Last updated: 2026-08-12
This Privacy Policy explains how personal data is handled when you use the Toolkit for Janitor AI browser extension, visit our website, purchase a Pro license, or contact our support/community channels.
The important distinction is:
We do not use advertising trackers, behavioral analytics, or fingerprinting, and we do not sell personal data.
The service is operated under the name Volcanixduo, which is the controller for the purchase fulfillment, website, and direct support processing described in this policy.
Privacy questions and data requests can be sent to volcanixduo@outlook.com.
For data processed independently by Stripe, Discord, JanitorAI, or a provider you configure in the extension, that provider's own privacy policy also applies.
This policy covers:
janitorai-toolkit.volcanixduo.com and its
release downloads;
It does not govern janitorai.com or third-party AI, image, speech, payment, email, or community platforms acting under their own terms and policies.
The following data is stored in the browser's local
extension storage (chrome.storage.local) and is
not transmitted to Volcanixduo by the extension:
This data remains until you remove it with the extension's deletion controls, clear the extension's browser storage, or uninstall the extension. Some chat-scoped data and generated media may also be removed automatically when a user-configured history limit is reached.
We cannot access, restore, correct, or delete data that exists only in your browser.
Provider API keys are stored unencrypted in the browser's local extension storage. Anyone who gains access to your browser profile or an exported copy of your extension data may be able to read them. Use restricted provider keys when available, do not share exported settings, and revoke any key you suspect has been exposed.
The Pro license key is verified locally using a cryptographic signature. Pasting or validating the key does not send it to Volcanixduo. This is separate from the purchase and delivery process described below.
The extension connects directly from your browser to providers that you configure. Depending on the feature you use, the data sent may include:
Examples include self-hosted services such as ComfyUI, A1111/Forge, Ollama, AllTalk, or Kokoro, and hosted services such as NovelAI, AI Horde, Replicate, fal.ai, ElevenLabs, Edge TTS, or OpenAI-compatible endpoints. The available integrations may change over time.
Volcanixduo does not proxy or receive this provider traffic. You choose the provider and endpoint, and the provider's privacy policy, retention rules, and terms apply. Review them before sending chat content or personal data. A self-hosted endpoint is controlled by whoever operates that endpoint.
The extension asks for host access only when it needs to connect to a provider address selected or configured by you. Permission is granted per provider origin, can be revoked from the extension's settings, and is used only for provider requests. It is not used to read, monitor, or track your browsing on other websites.
When you visit the website or download a release, the web server and hosting infrastructure may process standard request data, including:
This data is used to deliver the requested content, maintain availability, diagnose faults, and protect the service against abuse. We do not use it to build advertising profiles.
The extension checks /releases/version.json for
updates no more than about once every six hours. The request
does not contain an account, license key, chat content, or a
Volcanixduo-generated user identifier, but it necessarily
exposes ordinary network data such as the IP address, time,
and user agent to the web server.
The website currently uses no analytics service, advertising pixels, or non-essential cookies. If this changes, this policy and any required consent mechanism will be updated before those tools are enabled.
When you purchase Pro, Stripe processes the Checkout and payment. Stripe may collect your name, email address, billing address, country, payment details, tax-related information, and transaction/device information under its own privacy policy. Depending on the Checkout configuration, Stripe or Link may also act as merchant of record.
Volcanixduo does not receive or store your full payment-card number or card security code. To validate the purchase, prevent duplicate fulfillment, generate a license, deliver it, and support the order, our fulfillment service processes and stores:
The full license key is generated in memory and sent to the buyer through Resend. The fulfillment store is configured not to retain the plaintext license key; it retains its cryptographic hash instead. The email message handled by Resend contains the recipient address and the full license key.
A valid payment confirmation and deliverable email address are necessary to fulfill a Pro purchase. If they are not provided, we cannot validate the order or deliver the license automatically.
Relevant provider policies: Stripe Privacy Policy and Resend Privacy Policy.
If you contact us, we process the information you choose to provide, such as your email address, Discord username, order reference, message content, attachments, and the history of the support conversation. Do not send API keys, passwords, full payment-card details, private chat transcripts, or other unnecessary sensitive information.
Email is currently handled through Microsoft Outlook for incoming support and through Resend for transactional license delivery. If you join or contact us through Discord, Discord independently processes your account and usage data under the Discord Privacy Policy.
Discord is optional and is not the only way to make a privacy request or ask for purchase support.
Where the GDPR or similar law applies, we rely on the following legal bases:
We do not use the personal data we receive for automated decision-making or profiling that produces legal or similarly significant effects. Stripe may use automated systems for fraud and payment-risk decisions under its own policy.
We disclose data only as needed to operate the service, fulfill a request, or comply with law. Recipients may include:
We do not sell or rent personal data. We do not disclose your locally stored chat content or API keys because we do not receive them.
Some providers may process data outside your country or outside the European Economic Area. Where we appoint a provider to process personal data on our behalf, transfers must use an applicable legal mechanism, such as an adequacy decision or approved contractual safeguards. Providers that act independently describe their own transfer arrangements in their privacy policies.
Your direct use of a provider configured in the extension is a direct connection between you and that provider. Check the provider's location and transfer terms before using it with personal data.
We use the following retention criteria:
When data is no longer required, it will be deleted or anonymized where reasonably possible. A deletion request may not apply to records we must keep by law or need to establish, exercise, or defend legal claims.
We use reasonable technical and organizational measures intended to limit access to the fulfillment service and its records. Stripe webhook signatures are verified before an event is processed, and the stored license value is a cryptographic hash rather than the plaintext key under the current configuration.
No method of network transmission, browser storage, or electronic storage is completely secure. In particular, license keys are delivered by email and local provider API keys are not encrypted in browser storage.
Depending on your location, you may have rights to:
To exercise a right, email volcanixduo@outlook.com. We may ask for enough information to verify your identity and locate the relevant order or support record. Do not send your complete license key unless specifically required through a suitable support process.
For data stored only in the extension, use its deletion controls or clear the extension's browser storage; we cannot access that local data. Requests to Stripe, Discord, JanitorAI, or a provider you selected may also need to be made directly to that provider.
If you are in Italy, you may lodge a complaint with the Garante per la protezione dei dati personali. You may instead contact the supervisory authority for your habitual residence, place of work, or the place of an alleged infringement where applicable.
The extension and paid service are intended only for users aged 18 or older. We do not knowingly offer the service to children.
We may update this policy when the product, providers, or legal requirements change. The current version and update date will be published at https://janitorai-toolkit.volcanixduo.com/privacy. Material changes will also be highlighted in an appropriate product or website notice where required.
Privacy questions and requests: volcanixduo@outlook.com.