifest, including session/step text, sanitized page title/origin/path, and target labels/context, with no screenshots. The separate Studio generation flow sends that manifest and only the already-redacted screenshots the user explicitly checks after Confirm & generate. Generic planning input has a 15-minute job TTL and is cleared after planning, cancellation, or failure; its encrypted plan is cleared on completion/cancellation or scheduled cleanup after its 24-hour expiry. Studio generation input is cleared after processing or failure, and its server job/result expires within 24 hours. Recording alone does not upload screenshots or workflow content.
AI Shopee Data Extractor – CTC Shopee keeps extracted product/review rows, author names, media URLs, media bytes, and dataset history local. Pressing Create plan sends the signed-in user's request text, full active-tab URL/title, market/page type, active-job status, feature limits, capabilities, and opaque selected job/dataset identifiers and versions through CTC to the configured AI provider. Dataset rows and media are not automatically included; anything the user types or pastes into the request is included. Planning input has a 15-minute job TTL and is cleared after planning, cancellation, or failure; the encrypted reviewable plan is cleared on completion/cancellation or scheduled cleanup after its 24-hour expiry. Public media selected for export is fetched directly from Shopee's CDN with credentials omitted.
AI China Sourcing Extractor: 1688, Taobao, Tmall – CTC China Source keeps anonymous Free sourcing work and Discover datasets local. Product-list crawling runs only after a user action while Chrome remains open. Native image search redraws the selected local image to remove metadata, stores it temporarily in extension IndexedDB, uploads it only to the selected marketplace's native UI, and deletes it after completion, cancellation, or failure; the image is not sent to CTC servers. After an explicit Upgrade and sign-in, only products the user selects and saves may sync to the user's personal CTC workspace. Only a user-requested review or negotiation operation sends the selected sourcing input through CTC APIs to Orimise. Reports are generated and downloaded locally, and price checks run only while the user has the saved marketplace page open.
Accounts, authentication, and storage
Signing in sends account, workspace, installation, and authorization information to CTC APIs. Google receives and returns identity information only when you choose Google sign-in. We use essential cookies or similar storage for authentication, security, language, and service preferences; these controls are not used for third-party advertising.
Signed-in extensions may send entitlement, quota, extension version, aggregate feature status, and categorized error diagnostics. Product records, URLs, keywords, form values, lead records, review text, notes, project names, custom requests, messages, screenshots, filenames, and report bodies are excluded from aggregate telemetry. They are transmitted only when an explicit product sync, share, upload, or AI action says so.
Billing and service providers
Paddle processes checkout, payment, tax, subscription, invoice, and refund information. CTC Extensions receives transaction and subscription references but does not store full payment-card details. Catalog prices are displayed in the supported region and currency; Paddle Checkout displays the final currency, tax, and total before payment.
We use service providers only where needed to operate the service, including Google for optional identity and cloud infrastructure, Cloudflare for security and selected storage or delivery functions, Resend for service email, Paddle for billing, and configured AI providers—including Orimise, OpenAI, Anthropic, or Gemini when selected for the requested feature—for user-requested AI processing. Their processing is governed by their applicable terms and privacy commitments.
Retention
Local extension data remains on your device until you delete it, a configured retention rule removes it, or the extension is uninstalled. Temporary screenshot shares expire after 24 hours. Generic Automate with AI input has a 15-minute job TTL; reviewable plans and SOP generation jobs/results expire within 24 hours as described above.
Account, workspace, security, support, subscription, and transaction records are retained only as long as reasonably required to provide the service, resolve disputes, prevent abuse, satisfy accounting or legal obligations, and enforce agreements. Retention can differ where law requires preservation.
Security
We use role- and workspace-based access controls, signed authorization flows, transport encryption, provider webhook verification, and operational safeguards appropriate to the information processed. No system is completely secure, so you should protect your account, device, exports, and shared links and notify us promptly of suspected unauthorized access.
Your choices and rights
You can manage Chrome site permissions, delete local extension data, revoke a share link, sign out to revoke an installation session, cancel a subscription, and change available account settings. Depending on applicable law, you may request access, correction, export, deletion, restriction, or objection through the contact page. Some billing, security, and audit records may be retained where legally required.
Children
CTC Extensions is not directed to children below the minimum age required to consent to online services in their location, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information without valid authorization.
Policy changes and contact
We may update this policy when products, providers, or legal requirements change. We will publish the revised version and update the date on this page. Send privacy questions or rights requests through the contact form or to [email protected].
