隐私政策
生效日期:2026-08-15 · English below
双译是一款无账号、无遥测、无开发者中转服务器的浏览器扩展。开发者不运营任何接收你正文的服务器,也无法看到你的翻译内容。
首次同意
安装后首次打开时,扩展会展示一份说明并要求你明确勾选同意,之后才会发送任何正文。在你同意之前,网页翻译、划词翻译、输入框翻译与 PDF 视觉识别全部会被拒绝。你可以随时在「设置 → 隐私与数据」重新查看这份说明。
何时读取网页内容
双译没有自动注入的内容脚本,安装后不会自动读取任何网页。只有在以下情形之一发生时,才会处理当前页面内容:
- 你点击「翻译此页面」;
- 你翻译所选文字;
- 你按下输入框翻译快捷键;
- 你明确为某一网站启用「始终翻译此网站」。
提取正文时,以下内容一律跳过:input、textarea、select 等全部表单控件(因此包括密码框)、script、style、代码块、隐藏与 aria-hidden 内容,以及带 translate="no" 或 .notranslate 标记的元素。输入框内容只在你按下快捷键后读取。跨域框架在没有相应网站权限时不会处理。
会发送什么、发给谁
以下内容会从你的浏览器直接发送到你在设置中选择的翻译服务,不经过开发者:
- 网页正文、所选文字、输入框文字;
- PDF 提取出的文字;
- YouTube 已有字幕与实时字幕。
扫描版 PDF 默认在本机使用 PP-OCRv5 识别,不上传。只有当你点击「用视觉 AI 重新识别本页」、看到供应商名称与页码并再次确认后,该单页的 JPEG 图像才会发送到你选择的视觉服务。任何情况下都不会自动上传整份 PDF。
在设置页点击「保存并测试」时,扩展会向该服务发送一条固定的探测文本(hello)以验证连通性,其中不含你的任何内容。
如果你配置了供应商回退顺序,请求只会按你指定的顺序尝试;未配置时,不会静默改发给另一家服务。
第三方服务
| 服务 | 何时连接 |
|---|---|
| 你自己配置的翻译 / 视觉服务 | 你触发翻译,或点击「保存并测试」时 |
huggingface.co | 仅当你在设置中主动下载可选 OCR 模型包时。核心 OCR 模型随扩展一起打包,不需要下载 |
除此之外,扩展不会连接任何固定服务器。选项页中出现的 OpenAI、DeepSeek、DeepL、Google 地址只是填写表单时的默认建议值;你不配置、不使用,就不会产生任何连接。
你的内容一旦发送给第三方服务,其保留与使用方式由你与该服务之间的条款和设置决定。
本机保存的数据
全部保存在浏览器本地(storage.local 与 IndexedDB),不会同步给开发者:
- 扩展设置与逐站点规则;
- API 密钥保险库,默认经主密码派生密钥以 AES-GCM 加密;
- 普通网页正文的译文缓存;
- 请求数、字符数、缓存命中数与错误数(仅用于设置页显示,不外发);
- 你主动下载并通过 SHA-256 校验的可选 OCR 模型包。
解锁后的密钥只存在浏览器会话存储中,浏览器重启即失效。你也可以明确选择「便捷模式」,此时密钥以明文保存在浏览器本地数据中——切换前扩展会先说明后果并要求确认。输入框内容默认不缓存。设置导出始终不含任何密钥。
权限与保留
手动翻译使用浏览器临时授予的当前标签页访问权限(activeTab)。长期的网站权限只在你启用某网站的自动翻译时逐来源申请,并可随时在设置页移除。下载可选 OCR 模型所需的网站权限,在下载完成或失败后会立即撤销。
你可以通过清除扩展数据或卸载扩展删除全部本机数据。
儿童与数据出售
双译不出售个人数据,不投放广告,不建立用户画像,也不进行任何形式的用户追踪。
Privacy Policy
Effective: 2026-08-15
Doublet is a browser extension with no accounts, no telemetry, and no developer relay server. The developer operates no server that receives your text and cannot see what you translate.
First-run consent
On first launch, the extension shows a disclosure and requires you to tick a box before any text is sent. Until you do, page translation, selection translation, input translation and PDF vision recognition are all refused. You can review the disclosure again at any time under Settings → Privacy & Data.
When page content is read
Doublet registers no automatically injected content scripts and reads nothing after installation on its own. Page content is processed only when:
- you click “translate this page”;
- you translate a selection;
- you press the input-translation shortcut;
- you explicitly enable “always translate this site” for a site.
Extraction always skips every form control (input, textarea, select — password fields included), script, style, code blocks, hidden and aria-hidden content, and anything marked translate="no" or .notranslate. Input fields are read only after you press the shortcut. Cross-origin frames are not processed without the corresponding site permission.
What is sent, and to whom
The following is sent from your browser directly to the translation service you configured, never through the developer:
- page text, selected text, input-field text;
- text extracted from PDFs;
- existing and live YouTube captions.
Scanned PDFs are recognised on-device by default using PP-OCRv5 and are not uploaded. Only after you click “re-recognise this page with vision AI”, see the provider name and page number, and confirm a second time is that single page’s JPEG sent to your chosen vision service. A whole PDF is never uploaded automatically.
Clicking “save and test” in settings sends a fixed probe string (hello) to that service to verify connectivity. It contains none of your content.
If you configure a provider fallback order, requests are attempted only in the order you specified; with none configured, requests are never silently redirected to a different service.
Third parties
| Service | When contacted |
|---|---|
| The translation / vision service you configured | When you trigger a translation, or click “save and test” |
huggingface.co | Only when you choose to download an optional OCR model pack. The core OCR model ships with the extension and needs no download |
Nothing else is contacted. The OpenAI, DeepSeek, DeepL and Google addresses shown in settings are default suggestions for the form; if you do not configure and use them, no connection is made.
Once your content reaches a third-party service, its retention and use are governed by your agreement and settings with that service.
Data stored on your device
All of it stays in browser-local storage (storage.local and IndexedDB) and is never sent to the developer:
- extension settings and per-site rules;
- the API key vault, encrypted by default with AES-GCM under a key derived from your master password;
- a cache of translated page text;
- counts of requests, characters, cache hits and errors (shown in settings only, never transmitted);
- optional OCR model packs you chose to download, each verified by SHA-256.
An unlocked key exists only in browser session storage and is gone when the browser restarts. You may explicitly choose “convenient mode”, which stores keys in plaintext in browser-local data — the extension explains the consequence and asks for confirmation before switching. Input-field text is not cached by default. Settings exports never contain keys.
Permissions and retention
Manual translation uses the browser’s temporary activeTab access. Long-lived site permissions are requested per origin only when you enable automatic translation for that site, and can be removed at any time from settings. The site permission needed to download an optional OCR model is revoked immediately once the download finishes or fails.
You can delete all local data by clearing the extension’s data or uninstalling it.
Children and sale of data
Doublet does not sell personal data, serve ads, build user profiles, or perform tracking of any kind.