PRIVACY
How VignetteLens handles data
Last updated August 27, 2026
What we collect
We store the email address you use for your account, a securely hashed password, login and password-reset tokens, your current and scheduled subscription plan, and Stripe customer/subscription identifiers. For API-model subscribers, we also store API usage totals, estimated costs, the encrypted dedicated-key record, and hard-fallback error events.
What the extension processes
When you ask VignetteLens for help, the extension processes the selected study text, your question, and the relevant vignette context. On Amboss, it reads the highlights already rendered in your question page and does not collect Amboss credentials. It temporarily stores membership details and short-lived study state in Chrome extension storage.
Payments
Card details are collected and processed by Stripe’s secure checkout. VignetteLens does not receive or store your full card number or security code.
AI processing
Study content is sent directly to OpenAI using a project-scoped key assigned to the VignetteLens account. If the API has a hard provider failure, the extension may use a signed-in ChatGPT account as a fallback and send a limited technical error record to VignetteLens. Do not submit real patient identifiers or protected health information.
Usage limits and safeguards
VignetteLens does not impose API-cost caps on Web-model usage; limits applied by the user’s ChatGPT account still apply. API-model accounts are limited to 30,000 API requests per calendar month, an estimated $1.00 per day, $7.00 per week, and $15.00 per month, plus daily ceilings of 5,000,000 input tokens and 350,000 output tokens. A single API request is limited to 12,000 input tokens and 2,000 output tokens.
API question threads reset after 20 user messages, 100,000 accumulated input tokens, or 24 hours without activity. Web-model ChatGPT conversations reset after 100 total interactions. Question-panel history can be restored while the current Web conversation cycle remains active.
API usage is checked approximately every 30 minutes. If any API limit is exceeded, VignetteLens disables that account’s dedicated AI credential and records the reason and triggering usage. This intentional limit does not activate web fallback. Access stays disabled until the owner manually reviews and reactivates that account.
How we use data
We use account, subscription, API-usage, and fallback-error data to authenticate you, route the correct plan, operate the extension, prevent abuse, diagnose provider failures, and support your account. We do not sell account data or use it for advertising profiles.
Security and contact
VignetteLens uses HTTPS for communication between the extension, website, and service. For privacy questions or an account-data request, email shubhamsinghcol@gmail.com.