Privacy Policy
This Privacy Policy describes how 321BRO (“321”, “we”) currently processes information for 321 Downloader: the public website at downloader.321bro.com, related account and license services, and the browser extension for Google Chrome, Microsoft Edge, and Mozilla Firefox.
This is a shared product policy. Store listings for Chrome, Edge, and Firefox point to this page. It does not invent processors, analytics SDKs, or retention periods that the current product does not implement. Some legal-process items remain marked for review.
#Introduction
321BRO operates 321 Downloader at https://downloader.321bro.com. The product includes the public website, account and billing pages, APIs used by the browser extension, and the Chrome, Edge, and Firefox extensions themselves.
The extension communicates with 321 first-party services at downloader.321bro.com for product functionality. Depending on the request, that can include product configuration or support information, platform or site-support resolution, account authentication, license or entitlement checks, account status, and compatibility or review information. Not every request contains every field.
This policy describes current behavior. It does not make claims about future AI features or about the privacy practices of third-party websites you visit.
#Chrome Web Store version
This page is a shared product policy. Edge, Firefox, and Chrome builds that are not the Chrome Web Store distribution may still send a hostname or hostKey for site-support resolution, may run a signed-in compatibility or review-session flow, and may request a site icon from Google’s favicon service using a domain.
The Chrome Web Store version of 321 Downloader is a more restricted distribution. In that Chrome Web Store distributed version: automatic hostKey or domain capability lookup to 321 is disabled; signed-in compatibility or review-session reporting to 321 is disabled; and Google favicon or domain lookup is disabled.
The Chrome Web Store version may still transmit to 321, when the user signs in or the product needs entitlement, an installation identifier, authentication or session credentials, extension version, platform or store information, locale, and account or license information. It may also fetch product or recipe configuration artifacts that do not include the current page’s hostname. Session credentials are tokens used to keep the signed-in session, not website passwords and not raw payment-card numbers.
Other Chrome builds, Microsoft Edge, and Firefox are not described by the Chrome Web Store restrictions above unless those distributions are separately documented.
#Information We Process
321 processes information needed to run the product: account identity from sign-in, authentication and session information, a persistent installation identifier used to connect the extension, license and usage counters, product, version, platform, store, and locale information where applicable, hostname or hostKey information for supported-site detection and related operation, signed-in compatibility or review outcomes where that flow runs, and operational cookies that keep you signed in and remember locale.
The sections below list categories that exist in the current implementation. 321 does not collect your website passwords through the extension, and the extension does not collect raw payment-card numbers.
#Account Information
Signed-in users have a profile record that can store email, display name, avatar URL, sign-in provider, locale, and a diagnostics access level used by admins.
Account pages can show plan and device summaries derived from license and installation records tied to that user. The extension may transmit account or license status needed to show entitlement. 321 does not ask the extension to send passwords for third-party websites.
#Authentication Providers
Account sign-in is implemented with Supabase Auth. The live OAuth providers on the login screen are Google, Apple, and Facebook.
WeChat and Microsoft appear as UI placeholders and do not complete OAuth in the current website. Kakao and email/password controls are hidden from the login UI; those backend capabilities are not presented as active collection on this page.
#Device and Installation Information
Connecting the browser extension creates or updates an installation record with a persistent installation identifier. That identifier is used for ownership, last-seen, revocation, connect/exchange, and related product operation. It can be associated with an account when the extension is connected.
The website can bind the current browser to the last approved installation with an HttpOnly cookie. Device count is recorded for account views; it is not used to reject login or token exchange. The extension may also send product, version, platform, store, and locale information where that is needed for support or entitlement.
#Browsing and Website Information
For supported-site detection, product policy or configuration, and related operation, the extension may send the current page’s hostname or a derived hostKey to 321 services. That is domain-level website activity, not a copy of your complete browsing history.
The normal product data flow does not send the full page URL to 321. It does not send the media URL to 321. It does not send a video or content ID to 321 as a content identifier.
321 therefore can receive hostname or domain-level information needed to operate the product. 321 does not, in normal operation, receive the full browsing URL or media location.
The Chrome Web Store version does not send that hostname or hostKey; see Chrome Web Store version.
#Review and Compatibility Information
When a signed-in review or compatibility flow runs, the extension may send 321 the hostname or domain, extension public and internal version information, platform or store information, detection result, download compatibility result, detection mode, and failure stage or evidence where applicable.
This information is used for product compatibility and reliability. It is not used for advertising measurement, and it is not a full browsing-history collection.
The Chrome Web Store version does not run that signed-in compatibility or review-session reporting; see Chrome Web Store version.
#Download / Processing Metadata
The website stores plan usage related to premium downloads. It does not store the downloaded media files themselves.
Page URLs, media URLs, filenames, and other per-download content identifiers are not sent to 321 as the normal product data flow, and they are not modeled as a first-class web database in the current implementation.
#Media Content
Normal extension operation does not transmit to 321 the downloaded media bytes, audio used for transcription, transcript or caption text, the full media URL, or the full page URL.
To perform the browser or media operation you requested, the extension may communicate directly with the website or media host you are accessing. That communication is with the origin you chose, not a copy of the media sent to 321 servers.
#321 Scripter and On-Device Speech Recognition
321 Scripter speech recognition currently runs locally, on-device, in the extension or browser. AI model and runtime assets are packaged with the product. Remote speech-to-text to 321 is not used (remote STT = 0).
Audio is not uploaded to 321 for transcription. Generated transcript or caption text is not uploaded to 321 for transcription. Chrome and Edge may use local WebGPU acceleration when enabled. Firefox uses its local WASM path. These are local processing paths, not remote transcription services.
Caption Assets and related history may be stored in the browser. Exported TXT or SRT files are user-controlled local files. STT on the website is implemented as a licensed usage bucket measured in capacity, not as a transcript archive. This section describes current Scripter behavior only; it does not claim how all future AI features will work.
#Usage Data
The license server stores usage buckets for plan metrics that the product already implements, including Fast-Track premium downloads and STT capacity.
These records are counters and remaining-capacity snapshots used to enforce the plan. They are not a full analytics product. No third-party web analytics library or telemetry SDK (for example a page-view tracker) is present in the website source.
#Cookies and Similar Technologies
The site uses Supabase Auth session cookies to keep a signed-in browser session.
It also sets a locale cookie named libu_locale and, after an approved extension connect, an HttpOnly cookie named libu_ext_installation_id (about 30 days) that binds the browser to that installation. No separate advertising or analytics cookie SDK is included in the website source.
#Payments
Paid plans are processed on the website through Stripe Checkout and related Stripe billing, not inside the browser extension. The extension does not itself collect raw payment-card information.
Stripe processes the payment details you submit on Stripe-hosted pages. 321 stores order, subscription, and payment records needed to provide the plan and meet legal billing duties. Those records do not include raw card numbers in the current website implementation.
#Third-Party Requests from the Extension
The extension may request Google’s favicon service using domain or hostname information so the product can show a site icon. Google receives the hostname needed to fetch that icon. This does not send media contents from 321 to Google.
Other third-party requests that happen because you opened a website or media host are described in Media Content. They are not 321 sending that media to 321 servers.
The Chrome Web Store version does not request Google’s favicon service; see Chrome Web Store version.
#How We Use Information
We use this information to provide supported-site detection and other product functionality you request, authenticate you, connect and sync the extension, issue and enforce licenses, show account and plan status, operate compatibility and reliability review, and operate admin tools for support and abuse response where those tools exist.
The current website and extension do not use this information for advertising, to build behavioral advertising profiles, or “for any business purpose” beyond operating the product as described here.
#Service Providers
Authentication and the application database run on Supabase. The production website is deployed on Vercel to downloader.321bro.com. Paid checkout and subscription billing run through Stripe.
Sign-in with Google, Apple, or Facebook, and the Google favicon request described above, are processed by those providers under their own policies. 321 does not name additional email, analytics, or support-desk processors here because they are not wired as live collection in the current website.
#Sharing, Sale, and Advertising
The current product does not sell personal data. It does not use browsing or website-activity information for targeted advertising. It does not share audio or transcripts for advertising.
Infrastructure and service providers named above process information as needed to operate authentication, hosting, and payment. 321 does not claim that no service provider ever processes data on 321’s behalf.
#Data Retention
Scripter Caption Assets kept in the browser use a local cache with a sliding last-access lifetime of about 30 days. Physically exported TXT or SRT files on your device are not deleted by that cache lifetime.
You can delete your account from Account. Deletion is scheduled with a grace period of seven days, not immediate. After confirmation completes, personal account data is deleted or de-identified as described in the account-deletion process. Payment, tax, and audit records may be kept for legal duties.
Server-side authentication, license, installation, and compatibility records are kept while needed to operate the account, provide the product, prevent abuse, and meet legal duties. Exact statutory retention periods are not published here.
#Data Security
Session cookies are set by the auth stack. The extension installation cookie is HttpOnly, Secure, and SameSite=Lax. License signing keys are server-side and are not shipped to the public website bundle.
No specific certification (for example ISO or SOC) is claimed in this policy.
#International Data Transfers
TODO — pending legal review. Facts below are limited to what the current product actually implements.
Supabase, Vercel, Stripe, and sign-in providers may process data on infrastructure outside the country where you use the Service.
Transfer mechanisms, regions, and any standard-contractual-clause language are not confirmed. No destination country is invented here.
#Your Rights and Controls
You can sign out and request account deletion from Account. Deletion is scheduled after a seven-day grace period, not immediate. You can uninstall the browser extension, which removes extension data stored in that browser according to the browser’s uninstall behavior.
Local Caption Assets in the browser follow the cache lifetime described above. Exported TXT or SRT files remain on your device until you delete them. A self-serve data-export console is not documented as a live feature.
Statutory rights (access, correction, deletion, portability, objection) depend on applicable law. Privacy questions and requests can be sent to support@321bro.com.
#Children’s Privacy
TODO — pending legal review. Facts below are limited to what the current product actually implements.
This policy does not state a minimum age and does not claim that the Service is directed to children.
The age rule and any parental-consent language remain subject to legal review.
#Third-Party Links and Services
Sign-in with Google, Apple, or Facebook, Stripe checkout, browser store listings, origin websites or media hosts you visit, and links on marketing pages send you to third parties that have their own privacy policies.
Those policies are not restated here.
#Changes to This Privacy Policy
TODO — pending legal review. Facts below are limited to what the current product actually implements.
This page will be updated when the product’s actual collection or processing changes.
How we notify users of material changes remains subject to legal review.
#Contact Us
Privacy questions and requests can be sent to support@321bro.com.
321 Downloader is operated by OK TK COMPANY LIMITED. No postal address or data-protection officer is named in this policy.