diff --git a/web/src/pages/privacy.astro b/web/src/pages/privacy.astro index 377b3ee..9e64e6c 100644 --- a/web/src/pages/privacy.astro +++ b/web/src/pages/privacy.astro @@ -18,29 +18,47 @@ import Layout from "../layouts/Layout.astro"; server backend for it, so there is nothing for us to collect: no accounts, no analytics, no logs, no data sold or shared.

-

Last updated: August 8, 2026.

+

Last updated: August 12, 2026.

What the extension does with data

To detect publications, the extension reads the page you are viewing - and makes requests directly from your browser to that site and to - public AT Protocol services (your PDS, the publication's PDS, and the - DID directory). None of that traffic passes through us, and we cannot - see it. + and asks that site whether it publishes on + standard.site. There is no way to + know in advance which sites do, so that check runs on the sites you + visit. It also makes requests to public AT Protocol services, such as + your PDS, the publication's PDS, and the DID directory. +

+

+ To show context around a publication — who it belongs to, how many + people subscribe, what moderation labels apply — the extension may + request public data from other services in the ecosystem, such as + directories, indexes and labelers. What it asks them for is public + information about the publication, not about you. +

+

+ None of that traffic passes through us, and we cannot see it. It + carries no cookies or credentials, and the answers are cached in your + browser.

Signing in uses OAuth with your own PDS. You enter your credentials on your PDS's page, never in the extension, and we never see them or the sign-in request. The resulting tokens are stored locally in your browser and sent only to your PDS. - +

- The extension asks for one narrow permission: - managing your standard.site records to enable subscribing (or unsubscribing) from publications. - Subscribing only writes a subscription record to your own AT Protocol - repository, and does not contact the publication or our servers. + The permissions the extension asks for on your account are narrow, and + listed in full in its + client metadata: managing your + standard.site subscription records, + posting feedback as you if you use the feedback form, and reading your + account preferences so it can respect the moderation labelers you + already subscribe to. Subscribing only writes a record to your own AT + Protocol repository, and does not contact the publication or our + servers.

Everything else the extension keeps — cached lookups, your reader