本地加密题库Local encrypted banks
题库存入扩展加密保险库;普通 JSON、Excel、HTML 导出为明文。
Banks are stored in an encrypted extension vault; ordinary JSON, Excel and HTML exports are plaintext.
本政策说明题库与答题助手如何处理网页题目、保存加密题库、调用用户配置的 AI 服务,以及在启用时进行 License 校验。
This policy explains how the Question Bank & Answer Assistant handles page questions, stores encrypted banks, calls user-configured AI services, and validates a License when enabled.
题库存入扩展加密保险库;普通 JSON、Excel、HTML 导出为明文。
Banks are stored in an encrypted extension vault; ordinary JSON, Excel and HTML exports are plaintext.
AI 思考默认关闭。思考、学习解析和模型测试会按用户操作请求模型服务。
AI thinking is off by default. Thinking, study explanations and model tests contact providers following user actions.
发布者不出售题库数据,不用于广告或信用判断;模型服务适用其自身政策。
The publisher does not sell bank data or use it for advertising or credit decisions. Model providers have their own policies.
本政策适用于 Tools Platform 提供的题库与答题助手浏览器扩展。网站、浏览器商店及用户配置的模型服务适用各自政策。仅在自有或已授权、允许辅助工具的练习场景使用;不保证 AI 答案正确或考试结果。
This policy applies to the Question Bank & Answer Assistant extension provided through Tools Platform. Websites, browser stores and user-configured model providers have their own policies. Use only with your own or authorized practice content where assistance is permitted. AI accuracy and examination outcomes are not guaranteed.
新版扩展将题库保存在扩展的加密保险库中。历史 F12 脚本或旧版扩展可能在网站 localStorage 留有明文题库;新版仅在加密写入验证成功后删除成功迁移且未变化的旧记录。无法迁移、格式异常或迁移期间变化的旧记录可能继续保留。
The current extension stores banks in its encrypted vault. Older versions or F12 scripts may leave plaintext banks in website localStorage. The current version removes successfully migrated, unchanged legacy records only after verified encrypted persistence. Unmigratable, malformed or concurrently changed records may remain.
| 类别Category | 内容Details | 处理位置与用途Handling |
|---|---|---|
| 网站内容Website content | 题干、题型、题号、选项、答题反馈、标注、错误答案组合、学习翻译和解释。Question text, types, IDs, options, feedback, annotations, failed combinations, translations and explanations. | 本地保险库;使用 AI 时相关内容发送给启用的模型服务。Local vault; relevant content is sent to enabled providers when AI is used. |
| 身份验证信息Authentication information | 用户输入的密码/PIN、派生密钥、AI API Key;如启用 License,还有许可凭据。Entered password/PIN, derived key, AI API keys and, if licensing is enabled, License credentials. | 密码在扩展内处理;解锁密钥和模型凭据保存在可信扩展会话中。API Key 仅向对应模型服务鉴权;License 用于许可验证。Passwords are handled inside the extension; unlock keys and model credentials are held in trusted session storage. API keys authenticate with their respective providers; License credentials are used for licensing. |
| 来源与请求记录Origins and requests | 网站来源(origin)、用于默认题库名称的页面标题、模型端点、请求/响应与时间及用量。Website origin, page title used for a default bank name, model endpoints, requests/responses, timing and reported usage. | 用于按网站隔离题库、配置服务和本地诊断;不读取浏览器全部历史。Used for origin isolation, service configuration and local diagnostics; the extension does not read full browser history. |
| 相关使用记录Related activity | 答题结果、错误记录、出现次数、AI 请求耗时及返回的 token 用量。Answer results, mistakes, occurrence counts, AI request duration and reported token usage. | 本地题库与日志;相关错误经验可随 AI 请求发送。不持续记录全局鼠标或键盘行为。Local banks and logs; relevant mistakes may be sent with AI requests. No continuous global mouse or keyboard tracking. |
| 偏好与配置Preferences | 界面语言、缩放、透明度、延迟、模型协议和优先策略等。Language, scale, opacity, delays, model protocols and priority preferences. | 本地或扩展会话存储;非敏感语言等偏好可明文保存。Local or session storage; non-sensitive preferences such as language may be stored in plaintext. |
| 可选许可验证Optional licensing | License、产品标识、随机 nonce;许可服务还接收 IP、User-Agent、请求时间和验证结果。License, product identifier and random nonce; the licensing service also receives IP address, User-Agent, request time and validation results. | 仅在发行包启用 License 时连接其配置的许可验证服务器;服务器可能保存必要的许可与安全日志。Only builds with licensing enabled contact the configured validation service; it may retain necessary licensing and security logs. |
本扩展不专门采集姓名、邮箱、健康、支付、私人通讯、GPS 或通讯录,也不读取 Cookie 或完整浏览历史。题目、导入文件或用户配置若包含个人或保密信息,相关内容仍可能被保存或随 AI 请求发送。发送前请自行检查,不导入或发送无权处理的信息。AI/许可服务器可从连接中获得 IP 等常规网络信息,这不等于插件读取 GPS。
The extension does not specifically collect names, email addresses, health, payment, private communications, GPS or contacts, and does not read cookies or full browser history. Questions, imported files or configuration may nevertheless contain personal or confidential information, which could be stored or sent in AI requests. Review content before sending and do not process information without authorization. AI/licensing servers can receive standard connection information such as IP addresses; this is not GPS collection.
模型服务由用户配置,不限于某一厂商。开启 AI 前请核对端点、所有启用模型、提供者隐私政策、数据地区、保存期限与训练用途;模型服务可能收费。不将题目发送到许可验证服务器;若用户将平台 AI 服务配置为模型端点,该服务也将接收必要请求。
Users configure model services, which are not limited to one vendor. Before using AI, check endpoints, all enabled models, provider policies, processing regions, retention and training practices. Fees may apply. Question content is not sent to the licensing server; a platform AI service receives necessary requests if configured by the user as a model endpoint.
storage:保存加密题库、偏好、日志和可信会话状态;如启用许可还保存相关状态。storage: stores encrypted banks, preferences, logs and trusted session state, plus licensing state when enabled.unlimitedStorage:支持较大题库和学习解析的本地扩展存储。unlimitedStorage: supports larger local banks and study explanations.activeTab 与 scripting:用户点击并启动后,在当前普通页面注入包内助手。匹配网址不是手动启动的唯一访问来源,activeTab 提供临时授权;是否识别题目取决于页面结构。activeTab and scripting: inject the bundled assistant into the current ordinary page following user launch. Match patterns are not the sole source of access for manual launch; activeTab grants temporary access. Question recognition depends on page structure.https://*/*、http://localhost/*、http://127.0.0.1/*,用于用户配置的模型服务;不意味着持续扫描所有网站。浏览器设置可限制权限,限制后对应功能可能无法使用。Host permissions include configured sites plus https://*/*, http://localhost/* and http://127.0.0.1/* for user-configured models. They do not imply continuous scanning of all sites. Browser restrictions may prevent corresponding features from working.本政策说明内置助手的基础发行包。自定义额外权限、自动注入、许可服务或代码改动可能改变处理方式,发布者需同步更新政策和商店披露。
This policy describes the built-in assistant’s base package. Added permissions, automatic injection, licensing services or code changes may alter data practices; the publisher must update policy and store disclosures accordingly.
本地题库不自动同步至发布者服务器。AI 功能按用户操作向所有启用的模型服务传输必要内容;这些提供者有独立的数据保存、训练和访问政策,发布者不能保证其不保留或不训练,请只选择可信且符合您要求的服务。用户自行导出的文件可被接收者读取,分享前请检查。
Local banks are not automatically synchronized to the publisher’s servers. AI features transmit necessary content to all enabled providers following user actions. Providers have independent retention, training and access policies; the publisher cannot guarantee that they do not retain data or train on it. Choose trusted services that meet your requirements. Recipients can read ordinary exported files; review before sharing.
发布者不出售用户数据,不用于个性化广告、无关画像、信用评估或贷款决策。发布者对数据的使用与传输仅限已披露的题库学习功能及相关安全运营,并遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。不会为无关目的提供数据给经纪商或广告平台。
The publisher does not sell user data or use it for personalized advertising, unrelated profiling, creditworthiness or lending decisions. Publisher use and transfers are limited to the disclosed question-bank study functions and related security operations and adhere to the Chrome Web Store User Data Policy, including Limited Use requirements. Data is not provided to brokers or advertising platforms for unrelated purposes.
如发行包启用 License,许可基础设施及管理员处理验证数据,用于授权、防滥用和必要排障;可按法律要求、安全需要或用户请求披露必要信息。
If the build enables licensing, its infrastructure and administrators process validation data for authorization, abuse prevention and necessary troubleshooting. Necessary information may be disclosed as required by law, for security, or at the user’s request.
保险库采用 AES-256-GCM,加密密钥由密码经 PBKDF2-SHA256(600,000 次迭代与随机盐)派生。提供默认 6 位数字 PIN 和可选复杂密码(至少 16 位,含字母、数字、符号)。PIN 离线猜测防护较弱,敏感题库建议使用复杂密码。密码在扩展页面输入,不交给考试网页;实体键盘和屏幕键盘均可使用。
The vault uses AES-256-GCM with a key derived through PBKDF2-SHA256 (600,000 iterations and random salt). Choose a six-digit PIN or a complex password of at least 16 characters including a letter, digit and symbol. PINs offer weaker resistance to offline guessing; use complex passwords for sensitive banks. Passwords are entered in an extension page, not supplied to the exam website; physical and on-screen keyboards are supported.
模型请求使用 HTTPS,或同一设备 localhost/127.0.0.1 的 HTTP 模型服务。可信会话限制、来源隔离、写入验证和凭据脱敏降低风险。如启用许可,可使用本地验签与配置的在线校验。
Model requests use HTTPS or local HTTP model services on localhost/127.0.0.1. Trusted session access, origin isolation, write verification and credential redaction reduce risk. Licensed builds can use local signature verification and configured online validation.
不承诺加密无法破解、免受键盘监控或受控设备上的恶意软件保护。源码不包含您的个人密码,但弱 PIN 仍可被离线猜测。忘记密码无法保证找回题库;请保管密码和备份,并留意旧版残留明文及普通导出文件。
Encryption does not promise unbreakability or protection against keylogging or malware on a compromised device. Source code does not contain your personal password, but weak PINs remain susceptible to offline guessing. Recovery is not guaranteed if the password is lost. Protect passwords/backups and check for legacy plaintext and ordinary exports.
本扩展面向获授权的学习、业务或培训场景,并非面向儿童设计,不故意收集儿童个人信息。
The extension is intended for authorized study, business or training, is not directed to children, and does not knowingly collect children’s personal information.
本次更新说明新增 AI 功能、加密保险库、会话凭据、日志与导出方式。功能、权限或数据处理方式变化时,我们会在本页更新日期并通过合理的产品内提示说明重大变化。商店数据披露应与本政策及实际发行包保持一致。
This update describes AI features, the encrypted vault, session credentials, logs and exports. When features, permissions or data practices change, we update this page’s date and communicate material changes through appropriate in-product notices. Store disclosures must match this policy and the actual release.
如对本政策、许可记录或数据请求有疑问,请联系 Tools Platform 管理员。涉及用户自行配置的模型服务,请同时联系该服务提供者。
For policy, licensing-record or data-request questions, contact the Tools Platform administrator. For a user-configured model service, also contact its provider.
✉ [email protected]