Privacy · character-studio

Privacy Policy

character-studio browser extension
Effective date: 10 August 2026 · Operator: NOHNAI TECHNOLOGY PTE LTD (Singapore)

1. Overview

character-studio is a local-first browser extension that lets you build and simulate 8-dimensional psychological-fluid agents. It is published by NOHNAI TECHNOLOGY PTE LTD. The extension runs entirely on your device. It is designed so that your personal data is never uploaded to NOHNAI or to any third party, except for the model-provider API calls you initiate.

This Privacy Policy also applies to your-mirror, the app released by the same operator, NOHNAI TECHNOLOGY PTE LTD.

2. What data we collect and how we use it

character-studio is local-first. The data listed below is stored only on your device and is never transmitted to NOHNAI servers:

  • API key — entered by you to call your chosen model provider (e.g., Google Gemini). Stored locally in the browser's extension localStorage.
  • Agent and persona configurations — names, descriptions, personality traits, and system prompts you create. Stored locally.
  • Chat history and prompts — messages exchanged with your agents. Stored locally.
  • User preferences — model selection, temperature, display language, and other settings. Stored locally.

We use this data solely to provide the extension's core functionality: running psychological-fluid agent simulations in your browser.

3. What we do not collect

We do not collect, transmit, or store on any NOHNAI server:

  • Browsing history or any content of the websites you visit.
  • Personally identifiable information such as name, email, address, or phone number.
  • Analytics, telemetry, crash reports, or diagnostic data — none are sent.
  • Cookies, tracking identifiers, or advertising identifiers of any kind.
  • Device identifiers, IP addresses, or geolocation data — none are collected.

4. How we handle your API key

You may choose to enter a model-provider API key (for example, a Gemini key) so that the extension can call the model endpoint you specify. We handle it as follows:

  • Storage location: The key is stored locally inside the browser's extension localStorage, isolated from ordinary websites.
  • Security: The key is encrypted at rest using AES-256 encryption with a device-specific key derived from the browser's built-in crypto API.
  • Use purpose: The key is used only to authenticate requests to the model endpoint you configure, directly from your browser.
  • No transmission to NOHNAI: The key is never sent to NOHNAI servers. It is never logged, never backed up, and never synchronized across devices.
  • Retention & deletion: The key remains on your device until you clear it in the extension settings, clear browser data, or uninstall the extension. NOHNAI cannot delete it for you because we never have a copy.

5. Data processing, storage, and security

Processing: All data processing occurs entirely within your browser on your local device. NOHNAI does not process your data on our servers.

Storage: All data is stored in the browser's extension localStorage, which is isolated from ordinary websites. Data is retained until you manually delete it, clear browser data, or uninstall the extension.

Security measures:

  • API keys are encrypted at rest using AES-256 encryption with a device-specific key.
  • Extension storage is sandboxed and inaccessible to other websites or extensions.
  • No network transmission of your data to NOHNAI servers occurs.

Data breach notification: Because NOHNAI never receives or stores your data, we cannot be notified of a breach involving your local device. You are responsible for keeping your device and browser secure.

6. Permissions we request

character-studio does not request any special browser permissions. We keep the permission surface as small as possible because every permission should have a clear, user-visible reason. Below is the complete list of what we do not request, and why we do not need it.

storage

We do not request the storage permission because the extension already uses the browser's built-in localStorage, which is available to any popup without an extra permission. Your settings, API key, agents, and chat history are stored there.

tabs / activeTab

We do not read or interact with your tabs. The extension is a self-contained popup; it does not know which page you are on and cannot open, close, or inspect any tab.

host_permissions

We do not request access to any website or domain. The extension does not run content scripts on pages, does not inject code, and does not read page content.

background / service worker

The extension only runs when you open the popup. It does not run a background service worker, does not listen for events while closed, and does not consume resources or collect data in the background.

network / proxy / webRequest

We do not intercept, route, or proxy your network traffic. The only outbound request is the one you trigger directly: from your browser to your chosen model endpoint, using your own API key.

7. Third-party services and data sharing

When you configure and use a model-provider API key, your prompts, agent configurations, and chat messages are sent directly from your browser to that third-party provider's API endpoint. This is the only circumstance under which your data leaves your device.

Third-party providers we support (user-configured):

These providers process your data under their own privacy policies and terms of service. We do not control their data practices. You should review their policies before using their services.

NOHNAI does not: sell, rent, or share any user data with advertisers, data brokers, analytics providers, or any other third party (beyond the model-provider API calls you initiate).

8. User rights and control

You have the following rights regarding your data:

  • Access: All your data is stored locally on your device and is fully accessible within the extension interface.
  • Modification: You can edit, update, or delete your agents, personas, settings, and chat history at any time through the extension UI.
  • Deletion: You can clear all stored data by clicking the clear button inside the extension, by removing the extension's site data in your browser settings, or by uninstalling the extension entirely. Because data is local-only, deletion is immediate and irreversible.
  • Export/Portability: You can export your agent configurations and chat history as JSON files from within the extension.
  • Opt-out: You are never required to provide any personal information. You may use the extension without entering an API key (in which case the extension operates in a limited, offline mode).

9. Data retention

All data lives on your device. It is retained until you delete it manually, clear the extension's local storage, or uninstall the extension. NOHNAI cannot delete it for you because we never have a copy of it.

10. Security

Your API key and local data are stored inside the browser's extension sandbox, which is isolated from ordinary websites. API keys are encrypted at rest using AES-256 encryption. However, you are responsible for keeping your device and browser secure. We recommend that you do not install character-studio on shared or untrusted devices.

11. Legal basis for processing (GDPR)

For users in the European Economic Area (EEA), our legal basis for processing your data is legitimate interest (providing the core functionality of the extension) and consent (for storing your API key and chat data). You provide explicit consent when you enter your API key or create agent configurations. You may withdraw consent at any time by clearing your data or uninstalling the extension.

For users in other jurisdictions, we process data based on the necessity to perform our contract with you (providing the extension service).

12. International data transfers

Because all data is stored locally on your device, NOHNAI does not transfer your data across borders. However, when you use a third-party model provider API (e.g., Google Gemini, OpenAI), your data is transmitted to that provider's servers, which may be located in the United States or other jurisdictions. Please review the provider's privacy policy for details on international transfers.

13. Children

character-studio is not directed to children under 13 and does not knowingly process their data.

See our full Child Safety Standards (CSAE) below.

Child Safety Standards (CSAE Prevention)

NOHNAI TECHNOLOGY PTE LTD ("NOHNAI", the developer and publisher named on the Google Play listing for character-studio) maintains the following published standards against Child Sexual Abuse and Exploitation (CSAE). This section is the globally accessible web resource referenced in the Google Play Child Safety Standards declaration.

CSAE policy statement

NOHNAI has a zero-tolerance policy for child sexual abuse and exploitation in any form. We prohibit the use of character-studio to create, share, or solicit any content that sexually exploits, abuses, or endangers children, including grooming a child for sexual exploitation, sextorting a child, or trafficking a child for sex. This standard applies regardless of whether the app has any child users.

In-app feedback mechanism

character-studio provides an in-extension feedback entry inside the popup interface through which users can report child-safety concerns without leaving the extension. As a fallback, users may report directly to our child-safety contact at ai@nohnlins.com. Both routes are monitored by the same responsible owner.

CSAM handling procedure

Upon obtaining actual knowledge of Child Sexual Abuse Material (CSAM) within character-studio, NOHNAI will take immediate appropriate action in line with this standard and applicable law: remove or disable access to the material, preserve relevant records, and report confirmed CSAM to the National Center for Missing & Exploited Children (NCMEC) or the relevant regional authority. Because the extension is local-first and NOHNAI never receives user content, reports typically originate from user-initiated disclosure.

Compliance with child-safety laws

NOHNAI complies with applicable child-safety laws and regulations across its operating jurisdictions, including Singapore's Children and Young Persons Act and relevant international frameworks. We review this standard periodically and update it as laws and platform requirements evolve.

CSAM point of contact

Our designated point of contact for CSAE/CSAM notifications is ai@nohnlins.com, operated by NOHNAI TECHNOLOGY PTE LTD. This individual is empowered to discuss our CSAE prevention practices and respond to enforcement inquiries from Google Play or relevant authorities.

14. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the effective date above. Continued use of the extension constitutes acceptance of the updated policy.

15. Contact

Questions about this policy or your data: ai@nohnlins.com

This page is provided for the Chrome Web Store privacy disclosure. It describes the extension's actual behaviour as built.

隐私权 · character-studio

隐私权政策

character-studio 浏览器扩展
生效日期:2026 年 8 月 10 日 · 运营方:NOHNAI TECHNOLOGY PTE LTD(新加坡)

1. 概述

character-studio 是一款本地优先的浏览器扩展,用于构建与模拟八维心理流体智能体,由 NOHNAI TECHNOLOGY PTE LTD 发布。扩展完全运行在你的设备上,设计上确保你的个人数据绝不上传至 NOHNAI 或任何第三方,除非你主动发起模型提供商 API 调用。

本隐私权政策同样适用于 your-mirror(由同一运营方 NOHNAI TECHNOLOGY PTE LTD 发布的 App)。

2. 我们收集哪些数据及如何使用

character-studio 采用本地优先架构。以下数据仅存储在你的设备上,绝不会传输到 NOHNAI 服务器:

  • API Key——由你输入,用于调用你选择的模型提供商(例如 Google Gemini)。本地存储在浏览器扩展的 localStorage 中。
  • 智能体与角色配置——你创建的名称、描述、性格特征和系统提示词。本地存储。
  • 聊天历史与提示词——你与智能体之间的对话消息。本地存储。
  • 用户偏好设置——模型选择、温度参数、显示语言及其他设置。本地存储。

我们仅使用这些数据提供扩展的核心功能:在你的浏览器中运行心理流体智能体模拟。

3. 我们不收集的内容

我们不会在 NOHNAI 的任何服务器上收集、传输或存储以下内容:

  • 浏览历史或你访问的任何网页内容。
  • 个人身份信息,如姓名、邮箱、地址或电话号码。
  • 分析、遥测、崩溃报告或诊断数据——均不发送。
  • 任何类型的Cookie、追踪标识或广告标识。
  • 设备标识符、IP 地址或地理位置数据——均不收集。

4. 我们如何处理你的 API Key

你可以自行输入模型服务商的 API Key(例如 Gemini Key),以便扩展调用你指定的模型端点。我们的处理方式如下:

  • 存储位置:该 Key 存储在浏览器扩展的 localStorage 中,与普通网页隔离。
  • 安全措施:该 Key 使用 AES-256 加密算法进行静态加密,密钥通过浏览器内置的加密 API 基于设备特征派生。
  • 使用目的:该 Key 仅用于对你配置的模型端点进行身份验证请求,直接从你的浏览器发出。
  • 不向 NOHNAI 传输:该 Key 绝不会发送给 NOHNAI 服务器。它不会被记录、不会备份、不会跨设备同步。
  • 保留与删除:该 Key 保留在你的设备上,直到你在扩展设置中清除、清除浏览器数据或卸载扩展。NOHNAI 无法替你删除,因为我们从未保留任何副本。

5. 数据处理、存储与安全

处理:所有数据处理完全在你的浏览器本地设备上进行。NOHNAI 不在我们的服务器上处理你的数据。

存储:所有数据存储在浏览器扩展的 localStorage 中,与普通网页隔离。数据将保留到你手动删除、清除浏览器数据或卸载扩展为止。

安全措施:

  • API Key 使用 AES-256 加密算法配合设备特定密钥进行静态加密。
  • 扩展存储处于沙盒环境中,其他网站或扩展无法访问。
  • 你的数据不会通过网络传输到 NOHNAI 服务器。

数据泄露通知:由于 NOHNAI 从未接收或存储你的数据,我们无法获知涉及你本地设备的数据泄露事件。你有责任保证你的设备和浏览器安全。

6. 我们所申请的权限

character-studio 不申请任何特殊的浏览器权限。 我们把权限范围压到最小,因为每一项权限都应该有清晰、可见的用户价值。以下是我们不申请的权限及其原因。

storage

我们不申请 storage 权限,因为扩展已经使用浏览器内置的 localStorage,任何弹窗都无需额外权限即可使用。你的设置、API Key、智能体与聊天历史均保存在其中。

tabs / activeTab

我们不读取或操作你的标签页。扩展是一个自包含的弹窗,它不知道你正在访问哪个页面,也无法打开、关闭或检查任何标签页。

host_permissions

我们不申请访问任何网站或域名。扩展不在网页上运行 content script、不注入代码、也不读取页面内容。

background / service worker

扩展仅在你打开弹窗时运行。它没有后台 service worker,不在关闭时监听事件,也不在后台消耗资源或收集数据。

network / proxy / webRequest

我们不拦截、路由或代理你的网络流量。唯一的出站请求是由你主动触发、从你的浏览器发往你选定的模型端点,并使用你自己的 API Key。

7. 第三方服务与数据共享

当你配置并使用模型提供商 API Key 时,你的提示词、智能体配置和聊天消息将直接从你的浏览器发送到该第三方提供商的 API 端点。这是你数据离开设备的唯一情形。

我们支持的第三方提供商(由用户配置):

这些提供商依据其自身的隐私政策和服务条款处理你的数据。我们不控制其数据实践。在使用其服务前,请查阅其政策。

NOHNAI 不会:向广告商、数据经纪人、分析服务商或任何其他第三方(除你主动发起的模型提供商 API 调用外)出售、出租或共享任何用户数据。

8. 用户权利与控制

你享有以下数据权利:

  • 访问权:你的所有数据均存储在你本地的设备上,可通过扩展界面完全访问。
  • 修改权:你可以随时通过扩展 UI 编辑、更新或删除你的智能体、角色、设置和聊天历史。
  • 删除权:你可以通过点击扩展内的清除按钮、在浏览器设置中移除扩展的站点数据,或直接卸载扩展来清除所有存储数据。由于数据完全本地存储,删除是即时且不可逆的。
  • 导出/可携带权:你可以从扩展内导出你的智能体配置和聊天历史为 JSON 文件。
  • 退出权:你无需提供任何个人信息即可使用扩展。你可以在不输入 API Key 的情况下使用扩展(此时扩展以有限的离线模式运行)。

9. 数据留存

所有数据均存于你的设备,在你手动删除、清除扩展的本地存储或卸载扩展之前一直保留。NOHNAI 无法替你删除,因为我们从未保留任何副本。

10. 安全

你的 API Key 与本地数据保存在浏览器的扩展沙盒中,与普通网页隔离。API Key 使用 AES-256 加密算法进行静态加密。但你需要自行保证设备与浏览器的安全。我们不建议在共享或不受信任的设备上安装 character-studio。

11. 处理的法律依据(GDPR)

对于欧洲经济区(EEA)用户,我们处理你数据的法律依据是合法利益(提供扩展核心功能)和同意(存储你的 API Key 和聊天数据)。你在输入 API Key 或创建智能体配置时提供明确的同意。你可以随时通过清除数据或卸载扩展撤回同意。

对于其他司法管辖区的用户,我们基于履行与你的合同之必要性(提供扩展服务)来处理数据。

12. 国际数据传输

由于所有数据均存储在你本地的设备上,NOHNAI 不会将你的数据传输至境外。但是,当你使用第三方模型提供商 API(例如 Google Gemini、OpenAI)时,你的数据将被传输至该提供商的服务器,其可能位于美国或其他司法管辖区。请查阅提供商的隐私政策以了解国际传输详情。

13. 未成年人

character-studio 不面向 13 岁以下儿童,也不会有意处理其数据。

查看下方完整的儿童安全标准(CSAE 防范)。

儿童安全标准(CSAE 防范)

NOHNAI TECHNOLOGY PTE LTD(以下简称"NOHNAI",即 Google Play 商店 character-studio 应用列出的开发者与发布者)制定以下反对儿童性虐待与性剥削(CSAE)的公开标准。本节为 Google Play 儿童安全标准中声明的全球可达网络资源。

CSAE 政策声明

NOHNAI 对任何形式的儿童性虐待与性剥削采取零容忍政策。我们禁止将 character-studio 用于创建、分享或索取任何性剥削、虐待或危害儿童的内容,包括诱奸儿童、对儿童实施性勒索,或对儿童进行性贩卖。无论应用是否存在儿童用户,本标准均适用。

应用内反馈机制

character-studio 在弹窗界面内提供扩展内反馈入口,用户无需离开扩展即可举报儿童安全相关问题。作为兜底,用户也可直接向我方儿童安全联络邮箱 ai@nohnlins.com 举报。两条渠道由同一责任主体受理。

CSAM 处理流程

一旦确知 character-studio 内存在儿童性虐待素材(CSAM),NOHNAI 将依据本标准与适用法律立即采取适当行动:移除或禁用对该素材的访问、留存相关记录,并向美国国家失踪与受剥削儿童中心(NCMEC)或相应区域主管机关报告已确认的 CSAM。由于扩展本地优先、NOHNAI 从不接收用户内容,举报通常源于用户主动披露。

遵循儿童安全法律

NOHNAI 遵守各运营司法管辖区适用的儿童安全法律法规,包括新加坡《儿童与青少年法》及相关国际框架。我们定期审阅本标准,并随法律与平台要求的变化而更新。

CSAM 联络人

我方指定的 CSAM 通知联络人为 ai@nohnlins.com,由 NOHNAI TECHNOLOGY PTE LTD 运营。该联络人有权就我们的 CSAE 防范实践进行沟通,并响应 Google Play 或相关主管机关的执行问询。

14. 本政策的变更

我们可能不时更新本政策。重大变更将通过以上生效日期体现。继续使用扩展即视为接受更新后的政策。

15. 联系我们

有关本政策或你的数据问题:ai@nohnlins.com

本页面为 Chrome 应用商店隐私权披露而提供,如实描述扩展的实际行为。