Privacy

Covering the Social Compounder browser extension and the account it connects to. Last updated 13 September 2026.

What the extension does

It publishes and schedules Substack Notes, and reads back your own notes, newsletter stats, and the replies people leave you — using the Substack session already signed in on your own browser. Nothing it does requires giving us your Substack password.

What it cannot do, by construction

The extension does not request Chrome’s cookies permission. It sends requests to Substack with your existing session attached, but it has no way to read that session value, store it, or transmit it. Your Substack credentials never reach our servers and never leave your device.

This is verifiable rather than a promise: open manifest.json in the extension package. The only permissions requested are storage and alarms. There are no content scripts, no tabs access, and no ability to read pages you visit.

What it sends to us

Only what the app needs to show you your own numbers and your inbox:

  • Your Substack profile — name, handle, subscriber and follower counts
  • Notes you have published, and their engagement metrics
  • Your newsletter posts and their open and view statistics
  • Replies to your notes — the commenter’s display name, handle, and text

It does not read your email, your subscriber list, your drafts, or any Substack publication you do not own.

Other people’s information

Replies to your notes are written by other people, and we store them only so you can read and answer them in one place. They are deleted automatically on a schedule you choose — 5, 10, 20, or 30 days, set on the Inbox page and defaulting to 30. Deletion applies whether or not you replied; we do not keep answered conversations as a record.

What is stored on your device

A pairing token identifying your browser to your account, and the timestamp and status of the last sync. Both live in the extension’s own chrome.storage.local and are removed when you uninstall it or revoke the device from Settings. We store only a hash of that token, never the token itself.

Who else sees it

We do not sell your data, share it with advertisers, or use it to train models. It is processed by the infrastructure the product runs on — hosting, database, queue, and media storage providers — acting on our instructions and nothing else.

Deleting it

Revoking a device in Settings stops the extension immediately. Deleting your account removes your posts, metrics, comments, and devices. You can also uninstall the extension at any time; it holds nothing you cannot discard that way.

Contact

Questions about any of this, or a request to see or delete your data: c_dow11@yahoo.ca