Last updated: August 7, 2026
This policy covers the Cha-Ching Thumbnails browser extension (“the extension”), published by Average Guy Making Money (“we,” “us”). The extension adds a thumbnail editor to YouTube Studio and Amazon video upload pages — it captures a frame from the video you’re uploading, lets you layer text, shapes and images on top of it, and can optionally generate or restyle images with AI using your own OpenAI account.
What the extension collects
The transmission described in this section only happens once you start using the AI features — if you never enter an email address, license key or OpenAI key, the extension never contacts our server at all, and the editor, image library, templates, background removal and exporting all work without a single request to us. Once you have saved an email address or license key, the extension re-checks your access each time you open the editor, which sends just those two values to our server. Clear both fields and it stops contacting us entirely.
The extension does store some things on your computer whether or not you use AI; those are marked stored locally only.
Email address. The address you type into the AI panel to activate a Cha-Ching Automate license or a $5/month AI subscription. It’s saved on your computer and sent to our license server (cha-ching-automate.averageguymakingmoney.com) when we check your access and with every AI request. If you subscribe, it’s also sent to Stripe to create the checkout. The access check runs whenever you open the editor, not only when you press an AI button — so once you’ve saved a license key or an email address, opening the editor sends those two values to our license server even if you’re only cropping a frame. If you’ve never entered either one, nothing is sent, ever.
Cha-Ching Automate licence key. Saved on your computer in plain text and sent to our license server with the access check and with every AI request, so we can tell whether your license covers the AI features.
Your OpenAI API key. The extension is bring-your-own-key: AI generations run on your OpenAI account, billed to you. Your key is saved on your computer in plain text using Chrome’s storage.local API, and it is sent to our license server inside each generation request, where it is used as the authorization header for the OpenAI call or calls that request needs (the template designer’s image mode makes two), and then dropped. We do not write it to our database, we do not print it to our logs, and we never return it in a response. The extension does not send it anywhere else — not to OpenAI directly, and never in your saved templates, image library or session files. One thing worth knowing: the editor panel is drawn into the page you’re working on, so while the panel is open the key is present in that page’s document alongside your email and license key, where other scripts running on that page could in principle read it. If that concerns you, clear the field when you’re done, and rotate or delete the key at OpenAI at any time. Everything the extension sends travels over HTTPS; it cannot talk to any host over an unencrypted connection.
The image you send for AI generation. When you click Generate, the extension re-renders your whole editor canvas — the captured video frame plus every text, shape and image layer you’ve added — as a JPEG 1,536 pixels wide, which passes it to OpenAI. The “use this frame” checkbox that controls this is ticked by default, so anything visible in the editor, including faces and any personal photos you’ve added, leaves your device when you press Generate.
Style reference images. If you pick an image from your library as a style reference, that image is re-encoded as a JPEG no more than 768 pixels wide and sent with the request. If you use the AI template designer’s “match this image” mode, the file you choose is sent exactly as it is on disk (up to 12 MB), which means any metadata inside that file — including EXIF such as camera or location data — travels with it.
Prompt text. What you type is sent to OpenAI. Our server does not store the prompt itself; it records only how many characters it was.
Usage metadata for billing. For each generation attempt our server writes one row: the account email on your license or subscription record (which may differ from the address you typed, if your license is registered to another one), your license key (or, for $5/month subscribers, the literal text email: followed by that address), the character count of your prompt, whether the request succeeded, and a timestamp. This is a best-effort record — if the database is unavailable the request still runs and no row is written.
Diagnostic logs. Our server prints non-personal details of each AI request (model name, mode, status code). If something goes wrong it also prints the error and a stack trace. We don’t put your prompt, your images or your API key into those logs. There are two places where personal or user-derived text can reach them: if the AI template designer returns a response we can’t parse, the first 300 characters of that response are printed to our console, and that text is derived from your prompt or example image; and when Stripe notifies us about your subscription, your email address is printed to our console alongside the new status.
The media URL of the video you’re editing — stored locally only. So the editor can restore an interrupted edit, the extension saves a snapshot on your computer keyed to the video’s media URL, and stores that URL, and the timestamp you were paused at, inside the snapshot. It stays on your device, is never sent to us or to anyone else, and is cleared once it’s more than 24 hours old.
Images you add yourself — stored locally only. When you import a photo, logo or cut-out, the extension saves the file’s contents and its original filename to your computer in Chrome’s storage.local, so you can reuse it later. Nothing is downscaled or stripped, and nothing is sent to us. These images only ever leave your device by the two paths described above — as part of the composite you generate from, or as a style reference you deliberately pick.
What we do NOT collect
There is no analytics, no telemetry, no tracking library, no error-reporting service and no beacons anywhere in the extension. It generates no install ID, device ID or advertising identifier, sends no install or startup ping, and never phones home on a timer.
We don’t collect your browsing history, the URLs of pages you visit, the title of the video you’re editing, your YouTube or Amazon account identity, or your browser, OS or user-agent details — none of these are included in any request the extension sends. The media URL of the video you’re editing and the timestamp you were paused at are saved on your computer only, as part of the autosave snapshot described above; they are never sent to us or to anyone else. Like any web server, ours does receive the connection details your browser attaches automatically to every request — your IP address and browser user-agent string. Our code never reads, uses, stores or forwards them, and they appear in no database record.
Payment card information never touches the extension or our server — Stripe handles all of it. Your saved image library, templates and in-progress editing sessions are never uploaded as stored; their contents can only leave your device through the two paths described above: the composed image you generate from — which includes any library image you have placed on the canvas — and a style reference you deliberately pick.
How your information is used
We use what we collect only to:
- check whether your licence key or subscription entitles you to the AI features;
- pass your prompt, image and your own OpenAI key to OpenAI so the generation runs on your account;
- count generations against a daily limit so the service isn’t abused;
- create and manage your $5/month subscription through Stripe.
We do not sell, rent, or trade your personal information, and we do not use it for advertising or profile-building. Our use of information received through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Third parties your data is shared with
Our licence server (cha-ching-automate.averageguymakingmoney.com) is run by us and is the only server the extension uploads your data to. It receives your email, licence key, OpenAI key, prompt and images as described above. (The extension also fetches the video you’re editing from YouTube’s and Amazon’s own CDNs — see below — but sends them nothing of yours beyond the cookies your browser would already attach.) That domain also serves our other products; this policy covers only what the Cha-Ching Thumbnails extension sends to it.
OpenAI receives your prompt and, when you run an image generation, your composed thumbnail and any style reference you picked. The AI template designer sends only your prompt or the example image you chose — never the thumbnail you’re editing. All of it is authenticated with your own API key and billed to your own OpenAI account. Their policy: openai.com/policies/…
Stripe receives your email address if you start the $5/month subscription, and we store back the Stripe customer ID, subscription ID, status and renewal date against that email. Their policy: stripe.com/privacy
Google (YouTube) and Amazon are contacted to download the video you’re already uploading so a frame can be captured. When you press Set as Thumbnail, the extension places the finished 1280×720 JPEG into that page’s own thumbnail upload field — the same field you would use by hand — and YouTube’s or Amazon’s normal upload flow takes over and uploads it, exactly as it would if you had chosen the file yourself. So your finished thumbnail, which contains the captured frame and everything you layered on it, does reach YouTube or Amazon, because that is the point of the extension. We send them nothing else. For Amazon videos served from CloudFront, the video download is made with your normal Amazon cookies attached, exactly as your browser would send them. Policies: policies.google.com/… and www.amazon.com/priva…
Where data is stored
- On your computer, in Chrome’s
storage.local: your image library, saved templates, your email, licence key and OpenAI key, and a per-video autosave snapshot so an interrupted edit can be restored. Each snapshot is filed under a key derived from the media URL of the video you were editing, and holds that URL, the timestamp you were paused at, and a full copy of every text, shape and image layer on the canvas. None of it is sent anywhere. Nothing is synced to your Google account, and undo history lives in memory only. A working image library plus a few days of saved thumbnails can easily run to 50–150 MB, well past Chrome’s 10 MB default for extension storage, which is why the extension requests theunlimitedStoragepermission. You can also export your templates to a JSON file at any time; that file is written to your downloads folder and contains a full-resolution copy of any image embedded in a template, so treat it as you would the images themselves. - Where your finished thumbnail goes. When you press Download, the extension saves a 1280×720 JPEG to your computer’s downloads folder. When you press Set as Thumbnail, it puts that same JPEG into the thumbnail upload field on the YouTube Studio or Amazon page you’re already on, and the site uploads it the way it would any file you picked yourself. Either way the image goes where you sent it — it is not copied to us.
- On your computer only: background removal and masking run entirely on your device using AI model files bundled inside the extension, and auto-enhance is plain image maths in your browser. No image leaves your computer for any of these features.
- On our server: the per-generation row described above, and — for subscribers — your email with the Stripe customer ID, subscription ID, status and renewal date. Your images and prompts are held in memory for the length of the request and are never written to disk or to a database.
Retention
- On your computer: your image library and templates stay until you delete them or remove the extension. Per-video editing snapshots older than 24 hours are deleted the next time you save an edit; if you stop using the extension they stay on your computer until you uninstall it or clear its storage. Your email, licence key and OpenAI key stay until you clear those fields or uninstall.
- On our server: generation records and subscription records are currently kept indefinitely — we have no automatic deletion schedule for them. Prompt text and images are never written to our database and never saved to disk. The one exception is the diagnostic case described above: if the template designer returns an unparseable response, up to 300 characters of that prompt-derived output is written to our server console log.
- On request: email us and we’ll delete your server-side records.
Your rights
- You can delete everything held locally yourself, at any time, by clearing the credential fields, deleting library images and templates, or uninstalling the extension. Per-video editing snapshots have no delete button — they’re cleared the next time you save an edit once they’re more than 24 hours old, and uninstalling removes them immediately.
- You can ask us for a copy of everything our server holds against your account email address — the generation records made against your account, and your subscription record if you have one.
- You can ask us to delete your server-side records and cancel your subscription. You can also revoke your OpenAI key directly at OpenAI at any time, which immediately stops it working anywhere, including here.
Children
The extension is not directed at children under 13, and we don’t knowingly collect anything from them.
Changes to this policy
If we make a material change to how the extension handles your data, we’ll update this page and the extension’s Chrome Web Store listing before the change takes effect.
Contact
Questions, data-deletion requests, or anything else: Email: chris@averageguymaki…