Privacy Policy
Last updated: September 11, 2026
Recommendarium ("the Extension") is a browser extension that helps you sort, filter, save, and share YouTube comments. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
1.1 Locally Stored Data
The Extension stores the following data in your browser's local storage (chrome.storage.local):
- Saved comments — comment text, author name, video title, timestamps, like/reply counts, and related metadata you choose to save.
- Extension settings — your preferences (sort order, filter state, design theme).
- Cached data — premium status, fact-check results, and subscription lists to reduce repeated network requests.
This data never leaves your browser unless you explicitly enable cloud sync by signing in.
1.2 Account Data (Optional)
If you choose to sign in with Google, we receive:
- Your Google email address and display name
- Your profile picture URL
- A unique user identifier
This data is used solely for authentication and to display your profile within the Extension.
1.3 Cloud-Synced Data (Optional)
When signed in, your saved comments are synced to our cloud database (hosted on Supabase) so you can access them across devices.
Saves are public by default. On the free plan, every comment you save is published to the shared feed, where other signed-in Recommendarium users can see it — the comment's text and author (both already public on YouTube), the video it came from, and when it was saved. The feed never shows who saved it. Saving privately, so that a comment is synced for you alone and never reaches the feed, is a Premium feature; the "Public saves" switch in Settings says which way it is set.
The personal part of a save is not the comment — that text is public on YouTube and was written by someone else — but the link between it and your profile. That link is ours to break on request: see "Delete" in section 4.
1.4 Usage Data (Optional)
If you are signed in, we record on our backend: changes to extension settings
(setting name, old and new value, whether the change was manual or automatic),
aggregate feature-usage counters (saves, sorts, loads), and usage counts for
rate-limited features (e.g. AI fact-check). We use this to improve the product,
enforce usage limits, and prevent abuse. Usage records may be retained after
account data deletion for limit accounting and abuse prevention.
2. Third-Party Services
- Supabase (supabase.com) — authentication and cloud database. Subject to Supabase Privacy Policy.
- YouTube Data API — used to fetch your subscribed channels for the Subscriptions filter (premium feature) and public video statistics (view counts). Subject to Google Privacy Policy.
- Anthropic API — powers the AI fact-check feature via server-side Edge Functions. Comment text is sent for analysis but is not stored by the Extension beyond the request. Subject to Anthropic Privacy Policy.
- Lemon Squeezy (lemonsqueezy.com) — handles premium subscription payments. We do not process or store payment information. Subject to Lemon Squeezy Privacy Policy.
3. What We Do NOT Do
- We do not use third-party analytics or tracking pixels. If you are signed in, we record feature-usage events on our own backend (see 1.4); this data is never sold or shared.
- We do not serve advertisements.
- We do not sell, rent, or share your data with third parties for marketing purposes.
- We do not collect browsing history beyond the YouTube pages you interact with.
4. Your Rights
- Export — you can export all saved comments as a JSON file from Settings.
- Delete — "Delete my data" in Settings removes your saved comments from this browser and deletes ALL of them from the cloud, published ones included, along with every video recommendation you published and your profile details (email, name, picture). Nothing is left linking you to anything you saved. An anonymised copy of the content you had published — the comment, its author and the video, with no reference to you, not even the time of day it was archived — may be kept so the shared feed does not lose it, and so moderators can put a worthwhile comment back under the project's own curator account. That copy contains no data about you: it says what was said on YouTube, not who saved it. Usage and quota records are retained (see 1.4).
- Sign out — signing out stops cloud sync. Your local data remains until you delete it.
- Uninstall — uninstalling the Extension removes all locally stored data.
5. Data Security
Cloud data is protected by Supabase Row Level Security (RLS) policies, ensuring users can only access their own data. All communication between the Extension and our servers uses HTTPS encryption.
6. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision.
7. Contact
Questions about this policy, and requests concerning your data — access, export, deletion — go to privacy@recommendarium.com.