|
| 1 | +--- |
| 2 | +import BaseLayout from "../../../../../layouts/BaseLayout.astro"; |
| 3 | +--- |
| 4 | + |
| 5 | +<BaseLayout |
| 6 | + title="mdbase Reader extension privacy" |
| 7 | + description="How the mdbase Reader browser extension handles page content, annotations, browsing addresses, and Connect authorization." |
| 8 | +> |
| 9 | + <article class="legal"> |
| 10 | + <header> |
| 11 | + <h1>mdbase Reader browser extension privacy</h1> |
| 12 | + <p> |
| 13 | + This page covers the mdbase Reader browser extension, operated by |
| 14 | + Callum Alpass. The <a href="/privacy/">mdbase website and Connect privacy page</a> |
| 15 | + covers the related website and Connect service. |
| 16 | + </p> |
| 17 | + </header> |
| 18 | + |
| 19 | + <h2>What the extension does</h2> |
| 20 | + <p> |
| 21 | + Reader lets you save supported web articles and PDFs, add highlights and |
| 22 | + notes, and revisit them in a collection you authorize through mdbase |
| 23 | + Connect. The extension is not a standalone storage service. |
| 24 | + </p> |
| 25 | + |
| 26 | + <h2>Pages and information you choose to save</h2> |
| 27 | + <p> |
| 28 | + When you open Reader on a supported page, it reads the page address, |
| 29 | + title, content, available citation metadata and selected text to prepare |
| 30 | + a capture. Saving is a separate action. When you save, Reader transfers |
| 31 | + the source content and any tags, notes, comments or highlights you enter |
| 32 | + through Connect to your selected collection. |
| 33 | + </p> |
| 34 | + <p> |
| 35 | + For articles, new captures include a readable copy and a minimized |
| 36 | + text-and-structure HTML archive. The archive leaves out scripts, forms, |
| 37 | + embedded application state, arbitrary attributes and resource or link |
| 38 | + addresses from the document markup. Explicitly hidden elements are |
| 39 | + removed. This is not anonymization: visible text, titles, citation |
| 40 | + metadata and the separately saved source address, including any query |
| 41 | + parameters, may still contain private information. Existing captures are |
| 42 | + not rewritten. Only save pages you intend to keep in that collection. |
| 43 | + </p> |
| 44 | + <p> |
| 45 | + For supported PDFs, Reader downloads the document for saving. Where |
| 46 | + Chrome permits, the download uses your existing access to the original |
| 47 | + website. The extension does not copy the website's login cookies into |
| 48 | + the saved PDF as part of that operation. |
| 49 | + </p> |
| 50 | + |
| 51 | + <h2>Citation lookups</h2> |
| 52 | + <p> |
| 53 | + If a DOI is available, citation preparation may send that DOI to{" "} |
| 54 | + <code>doi.org</code> and the registry it redirects to, such as Crossref |
| 55 | + or DataCite. This can happen before you save. The lookup does not |
| 56 | + intentionally send your notes, highlights or full article content. |
| 57 | + Those services also receive ordinary network information such as your IP |
| 58 | + address. Extension DOI requests omit cookies. |
| 59 | + </p> |
| 60 | + |
| 61 | + <h2>Optional saved-page recognition</h2> |
| 62 | + <p> |
| 63 | + “Mark pages I've saved and show my highlights on them” is optional. If |
| 64 | + enabled, Chrome requests access to HTTPS websites. Reader then sends the |
| 65 | + addresses of HTTPS pages you visit, including pages you have not saved, |
| 66 | + through your configured Connect route to query your selected collection. |
| 67 | + It retrieves matching saved highlights and may read page text to display |
| 68 | + them. This is not merely an on-device browser comparison. Turning the |
| 69 | + feature off stops these background lookups and requests removal of the |
| 70 | + optional website permission. |
| 71 | + </p> |
| 72 | + |
| 73 | + <h2>Connection and local browser data</h2> |
| 74 | + <p> |
| 75 | + The extension keeps Connect authorization state, the selected collection, |
| 76 | + preferences and interrupted-write recovery information in Chrome's |
| 77 | + extension-local storage. Signing keys and application identity are held |
| 78 | + in the extension's IndexedDB databases. Recovery data can include |
| 79 | + identifiers, addresses and pending changes. Draft text and selected |
| 80 | + passages are kept in extension session storage and cleaned up when their |
| 81 | + tab closes. This implementation does not use Chrome's synchronized |
| 82 | + storage for those drafts. |
| 83 | + </p> |
| 84 | + <p> |
| 85 | + Connect grants are sensitive credentials used to access only collections |
| 86 | + you authorize. Extension API requests do not use ambient Connect portal |
| 87 | + cookies. The separate Connect approval website handles its own sign-in. |
| 88 | + </p> |
| 89 | + |
| 90 | + <h2>Where data goes</h2> |
| 91 | + <p> |
| 92 | + The production extension contacts <code>connect.mdbase.dev</code> for |
| 93 | + authorization and collection operations. Depending on your collection, |
| 94 | + records and files are handled by a hosted collection service or your own |
| 95 | + connector, with a cloud relay where applicable. Not all traffic remains |
| 96 | + on your computer. The <a href="/privacy/">Connect privacy page</a> |
| 97 | + describes account, routing and hosted-collection handling. |
| 98 | + </p> |
| 99 | + <p> |
| 100 | + For a collection served from your computer, you may separately allow |
| 101 | + direct access to the connector on your own device. This is optional; |
| 102 | + Chrome controls the localhost and local-network permissions. Websites |
| 103 | + you capture and DOI registries have their own privacy practices. |
| 104 | + </p> |
| 105 | + |
| 106 | + <h2>Purposes, service providers and sharing</h2> |
| 107 | + <p> |
| 108 | + Reader uses this information to prepare and save sources, look up citation |
| 109 | + metadata, store annotations, access an authorized collection, recover |
| 110 | + interrupted writes and, if enabled, recognize saved pages. Connect |
| 111 | + processes account and grant details, routing metadata and bounded usage |
| 112 | + counts needed to operate the service; its operator report uses aggregate |
| 113 | + counts rather than returning individual records or page contents. |
| 114 | + </p> |
| 115 | + <p> |
| 116 | + Production Connect and its hosted provider run on Render with managed |
| 117 | + PostgreSQL. Hosted files are stored as opaque objects in Cloudflare R2; |
| 118 | + the hosted provider handles authorized record and file operations. |
| 119 | + Render provides database recovery, and encrypted logical database |
| 120 | + backup artifacts are retained through GitHub Actions. Account email may |
| 121 | + be delivered through Resend. DOI registries receive a DOI when |
| 122 | + a lookup is made, and the original website serves content or a PDF when |
| 123 | + you choose to capture it. These providers may process the network and |
| 124 | + operational information necessary to provide those services. The |
| 125 | + extension does not contain an advertising or third-party analytics SDK. |
| 126 | + We do not sell user data, use or transfer it for purposes unrelated to |
| 127 | + Reader's stated function, or use or transfer it to determine |
| 128 | + creditworthiness or for lending. Transfers to service providers and DOI |
| 129 | + registries are limited to the functions described above. |
| 130 | + </p> |
| 131 | + |
| 132 | + <h2>Retention and controls</h2> |
| 133 | + <ul> |
| 134 | + <li> |
| 135 | + Saved sources, files and annotations remain in the selected collection |
| 136 | + until removed using the collection's controls. Removing the extension |
| 137 | + does not delete them. |
| 138 | + </li> |
| 139 | + <li> |
| 140 | + Session drafts are temporary. Local preferences, authorization and |
| 141 | + recovery state can persist across browser restarts. |
| 142 | + </li> |
| 143 | + <li> |
| 144 | + Turn off saved-page recognition in extension Settings to stop |
| 145 | + background address lookups and request removal of website access. |
| 146 | + </li> |
| 147 | + <li> |
| 148 | + Settings → Disconnect this browser → Disconnect and clear local data |
| 149 | + removes extension-local state, session drafts and IndexedDB credentials |
| 150 | + after confirmation. It also requests removal of optional website and |
| 151 | + local-connector permissions. Finish pending saves first: a write already |
| 152 | + sent may still complete, and recovery information is discarded. |
| 153 | + </li> |
| 154 | + <li> |
| 155 | + Clearing this browser does not revoke server-side grants or delete |
| 156 | + collection content, and does not affect other browsers. Highlights |
| 157 | + already drawn on an open page may remain until it is reloaded. Revoke |
| 158 | + Reader's application access in Connect and remove records/files in |
| 159 | + your collection using its controls. Revocation for a connector-backed |
| 160 | + collection can remain pending until that connector confirms it. |
| 161 | + </li> |
| 162 | + </ul> |
| 163 | + <p> |
| 164 | + Connect deletes expired authorization and usage rows that are no longer |
| 165 | + needed, generally after about 13 months. Other account, grant and audit |
| 166 | + information can be retained while needed for service, security or legal |
| 167 | + purposes. Hosted file deletion may first leave retained versions and |
| 168 | + backups that are removed through maintenance or backup expiry; deletion |
| 169 | + from all recovery copies is not immediate. The provider and Render may |
| 170 | + retain operational logs. The <a href="/account-deletion/">Connect account-deletion page</a> |
| 171 | + explains account-level controls and exceptions; local collection files |
| 172 | + on your own computers are not removed by deleting an account. |
| 173 | + </p> |
| 174 | + |
| 175 | + <h2>Contact and changes</h2> |
| 176 | + <p> |
| 177 | + For privacy questions or requests, contact |
| 178 | + <a href="mailto:callum@mdbase.dev">Callum Alpass at callum@mdbase.dev</a>. |
| 179 | + Changes to this policy will be posted at this address with an updated |
| 180 | + effective date. |
| 181 | + </p> |
| 182 | + <p>Effective date: 27 September 2026.</p> |
| 183 | + </article> |
| 184 | +</BaseLayout> |
0 commit comments