KM Studio — Privacy Policy

Last updated: 26 September 2026 · O'zbekcha

KM Studio is a Chrome extension that runs image and video generation in Google Flow in batches. This document explains what the extension collects, why, and — just as importantly — what it does not collect.

The short answer: we never see or store your prompts, or the images and videos you generate. Those stay between your browser and Google Flow. The only usage data that reaches our server is how many generations you ran (a number, for statistics). The one exception is a problem report that you choose to send (section 1c). Prompts are unlimited on every plan; the paid Pro plan unlocks extra features (section 1d).

1. What is collected

a) When you sign in with Google

Signing in happens through Google only. Google gives us:

DataWhy it is needed
The stable identifier of your Google account To recognise your account. We rely on this identifier rather than the email address, so changing your Gmail address does not lose your account or subscription
Email address To show which account is signed in, and to contact you about subscription and payment
Name and profile picture So the extension panel can show who is signed in

We request only the openid, email and profile scopes. We have no access to your Gmail messages, Google Drive files, contacts, calendar or any other Google data — not by policy, but technically.

We never see or store your password: it is entered only on Google's own page.

b) For the extension to work

DataWhy it is needed
Install identifier (install_id) — a random number created when the extension is installed To recognise this computer: so the one-time free Pro trial is given only once per computer, and to count usage for users who are not signed in
Device name — operating system and browser version (for example «Windows · Chrome 141») To list the devices linked to one account and to cap their number (this prevents subscription sharing)
Daily generation count (a number only) Usage statistics (and a daily limit, if one is ever switched on again)
Free-trial markers: your Google account identifier and the install identifier (both listed above), plus a salted one-way hash of your network address (IPv4 address or IPv6 /64 — the address itself is not stored) To give the free 3-day Pro trial only once and to stop one person from collecting trials with many accounts. Kept while the account exists; the network hash is only compared within 30 days
Telegram chat ID — only if you link Telegram in the bot Payment and subscription notices; on Pro, a «queue finished» message with numbers only (how many done / failed)
Payment identifier and amount — only if you buy a subscription To confirm the payment and activate the subscription

Your card details (number, expiry, CVV) never reach our server — they are handled by the payment provider itself.

c) Only if you send a problem report or contact support

DataWhy it is needed
Problem report — sent only when you press «Report a problem» in the extension and confirm it: extension version, interface language, the latest part of the extension's log (it can contain prompt titles or text and file names), panel settings and the browser's user-agent So the developer can find the cause of the error. The report is kept on our server for up to 7 days and is delivered as a file to the developer's Telegram chat. Nothing is sent unless you press the button and confirm
Support messages — what you write or attach in the Telegram bot @KMStudioPro_bot after «Message the admin»; a ticket record (Telegram chat ID, ticket number, your account email and plan, timestamps) To forward your message to the developer and deliver the reply back to you. Ticket records are kept for up to 180 days
Help-center questions the bot could not answer (the question text, Telegram chat ID, language; the latest 300 only) To improve the help answers

d) Free and Pro plans

Prompts are unlimited for everyone. The paid Pro plan unlocks extra features (background upscale, 2–5 images in parallel, x3–x4 results per prompt, gallery ZIP, frame chain, Telegram report, automatic resend of failed prompts, CSV report). If you sign in with Google you can try Pro free for 3 days, once — no card is asked and it ends on its own. The seller is KM Studio, not Google. Terms of sale and refunds: kontent-markazi.pages.dev/shartlar.

2. What is NOT collected

3. Why each permission is requested

PermissionWhy
debugger Google Flow's prompt field is a rich-text editor that rejects synthetic input events; attaching the debugger to that one tab is the only method that actually works. It is used only on Google Flow pages and only after you press «Start». Chrome shows its own banner while it is attached
downloads To save each finished image/video under the correct, numbered file name
storage To keep your settings and sign-in state inside your own browser
identity To open the Google sign-in window
tabs To detect whether a Google Flow tab is open and to focus it. The URLs of your other tabs are not read and never leave your machine
sidePanel To open the extension's own side panel (the whole workspace lives there)
notifications A browser notification when a long queue finishes, so you can work on something else meanwhile
cookies (optional) Only when you press the «🧹 Flow cache» button, and only to clear the rate-limit cookie on the Google Flow domain. If you decline this permission the extension keeps working
host_permissions labs.google and flow.google.com — where the work happens; kontent-markazi.pages.dev and km-studio-api…workers.dev — our own server (account, plan, trial). No other site can be accessed

3-bis. Limited Use of Google user data

KM Studio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, the data obtained from your Google account (openid, email, profile):

Your prompts, images and videos are not Google API data — they stay between your browser and Google Flow and never pass through our server, except the log excerpt inside a problem report that you choose to send (1c).

4. Who the data is shared with

We never sell your data and never use it for advertising. It passes only through these services:

Data may be disclosed on a formal legal request where the law requires it.

5. Security

6. How long data is kept

7. Your rights

At any time you may request:

Write to the address below. Account deletion requests are completed within 30 days.

8. Children

KM Studio is not directed to children under 13 and we do not knowingly collect data from them.

9. Changes to this policy

If this policy changes, the date at the top of the page is updated and the change is announced in the extension panel. Continuing to use the extension after a change means you accept the updated policy.

10. Contact

Questions, data requests, account deletion: behzodbekolimov@gmail.com · Telegram @KMStudioPro_bot