Privacy Policy
Last updated: August 19, 2026
Overview
HeyGen Bulk Downloader ("the Extension") is a Chrome browser extension built and operated by an independent developer ("we", "us"). This page explains what information the Extension handles, how it is used, and what we do not collect.
We built this Extension with a minimal data footprint by design. We do not run servers that receive or store your personal data. We do not sell, share, or monetize any information from users.
What the Extension stores locally
The Extension stores the following items in your browser's local storage (chrome.storage.sync) on your own device:
- Your Gumroad license key — stored to verify that you have a valid license. This key is periodically re-verified against Gumroad's public license verification API.
- Your HeyGen API key — stored so you do not need to re-enter it each time you open the Extension. This key is used exclusively to communicate with HeyGen's servers on your behalf.
- Your last download date — a simple timestamp stored locally to display in the Extension UI.
None of this information is transmitted to us. It lives in your browser and stays there.
What the Extension transmits to third-party services
To HeyGen (api.heygen.com): Your HeyGen API key is sent with each request to HeyGen's servers to retrieve your video library and download URLs. This is identical to what the HeyGen web app does when you log in and view your videos. Your API key is sent directly from your browser to HeyGen — it does not pass through our servers. HeyGen's own privacy policy governs how they handle this data: heygen.com/privacy-policy.
To Gumroad (api.gumroad.com): When you activate the Extension or when the Extension silently re-verifies your license on startup, your Gumroad license key is sent to Gumroad's license verification endpoint. This is a standard Gumroad-provided mechanism for license validation. Gumroad's own privacy policy governs how they handle this: gumroad.com/privacy.
To HeyGen file servers (files.heygen.ai): When you trigger a bulk download, your browser downloads video files directly from HeyGen's file hosting servers. This is a standard browser file download, identical to clicking a direct link in Chrome.
What we do not collect
- We do not operate any backend server or database.
- We do not receive, log, or store your HeyGen API key.
- We do not receive, log, or store your license key beyond what Gumroad's API requires for verification.
- We do not collect analytics, usage statistics, or telemetry of any kind.
- We do not collect your name, email address, or any personally identifiable information through the Extension itself.
- We do not use cookies.
- We do not track which videos you download or how often you use the Extension.
Permissions the Extension requests and why
The Extension requests the following Chrome permissions:
- storage — to save your API key and license key locally in your browser so you don't have to re-enter them each session.
- downloads — to trigger video file downloads to your Downloads folder on your behalf.
- host permissions for api.heygen.com — to communicate with HeyGen's API to fetch your video list and download URLs.
- host permissions for api.gumroad.com — to verify your license key against Gumroad's verification endpoint.
No other permissions are requested or used.
Data retention
All data the Extension stores (your API key, license key, and last download timestamp) remains in your browser until you either:
- Click "Disconnect" in the Extension, which removes your HeyGen API key from storage.
- Uninstall the Extension, which removes all stored data.
- Manually clear your browser's extension storage.
We have no way to delete data stored in your browser on your behalf because we never receive it in the first place.
Children's privacy
This Extension is not directed at children under the age of 13 and we do not knowingly collect any information from children.
Changes to this policy
If we update this policy, we will update the "Last updated" date at the top of this page. Continued use of the Extension after any changes constitutes acceptance of the updated policy. We will not make changes that retroactively grant us new rights over data we do not currently collect.
Contact
If you have any questions about this privacy policy or how the Extension handles your data, contact us at support.grabkit@gmail.com.