Legal · Privacy

Privacy Policy

Overset has no account, no analytics, no advertising and no server of its own. Here is exactly what that means, including the times text leaves your device.

Updated 11 October 2026 · Applies to Overset 1.5.0

The short version
  • Your projects, fonts and memories stay in your browser. The developer of Overset receives none of them.
  • Text leaves your device only when you load a Google Sheet (read with your own sign-in), start a Claude action (sent to Anthropic with your own key), or use a connection you set up yourself.
  • Keys and tokens stay in your browser and never go into project files or backups. Each project can switch Claude and DeepL off.
  • Nothing is sold, shared or tracked. This website uses analytics only if you accept cookies.

01What this covers

This policy covers the Overset browser extension for Chrome, Microsoft Edge and Firefox, the Overset web app at overset.alpyalay.org, and this website. Overset is made by Alp Yalay, an independent developer based in Istanbul, Türkiye, who is responsible for it. Contact: alpyalay@gmail.com.

The extension and the web app are built so that the developer receives none of your data. Most of this policy is therefore about what stays on your device, and the occasions when something leaves it at your request.

02What is stored, and where

Your projects — strings, translations, glossaries, notes and settings — together with uploaded fonts and imported translation memories, are stored in your browser’s own storage (IndexedDB) on your device. Overset asks the browser to keep that storage persistent, so it isn’t cleared automatically when space runs low.

In the extension, the keys and tokens you choose to add are stored in the browser’s extension storage on your device: an Anthropic API key, a DeepL key, tokens for GitHub, Crowdin and Weblate, and the address of a Discord channel webhook. They are never written into project files or backups, and each is sent only to the service it belongs to, as described below. Overset does not sync them through your browser account.

If you choose a game folder, your browser remembers which folder you picked so you don’t have to pick it again; Overset can reach only what your browser lets it in that folder.

  • Removing a project in Overset deletes it.
  • Uninstalling the extension, or clearing this site’s data for the web app, deletes everything Overset stored.
  • Export → Backup saves a project file you can keep, move to another browser, or delete yourself.

03When data leaves your device

Google Sheets, reading. When you load or sync a sheet in the extension, Overset downloads that sheet from Google as CSV, using your existing Google sign-in, and processes it on your device. While the panel is open, a small script on Google Sheets pages tells it which cell you have selected and the text you are typing there, so the checks can follow you. That information goes only to the Overset panel in your own browser. Google’s privacy policy applies to your use of Google Sheets.

Claude, by Anthropic. Only when you start an AI action — translate, shorten, review, compare with the original, or suggest glossary terms — is the text needed for that action sent to Anthropic. In the extension it goes directly from your browser to Anthropic’s API with your own API key; it does not pass through any server of Overset’s. The text sent can include the strings involved, your translation, and the glossary entries and memory matches used as context. Anthropic’s terms and privacy policy apply to that request. Each project has a Confidential switch that turns Claude off for it.

The web app has no API key setting, so Claude features are unavailable there — except when the same page is opened inside Claude at claude.ai, where requests go through your own Claude account under Anthropic’s terms.

Connections you set up. See the next section. Nothing in it happens until you use that connection.

Fonts. The web app loads its typeface from Google Fonts, which receives your IP address and browser details when it does. The extension bundles its fonts and doesn’t. Fonts you upload to measure text stay on your device.

04Connections you choose

Connections are available in the extension only; the web app has none. Each is off until you use it. The first time, your browser asks for permission to reach that service, and you can decline. The service’s own terms and privacy policy apply to what you send it.

  • Google Sheets, writing. If you choose to write your changes to a sheet, you sign in with Google in a window your browser opens. Google gives Overset a short-lived access token with permission to work with your spreadsheets (Google’s spreadsheets scope). Overset keeps it only in memory for that session, doesn’t save it, and uses it for two things: reading the sheet’s cell notes, and writing only the cells you changed in your own column — as plain text, never formulas — after reading each one again so it doesn’t overwrite someone else’s edit.
  • Game folder (Chrome and Edge). Overset reads and writes only inside the folder you pick, and copies any file it replaces into a .overset-backup folder there first.
  • GitHub. Overset reads the repository you open and sends back what you choose: a pull request (from a fork when you can’t push) or an issue. If you sign in with GitHub, you see a short code and approve it on github.com; GitHub gives Overset a token with the access you approve — every repository you can see, if you include private ones. It is kept in this browser, and you can revoke it at any time at github.com/settings/applications. You can also paste a token yourself.
  • Crowdin and Weblate. Overset reads the project you open and sends back only what you changed: translations and, for Crowdin, problems posted as issues on a string. For a self-hosted Weblate server, your browser is asked for access to that one address only, never to other sites.
  • DeepL. The text of the strings you ask it to translate, and your glossary terms, are sent to DeepL under your own key. It is off for projects marked Confidential.
  • Discord. Progress, release notes or developer questions are posted to the channel webhook you add.

05Google user data

Overset’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

  • Information from Google is used only to provide the features you ask for: reading a sheet’s notes and writing your changed cells.
  • It is processed on your device. It is not sent to the developer, and it is not sold, shared with third parties, or used for advertising.
  • No person reads your spreadsheet data; there is no server where it could be read.

06What Overset does not do

  • No account, sign-in or user profile of Overset’s own.
  • No tracking, analytics, telemetry or crash reporting in the extension or the web app.
  • No advertising, and no selling, renting, sharing or transferring of your data to anyone.
  • No use of your data to determine creditworthiness or for lending.
  • No remote code: everything the extension runs ships in the package you install.

07This website

overset.alpyalay.org is part of alpyalay.org and runs on the same hosting. A few things here work differently from the extension:

  • Hosting. The site is served by Cloudflare. Like any web server, it processes your IP address and request details to deliver pages, keep the service secure and limit abuse.
  • Analytics, only with consent. The site can use Google Analytics 4 with Google Consent Mode. Analytics storage is denied by default and stays denied unless you choose Accept in the cookie banner; advertising storage is always denied. Your choice is kept in your browser’s local storage, and you can change it at any time with Cookie settings in the footer.
  • Support form. If you use the form on the support page, your name, email address, topic and message are delivered by Web3Forms to the developer’s Gmail inbox. They are used only to answer you and kept while your request and any follow-up need them. You can email alpyalay@gmail.com instead.
  • Site-wide features. Two features of alpyalay.org also appear here. The “Ask about my work” assistant can send a question you type to this site’s server, which matches it against a fixed set of answers and does not store it. Finding one of the hidden easter eggs sends an anonymous count — the egg’s name and your language setting, with no identifier — and your IP address is used briefly to rate-limit that count. See also the alpyalay.org privacy policy.

None of this applies to the extension, and none of it can see your Overset projects.

08Your rights

Depending on where you live, laws such as the GDPR and Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK) give you the right to access, correct, delete or object to the processing of personal data about you, and to complain to a data protection authority.

Because Overset keeps your project data on your device, you exercise most of these rights directly: edit or delete the project, or remove the extension. For anything the developer does hold — a support email, for example — write to alpyalay@gmail.com and it will be handled without charge.

09Security

Data on your device is protected by your browser and operating system; keep them updated and lock your device. Requests to Google, Anthropic and the services you connect are made over HTTPS.

Keys and tokens are stored like other extension data, so anyone with access to your browser profile could read them. Remove one from Overset’s settings when you no longer need it, and revoke it at its source: Anthropic’s console, GitHub’s application settings, your Google account’s third-party access page, or the service’s own token page.

10Children

Overset is a professional tool, not directed at children under 13, and it collects no personal information from anyone.

11Changes to this policy

If Overset starts handling data differently, this page will be updated before or with the release that changes it, with a new date, and the change will be noted in the changelog. This revision, dated 11 October 2026, adds the optional connections introduced in version 1.3.

12Contact

Alp Yalay, Istanbul, Türkiye — alpyalay@gmail.com.