Browser Extension Privacy Policy

YouTube Video Download—4K&YouTube Shorts · version 0.4.42 · Last updated September 5, 2026

Only save content that you own or are authorized or otherwise permitted to save. This notice covers the browser extension; see the general HSK website privacy policy for other services.

English

Purpose and paid features

After a user opens the current YouTube video or Short, confirms the right or permission to save it, and clicks download, the extension reads available formats and saves the selected video, audio, or subtitles directly to that user's device. It does not continuously collect unrelated browsing history.

An HSK account is required. Subtitle-only saves cost no credits; video and MP3 tasks consume download credits; 1080p and above also require an active membership. Purchases happen at the HSK website checkout. The extension does not receive card numbers, payment passwords, verification codes, or payment-provider credentials.

Data handled and transmitted

DataUse and recipient
Email, username, random device ID, one-time authorization code, access token, device-bound refresh token, authorization stateHSK for sign-in, renewable device authorization, account display, and authenticated account/task requests. The refresh token is used only to rotate an expired session and is revoked on sign-out.
Membership status/expiry, credit balance, task debit/refund resultHSK for format authorization and entitlement accounting; no payment credential enters the extension.
IP address and country/region/city inferred from IPHSK records these during authorization-code exchange for sign-in security, device management, abuse prevention, and access-security logs. No GPS or precise location is requested.
Install, welcome page, toolbar click, panel open, authorization completionBefore sign-in, HSK receives only a random installation ID, extension version, UI locale, browser category, and allowlisted step. The installation-funnel table stores only an HMAC of that random ID and does not write the raw ID, IP address, page URL, video information, or account data. Normal HTTPS connections still expose the network address and may enter necessary short-lived security logs. Lifecycle events expire within 180 days.
Canonical URL/title of the current user-selected videoHSK for task deduplication, history, display, and entitlement accounting. Unrelated browsing history is not sent.
Panel open, format-detection result, download action, selected quality category/delivery mode, task-creation result, task state, sparse progress, final filename, structured errorHSK uses an allowlisted authorized-user funnel to distinguish no attempt, detection failure, and rejected task creation. Funnel events exclude video URLs, titles, media, tokens, and raw device identifiers. Task state supports concurrency, recovery, credits, refunds, and support. Live speed, ETA, and per-segment progress remain local.
Public format/subtitle descriptions and Google Video request/response metadataProcessed in the browser for selection and retrieval. HSK does not receive signed media URLs, subtitle text, full pages, or media bytes.

Normal HTTPS requests also expose User-Agent, UI locale, and request time to HSK for security and troubleshooting. HSK does not sell extension data or use it for advertising profiles, lending, credit eligibility, or marketing unrelated to this single purpose.

Temporary SABR context and media

For some YouTube SABR playback, the extension reads ustreamerConfig, clientInfo, short-lived poToken, a one-use player-response reload token, and the Google Video SABR URL from the same request already issued by the current player. The poToken, decoded clientInfo, and reload token stay in runtime memory and are stripped before task persistence; the reload token is discarded immediately after one player-response refresh attempt. To describe the current task for reload/recovery, ustreamerConfig, the SABR URL, client version, duration, and selected-format metadata are stored in local extension task state, not OPFS. None of this SABR context is sent to HSK; the complete temporary context is returned only to YouTube/Google Video for the user-requested player refresh and media fetch. In-memory context older than five minutes is unusable and is removed when the tab changes video or closes. The persisted SABR task description is removed at completion or retained for no more than 24 hours after cancellation or a recoverable failure.

Media, segments, and subtitle text travel directly from YouTube/Google Video to the browser. Segments needed for muxing, MP3, or SRT are processed locally in OPFS. HSK receives no downloaded video, audio, subtitle text, or media bytes.

Retention, deletion, permissions

  • Local access-token, device-bound refresh-token, account, and entitlement data remains until sign-out, session failure, revocation, clearing extension data, or uninstall. Sign-out revokes the refresh token. The random device ID and separate random installation-analytics ID survive ordinary sign-out and are removed when extension data is cleared or the extension is uninstalled.
  • Completed local task history is kept up to 30 days; notification deduplication up to 7 days; cancelled/recoverable failed OPFS segments and recovery state up to 24 hours. Completed OPFS data is removed after save.
  • Installation-funnel and account-scoped extension product events expire within 180 days. Account-scoped product events are included in account export and removed with approved account deletion; unlinkable installation events contain only the installation-ID HMAC.
  • HSK retains account, device, membership/credit, current-video task, debit/refund, privacy-minimal funnel, and necessary security records for service, history, accounting, refund, abuse, and disputes. These task records are not local-only or immediately deleted.
  • Users may export data or request deletion in the account dashboard or email support@hsk996.com. Approved deletion removes extension devices, short-lived credentials, download tasks, most account-scoped operational data, and invalidates tokens. Legally necessary order, refund, invoice, credit/membership transaction, anti-fraud, and dispute records may remain after identity links are removed or data is anonymized.

storage, unlimitedStorage, identity, downloads, webRequest, tabs, notifications, alarms, and Edge offscreen provide the account, OPFS, sign-in, saving, current-player observation, panel synchronization, completion notice, reliable active-task heartbeat/terminal-state scheduling, and local processing functions described above. alarms wakes the extension at fixed intervals when the browser suspends its background worker; it does not read system alarms, calendars, or other application data. Host access is limited to YouTube, Google Video, and download.hsk996.com. The extension does not request cookies or nativeMessaging, read/upload YouTube cookies or sessions, or download/execute remote code. Use and transfer comply with applicable browser-store data policies.

简体中文

用途与付费功能

用户打开当前 YouTube 视频或 Shorts、确认拥有保存权利或许可并主动点击后,扩展读取实际可用格式,把所选视频、音频或字幕直接保存到该用户设备,不持续收集无关浏览历史。

创建任务需登录 HSK 账号。字幕单独保存不消耗积分;视频和 MP3 消耗积分;1080p 及以上还需有效会员。购买在 HSK 网站收银台完成,扩展不接收银行卡号、支付密码、验证码或支付方凭证。

数据范围

HSK 为登录、设备、任务和权益处理邮箱、用户名、随机设备标识、一次性授权码、访问令牌、设备绑定刷新令牌、会员/积分状态;在授权换取令牌时记录 IP 及由 IP 推断的国家/地区/城市(不请求 GPS);用户创建任务时接收当前视频规范化 URL、标题、所选规格/交付方式、任务状态、稀疏进度、最终文件名和结构化错误。登录前安装漏斗只发送随机安装标识、版本、界面语言、浏览器类别及安装/欢迎页/工具栏/面板/授权完成步骤;安装漏斗表仅保存随机标识的 HMAC,不写入原始标识、IP、页面地址、视频信息或账号数据。正常 HTTPS 连接仍会向服务器暴露网络地址,并可能进入必要的短期安全日志。授权用户漏斗用于区分未尝试、识别失败和创建被拒绝;两类漏斗均不含视频 URL、标题、媒体内容或令牌。HSK 不接收无关浏览历史、签名媒体地址、字幕正文、完整网页或媒体字节。

SABR、保存与删除

部分 YouTube SABR 播放中,扩展会从播放器已发出的同一条请求读取 ustreamerConfigclientInfo、短期 poToken、一次性播放器响应刷新令牌和实际 SABR 地址。短期 poToken、解码后的 clientInfo 和刷新令牌只在内存暂存,写任务状态前清空;刷新令牌在一次播放器响应刷新尝试后立即丢弃。为保存当前任务的重载/恢复描述,ustreamerConfig、SABR 地址、客户端版本、时长和已选格式元数据会写入扩展本地任务状态(不写 OPFS)。这些 SABR 上下文都不发 HSK,完整临时上下文只返回 YouTube/Google Video,用于用户请求的播放器刷新和媒体获取。超过 5 分钟的内存上下文即不可用,切换视频或关闭标签页时移除;持久化描述在完成时删除,取消或可恢复失败后最多保留 24 小时。媒体、分片和字幕正文直接从 YouTube/Google Video 到浏览器,并在 OPFS 本地合并、转 MP3 或生成 SRT。

  • 本地访问令牌、设备绑定刷新令牌、账号和权益保留到退出、会话失效、撤销、清除数据或卸载;退出会撤销刷新令牌,随机设备 ID 和独立随机安装统计 ID 在普通退出后保留,清除扩展数据或卸载时删除。
  • 完成任务本地历史最多 30 天、通知去重最多 7 天、取消/可恢复失败的分片与恢复状态最多 24 小时;成功保存后删除对应 OPFS。
  • 安装漏斗与账号范围扩展产品事件最多保留 180 天。账号范围事件随账号数据导出并在批准删除账号时删除;无法关联账号的安装事件只含安装 ID 的 HMAC。
  • HSK 为服务、历史、权益、退款、反滥用和争议保留账号、设备、会员/积分、当前视频任务、扣减/退款、隐私最小化漏斗及必要安全记录;不是“仅本地”或“立即删除”。
  • 可在账号中心导出/申请删除,或联系 support@hsk996.com。批准删除后删除扩展设备、短期凭据、下载任务和大部分账号范围运行数据并使令牌失效;依法或为财务、反欺诈、争议所需记录可在解除身份关联/匿名化后保留。

权限仅用于上述账号、OPFS、登录、保存、当前播放器请求观察、面板同步、完成通知、活动任务心跳/终态的可靠调度和 Edge 本地后台处理。alarms 仅在浏览器暂停后台工作线程后按固定间隔唤醒扩展,不读取系统闹钟、日历或其他应用数据。主机限 YouTube、Google Video、download.hsk996.com。不申请 cookies/nativeMessaging,不读取或上传 YouTube Cookie/会话,不下载或执行远程代码,并遵守适用浏览器商店用户数据政策。