# Browser extension privacy policy (/docs/support/extension-privacy)



Prepared: 18 September 2026

## Scope and contact [#scope-and-contact]

eReader Relay is operated by &#x2A;*Nodular Pty Ltd (Australia)**. In this policy,
“we” and “us” refer to Nodular Pty Ltd.

This policy describes the eReader Relay browser extension and the eReader Relay
service operations it requests: signing in, saving a public page to a reading
list, and generating or delivering an EPUB. For privacy questions, access or
correction requests, deletion requests, or complaints, email
[support@ereaderrelay.com](mailto:support@ereaderrelay.com).

The extension uses your eReader Relay account. Installing or removing the
extension does not create or delete the associated service account. Other
features, such as newsletter inboxes and website billing, also process data;
see [Privacy and data](/docs/support/privacy-and-data) for additional context.

## Information used by the extension [#information-used-by-the-extension]

* **Account and authentication information.** Sign-in exchanges a temporary
  authorization code and verification information for an access token. The
  extension stores that token, your display name, and your email address in
  browser-local extension storage. Temporary sign-in state and verification
  information may also be stored while authorization is pending. Authenticated
  requests send the token to eReader Relay. The extension does not receive your
  eReader Relay account password.
* **The current page.** When you open the extension, it reads the active page's
  URL and title to display the page you can save or send. When you choose an Add
  or Send action, the extension submits the page URL, title, destination choices,
  and request information to eReader Relay. It does not continuously upload your
  browsing history or request access to the browser's history database.
* **Reading lists and devices.** The extension retrieves your reading-list names
  and identifiers, and device names, types, and identifiers. It remembers your
  selected destinations in browser-local storage. The service resolves device
  identifiers to the delivery addresses configured in your account.
* **Content and delivery records.** The service fetches the submitted public URL
  to extract article content and images. Depending on your action, it stores
  the capture with your reading list or creates an EPUB and delivery job. The
  extension does not copy the active tab's complete page document, browser
  cookies, or other sites' login credentials into the capture request.
* **Technical diagnostics.** The extension sends error reports, operation
  outcomes, and sampled performance traces to Sentry. These can include error
  messages and stack traces, request breadcrumbs, browser/runtime information,
  extension version, environment, timing, and operation/reason codes. Sentry's
  default personal-information collection is disabled. This setting does not
  guarantee that every diagnostic event contains no personal information:
  network metadata and error or request context can still be processed. The
  extension does not deliberately attach article bodies or access tokens to its
  structured operation logs.

## Why information is processed [#why-information-is-processed]

Information is used to authenticate requests, show your available destinations,
remember your choices, save requested pages, generate and deliver EPUBs, apply
account permissions and plan limits, investigate failures, and respond to
support and privacy requests. The extension has no advertising or browsing-history
resale feature. Its requested page information is used for the reading actions
you initiate.

## Service providers and recipients [#service-providers-and-recipients]

The production API is hosted at `ereaderrelay.com`. Cloudflare supplies hosting,
processing, storage, and delivery infrastructure. Sentry supplies diagnostic
monitoring; the extension is configured to use a US ingestion endpoint. Content
and delivery addresses are passed to the email or device service involved in a
delivery you request, such as Amazon's Send to Kindle service. The source website
receives the service's request when it fetches your submitted URL.

These providers may process information outside your country. A US ingestion
endpoint does not by itself establish every location in which a provider stores
or processes data. Contact support for information about current processing
locations and provider arrangements. Device providers and source websites apply
their own policies to the operations they control.

Payment details are handled through Stripe on the website, not inside the
extension. The website also has separately configured analytics, including
PostHog when enabled; this policy's description of extension diagnostics should
not be read as a statement that the website has no analytics.

## Storage, retention, and your choices [#storage-retention-and-your-choices]

Local account information remains in extension storage until it is cleared.
Signing out clears the local session and attempts to revoke the server token;
remembered destinations are stored separately. Clearing extension storage removes
local preferences and pending sign-in state. Server extension sessions are
configured to expire after 30 days. Expiry limits token use and is not a promise
that every associated record is immediately erased.

Stored reading content is retained for the duration of your active account,
subject to the content-management controls you use. Saved captures, generated
EPUBs, delivery records, and diagnostics have separate
storage lifecycles. Removing the extension does not delete those service records
or copies already delivered to a device. This policy does not promise a fixed
automatic deletion period for those records. Contact support to request deletion
or obtain current retention information. Any request may need identity
verification and consideration of security, accounting, and legal requirements.
You can also use available account controls to manage reading lists, devices,
and library items.

You can stop future extension activity by signing out or disabling/uninstalling
it. There is currently no separate diagnostic opt-out control in the extension.
Do not submit sensitive or private page URLs that you do not want the service to
process, and do not include passwords or access tokens in support messages.

## Security and complaints [#security-and-complaints]

Production API requests use HTTPS. The service verifies account authorization
for reading-list and device operations. Browser-local token storage depends on
the security of your browser profile and device; no storage or transmission
method is risk-free.

Send privacy concerns to [support@ereaderrelay.com](mailto:support@ereaderrelay.com)
with enough information for us to investigate, without sending account secrets.
You may also have rights to contact a privacy regulator in your jurisdiction.

## Changes [#changes]

This page will be updated when the extension's data practices change. Review the
page date and contact support if you need an explanation of a change.
