01 / Summary
Most processing stays on your device.
Active Reader reads only the text you deliberately select for a reading session. It uses that text in the page you are viewing and does not send it to Synodic Hub, Supabase, Ko-fi, advertising networks, or analytics services.
The extension does not contain advertising, behavioural analytics, tracking pixels, or remote executable code. The optional Supporter Programme is the only feature that sends extension-entered information to a Synodic Hub service.
02 / Data handled
What is stored, and where.
| Information | Purpose | Location | Sent to us? |
|---|---|---|---|
| Preferences | Reading mode, keybindings, themes, pacing, and display choices | Browser storage | No |
| Reading progress | URL, current segment, scroll position, and timestamp used to offer local resume; automatically removed after 180 days | Browser storage | No |
| Reading history | Page title, URL, short selected-text snippet, and timestamp when you enable history; automatically removed after 90 days | Browser storage | No |
| Selected page text | Creates the active reading session; True Isolation holds plain text in extension session storage and removes a stale session after 30 minutes | Temporary page or extension-session memory | No |
| Supporter record | Email, initial code, tier, active status, Ko-fi transaction reference, device allowance, a one-way hash of a random installation identifier, and a one-way hash of a revocable installation credential | Supabase; after successful activation the browser stores the credential, random identifier, and a short-lived signed entitlement instead of the email and code | Yes, if used |
03 / Supporter Programme
Optional verification only.
If you support Active Reader through Ko-fi, Ko-fi sends the email address associated with the payment and the contribution type to a Synodic Hub Supabase function. A redemption code is created and may be delivered through Resend.
When you enter that email and code in Active Reader, the extension sends both and a randomly generated installation identifier to Supabase over HTTPS. Supabase stores one-way SHA-256 hashes of that identifier and a newly generated installation credential; the identifier is not a hardware or browser fingerprint. After successful activation, the extension removes the email and code from its saved state and uses the revocable credential to request a short-lived, cryptographically signed cosmetic entitlement at browser startup and approximately every hour. The entitlement also expires locally at its signed deadline. These checks do not include page text, reading history, reading progress, or unrelated browsing information.
As with any internet request, Supabase may process ordinary network metadata such as an IP address and request headers for delivery, reliability, and security. Synodic Hub does not intentionally add that metadata to the supporter database.
Supporter information is used only to create, deliver, verify, revoke, or delete supporter access. It is not used for advertising or marketing.
04 / Service providers
Who processes information.
Supabase
Hosts the supporter redemption database and verification function. Read Supabase’s privacy policy.
Ko-fi
Processes voluntary contributions under its own terms. Synodic Hub does not receive card or bank details from Ko-fi. Read Ko-fi’s privacy policy.
Resend
May process the supporter email address to deliver a redemption code. Read Resend’s privacy policy.
Netlify
Hosts the Synodic Hub website. This website does not add analytics or advertising cookies, although Netlify may process ordinary network and security logs as the hosting provider. Read Netlify’s privacy statement.
05 / Your choices
View less, save less, delete it.
- Disable or clear local reading history and progress from Advanced settings.
- Sign out this device from the Settings page, which removes its server-side device registration and locally saved credential and entitlement.
- Uninstall Active Reader to remove its browser-managed local storage.
- Request deletion of the supporter record held in Supabase by contacting us from the email address associated with it.
Supporter records are retained for as long as needed to administer the programme, resolve payment or access issues, and meet applicable legal obligations, unless deletion is requested sooner and no legal requirement prevents it.
06 / Security
Designed around limited access.
Network requests use HTTPS. The extension contains a public Supabase publishable key and a public signature-verification key, both of which are expected to be visible in client software. Supporter database operations run behind a rate-limited server function; administrative database and entitlement-signing credentials are not included in the extension. Signed entitlements are bound to the random installation identifier and are rejected after expiry or if altered.
No internet service can guarantee absolute security. We limit the information collected, restrict database access, and will update this policy if the extension’s data handling changes materially.
07 / Contact
Questions or deletion requests.
Email synodicentertainment.official+privacy@gmail.com. To protect supporter records, we may ask you to write from the email address attached to the code.
Policy updates will be published at this URL with a revised effective date. If a change materially expands data collection or use, we will provide notice appropriate to the change before it takes effect.