Who We Are
Auto Heygen by BU Labs is a Chrome Extension developed and maintained by BU Labs. We build productivity tools to help creators automate AI video production on the Heygen platform.
Our website and backend API operate at heygen-bu-labs.toolsfinity.io. You can reach us at any time at baddarbukhari@gmail.com.
What Data We Collect
We collect only the minimum data necessary to operate the extension. Here is a full breakdown:
| Data Type | Collected? | Purpose |
|---|---|---|
| Email address | Yes | Account creation and license verification on our backend |
| Authentication token | Yes | Keep you logged in to your BU Labs account across sessions |
| User preferences | Yes | Remember avatar, voice and settings locally in Chrome storage |
| Browsing history | No | — |
| Personal identifiable info | No | — |
| Financial or payment data | No | — |
| Health information | No | — |
| Location data | No | — |
| Personal communications | No | — |
How We Use Your Data
- To authenticate your BU Labs account and verify your license to use the extension.
- To store your avatar, voice, and generation preferences locally so you don't have to reconfigure each session.
- To communicate with our backend API for session management and feature access control.
We do not sell, rent, share, or trade your personal data with any third parties for marketing, advertising, or any other commercial purpose.
Where Data Is Stored
-
Locally on your device: Authentication tokens and user preferences are stored in Chrome's
chrome.storage.localAPI. This data never leaves your browser unless you explicitly trigger an API call. -
Our secure server: Your email address and account record are stored on our backend at
heygen-bu-labs.toolsfinity.iousing industry-standard HTTPS (TLS) encryption.
You can delete all local data at any time by uninstalling the extension or clearing Chrome's extension storage from chrome://settings.
Permissions Explained
The extension requests the following Chrome permissions. Every permission is required for a specific function — we request nothing extra.
| Permission | Why It's Needed |
|---|---|
| activeTab | Detects when you are on app.heygen.com to activate automation features on the correct page only. |
| scripting | Injects automation controls into Heygen to fill scripts and trigger video generation on your behalf. |
| storage | Saves your session token and preferences locally so you don't need to log in every browser session. |
| tabs | Detects navigation to Heygen to automatically open the side panel and provide contextual controls. |
| sidePanel | Renders the extension UI as a Chrome Side Panel alongside app.heygen.com — a non-intrusive workspace. |
| downloads | Allows generated videos to be saved directly to your computer from within the side panel. |
| webRequest | Monitors Heygen's API responses to accurately track and display video generation progress in real time. |
| host_permissions | Required access to app.heygen.com (main platform), our backend API, Pexels media, and Heygen's AWS/CloudFront CDN infrastructure for complete functionality. |
This extension does not execute any remote code. All JavaScript is bundled locally within the extension package. External services are only contacted via standard fetch() requests to retrieve data (JSON responses).
Third-Party Services
The extension interacts with the following third-party services as part of its operation. Each service has its own privacy policy that governs their data practices:
- app.heygen.com — The Heygen video platform (Heygen Inc.). The extension automates actions on this site on your behalf.
- api.pexels.com — Stock media library (Canva/Pexels). Used optionally to browse royalty-free assets.
- AWS S3 / CloudFront — Media delivery infrastructure used by Heygen to serve video thumbnails and rendered outputs.
- heygen-bu-labs.toolsfinity.io — Our own backend API for authentication and license management.
We do not control the data practices of Heygen, Pexels, or AWS. Please review their respective privacy policies for more information.
Data Retention
Local data (token, preferences) can be deleted at any time by uninstalling the extension or clearing its Chrome storage.
Account data on our server is retained while your account is active. You may request permanent deletion of your account and all associated data at any time by contacting us at baddarbukhari@gmail.com. Deletion requests are processed within 30 days.
Children's Privacy
This Extension is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately at baddarbukhari@gmail.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will revise the "Last Updated" date at the top of this page.
Continued use of the extension after changes are posted constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
Contact Us
If you have any questions, concerns, or data deletion requests regarding this Privacy Policy or how we handle your data, we are here to help.
Get in Touch with BU Labs
We typically respond within 1–2 business days. For data deletion requests, we process them within 30 days.