# Chrome Web Store 审核与隐私字段说明

核对日期：2026-10-08。适用于当前 0.1.0 源码及 manifest。以下英文纯文本块可用于审核字段；中文说明用于发布前核对。此文件没有替你执行发布、勾选认证或提交审核。

## 单一用途（Single purpose description）

```text
Let users check an individual webpage image for a Google SynthID watermark through synthid.com after choosing the extension's image context-menu item, and display the service's result beside that image. The user must already be signed in to synthid.com in the same browser profile. The chosen image is submitted to Google's service for processing.
```

登录提示、重试、配额提示和结果卡片均服务于这一个用途。官网要求用途明确、易理解，并要求按实际 manifest 解释权限。[官方隐私字段说明](https://developer.chrome.com/docs/webstore/cws-dashboard-privacy/)

## 权限理由

### contextMenus

```text
Adds the “SynthID Detector” menu item only to image context menus. A user selects this item to initiate a check of that image; the extension does not start detection automatically when a webpage loads.
```

### scripting

```text
Injects the packaged page content script into the frame selected by the user when that script is missing, such as a page opened before the extension was installed. The script anchors the result card to the selected image and retrieves image data in the page context when required. It does not inject remotely downloaded code.
```

### storage

```text
Uses chrome.storage.session to store only the identifier of the temporary synthid.com work tab. This allows the extension to reuse that tab for queued checks and close it after the queue finishes. The extension does not store image data or a detection history in extension storage.
```

### 主机权限 <all_urls>（当前实现的理由）

```text
The user may select an image on webpages across different origins, and the image itself may be hosted on a separate origin or CDN. The current implementation uses host access to fetch the selected image with the browser's applicable credentials, locate that image in the originating frame, and display its result card. Access to https://synthid.com/ is also used to supply the image to the site's upload control and read the resulting status through the user's existing signed-in session. Image data is fetched and submitted only after the user's context-menu or Retry action.
```

此段说明当前架构，不能证明它已是最小权限方案。普通网页内容脚本在页面加载后即注入，记录右键目标元素以定位结果卡片；并非只有点击菜单后才获得全部网页访问能力。要审查是否可改为 activeTab、按需注入及范围更窄或可选的主机权限。任意图片可能来自跨域 CDN，不能只将图片下载权限改成 synthid.com 就认为功能等价。官方要求申请实现功能所需的最小权限。[Use of Permissions](https://developer.chrome.com/docs/webstore/program-policies/permissions)

### tabs（已从 manifest 移除）

扩展会创建、更新、读取指定工作标签页、等待其加载、发消息和关闭标签页，这些操作都不需要 `tabs` 权限。官方说明 `tabs` 主要开放 URL、标题等敏感属性，而当前代码未使用这些属性，所以已从 manifest 移除该权限，权限字段中无需再说明。发布前仍应用最终包验证完整图片检查与登录流程。[官方 Tabs API 权限说明](https://developer.chrome.com/docs/extensions/reference/api/tabs)

## 数据使用披露

可用于补充说明字段的英文：

```text
After a user chooses the extension's image context-menu item or Retry action, the extension processes that selected image, its source URL, a file name derived from the URL, and the detection result to provide the requested check. The image and derived file name are supplied to the upload control on synthid.com, whose own website uploads and processes them using the user's existing signed-in browser session. The original image source URL is used to retrieve the image and place the result card; the extension does not intentionally submit the full source URL as a separate field to synthid.com.

The extension checks whether synthid.com's local Firebase authentication storage contains an authenticated-user key. It reads key names, not the account record values, passwords, or authentication tokens, and does not send those key names to the developer. Image retrieval uses browser-managed credentials where applicable; the extension does not read cookie values.

No developer-operated upload endpoint, analytics, advertising, or persistent image/result history is present in the current extension. Image data and results are handled temporarily in browser memory; the result card remains on the originating page until closed or the page ends. Session storage contains a temporary work-tab identifier. Normal browser caching and the third-party service's data retention are not controlled by the extension. Google's processing is governed by the notices and terms shown by synthid.com.
```

提交“Data usage”时应以当时表单的定义及最终包为准。当前至少需要披露“Website content”：选择的图片会被访问并传至 Google；不能勾选“未收集/处理任何用户数据”。图片 URL 也会被处理，应按表单对 “Web history” 的定义披露其使用范围是用户主动选择的图片来源，未创建浏览历史记录。对 “Authentication information” 应说明只检查登录状态对应的存储键名，不读取密码或令牌；若当期表单将登录状态纳入该类，也需勾选。其他类别按实际主动处理的数据填写，不能声称图片永远不含个人信息。开发者的客服或网站如有额外数据处理，应在正式政策中补充。

隐私政策 URL 必须公开可访问，并与商店披露和产品行为一致；本目录附带中英文草案，发布者名称、邮箱和生效日期仍须填入。[Privacy Policies](https://developer.chrome.com/docs/webstore/program-policies/privacy)

## 远程代码字段

当前源码未发现下载并执行扩展逻辑、`eval`、`new Function` 或远程脚本注入；检测逻辑打包在扩展内。synthid.com 是浏览器加载的普通网站，扩展与其上传控件和结果 DOM 交互。按当前源码判断，远程代码字段应选择 “No, I am not using remote code”；仍需检查最终构建产物和依赖，确保与源码判断相符。[官方字段说明](https://developer.chrome.com/docs/webstore/cws-dashboard-privacy/)

可粘贴补充说明：

```text
All extension logic is packaged with the extension. The extension does not fetch or execute remotely hosted extension code. It opens synthid.com as a normal browser tab and uses packaged content scripts to interact with the site's upload control and read the detection result.
```

## 给审核员的复现步骤

```text
This is an independent third-party extension for image checks only. It requires access to synthid.com and a Google account that can use that service; no extension-specific account or subscription is required.

1. Install the extension and open an ordinary HTTPS webpage containing an accessible JPG or PNG image that you are permitted to upload to Google. Do not use chrome:// pages or the Chrome Web Store itself as the test page.
2. In the same Chrome profile, sign in to https://synthid.com/ with a Google account that is eligible to use the service. Allow the site to finish loading.
3. Return to the image page. Right-click the image and choose “SynthID Detector.”
4. A loading card should appear beside the image. The extension opens a non-active synthid.com work tab, supplies the selected image to the site's upload control, and waits for the site's result.
5. When the service responds, the card shows its result. A watermark is not guaranteed for an arbitrary test image: not detected, inconclusive, quota, and error states are valid outcomes. Confidence is shown only when supplied by the service.
6. After queued checks finish, the extension closes its own work tab. The card can be closed with its close button.
7. To inspect the sign-in flow, test in a browser profile that is not signed in to synthid.com. The card should show “Sign in required” and offer “Open synthid.com.” After signing in, return and choose Retry.

Checks are serialized and depend on service quota, access, website structure, and network availability. This extension does not bypass login, quota, or other website restrictions. It is not a general detector for all AI-generated images.
```

不要把素材里的示例阳性结果当作实测证明。审核用阳性图片应由发布者提供具有 SynthID 水印、允许上传且能通过当前网站检测的实际样本；未提供样本时可验证操作和正常返回状态，不能承诺一定检测到水印。不要将个人账号密码写进公开的说明或素材。

## 当前实现与上架文案之间的发布前检查

1. 用最终包验证 synthid.com 的实际可用性、登录和检测流程。驱动依赖网站 DOM 与英文结果匹配规则，中文扩展界面不代表 synthid.com 的所有语言都能可靠解析。
2. 检查最小权限，尤其是 `<all_urls>`。以上理由基于当前代码，不替代必要性验证。
3. 清楚披露上传对象、用途和已有登录会话。当前右键项只有名称，选择后立即开始获取和上传；加载卡片说明上传不等于已验证所有披露与同意要求。建议增加上传前明确说明的产品入口或确认流程，并确认是否已有安装前充分披露和知情同意。[Disclosure Requirements](https://developer.chrome.com/docs/webstore/program-policies/disclosure-requirements/)
4. 补齐发布者和支持渠道，发布隐私政策，然后填正式 URL。有限使用承诺应由发布者确认真实适用，不能仅因为草案已有文字就直接认证。[Limited Use](https://developer.chrome.com/docs/webstore/program-policies/limited-use)
5. 名称和图标不得暗示 Google 官方发布。文案已写明独立第三方；检查最终截图和宣传图的同类表述。
6. 对照素材与最终包：只支持图片、原图旁卡片、英文/简体中文界面，以及登录、配额、网络与页面访问限制；不要宣称所有图片均支持、即时返回或完全准确。

## 待发布者填写

- 实际发布者/运营主体：`[PUBLISHER NAME]`
- 联系邮箱：`[SUPPORT EMAIL]`
- 正式隐私政策 URL：`[PUBLIC PRIVACY POLICY URL]`
- 支持页面 URL：`[SUPPORT URL]`
- 隐私政策生效日期：`[EFFECTIVE DATE]`
- 实际审核用测试页面/样本（如准备）：`[TEST PAGE OR SAMPLE URL]`

素材制作过程中没有代填以上身份信息，没有创建或发布网页，没有提交 Chrome Web Store。
