Privacy manifesto

Why Vidora will never sell your data

In 2025, twelve TikTok downloader extensions were caught infecting 130 thousand users with credential harvesters and remote backdoors. Most popular Chrome video downloaders ask for "read all data on all websites" without telling you why. This page exists so you can verify, line by line, what Vidora collects, what it does not, and how to turn the rest off.

What Vidora never does

  • Never uploads your videos to our servers. Downloads go from the platform CDN straight to your disk. We have no infrastructure capable of storing user video content.
  • Never sends URLs, titles, or page contents in the background. Telemetry uses platform tokens (vimeo, skool, hls, etc.) or a bare root domain (example.com), not the actual URL or title of any video you watched. The only exception is a problem report you send yourself by clicking Report or Send (see the last item of the list below).
  • Never injects ads, affiliate links, or third-party scripts. The popup contains only video cards and download buttons. There is no analytics SDK loaded into your browser.
  • Never persistent user IDs. Our session ID is random, regenerated each time the extension's background worker starts, never saved on your device, and not correlated across sessions. Our server keeps it for about 48 hours, only to link the errors of one short session, then erases it. It never appears in any email.
  • Never sells data to brokers. RGC Digital LLC has no business relationship with any data broker. Vidora is currently free during the launch period and has no payment flow at all.

What Vidora actually collects (and you can disable)

Five categories. The first four are anonymous and switched off by a single toggle in the options page (Settings, Anonymous statistics). The fifth is only ever sent when you click a button yourself: Send in a form, or Report on a failed download.

  1. Usage events. Counters like "popup_opened", "download_completed", "scan_started". No URL, no title. Sent in batched daily digests.
  2. Error reports. When a download fails, we receive a platform token or root domain (never a subdomain; a numeric address as ip, a local network name as local), engine (hls/dash/direct), stage (preflight/segment-fetch/mux), error class (may be tagged with the media server root domain, host=example.com), HTTP status, retry count, encryption type, codec, extension version, browser UI language, operating system family (8 values), Chrome major version, the browser family (Chrome, Edge, Brave, Opera, Vivaldi or other, read from the browser brand names, never from the browser identification string), a yes/no flag for the WebKit JavaScript engine (JavaScriptCore, deduced from an error message format, never from the browser identification string), the ephemeral session ID described above, a random report ID (so a report sent twice is stored once) and the location inside Vidora's own code where the error happened (never browsing data). Never the URL. At most 30 detailed reports per day per device; further occurrences are only counted, so no failure goes unnoticed.
  3. Sites without detection. When the popup finds no video for a reason we can fix (no media element, a player that assembles the stream in the page script, an embedded player we do not recognize yet), one diagnostic report with the root domain of the page (example.com) and that reason. At most once per site and reason per day and 5 per day, never from an incognito window, never emailed, never the URL, and deleted after 90 days (never kept in the long-term daily totals).
  4. Slow download signals. When a download takes 60+ seconds for a large file, we receive duration plus size bucket so we can identify CDN bottlenecks. No URL, no title.
  5. User feedback. Only when you explicitly click Send Feedback and type a message. Your email is optional. This endpoint is the only path that touches data you authored, and it is opt-in by definition. A problem report about a failed download also carries the page address and the technical error class. With the report form, the page address is shown in an editable field and the full video address under Include technical details (untick it to leave the video address and the technical details out) before you click Send. The one-click Report button sends at once, without a preview: the page address, the video address without its query string (the part after the question mark, where sites put access tokens), the technical error class and the download engine; its tooltip lists these items. Either report is emailed to us and kept in our database for 90 days so the failure can be reproduced (details in the privacy policy, section 2.2).

How to verify these claims yourself

Verification matters more than promises. Three ways to check, all in under 5 minutes.

Why this matters in 2026

Chrome extensions are the new browser plugins, and they sit in the same trust position. A video downloader extension has, by design, access to the network traffic of every site you visit. That privilege is too valuable to abuse. The 2025 wave of malicious TikTok downloaders proved the obvious: most users assume an extension on the Chrome Web Store has been vetted, and most have no way to verify the claims a developer makes. Vidora exists to prove that a Chrome extension with a transparent codebase and a single-developer LLC can compete with adware on user experience while never crossing the privacy line.

Related pages