Subharvest
Privacy

Subharvest Privacy Policy

Last updated: July 24, 2026

Summary

Subharvest is a local-first Reddit research Chrome extension. Its single purpose is to help you collect, organize, analyze, and export Reddit research that you deliberately request. It does not monitor your browsing in the background.

When you invoke Subharvest, it reads the current active page URL, including the active Reddit page URL, to detect a thread or subreddit and prefill the workbench. It also measures viewport dimensions to fit the side panel. The viewport measurement is used transiently for layout and is not sent to Subharvest servers. Subharvest does not inspect unrelated page content.

Scraped Reddit content, saved projects, run history, evidence filters, and export files stay on your device unless you choose to share or upload an export yourself. Account linking and billing use the limited account, device, session, and subscription data described below; scraped Reddit research is not sent to Subharvest account servers.

Information the Extension Handles

  • The active page URL used for current-page detection and the last thread URL shown in local settings.
  • Viewport dimensions used transiently to size the side panel.
  • Reddit posts and comments you request, including usernames, text, scores, timestamps, IDs, subreddit names, and source URLs.
  • Local evidence themes, exact matched phrases, duplicate state, selected rows, and tracked-term matches.
  • Project names, audiences, keywords, tracked terms, queue settings, saved runs, seen-row keys, and export preferences.
  • An installation identifier, pending account-link state, linked device identifier, access and refresh tokens, and signed entitlement snapshots when you connect an account.

Persistent extension data is stored through Chrome extension storage. Exports are generated locally and passed to Chrome's download system. Copy JSON writes the selected export to your clipboard only when you click that command.

Chrome storage also holds a small shared Reddit rate-limit state containing request timing, cooldown, quota, and reset timestamps. It contains no Reddit content, URLs, cookies, passwords, or access tokens.

While a large user-requested scrape is running or incomplete, a local scrape recovery checkpoint can contain captured Reddit rows, the selected thread queue, pending collapsed comment IDs, progress counters, and capture settings. It supports pause, resume, cancel, and recovery; these fields are not sent to Subharvest servers.

Reddit Requests

Subharvest sends user-requested thread, subreddit, queue, and collapsed-reply requests to Reddit. Reddit receives the request URL and normal network information such as your IP address. Requests may use your existing Reddit browser session so content visible to your signed-in session can be returned.

The extension does not read, store, transmit to Subharvest, or export your Reddit password, cookie values, or Reddit session tokens. Reddit's own handling of requests is governed by Reddit's terms and privacy policy.

Accounts, Linking, and Billing

Account login is optional for Free use. If you create or connect an account, Supabase processes your email address, authentication session, profile, hashed installation identifier, link-request state, linked device identifier, extension version, session creation and last-seen times, revocation state, license status, and security or audit events. The extension stores its access and refresh tokens locally so it can refresh entitlements and briefly verify paid access offline. The website uses strictly necessary authentication cookies to keep you signed in.

If you subscribe, Stripe processes checkout and payment details. Subharvest stores Stripe customer, subscription, and price identifiers; plan and billing interval; subscription status; renewal or period-end dates; and cancellation state. Subharvest does not receive or store full payment card numbers.

Permissions

activeTabRead the active page URL after you invoke Subharvest so the side panel can detect and prefill Reddit threads or subreddit pages.
sidePanelShow the Subharvest research workbench beside the page you are viewing.
scriptingMeasure only the active page's viewport dimensions so the side panel can use the available height without inspecting page content.
storageSave projects, settings, run history, scraped rows, seen-row keys, export preferences, shared Reddit rate-limit state, resumable scrape checkpoints, and account-link state locally.
unlimitedStorageAllow larger local research projects and repeated run history in Chrome storage.
downloadsCreate CSV, TSV, JSON, and Markdown exports from your browser.
Reddit host accessFetch Reddit JSON for threads, subreddit discovery, selected queues, and collapsed replies you ask Subharvest to process.
Subharvest host accessLink an optional account, refresh plan entitlements, revoke extension sessions, and open account or billing pages.

Sharing and Service Providers

  • Reddit receives the research requests you initiate.
  • Supabase provides account authentication and stores account, entitlement, linking, device, and security records.
  • Stripe provides checkout, subscription billing, payment processing, and the billing portal.
  • Website infrastructure providers process ordinary request and server-log data needed to deliver and secure Subharvest.

We do not sell or rent user data, share it with data brokers, use it for personalized advertising, or use scraped Reddit research to determine creditworthiness. There are no ad network or behavioral analytics integrations in the extension.

Retention and Your Controls

Local research remains in Chrome extension storage until you delete a run or project, clear extension data, or uninstall Subharvest. Uninstalling the extension normally removes its local Chrome storage, but it does not cancel a paid subscription or delete a Subharvest web account. Downloaded exports remain wherever you saved them.

A completed scrape clears its recovery checkpoint. An incomplete checkpoint expires after 24 hours or can be discarded from the recovery controls.

The extension's Clear local research data control removes projects, run history, saved research settings and URLs, recovery checkpoints, and Reddit pacing state. Your account connection and interface preferences stay. Signing out and resetting interface preferences are separate controls.

Signing out clears local account-link credentials and requests revocation of the linked extension session. Account, subscription, revoked-device, and security records are retained while needed to provide the service, maintain billing records, prevent abuse, resolve disputes, and meet legal obligations. You may request access, correction, or deletion by emailing the address below. Some billing or security records may be retained when legally or operationally required.

Security and Human Access

Data sent between the extension, Subharvest, Supabase, Stripe, and Reddit uses HTTPS. Keep export files and account credentials secure, and never send access or refresh tokens in a support request.

Scraped Reddit research is not subject to routine human review. A person may access specific information only when you explicitly provide it for support, when reasonably necessary to investigate security or abuse, when required by law, or when using aggregated and de-identified information for internal operations.

Chrome Web Store Limited Use

Subharvest's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve Subharvest's disclosed Reddit research purpose and is not transferred for advertising or unrelated purposes.

Policy Changes

This policy may be updated when Subharvest's features or data practices change. Material changes to extension data handling will be disclosed before the changed practice takes effect, as required by Chrome Web Store policy.

Contact

For privacy questions or requests to access, correct, or delete account data, contact hello@subharvest.com.

HomeSupportContact