Toolkit for Janitor AI
Guide Demo Features Pro Download Privacy Terms

Privacy Policy

Last updated: 2026-08-12

This Privacy Policy explains how personal data is handled when you use the Toolkit for Janitor AI browser extension, visit our website, purchase a Pro license, or contact our support/community channels.

The important distinction is:

  • Extension data is primarily local. Chat context, generated media, provider credentials, preferences, and your license key are stored in your browser. The extension does not send that content to Volcanixduo.
  • Commercial and operational data is not entirely local. A purchase, license delivery, website request, support request, or Discord interaction involves the limited data described below and the relevant service providers.

We do not use advertising trackers, behavioral analytics, or fingerprinting, and we do not sell personal data.

1. Who is responsible for your data

The service is operated under the name Volcanixduo, which is the controller for the purchase fulfillment, website, and direct support processing described in this policy.

Privacy questions and data requests can be sent to volcanixduo@outlook.com.

For data processed independently by Stripe, Discord, JanitorAI, or a provider you configure in the extension, that provider's own privacy policy also applies.

2. Scope of this policy

This policy covers:

  • the Toolkit for Janitor AI browser extension;
  • janitorai-toolkit.volcanixduo.com and its release downloads;
  • Pro purchases, license generation, and transactional license emails;
  • support messages sent directly to us;
  • our handling of messages and moderation data in the Toolkit Discord server.

It does not govern janitorai.com or third-party AI, image, speech, payment, email, or community platforms acting under their own terms and policies.

3. Data handled locally by the extension

The following data is stored in the browser's local extension storage (chrome.storage.local) and is not transmitted to Volcanixduo by the extension:

  • chat messages and character/persona information read from the janitorai.com page you are viewing;
  • characters, cast, personas, scene state, prompt history, and other chat-scoped configuration created in the extension;
  • generated images and, when enabled, generated speech/audio;
  • image, language-model, and text-to-speech provider configuration, including provider URLs and API keys;
  • preferences, templates, defaults, and voice mappings;
  • your Pro license key and its local activation state.

This data remains until you remove it with the extension's deletion controls, clear the extension's browser storage, or uninstall the extension. Some chat-scoped data and generated media may also be removed automatically when a user-configured history limit is reached.

We cannot access, restore, correct, or delete data that exists only in your browser.

API keys and other local secrets

Provider API keys are stored unencrypted in the browser's local extension storage. Anyone who gains access to your browser profile or an exported copy of your extension data may be able to read them. Use restricted provider keys when available, do not share exported settings, and revoke any key you suspect has been exposed.

Local license verification

The Pro license key is verified locally using a cryptographic signature. Pasting or validating the key does not send it to Volcanixduo. This is separate from the purchase and delivery process described below.

4. Data sent to providers you choose

The extension connects directly from your browser to providers that you configure. Depending on the feature you use, the data sent may include:

  • relevant chat excerpts, character/persona information, scene summaries, or instructions sent to a configured LLM, summarizer, tagger, or TTS helper;
  • prompts, generation settings, reference images, or other inputs sent to an image provider;
  • text, speaker/voice selections, and synthesis settings sent to a text-to-speech provider;
  • API keys or other authorization credentials required by that provider.

Examples include self-hosted services such as ComfyUI, A1111/Forge, Ollama, AllTalk, or Kokoro, and hosted services such as NovelAI, AI Horde, Replicate, fal.ai, ElevenLabs, Edge TTS, or OpenAI-compatible endpoints. The available integrations may change over time.

Volcanixduo does not proxy or receive this provider traffic. You choose the provider and endpoint, and the provider's privacy policy, retention rules, and terms apply. Review them before sending chat content or personal data. A self-hosted endpoint is controlled by whoever operates that endpoint.

Optional provider access

The extension asks for host access only when it needs to connect to a provider address selected or configured by you. Permission is granted per provider origin, can be revoked from the extension's settings, and is used only for provider requests. It is not used to read, monitor, or track your browsing on other websites.

5. Website and update-check data

When you visit the website or download a release, the web server and hosting infrastructure may process standard request data, including:

  • IP address;
  • date and time;
  • requested path, response status, and transferred data size;
  • referring page, where supplied by the browser;
  • browser/user-agent information.

This data is used to deliver the requested content, maintain availability, diagnose faults, and protect the service against abuse. We do not use it to build advertising profiles.

The extension checks /releases/version.json for updates no more than about once every six hours. The request does not contain an account, license key, chat content, or a Volcanixduo-generated user identifier, but it necessarily exposes ordinary network data such as the IP address, time, and user agent to the web server.

The website currently uses no analytics service, advertising pixels, or non-essential cookies. If this changes, this policy and any required consent mechanism will be updated before those tools are enabled.

6. Purchases and license delivery

When you purchase Pro, Stripe processes the Checkout and payment. Stripe may collect your name, email address, billing address, country, payment details, tax-related information, and transaction/device information under its own privacy policy. Depending on the Checkout configuration, Stripe or Link may also act as merchant of record.

Volcanixduo does not receive or store your full payment-card number or card security code. To validate the purchase, prevent duplicate fulfillment, generate a license, deliver it, and support the order, our fulfillment service processes and stores:

  • the buyer email supplied through Stripe;
  • Stripe event type and event ID;
  • Checkout Session, PaymentIntent, and Customer identifiers, where supplied;
  • the purchased Stripe Price identifier;
  • an internally generated license identifier;
  • whether Stripe recorded acceptance of the Checkout Terms, the applicable Terms/Refund Policy versions, and the event time used as the consent record;
  • a cryptographic hash of the issued license key;
  • the email provider's delivery result/identifier;
  • the fulfillment date and time.

The full license key is generated in memory and sent to the buyer through Resend. The fulfillment store is configured not to retain the plaintext license key; it retains its cryptographic hash instead. The email message handled by Resend contains the recipient address and the full license key.

A valid payment confirmation and deliverable email address are necessary to fulfill a Pro purchase. If they are not provided, we cannot validate the order or deliver the license automatically.

Relevant provider policies: Stripe Privacy Policy and Resend Privacy Policy.

7. Support, email, and Discord

If you contact us, we process the information you choose to provide, such as your email address, Discord username, order reference, message content, attachments, and the history of the support conversation. Do not send API keys, passwords, full payment-card details, private chat transcripts, or other unnecessary sensitive information.

Email is currently handled through Microsoft Outlook for incoming support and through Resend for transactional license delivery. If you join or contact us through Discord, Discord independently processes your account and usage data under the Discord Privacy Policy.

Discord is optional and is not the only way to make a privacy request or ask for purchase support.

8. Purposes and legal bases

Where the GDPR or similar law applies, we rely on the following legal bases:

  • Performance of a contract or steps requested before a contract — to process an order, validate payment, generate and deliver a license, provide purchase support, and administer refunds or disputes.
  • Legal obligations — to retain or disclose records where required for tax, accounting, consumer-protection, fraud-prevention, or lawful authority requests.
  • Legitimate interests — to operate and secure the website and fulfillment service, maintain idempotent purchase records, prevent abuse, diagnose failures, respond to support, and establish or defend legal claims. We use only data reasonably necessary for those purposes.
  • Consent — only where we specifically ask for it for an optional purpose. We currently do not send marketing email or operate an analytics/advertising consent program.

We do not use the personal data we receive for automated decision-making or profiling that produces legal or similarly significant effects. Stripe may use automated systems for fraud and payment-risk decisions under its own policy.

9. Service providers and disclosures

We disclose data only as needed to operate the service, fulfill a request, or comply with law. Recipients may include:

  • Stripe/Link, for Checkout, payments, fraud prevention, tax handling where enabled, refunds, and disputes;
  • Resend, for transactional license email delivery;
  • our hosting and infrastructure providers, for serving the website, receiving the Stripe webhook, storing fulfillment records, backups, security, and operational logging;
  • Microsoft, for incoming email sent to our current support address;
  • Discord, when you voluntarily use our community server;
  • professional advisers, payment partners, or public authorities where reasonably necessary to comply with law or establish, exercise, or defend legal claims.

We do not sell or rent personal data. We do not disclose your locally stored chat content or API keys because we do not receive them.

10. International data transfers

Some providers may process data outside your country or outside the European Economic Area. Where we appoint a provider to process personal data on our behalf, transfers must use an applicable legal mechanism, such as an adequacy decision or approved contractual safeguards. Providers that act independently describe their own transfer arrangements in their privacy policies.

Your direct use of a provider configured in the extension is a direct connection between you and that provider. Check the provider's location and transfer terms before using it with personal data.

11. Retention

We use the following retention criteria:

  • Local extension data: until you delete it, clear extension storage, or uninstall the extension, subject to any history limit you configure.
  • Purchase and license-fulfillment records: for the operating life of the relevant license/service and, where necessary, for longer periods required by applicable tax, accounting, consumer, limitation, fraud, refund, or dispute obligations. These records are also needed to prevent duplicate fulfillment and verify purchase support requests.
  • Transactional email: according to the operational and retention settings of the email provider and for as long as needed to demonstrate delivery or resolve a purchase issue.
  • Website and infrastructure logs: only for the period reasonably needed for security, abuse prevention, and troubleshooting, according to the configured log-rotation and backup periods. Incident-related records may be kept longer where needed to investigate or defend a claim.
  • Support communications: until the request is resolved and for as long as reasonably needed to document the resolution, handle follow-up requests, or meet legal obligations.
  • Discord content: until deleted by the author or moderators, the server is closed, or Discord removes it under its own retention rules, subject to data needed for moderation or legal claims.

When data is no longer required, it will be deleted or anonymized where reasonably possible. A deletion request may not apply to records we must keep by law or need to establish, exercise, or defend legal claims.

12. Security

We use reasonable technical and organizational measures intended to limit access to the fulfillment service and its records. Stripe webhook signatures are verified before an event is processed, and the stored license value is a cryptographic hash rather than the plaintext key under the current configuration.

No method of network transmission, browser storage, or electronic storage is completely secure. In particular, license keys are delivered by email and local provider API keys are not encrypted in browser storage.

13. Your rights

Depending on your location, you may have rights to:

  • obtain confirmation and access to personal data we hold about you;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive applicable data in a portable format;
  • withdraw consent for future processing where consent is the legal basis;
  • lodge a complaint with a competent data-protection authority.

To exercise a right, email volcanixduo@outlook.com. We may ask for enough information to verify your identity and locate the relevant order or support record. Do not send your complete license key unless specifically required through a suitable support process.

For data stored only in the extension, use its deletion controls or clear the extension's browser storage; we cannot access that local data. Requests to Stripe, Discord, JanitorAI, or a provider you selected may also need to be made directly to that provider.

If you are in Italy, you may lodge a complaint with the Garante per la protezione dei dati personali. You may instead contact the supervisory authority for your habitual residence, place of work, or the place of an alleged infringement where applicable.

14. Children

The extension and paid service are intended only for users aged 18 or older. We do not knowingly offer the service to children.

15. Changes to this policy

We may update this policy when the product, providers, or legal requirements change. The current version and update date will be published at https://janitorai-toolkit.volcanixduo.com/privacy. Material changes will also be highlighted in an appropriate product or website notice where required.

16. Contact

Privacy questions and requests: volcanixduo@outlook.com.

© Volcanixduo. All rights reserved. JanitorAI is a trademark of its respective owners. Not affiliated, associated, authorized, endorsed by, or in any way officially connected with janitorai.com.
Guide FAQ Changelog Discord Privacy Policy Terms of Service Refund Policy Contact