Su Privacy Policy

Last updated 17 August 2026

Su never sends what you read or write. Your highlights, your notes, and the articles themselves stay on your computer. There are no accounts, no sync, and no advertising.

Su does send anonymous usage events: which features you used, and when. That is how I learn what to fix and what to build next. An event is a name like "export" plus a couple of labels like "markdown". It never contains the text of a note, the text of an article, a page title, or a web address.

What Su stores, and where

Everything Su saves is written to your browser's local extension storage on the device you are using. None of it is transmitted anywhere.

A record is created the first time you highlight or write a note on a page. Pages you only read are never stored.

How long it is kept

Su keeps a page for 7 days after the last time you add to it. Adding a highlight or a note restarts that clock; simply re-reading does not. After 7 days the article copy is discarded and your notes are set aside, where you can still recover them. 7 days after that, they are permanently deleted.

This deletion happens on your device, automatically. Removing the extension deletes everything it stored, immediately and completely.

Usage data

Su records a small set of events so I can see how the extension is actually used. If you would rather it did not, write to me at the address at the bottom of this page and I will tell you where things stand.

The complete list of what an event can contain:

What an event never contains: the text of your notes, the text of any article, page titles, web addresses, domain names, your name, your email, your IP address as a stored value, or anything you typed. There is no way to work back from this data to what you were reading, because what you were reading is never part of it.

Events are held on your device and sent in a batch about twice a day to a server I run myself at su-reader.joiqypu.workers.dev, hosted on Cloudflare. No analytics company is involved and the data is not shared with anyone.

The dictionary

Su includes an optional Define feature, which is off by default. If you enable it in Appearance and then look up a word, Su sends that single selected word to dictionaryapi.dev, a free public dictionary service, and shows you the definition it returns.

No page content, page address, article text, note text, or identifier is sent with it. The random installation id used for usage events is not attached to dictionary requests, and there is no account to attach. As with any request your browser makes to any website, your IP address is visible to that service. Su has no control over what that service does with the requests it receives, so if that matters to you, leave Define off and Su will never contact it.

Exporting

Exporting happens entirely on your device. Copying puts text on your clipboard, downloading writes a file to your computer, printing to PDF uses your browser's own print dialog, and Send to Obsidian opens the Obsidian app installed on your machine. None of these send your notes over the internet.

Permissions, and why each one exists

activeTab Lets Su open the reader on the page you are looking at, and only at the moment you ask for it by clicking the icon or pressing the shortcut. Su has no standing access to your browsing.
scripting Used to place the reader onto that page. Article extraction runs locally, in your browser.
storage Saves your highlights, notes, and settings on your device.
alarms Runs the periodic cleanup that enforces the retention window described above.
api.dictionaryapi.dev Contacted only when you use Define, and only with the single word you selected.
su-reader.joiqypu.workers.dev Where anonymous usage events are sent. This is my own server, not an analytics provider.

Su does not request permission to access all websites, and it cannot read pages you have not opened it on.

What Su does not do

Third parties

None of them receive your reading. Google distributes Su through the Chrome Web Store and collects its own install and usage statistics under its own privacy policy, which I do not control and cannot see beyond aggregate counts. dictionaryapi.dev receives a single word, and only if you enable Define. Cloudflare hosts the server that receives usage events; like any web host it can see the network requests reaching it, including the originating IP address, which I do not store or log.

Children

Su is not directed at children. It collects no personal information from anyone, including children: usage events carry no name, address, email, or any other identifier tied to a person.

Changes

If this policy changes, the date at the top changes with it. If Su ever begins collecting more than the events listed above, that will be stated here plainly and in the extension itself before it takes effect.

Contact

Questions about this policy, or about Su: contact@joipu.com