Summary

vOm is a browser extension that runs entirely on the user's own computer. It has no server and no user account. The publisher of vOm operates no backend that receives report data, and cannot read any user's report.

The extension contacts a third party only in three cases, each of which the user starts deliberately: reading Amazon pages during a scan, synchronizing with a cloud provider the user connected, and drafting review text with an AI service the user configured.

What is stored on the user's computer

All of the following is held in the browser's extension-local storage and never leaves the computer unless the user turns on cloud sync:

Choosing Delete data in the extension removes the cached report and scan progress from the computer.

Google user data

This section describes how vOm accesses, uses, stores, and shares Google user data, and applies only when a user has chosen Connect Google Drive. Cloud sync is off until then, and a user who never enables it is never asked to sign in to Google.

What is accessed

vOm requests one OAuth scope and no other:

https://www.googleapis.com/auth/drive.appdata

This scope grants access solely to the hidden application data folder that Google creates for vOm. It conveys no access to My Drive, shared drives, or any file the user created or received. vOm cannot list, read, modify, or delete any other file in the user's Drive, and does not request the drive, drive.file, or drive.readonly scopes.

How it is used

The scope is used for one purpose: to keep a single file, vOm-sync-v1.json, so that the user's other vOm installations can load the same report. The file contains the user's completed Vine report and VCS tags. It additionally contains the user's own OpenAI API key only when the user has explicitly enabled Sync this API key in cloud sync; that setting is off by default.

How it is stored and shared

The file is written directly from the user's browser to the user's own Google Drive over HTTPS. It passes through no server operated by the publisher. Google user data obtained through this scope is not shared with, sold to, or transferred to any third party. It is not used for advertising, and it is not used to train, retrain, or improve any machine-learning or artificial-intelligence model.

Retention and deletion

The file remains in the user's own Google Drive until the user removes it. Selecting Disconnect in the extension stops synchronization and discards the stored OAuth tokens on that computer; it deliberately does not delete the user's existing Drive copy. A user may revoke vOm's access at any time at myaccount.google.com/permissions, and may delete the stored application data through Google Drive's management of hidden app data.

Limited Use

vOm's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft OneDrive

When a user connects OneDrive instead, vOm requests the delegated Files.ReadWrite.AppFolder permission, which is limited to the extension's own application folder. The same single file is written there, and it is visible to the user at OneDrive/Apps/Vine Orders Manager/vOm-sync-v1.json. The same handling, sharing, and deletion terms described above apply.

Amazon

During a scan, vOm reads pages the signed-in user can already open themselves: Vine Orders, Amazon Order History, Order Details, package tracking, and Completed Reviews. It reads these pages in the user's own browser session and sends the extracted values to no one. vOm is not affiliated with Amazon or the Amazon Vine programme, and it never submits a review.

OpenAI

The AI review assistant is optional and runs only when the user selects Generate review. It then sends the drafting context shown in its dialog — the product title and details, Amazon's displayed aggregate rating, the loaded customer reviews, and the user's own rating and comments — to OpenAI using the user's own API key. The key is stored on the user's computer. No AI request is made without the user asking for one, and the Copy final prompt option lets a user work with an outside AI service without any API call from the extension.

User controls

Contact

Questions about this policy: vine-orders-manager@hotmail.com