From 8c802335509fa73990215442d2d2a2f035641012 Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Mon, 17 Aug 2026 12:41:22 -0400 Subject: [PATCH] feat: privacy policy updates --- web/src/pages/privacy.astro | 73 ++++--------------------------------- 1 file changed, 8 insertions(+), 65 deletions(-) diff --git a/web/src/pages/privacy.astro b/web/src/pages/privacy.astro index 131f684..3f21639 100644 --- a/web/src/pages/privacy.astro +++ b/web/src/pages/privacy.astro @@ -12,84 +12,27 @@ import Layout from "../layouts/Layout.astro";
-

The short version

- The substandard extension runs entirely in your browser. We operate no - server backend for it, so there is nothing for us to collect: no - accounts, no analytics, no logs, no data sold or shared. -

-

Last updated: August 12, 2026.

-
- -
-

What the extension does with data

-

- To detect publications, the extension reads the page you are viewing - and asks that site whether it publishes on - standard.site. There is no way to - know in advance which sites do, so that check runs on the sites you - visit. It also makes requests to public AT Protocol services, such as - your PDS, the publication's PDS, and the DID directory. -

-

- To show context around a publication — who it belongs to, how many - people subscribe, what moderation labels apply — the extension may - request public data from other services in the ecosystem, such as - directories, indexes and labelers. What it asks them for is public - information about the publication, not about you. -

-

- None of that traffic passes through us, and we cannot see it. It - carries no cookies or credentials, and the answers are cached in your - browser. -

-

- Signing in uses OAuth with your own PDS. You enter your credentials on - your PDS's page, never in the extension, and we never see them or the - sign-in request. The resulting tokens are stored locally in your - browser and sent only to your PDS. + substandard runs in your browser, and all processing is performed locally. We do not operate a backend server and we do not collect, sell, or share your data with any parties.

- The permissions the extension asks for on your account are narrow, and - listed in full in its - client metadata: managing your - standard.site subscription records, - posting feedback as you if you use the feedback form, and reading your - account preferences so it can respect the moderation labelers you - already subscribe to. Subscribing only writes a record to your own AT - Protocol repository, and does not contact the publication or our - servers. + To find publications, the substandard extension checks the sites you visit for publication info. It also looks up additional information about detected publications from user repositories and other public Atmosphere APIs.

- Everything else the extension keeps — cached lookups, your reader - preference, your session — stays in your browser's local extension - storage. Uninstalling the extension removes it. + Signing in happens on your own Atmosphere account's server, and we never see your + password. Subscribing to a publication saves it to your own server.

- The architecture page is the diagram of all - of the above: which part of the extension makes each of those requests, - what it sends, and where each answer is kept. + Installing from the Chrome Web Store will report certain usage analytics to Google. Users who wish to avoid this may directly build and install the extension from source code.

-
-

What this website does with data

- substandard.blog (this marketing website, not the extension) uses cookieless - analytics — PostHog, hosted in the EU — to count page visits. It sets - no cookies, stores nothing in your browser, and does not identify or - track you across sites. The extension does not ship with any analytics. + The substandard.blog website counts page visits with cookieless + analytics hosted in the EU.

-
-

Changes and contact

-

- If this policy changes, the new version appears on this page, and its - history is public in the - source - repository. Questions and concerns are welcome there too. -

-
+

Last updated: August 17, 2026.

-- 2.51.2