Q 题库与答题助手Question Bank & Answer AssistantPrivacy Center
Privacy · Transparency · Local First

隐私政策Privacy Policy

本政策说明题库与答题助手如何处理网页题目、保存加密题库、调用用户配置的 AI 服务,以及在启用时进行 License 校验。

This policy explains how the Question Bank & Answer Assistant handles page questions, stores encrypted banks, calls user-configured AI services, and validates a License when enabled.

🔐

本地加密题库Local encrypted banks

题库存入扩展加密保险库;普通 JSON、Excel、HTML 导出为明文。

Banks are stored in an encrypted extension vault; ordinary JSON, Excel and HTML exports are plaintext.

◎

可选 AI 联网Optional AI requests

AI 思考默认关闭。思考、学习解析和模型测试会按用户操作请求模型服务。

AI thinking is off by default. Thinking, study explanations and model tests contact providers following user actions.

◇

无广告与出售No ads or data sale

发布者不出售题库数据,不用于广告或信用判断;模型服务适用其自身政策。

The publisher does not sell bank data or use it for advertising or credit decisions. Model providers have their own policies.

01 · Scope

适用范围Scope

本政策适用于 Tools Platform 提供的题库与答题助手浏览器扩展。网站、浏览器商店及用户配置的模型服务适用各自政策。仅在自有或已授权、允许辅助工具的练习场景使用;不保证 AI 答案正确或考试结果。

This policy applies to the Question Bank & Answer Assistant extension provided through Tools Platform. Websites, browser stores and user-configured model providers have their own policies. Use only with your own or authorized practice content where assistance is permitted. AI accuracy and examination outcomes are not guaranteed.

新版扩展将题库保存在扩展的加密保险库中。历史 F12 脚本或旧版扩展可能在网站 localStorage 留有明文题库;新版仅在加密写入验证成功后删除成功迁移且未变化的旧记录。无法迁移、格式异常或迁移期间变化的旧记录可能继续保留。

The current extension stores banks in its encrypted vault. Older versions or F12 scripts may leave plaintext banks in website localStorage. The current version removes successfully migrated, unchanged legacy records only after verified encrypted persistence. Unmigratable, malformed or concurrently changed records may remain.

02 · Data

我们处理的数据Data we process

类别Category内容Details处理位置与用途Handling
网站内容Website content题干、题型、题号、选项、答题反馈、标注、错误答案组合、学习翻译和解释。Question text, types, IDs, options, feedback, annotations, failed combinations, translations and explanations.本地保险库;使用 AI 时相关内容发送给启用的模型服务。Local vault; relevant content is sent to enabled providers when AI is used.
身份验证信息Authentication information用户输入的密码/PIN、派生密钥、AI API Key;如启用 License,还有许可凭据。Entered password/PIN, derived key, AI API keys and, if licensing is enabled, License credentials.密码在扩展内处理;解锁密钥和模型凭据保存在可信扩展会话中。API Key 仅向对应模型服务鉴权;License 用于许可验证。Passwords are handled inside the extension; unlock keys and model credentials are held in trusted session storage. API keys authenticate with their respective providers; License credentials are used for licensing.
来源与请求记录Origins and requests网站来源(origin)、用于默认题库名称的页面标题、模型端点、请求/响应与时间及用量。Website origin, page title used for a default bank name, model endpoints, requests/responses, timing and reported usage.用于按网站隔离题库、配置服务和本地诊断;不读取浏览器全部历史。Used for origin isolation, service configuration and local diagnostics; the extension does not read full browser history.
相关使用记录Related activity答题结果、错误记录、出现次数、AI 请求耗时及返回的 token 用量。Answer results, mistakes, occurrence counts, AI request duration and reported token usage.本地题库与日志;相关错误经验可随 AI 请求发送。不持续记录全局鼠标或键盘行为。Local banks and logs; relevant mistakes may be sent with AI requests. No continuous global mouse or keyboard tracking.
偏好与配置Preferences界面语言、缩放、透明度、延迟、模型协议和优先策略等。Language, scale, opacity, delays, model protocols and priority preferences.本地或扩展会话存储;非敏感语言等偏好可明文保存。Local or session storage; non-sensitive preferences such as language may be stored in plaintext.
可选许可验证Optional licensingLicense、产品标识、随机 nonce;许可服务还接收 IP、User-Agent、请求时间和验证结果。License, product identifier and random nonce; the licensing service also receives IP address, User-Agent, request time and validation results.仅在发行包启用 License 时连接其配置的许可验证服务器;服务器可能保存必要的许可与安全日志。Only builds with licensing enabled contact the configured validation service; it may retain necessary licensing and security logs.

本扩展不专门采集姓名、邮箱、健康、支付、私人通讯、GPS 或通讯录,也不读取 Cookie 或完整浏览历史。题目、导入文件或用户配置若包含个人或保密信息,相关内容仍可能被保存或随 AI 请求发送。发送前请自行检查,不导入或发送无权处理的信息。AI/许可服务器可从连接中获得 IP 等常规网络信息,这不等于插件读取 GPS。

The extension does not specifically collect names, email addresses, health, payment, private communications, GPS or contacts, and does not read cookies or full browser history. Questions, imported files or configuration may nevertheless contain personal or confidential information, which could be stored or sent in AI requests. Review content before sending and do not process information without authorization. AI/licensing servers can receive standard connection information such as IP addresses; this is not GPS collection.

03 · Use

数据用途与 AI 请求Data use and AI requests

  • 用户手动启动后识别支持页面的题目和反馈,维护题库、标注与错误经验;可根据题库或 AI 推荐自动选择答案、翻页。After manual launch, recognize questions and feedback on supported pages and maintain banks, annotations and mistakes; optionally select answers and navigate based on bank or AI recommendations.
  • AI 思考默认关闭。用户开启后,将题干、题型、选项和相关错误经验发送到所有启用的模型,可能同时请求多个服务。AI thinking is off by default. When enabled, question text, types, options and relevant mistakes are sent to all enabled models, potentially to multiple providers concurrently.
  • 点击“解析与翻译”也会发送所选题库中的相关题目和答案信息,用于翻译、考点和解释;不要求先开启自动答题的 AI 思考。模型测试发送测试请求与鉴权信息。Study translation/explanation sends relevant questions and answer information from selected banks for translations and explanations, independently of the automatic-answer AI thinking switch. Model testing sends a test request and authentication information.
  • 使用 API Key 向对应服务鉴权。模型响应只作为答案、翻译或解释数据处理,不作为远程 JavaScript 执行。Use API keys for authentication with their respective services. Model responses are handled as answer, translation or explanation data, not executed as remote JavaScript.

模型服务由用户配置,不限于某一厂商。开启 AI 前请核对端点、所有启用模型、提供者隐私政策、数据地区、保存期限与训练用途;模型服务可能收费。不将题目发送到许可验证服务器;若用户将平台 AI 服务配置为模型端点,该服务也将接收必要请求。

Users configure model services, which are not limited to one vendor. Before using AI, check endpoints, all enabled models, provider policies, processing regions, retention and training practices. Fees may apply. Question content is not sent to the licensing server; a platform AI service receives necessary requests if configured by the user as a model endpoint.

04 · Permissions

权限说明Permissions

  • storage:保存加密题库、偏好、日志和可信会话状态;如启用许可还保存相关状态。storage: stores encrypted banks, preferences, logs and trusted session state, plus licensing state when enabled.
  • unlimitedStorage:支持较大题库和学习解析的本地扩展存储。unlimitedStorage: supports larger local banks and study explanations.
  • activeTab 与 scripting:用户点击并启动后,在当前普通页面注入包内助手。匹配网址不是手动启动的唯一访问来源,activeTab 提供临时授权;是否识别题目取决于页面结构。activeTab and scripting: inject the bundled assistant into the current ordinary page following user launch. Match patterns are not the sole source of access for manual launch; activeTab grants temporary access. Question recognition depends on page structure.
  • 主机权限包含配置的网站,以及 AI 包的 https://*/*、http://localhost/*、http://127.0.0.1/*,用于用户配置的模型服务;不意味着持续扫描所有网站。浏览器设置可限制权限,限制后对应功能可能无法使用。Host permissions include configured sites plus https://*/*, http://localhost/* and http://127.0.0.1/* for user-configured models. They do not imply continuous scanning of all sites. Browser restrictions may prevent corresponding features from working.

本政策说明内置助手的基础发行包。自定义额外权限、自动注入、许可服务或代码改动可能改变处理方式,发布者需同步更新政策和商店披露。

This policy describes the built-in assistant’s base package. Added permissions, automatic injection, licensing services or code changes may alter data practices; the publisher must update policy and store disclosures accordingly.

05 · Sharing

共享、出售与 Limited UseSharing, sales and Limited Use

本地题库不自动同步至发布者服务器。AI 功能按用户操作向所有启用的模型服务传输必要内容;这些提供者有独立的数据保存、训练和访问政策,发布者不能保证其不保留或不训练,请只选择可信且符合您要求的服务。用户自行导出的文件可被接收者读取,分享前请检查。

Local banks are not automatically synchronized to the publisher’s servers. AI features transmit necessary content to all enabled providers following user actions. Providers have independent retention, training and access policies; the publisher cannot guarantee that they do not retain data or train on it. Choose trusted services that meet your requirements. Recipients can read ordinary exported files; review before sharing.

发布者不出售用户数据,不用于个性化广告、无关画像、信用评估或贷款决策。发布者对数据的使用与传输仅限已披露的题库学习功能及相关安全运营,并遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。不会为无关目的提供数据给经纪商或广告平台。

The publisher does not sell user data or use it for personalized advertising, unrelated profiling, creditworthiness or lending decisions. Publisher use and transfers are limited to the disclosed question-bank study functions and related security operations and adhere to the Chrome Web Store User Data Policy, including Limited Use requirements. Data is not provided to brokers or advertising platforms for unrelated purposes.

如发行包启用 License,许可基础设施及管理员处理验证数据,用于授权、防滥用和必要排障;可按法律要求、安全需要或用户请求披露必要信息。

If the build enables licensing, its infrastructure and administrators process validation data for authorization, abuse prevention and necessary troubleshooting. Necessary information may be disclosed as required by law, for security, or at the user’s request.

06 · Retention

保存、导出与删除Retention, exports and deletion

  • 题库及学习解析以加密记录保留在 chrome.storage.local,直到用户通过题库管理删除、重置对应题库、清除扩展数据或卸载。重置一库不清除其他库、会话凭据或磁盘备份;仅清除网站浏览数据不一定清除扩展保险库。Banks and study explanations are retained as encrypted records in chrome.storage.local until managed/deleted, the corresponding bank is reset, extension data is cleared or the extension is uninstalled. Resetting one bank does not remove other banks, session credentials or disk backups; clearing website data alone may not clear the extension vault.
  • 解锁密钥和模型 API Key 保存在可信扩展会话存储中;锁定或浏览器会话结束后清除。锁定不删除持久化加密题库,关闭助手窗口不等于锁定。Unlock keys and model API keys are held in trusted extension session storage and cleared on locking or browser-session end. Locking does not delete persisted encrypted banks; closing the assistant is not equivalent to locking.
  • 最近一场 AI 请求与响应日志保存在本地,并在新的答题任务建立日志时替换旧场次,容量限制可能删去较早条目。包含题目、模型输出、地址、时间和用量;鉴权信息脱敏。请勿随意分享可能含敏感题目的日志。The latest run’s AI request/response log is stored locally and replaced when a new answer task creates its log; capacity limits may remove older entries. It contains questions, model outputs, endpoints, timing and usage with authentication information redacted. Do not indiscriminately share logs containing sensitive questions.
  • 普通 JSON、Excel、HTML 导出包含明文题库和已保存解析。加密备份需要原密码恢复,不包含模型 API Key 或解锁密钥。磁盘文件、接收者副本和模型服务保存的数据不会因卸载扩展自动删除。Ordinary JSON, Excel and HTML exports contain plaintext banks and saved explanations. Encrypted backups require the original password and do not include model API keys or unlock keys. Disk files, recipients’ copies and provider-held data are not automatically deleted by uninstalling the extension.
  • 许可签发、状态与必要安全日志按照运营方安全和运维策略保留;请求查询或删除请联系下方邮箱。模型服务数据的保留与删除须按其政策向对应服务申请。License issuance/status and necessary security logs are retained under operator security and operational policies; use the contact below to request access or deletion. Provider-held data is retained/deleted under the provider’s own policies and request channels.
07 · Security

安全措施Security

保险库采用 AES-256-GCM,加密密钥由密码经 PBKDF2-SHA256(600,000 次迭代与随机盐)派生。提供默认 6 位数字 PIN 和可选复杂密码(至少 16 位,含字母、数字、符号)。PIN 离线猜测防护较弱,敏感题库建议使用复杂密码。密码在扩展页面输入,不交给考试网页;实体键盘和屏幕键盘均可使用。

The vault uses AES-256-GCM with a key derived through PBKDF2-SHA256 (600,000 iterations and random salt). Choose a six-digit PIN or a complex password of at least 16 characters including a letter, digit and symbol. PINs offer weaker resistance to offline guessing; use complex passwords for sensitive banks. Passwords are entered in an extension page, not supplied to the exam website; physical and on-screen keyboards are supported.

模型请求使用 HTTPS,或同一设备 localhost/127.0.0.1 的 HTTP 模型服务。可信会话限制、来源隔离、写入验证和凭据脱敏降低风险。如启用许可,可使用本地验签与配置的在线校验。

Model requests use HTTPS or local HTTP model services on localhost/127.0.0.1. Trusted session access, origin isolation, write verification and credential redaction reduce risk. Licensed builds can use local signature verification and configured online validation.

不承诺加密无法破解、免受键盘监控或受控设备上的恶意软件保护。源码不包含您的个人密码,但弱 PIN 仍可被离线猜测。忘记密码无法保证找回题库;请保管密码和备份,并留意旧版残留明文及普通导出文件。

Encryption does not promise unbreakability or protection against keylogging or malware on a compromised device. Source code does not contain your personal password, but weak PINs remain susceptible to offline guessing. Recovery is not guaranteed if the password is lost. Protect passwords/backups and check for legacy plaintext and ordinary exports.

08 · Rights

用户控制User controls

  • 您可停止自动答题、关闭 AI 思考、停用或删除模型配置。关闭 AI 思考只停止对应的自动答题 AI 功能;不要再点击学习解析或模型测试,若不希望这些功能发出请求。You can stop automated answering, disable AI thinking and disable/remove model configurations. Turning off AI thinking affects that automatic-answer feature; avoid invoking study explanations or model tests if you do not want their requests.
  • 您可查看、搜索、标注、导入、导出、删除或重置题库,并手动锁定保险库。删除本地数据不会删除先前发给第三方或导出的副本。You can view, search, annotate, import, export, delete/reset banks and manually lock the vault. Local deletion does not delete data previously sent to third parties or exported copies.
  • 您可通过浏览器限制网站权限、停用或卸载扩展;涉及服务器数据的访问、更正或删除请求,请联系运营方或对应模型提供者。You can restrict site permissions, disable or uninstall the extension. Contact the operator or respective model provider for server-side access, correction or deletion requests.

本扩展面向获授权的学习、业务或培训场景,并非面向儿童设计,不故意收集儿童个人信息。

The extension is intended for authorized study, business or training, is not directed to children, and does not knowingly collect children’s personal information.

09 · Changes

政策更新Policy updates

本次更新说明新增 AI 功能、加密保险库、会话凭据、日志与导出方式。功能、权限或数据处理方式变化时,我们会在本页更新日期并通过合理的产品内提示说明重大变化。商店数据披露应与本政策及实际发行包保持一致。

This update describes AI features, the encrypted vault, session credentials, logs and exports. When features, permissions or data practices change, we update this page’s date and communicate material changes through appropriate in-product notices. Store disclosures must match this policy and the actual release.

10 · Contact

联系我们Contact

如对本政策、许可记录或数据请求有疑问,请联系 Tools Platform 管理员。涉及用户自行配置的模型服务,请同时联系该服务提供者。

For policy, licensing-record or data-request questions, contact the Tools Platform administrator. For a user-configured model service, also contact its provider.

✉ [email protected]