Privacy Policy
Last updated: July 24, 2026
1. Overview
Product Research Assistant (the “Extension”) is a Chrome extension for lawful product research, review export, local review insights, and local competitor comparison. The Extension is independently developed and is not affiliated with, endorsed by, or sponsored by Temu.
This policy explains what information the Extension handles, why it is handled, where it is processed, when it may be shared with service providers, and the choices available to users.
2. Information handled by the Extension
2.1 Temu page and review information
Only after the user starts an export or insight task, the Extension may read information visible or made available to the current Temu product page, including:
- product title, URL, product ID, displayed price, seller/store information, displayed rating, and displayed review total when available;
- review rating, displayed review text, original-language review text when available, review date, variant, helpful count, media links, and repeat-purchase count;
- publicly displayed reviewer name and country/region when available to the page and included in a user-requested review export; and
- technical, locally derived identifiers used to recognize duplicate review rows during the active task.
Exported CSV, Excel, or JSON files are created at the user's request and may contain the public review fields described above. After a file is downloaded, the user controls that file and is responsible for storing and using it lawfully.
2.2 Response-first parsing
If the user enables response-first parsing, the Extension may locally parse recognized review data already returned to the current page after the user starts a collection task. It does not independently request additional review pages, replay private API calls, alter responses, or capture historical responses from ordinary browsing. If response parsing is unavailable or disabled, the Extension uses DOM-only parsing.
The response-first parser is limited to allowlisted review fields needed for the requested export or insight. It discards cookies, authorization and CSRF values, request signatures, device or anti-abuse values, order IDs, account IDs, moderation internals, recommendation data, and experiment fields. Raw response payloads are not persisted. The parser is disarmed when the task completes, pauses, fails, is cancelled, times out, navigates to another page or product, or the tab closes.
2.3 Local insight and competitor-library data
Review cleaning, rule-based insight generation, report generation, and comparison calculations run locally in the browser. When the user selects “Add to competitor comparison,” the Extension stores a minimized product-insight snapshot in chrome.storage.local. That snapshot may contain product metrics, rating distribution, collection coverage, themes, scores, recommendations, source URL, and timestamps. It excludes the complete raw review list and excludes reviewer name, avatar, user/account ID, profile link, and displayed country/region.
The local competitor library is not automatically synchronized between devices. Users may export and restore its versioned JSON backup. Backups do not include Stripe payment data, cached license credentials, install/device identifiers, Google Analytics data, complete raw reviews, or reviewer identity fields.
2.4 Account, license, and purchased-credit information
For subscription checkout, one-time collection-credit purchases, customer-portal access, or purchase restoration, the user provides an email address. The Extension also creates a random installation/device identifier. These values are used to:
- create or locate Stripe checkout and customer records;
- verify subscription and purchased-credit entitlements;
- apply the disclosed device limit;
- reserve, commit, release, refund, reverse, or freeze purchased credits; and
- prevent duplicate charging for the same collection operation.
The Extension stores the entered email, cached entitlement status, cached credit balance/status, install identifier, and operation identifiers in Chrome local storage. The authoritative subscription and purchased-credit records are maintained by the Cloudflare backend.
2.5 Usage analytics
The Extension may send limited product-usage events through a Cloudflare Worker to Google Analytics 4, such as installation, export or insight actions, success/error categories, quota or paywall events, checkout creation, entitlement verification, and purchased-credit lifecycle events.
Analytics events are designed not to include email addresses, phone numbers, reviewer names, review text, comments, payment-card data, or other directly identifying content. The analytics sanitizer rejects sensitive keys and long free-form strings. For clarity, review text is not sent to Google Analytics 4.
3. How information is used
Information is handled only to provide or improve the Extension's disclosed user-facing functions, including review export, local insights, competitor comparison, entitlement verification, payment operations, abuse prevention, reliability measurement, and support. We do not sell or rent review data, browsing content, account information, or analytics data. We do not use Extension-handled user data for personalized advertising, creditworthiness, or lending decisions.
4. Information sharing and service providers
The Extension uses the following providers only for the stated operational purposes:
- Stripe processes monthly and annual subscription checkout, one-time collection-credit checkout, payment methods, billing, taxes when applicable, refunds/disputes, and customer-portal sessions. Stripe receives the email and payment or offer information needed for those services. The developer does not receive or store full payment-card details.
- Cloudflare Workers, KV, and Durable Objects provide backend endpoints for checkout creation, Stripe webhooks, entitlement verification, device-limit enforcement, purchased-credit accounting, customer-portal creation, and analytics forwarding. Backend account records may include email, Stripe identifiers, plan/status, subscription period, device IDs, credit balances, operation-ledger entries, refund/dispute state, and timestamps. Review text and raw Temu response payloads are not sent to this backend.
- Google Analytics 4 receives the limited, filtered usage events described above. It does not receive review text or the user's purchase email from the Extension.
These providers may process standard network and service metadata under their own terms and privacy policies. Information may also be disclosed when reasonably necessary to comply with law, protect users or the service from fraud or abuse, or complete a merger or sale after any consent required by applicable policy or law.
5. Storage and retention
- Active review rows and response-first data are held in memory or task-scoped local state for the requested operation and are cleared or replaced as the workflow ends or restarts.
- User-requested exports remain wherever the user chooses to save them.
- Competitor snapshots and backups remain under the user's local control until deleted, restored over, extension data is cleared, the Chrome profile is removed, or the Extension is uninstalled.
- Locally cached email, entitlement, device, and operation state remains until cleared or replaced by the user or Extension workflow.
- Backend subscription, payment index, device-limit, purchased-credit, ledger, refund, and dispute records are retained as reasonably necessary to provide paid access, maintain accounting integrity, resolve disputes, prevent abuse, and meet legal obligations. Stripe may retain transaction records under its own policies and legal requirements.
6. Security
The Extension uses HTTPS for backend and provider communications and limits remote payloads to the information needed for billing, entitlement, accounting, analytics, and support purposes. No security method can guarantee absolute protection, so users should also protect their browser profile, exported files, and email account.
7. User choices and deletion requests
Users can:
- disable response-first parsing and use DOM-only collection;
- choose whether to export review files or save a product to the local competitor library;
- delete individual or all locally saved competitor products;
- export a local backup before clearing data;
- clear Extension storage or uninstall the Extension to remove local Extension data;
- cancel a recurring subscription through the Stripe Customer Portal; and
- request access to or deletion of developer-controlled account, entitlement, or purchased-credit information by emailing cloudrivercode@gmail.com.
A deletion request may require verification of the purchase email. Some billing, fraud-prevention, ledger, dispute, or legal records may be retained where reasonably necessary or legally required. Files previously exported by the user must be deleted by the user from their own device or storage provider.
8. Chrome Web Store Limited Use disclosure
Product Research Assistant's use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve the Extension's disclosed single purpose and related user-facing functions; it is not sold, used for personalized advertising, or transferred except as necessary to provide the service, for security, to comply with law, or as otherwise permitted by that policy with any required consent.
9. Children
The Extension is a business and product-research tool and is not directed to children. Users must be legally able to enter into the applicable terms for paid services in their jurisdiction.
10. Changes to this policy
This policy may be updated when Extension features, service providers, or legal obligations change. The published page will show the latest revision date. Material changes will be disclosed through an appropriate product or listing notice when required.
11. Contact
For privacy questions or requests, contact cloudrivercode@gmail.com.