Privacy policy for Smart Video Controls
Smart Video Controls by Divyam Rastogi
Privacy policy for Smart Video Controls
Last updated: 2026-09-25
Smart Video Controls is built privacy-first. This document explains exactly what data the extension reads, what it stores, and where it goes.
- Free version: your playback positions sync through your own Chrome account (Chrome's built-in extension sync) — they never reach our servers. Everything else stays on your device. We collect small, anonymous usage counts (see below) — never URLs, titles, or page content.
- Pro version (cross-device sync): episode URLs and playback positions are sent over HTTPS to our backend so we can sync them to your other devices. That's it.
- Video page cleanup (hiding ad overlays, closing pop-under tabs, reverting hijacked navigations) runs entirely on your device. It never clicks ads, and its decisions stay in session-only local storage.
- Anonymous, opt-out usage counts. No tracking pixels, no Google Analytics, no ads, no third-party scripts.
- We never collect your browsing history, the content of pages you visit, or any personal identifier you didn't give us yourself.
To do its job — keyboard shortcuts, automatic position resume, and video page cleanup — the extension reads:
<video>elements on the page you're watching. SpecificallycurrentTime,duration,paused,playbackRate, andvolume. These are read in-memory only; we do not store the video content.- The URL of the page containing the video. Used as the storage key so we can restore the right position when you come back. The URL's fragment (
#…) is stripped before storage. - Keyboard events on pages with a video. We intercept Space, arrow keys,
>,<, and any custom shortcuts you set, only when no input field is focused. - Elements that overlap a
<video>(cleanup feature only). To hide ad overlays and stop pop-unders, we inspect the position, size, tag, class/id names, and visible text of elements covering the player, and the destination URL of newly opened tabs. This happens entirely on your device and the result is an action (hide an element, close a pop-under tab, restore a hijacked navigation) — page content is never stored beyond that decision or sent anywhere.
We do not read:
- Form data, passwords, cookies, or local storage of any website.
- Your browsing history, bookmarks, or the content of pages you visit outside the video-element and overlay checks described above.
Extension-scoped storage — not accessible to any website. Everything below lives
in
chrome.storage.local (this device only) except your playback positions,which live in
chrome.storage.sync so Chrome can mirror them to your otherdevices, and the pop-under protection's click records, which live in
chrome.storage.session (cleared automatically when the browser closes):
svc_pos::<episode_url>— your playback position per episode. Auto-deleted after 15 days of inactivity. Stored inchrome.storage.sync, notchrome.storage.local: Chrome mirrors that area to your other devices signed in to the same Chrome account, which is how free cross-device resume works. It travels via Google under your own account and is never sent to us. If Chrome's sync quota is full the entry falls back to local storage on this device only.svc_shortcuts— your custom keyboard bindings.svc_disabled_hosts— list of sites you've disabled the extension on.svc_usage_stats— counts of which shortcuts you used in the last 7 days, shown in the popup. Never leaves your device.svc_resume_events— timestamps of automatic position resumes in the last 7 days, used to estimate the "time saved" figure in the popup. Never leaves your device.svc_lifetime_stats— a running total of the seconds the extension has saved you (forward skips, auto-resumes, and time banked while watching above 1x speed), plus the per-source split shown as the popup's "You've saved…" line. Never leaves your device.svc_telemetry_pending— the daily tally of usage counts (shortcuts, resumes, popup opens, estimated seconds saved) waiting to be flushed. See "Product analytics" below.svc_telemetry_enabled— your opt-in/opt-out choice for anonymous usage stats. Defaults to on.svc_telemetry_last_flush— timestamp of the last successful stats report, used to send at most one report per day.svc_privacy_notice_2026_07_ack— whether you've dismissed the one-time notice about this policy change. Never leaves your device.svc_cleanup_overlays,svc_cleanup_popunders— your on/off choices for the two video-page cleanup features. Never leave your device.svc_tab_clicks— for pop-under protection only: a small in-memory session record (chrome.storage.session, cleared when the browser closes) of recent clicks on video pages — whether the click was inside a player area and whether it was on a text link — so a hijacked navigation can be traced back to the page you were on after that page is gone. Never synced, never sent anywhere.svc_last_popunder_decision,svc_last_tabunder_decision— the most recent cleanup decision (why a tab was closed or restored), kept locally so you can see what the feature did. Overwritten continuously; never leaves your device.svc_auth_token,svc_refresh_token,svc_user_id— an anonymous identifier used to authenticate Pro requests. Created on install; tied to no real-world identity unless you redeem a license key.svc_canonical_user_id,svc_license_key,svc_is_pro— set only after you purchase Pro and activate a license key.
If — and only if — you have purchased Pro and activated a license:
| Data | Where it goes | Purpose |
|---|---|---|
| Episode URL (no fragment) | Supabase Edge Function | Sync key |
| Playback position (seconds) and duration | Supabase Edge Function | Position to restore |
| Anonymous user ID | Supabase Edge Function | Tying your devices together |
| License key (at activation time) | Supabase Edge Function | Verifying your Pro status |
| Optional feedback text + rating | Supabase Edge Function | Bug reports / feature requests you write yourself |
All requests go over HTTPS to
https://pnjsyklmibspekxgslos.supabase.co. No third parties are involved. We use Supabase as a database host; they process the data on our behalf and do not share it.Free users' positions never reach our servers — that requires Pro. They do travel between your own devices via Chrome's built-in sync (see above), which is Google's infrastructure under your Chrome account, not ours. The extension authenticates anonymously at install time so feedback submission and the daily usage report below work.
To understand which features get used and how many people come back, the extension sends a small daily report to our backend over HTTPS. It contains only:
- Counts of shortcuts used, automatic position resumes, and popup opens from the last day.
- Counts of how many videos the extension found, how many times a site handled a keypress instead of us, and how many pages you visited where the extension stays switched off by design (YouTube and similar). These tell us whether the extension is working for you or quietly doing nothing — they are counts only, never which videos or which sites.
- The estimated seconds the extension saved you that day (the same conservative figure behind the popup's all-time line).
- The extension version.
- Your anonymous user ID — the random UUID created on install, tied to no real-world identity unless you redeem a license key.
It is sent at most once per day, and even when every count is zero (a zero report simply means "still installed and the browser is alive" — that's how we measure retention). No URL, title, hostname, or page content is ever sent or stored — the payload is counts, a version string, and the anonymous ID.
You can turn it off at any time in the popup under Settings → "Share anonymous usage stats". When off, no report is sent. Raw report rows are deleted after 13 months (see Data retention).
On video pages, the extension can hide ad overlays covering the player, close
pop-under ad tabs that a player click spawned, and send your tab back if a
site navigates it to an ad ("tab-under" hijacks). Three facts about how this
works:
- It never clicks, visits, or interacts with ads — it only hides page
elements, closes pop-up tabs, and uses the browser's own back navigation. - All decisions are made and stay on your device. No page content, URL, or
decision is transmitted; the decision records exist locally so the feature
is debuggable. - You control it. Both halves have toggles in the popup (on by default),
and the per-site disable switch turns everything off for that site.
storage— store positions and your shortcut settings locally.scripting— query<video>state in cross-origin iframe players (the extension's signature feature). Without this, video controls in embedded players would not work.alarms— wake the background service worker periodically: every 30 minutes to sync Pro positions across Chrome profiles, and every 4 hours as an opportunity to send the once-daily usage report.- Host permission
<all_urls>— we cannot know in advance which sites you'll watch videos on. We never read page content beyond<video>and<iframe>elements, and the extension is fully disabled on per-site basis via the popup.
YouTube, X (Twitter), Facebook, Instagram, and any host you add to the per-site disable list in the popup. On those domains we do not run the content script at all.
- Supabase (database + serverless functions) — all users: it stores the anonymous daily usage report (counts only), and for Pro users it also stores your synced positions. See Supabase's privacy practices.
- Stripe (payment processing) — only at the moment you click "Upgrade". Stripe receives no data from the extension; you're redirected to their hosted checkout page.
- Chrome Web Store — distributes updates. Google's standard analytics apply to the store listing itself; the extension does not call Google services at runtime.
No other third parties. No Google Analytics, no third-party analytics SDKs, no advertising. Usage stats are collected first-party (by us, directly) and contain no URLs, titles, or page content.
- Local positions: auto-deleted 15 days after the last update.
- Pro positions (server-side): retained while your Pro license is active. Deleted on request — email the address below.
- Anonymous usage stats: raw per-day report rows are deleted automatically after 13 months (via a scheduled database job). Only aggregated, non-identifying totals — such as the "time saved by all users" figure on our landing page — may be kept longer.
- Anonymous user IDs: retained for the lifetime of your install. Reset by uninstalling and reinstalling.
You can:
- Delete everything stored locally by uninstalling the extension (Chrome removes its storage automatically).
- Delete Pro server data by emailing the contact below with your license key.
- Disable the extension on specific sites via the popup's "Site Access" panel.
Material changes to this policy will trigger a popup notification on next launch and a version bump on the listing page.
Questions, deletion requests, or concerns: divyamrastogi2@gmail.com