Dual Subs
Back to home

Privacy Policy, Dual Sub

Last updated: July 22, 2026 Seller / data controller: Dual Sub ("we", "us") Extension: Dual Sub (Chrome Extension) Website: https://dualsub.dev Contact: infodualsubtitle@gmail.com

Dual Sub is a browser extension operated by Dual Sub that displays dual subtitles and an inline dictionary on Netflix, YouTube, Amazon Prime Video, and Disney+. Dual Sub acts as the data controller for personal data processed through the Dual Sub website and extension. This policy explains what data we handle, where it is sent, the legal basis for each use, and your choices. We have tried to keep it plain and accurate to what the code actually does.


1. Summary

  • You can try the extension for 8 days without an account. To keep using it after that, you create a free account (which includes a 15-day trial); continued use afterward requires a paid plan. An account also enables cloud sync of your vocabulary and settings.
  • We do not sell your data, show ads, or use third-party trackers/analytics.
  • The extension reads subtitle data from the page only to display dual subtitles and to look up words you click.
  • When you click a word, that word (and, for Spanish, the surrounding subtitle sentence) is sent to a dictionary/translation service to fetch its definition.
  • AI Subtitles (optional, paid feature): if a title has no subtitles in your chosen language, you can request AI-generated subtitles. This sends that episode's existing subtitle text to our server, which uses Google's Gemini API to translate it. This only happens when you explicitly select an "(AI)" language option.
  • If you sign in, your saved vocabulary and settings are stored in our cloud database (Supabase) so they sync across devices.

2. Data We Handle

2.1 Stored locally on your device (chrome.storage.local)

Used to make the extension work. Stays on your machine unless you sign in and sync.

  • Preferences: primary/secondary language, subtitle size, color, font, overlay position, interface language (ES/EN), enable/disable state.
  • Saved vocabulary: words you choose to save, with their reading, meaning, language, the subtitle sentence they appeared in (context), status (known/learning/unknown), and the date saved.
  • Optional API keys: a personal KRDICT (Korean dictionary) key and/or a DeepL key, only if you enter them. The DeepL key stays on your device. The KRDICT key stays on your device and, if you are signed in, is also saved to your account in our cloud so it follows you across devices (see 2.3).
  • Plan/trial state: your trial start date and current plan status (e.g. trial, active, expired) are cached locally to manage free-trial and plan features.
  • Session tokens: if you sign in, your authentication tokens are stored locally so you stay logged in.

2.2 Account data (only if you sign in)

  • Email address and account identifier, used to authenticate you and associate your synced data with your account.
  • Sign-in is handled on our website (dualsub.dev) via email/password or Google. The website returns a session token to the extension. We never see or store your password inside the extension.

2.3 Data sent to our cloud (only if you sign in and sync)

When signed in, the following is stored in our database (Supabase) under your account:

  • Your saved vocabulary words (word, meaning, language, context sentence, status, date).
  • Your settings/preferences, including your personal KRDICT key if you entered one.
  • Plan/subscription status: your plan type, trial start date, expiry date, and any review-bonus days, used to manage trial and paid features.
  • Feedback you submit (does not require an account): if you use the in-extension feedback form, the message you write is sent to our database along with the extension version, the streaming platform, your selected languages, and your plan. If you are signed in, your account identifier is also attached; if not, no identifier is attached.

Each user can only access their own data (enforced by row-level security).

2.4 Payments

Dual Sub offers optional paid plans. Payments are processed on our website by Paddle.com Market Ltd ("Paddle"), which acts as the Merchant of Record (reseller) for all our orders. Paddle handles the checkout, billing, tax collection, invoicing, subscription management, refunds, and payment-related customer service. The extension never sees or stores your card details; it only reads your resulting plan status (active / trialing / past due / canceled / expired) from your account. Paddle's own Buyer Terms (https://www.paddle.com/legal/checkout-buyer-terms) and Privacy Notice (https://www.paddle.com/legal/privacy) apply to the payment itself; we receive from Paddle only the information needed to activate and maintain your subscription (customer id, subscription status, plan, price, renewal date, and country for tax).


3. Subtitle Content

To show dual subtitles, the extension reads the subtitle/caption data already delivered to your browser by the streaming platform. This processing happens locally in your browser. Full subtitle text is not sent to us or to any third party, with two exceptions you trigger yourself:

  1. Word lookups: when you click a word, that single word is sent to the relevant dictionary service to fetch a definition.
  2. Spanish word analysis: when you click a word and your interface is set to Spanish, the surrounding subtitle sentence may be sent to a grammatical-analysis service (Apertium) to identify the word's base form. This sentence is used only for that lookup and is not stored by us.
  3. AI Subtitles (paid feature you activate): when you select an "(AI)" language for a title that lacks subtitles in that language, the extension sends the current episode's existing subtitle text to our server (Supabase), which forwards it to Google's Gemini API for translation. The translated subtitles are cached in our database, keyed by the title/episode, so an episode is translated only once and reused (including for other users). No account information beyond the sign-in token (used to verify your plan) is attached to the subtitle text. This feature requires a paid plan and being signed in, and is off unless you choose an "(AI)" language.

4. Third-Party Services

The extension contacts the following services. Most receive only the word (or short text) you are looking up. We do not control their data practices; please review their own policies.

ServiceWhat is sentPurpose
Supabase (our database/auth)Account email, session tokens, your saved vocabulary & settingsLogin and cloud sync
Our website (dualsub.dev)Login credentials you enter thereAuthentication (incl. Google sign-in)
Jisho.orgThe Japanese word clickedJapanese definitions
Wiktionary (en/es and others)The word clickedDefinitions
dictionaryapi.devThe English word clickedEnglish definitions
KRDICT (krdict.korean.go.kr)The Korean word clickedKorean definitions
jsDelivr CDN (CC-CEDICT data)The Chinese characters clickedChinese definitions
MyMemory (api.mymemory.translated.net)The short text being translatedTranslating definitions to Spanish
Apertium (apertium.org)The word and its subtitle sentence (context)Spanish base-form analysis
YouTube (timedtext)Subtitle track request for the current videoFetching YouTube subtitles
Google Gemini API (via our Supabase function)The current episode's subtitle textAI Subtitles translation (only when you select an "(AI)" language)

We do not send your account information to any of the dictionary/translation services above, only the text being looked up.

Note on AI Subtitles: the subtitle text is sent to our cloud function, which calls Google's Gemini API to translate it, and the result is cached in our database so each episode is translated only once and shared across users. Only the sign-in token (to verify your paid plan) accompanies the request; the cached translations are not linked to your identity. Google's API terms apply to the translation step.

Note on Korean lookups: Korean definitions come from a dictionary bundled inside the extension (no network needed). When your interface is Spanish, the clicked Korean word is also sent to a function in our cloud (Supabase) that returns a shared Spanish translation, so each word is translated only once for all users. Only the word is sent, no account information.


5. How We Use Data

We use the data only to:

  • Provide the dual-subtitle and dictionary features.
  • Save and sync your vocabulary and preferences (when signed in).
  • Authenticate you and keep you signed in.

We do not use your data for advertising, profiling, or sale, and we do not share it with third parties except the service providers listed above that are necessary to deliver the features.

5.1 Legal basis (GDPR / UK GDPR)

Where the EU/EEA or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) , creating and maintaining your account, syncing your vocabulary and settings, providing the dual-subtitle and dictionary features you request, and delivering paid plans.
  • Legitimate interests (Art. 6(1)(f)) , keeping the service secure, preventing abuse, debugging errors, and understanding aggregate feature usage.
  • Legal obligation (Art. 6(1)(c)) , tax, accounting, and record-keeping obligations relating to sales made via our Merchant of Record (Paddle).
  • Consent (Art. 6(1)(a)) , for optional features that you explicitly enable (e.g. entering a personal API key, or selecting an "(AI)" language which triggers AI translation of subtitle text). You can withdraw consent at any time by disabling the feature.

Paddle acts as an independent data controller for payment data it processes as Merchant of Record, see Paddle's Privacy Notice at https://www.paddle.com/legal/privacy.


6. Data Retention and Deletion

  • Local data stays until you clear it (remove saved words in the popup, or uninstall the extension, which clears local storage).
  • Cloud data is kept while your account exists. You can delete your saved words from within the extension. To delete your account and all associated cloud data, contact us at the email above.

7. Security

  • Communication with our servers and dictionary services uses HTTPS.
  • Cloud data is protected by per-user access controls (row-level security) so users can only access their own records.
  • Session tokens are stored in the browser's extension storage and are not exposed to web pages.

No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.


8. Children's Privacy

Dual Sub is a general-audience language-learning tool and is not directed to children under 13. We do not knowingly collect personal information from children.


9. Changes to This Policy

We may update this policy. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, noted in the extension or on our website.


10. Contact

Questions or requests (including data deletion): infodualsubtitle@gmail.com