Active Reader / LegalEffective 6 October 2026

Privacy, in plain language.

Your selected text, reading history, and reading progress are not sent to Synodic Hub. Optional Account linking sends a one-time link code and random installation identifier; legacy supporter verification also sends the email and redemption code entered for that older flow.

01 / Summary

Most processing stays on your device.

Active Reader reads only the text you deliberately select for a reading session. It uses that text in the page you are viewing and does not send it to Synodic Hub, Supabase, Ko-fi, advertising networks, or analytics services.

The extension does not contain advertising, behavioural analytics, tracking pixels, or remote executable code. Optional Account linking and the legacy supporter-code flow are the only features that send extension-entered information to a Synodic Hub service. Core reading features remain available without either flow.

02 / Data handled

What is stored, and where.

InformationPurposeLocationSent to us?
PreferencesReading mode, keybindings, themes, pacing, and display choicesBrowser storageNo
Reading progressURL, current segment, scroll position, and timestamp used to offer local resume; automatically removed after 180 daysBrowser storageNo
Reading historyPage title, URL, short selected-text snippet, and timestamp when you enable history; automatically removed after 90 daysBrowser storageNo
Selected page textCreates the active reading session; True Isolation holds plain text in extension session storage and removes a stale session after 30 minutesTemporary page or extension-session memoryNo
Account-link requestA single-use AR1 link code and random installation identifier bind eligible Account access to this extension installationProcessed by Synodic’s production Supabase function; the database stores one-way hashes and challenge state rather than the plaintext link code or credentialYes, if used
Account-linked accessA revocable installation credential requests short-lived signed entitlement data describing the eligible tier, capabilities, and expiryThe browser stores the random identifier, credential, and signed entitlement; Supabase stores hashed installation and credential values with access statusYes, if used
Legacy supporter recordEmail, initial code, tier, active status, Ko-fi transaction reference, device allowance, and one-way hashes used to verify previously issued accessSupabase; after successful activation the browser stores the random identifier, revocable credential, and short-lived signed entitlement instead of the email and codeYes, if used
Reading history is optional. Reading progress is enabled by default and can be disabled or cleared from Active Reader’s Advanced settings. Both remain local to the browser profile, are not saved in private/incognito contexts, and are automatically pruned at the periods listed above.

03 / Account and supporter access

Optional verification only.

For current Account linking, an authenticated Synodic Account can create a case-sensitive, single-use AR1 code that expires after ten minutes. Active Reader sends the code and a randomly generated installation identifier to Synodic’s production Supabase function over HTTPS. A successful exchange returns a revocable installation credential and short-lived, cryptographically signed entitlement. The browser stores the random identifier, credential, and entitlement so it can refresh and verify eligible paid capabilities at startup and approximately every hour.

The plaintext AR1 code is returned once to the authenticated Account page and is not stored in the database. Supabase stores a one-way hash with expiry, consumption, and invalidation state. The installation identifier and issued credential are also stored server-side only as one-way hashes. The identifier is random and is not a hardware or browser fingerprint. Signed entitlement data includes the installation binding, eligible tier and capabilities, issue and expiry times, an entitlement identifier, and a signature; it does not include reading content or browsing history.

For previously issued supporter access, Ko-fi may send the email address associated with the payment and the contribution type to a Synodic Hub Supabase function. A redemption code may be delivered through Resend. When you use that older flow, Active Reader sends the email, code, and random installation identifier to Supabase. After successful activation, the extension removes the email and code from its saved state and uses the same revocable credential and signed-entitlement model.

Disconnecting an Account-linked or legacy installation asks the service to revoke its credential and removes the local credential and entitlement. The random installation identifier remains in browser storage until Active Reader’s extension data is cleared or the extension is uninstalled. Server challenge and credential records retain expiry, consumption, invalidation, or revocation state as security and access records; the current implementation does not define a fixed automatic deletion period for those records.

As with any internet request, Supabase may process ordinary network metadata such as an IP address and request headers for delivery, reliability, and security. Synodic Hub does not intentionally add that metadata to the supporter database.

Account-link and supporter information is used only to create, deliver, verify, refresh, revoke, or support access. It is not used for advertising or unrelated marketing. These checks do not include passwords, Account browser sessions, selected page text, reading history, reading progress, or unrelated browsing information.

04 / Service providers

Who processes information.

Supabase

Hosts the Account-link and legacy supporter verification functions and related access records. Read Supabase’s privacy policy.

Ko-fi

Processes voluntary contributions under its own terms. Synodic Hub does not receive card or bank details from Ko-fi. Read Ko-fi’s privacy policy.

Resend

May process the supporter email address to deliver a redemption code. Read Resend’s privacy policy.

Netlify

Hosts the Synodic Hub website. This website does not add analytics or advertising cookies, although Netlify may process ordinary network and security logs as the hosting provider. Read Netlify’s privacy statement.

05 / Your choices

View less, save less, delete it.

  • Disable or clear local reading history and progress from Advanced settings.
  • Disconnect this device from the Settings page, which revokes its server-side credential and removes the locally saved credential and entitlement.
  • Uninstall Active Reader to remove its browser-managed local storage.
  • Clear Active Reader’s extension data or uninstall it to remove the random installation identifier that remains after disconnecting.
  • Ask about Account-link or legacy supporter records held in Supabase by contacting support; we may need to verify the associated Account or legacy supporter email.

Challenge and credential records currently have no fixed automatic deletion period in the implementation. They may remain with their expired, consumed, invalidated, or revoked state as bounded security and access records. Contact support for a record request; some records may need to be retained for security, access-integrity, or legal reasons.

06 / Security

Designed around limited access.

Network requests use HTTPS. The extension contains a public Supabase publishable key and a public signature-verification key, both of which are expected to be visible in client software. Account-link and legacy supporter operations run behind a rate-limited server function; administrative database and entitlement-signing credentials are not included in the extension. Link codes and installation credentials are stored server-side as one-way hashes. Signed entitlements are bound to the random installation identifier and are rejected after expiry or if altered.

No internet service can guarantee absolute security. We limit the information collected, restrict database access, and will update this policy if the extension’s data handling changes materially.

07 / Contact

Questions or deletion requests.

Email support@synodichub.com. To protect access records, we may ask you to authenticate the associated Account or write from the email address attached to a legacy supporter code.

Policy updates will be published at this URL with a revised effective date. If a change materially expands data collection or use, we will provide notice appropriate to the change before it takes effect.