Legal
Privacy Policy
Last updated 4 September 2026
This policy covers the Ai that Buy Chrome extension and this website. It is written to be read rather than to be technically true and practically useless — where something is a limitation, it says so.
1. Who we are
- Operator
- Rotara Labs
- Product
- Ai that Buy, a Chrome browser extension
- Contact
- rotaralabs@gmail.com
- Website
- https://aithatbuy.store
2. Card details
If you save a card in the extension, the card number, expiry, CVV and the label you give it are stored only on your own device, in the browser's local extension storage, encrypted with AES-GCM using a key generated on that device.
They are deliberately excluded from Chrome Sync, so they are never uploaded to your Google account and never appear on your other devices.
Card details are transmitted to exactly one destination, and only at the moment you run a checkout with Card mode selected: the store's own payment API (for example Flipkart's), over HTTPS. That is the same destination they would reach if you typed them into the store's checkout page yourself. They are never sent to us, and we have no ability to read them.
If you used an earlier version of the extension, any card that was previously held in Chrome Sync is moved into the encrypted local store and deleted from sync the first time you open the updated extension.
The encryption key is stored on the same device as the encrypted data. This protects your card details from being synced to Google's servers and from being read out of the browser profile as plain text. It does not protect against malware already running under your user account on your computer. Any software with that level of access can read what your browser can read.
3. Settings and preferences
Non-sensitive settings are stored in Chrome's sync storage, so they follow your Chrome profile between devices. These are:
- Payment mode preference (Cash on Delivery, Net Banking, Card, EMI, Gift Voucher or Manual)
- Selected bank for Net Banking
- Quantity preference and optional maximum price
- Sound and dark-mode preferences
- GST invoice setting
- Delivery pincode, if you set one
None of this identifies you, and none of it is sent to us.
4. Licence checks
To verify your licence, the extension sends two things to our server at
aithatbuy.store: your licence key, and a device
fingerprint.
The fingerprint is a one-way hash of coarse, non-identifying signals — operating platform, CPU core count, timezone and language. It exists so one licence cannot be shared across many machines. It contains no personal information, cannot be reversed into any, and is not used for tracking.
We retain, per licence key: the key itself, whether it is active, the fingerprint it is bound to, and the dates it was created and activated. That is the entire record.
5. Google account connection (optional)
The extension offers an optional OTP feature. If — and only if — you press Connect Gmail, Google's standard sign-in screen appears and you choose what to grant.
The extension reads your account's email address so it can show you which mailbox is connected. Your Google password is never seen, handled or stored by the extension. You can disconnect at any time from the extension popup, and you can revoke access yourself at myaccount.google.com/permissions.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use that data for advertising, and we do not allow humans to read it.
6. What we never collect
- Your card details — they never reach any server of ours
- Your store or bank login credentials
- Your browsing history
- The contents of pages you visit
- Your name, postal address or phone number, unless you write them to us yourself
The extension contains no analytics, no advertising, and no third-party tracking scripts. Neither does this website.
7. Where the extension can run
The extension only has access to the 18 retail sites listed on the home page, plus our own licence endpoint. It cannot read, modify or observe any other page you visit. Adding a site would require a new version of the extension, reviewed by Google.
8. This website
This site sets no cookies and runs no analytics. If you use the contact form, the name, email address and message you type are emailed to us so we can reply. Our web host keeps standard server access logs (IP address, timestamp, requested page) for security and troubleshooting, as every web host does.
9. Your choices
- Delete any saved card, or all of them, from the extension popup at any time.
- Disconnect a linked Google account at any time from the extension popup.
- Uninstalling the extension removes everything it stored on your device.
- Email us to request deletion of your licence record. Note that deleting it deactivates the licence.
10. Children
The extension is not directed at children and is not intended for anyone under 18. We do not knowingly collect information from children.
11. Changes to this policy
If this policy changes, the date at the top is updated and material changes are noted in the extension's update notes. Continuing to use the extension after a change means you accept the revised policy.
12. Contact
Questions about this policy, or a request about your data: rotaralabs@gmail.com. We aim to reply within three working days.