Skip to content
mdbaseSign up
HomeConnectDownloadsApps

mdbase Reader browser extension privacy

This page covers the mdbase Reader browser extension, operated by Callum Alpass. The mdbase website and Connect privacy pagecovers the related website and Connect service.

What the extension does

Reader lets you save supported web articles and PDFs, add highlights and notes, and revisit them in a collection you authorize through mdbase Connect. The extension is not a standalone storage service.

Pages and information you choose to save

When you open Reader on a supported page, it reads the page address, title, content, available citation metadata and selected text to prepare a capture. Saving is a separate action. When you save, Reader transfers the source content and any tags, notes, comments or highlights you enter through Connect to your selected collection.

For articles, new captures include a readable copy and a minimized text-and-structure HTML archive. The archive leaves out scripts, forms, embedded application state, arbitrary attributes and resource or link addresses from the document markup. Explicitly hidden elements are removed. This is not anonymization: visible text, titles, citation metadata and the separately saved source address, including any query parameters, may still contain private information. Existing captures are not rewritten. Only save pages you intend to keep in that collection.

For supported PDFs, Reader downloads the document for saving. Where Chrome permits, the download uses your existing access to the original website. The extension does not copy the website's login cookies into the saved PDF as part of that operation.

Citation lookups

If a DOI is available, citation preparation may send that DOI to doi.org and the registry it redirects to, such as Crossref or DataCite. This can happen before you save. The lookup does not intentionally send your notes, highlights or full article content. Those services also receive ordinary network information such as your IP address. Extension DOI requests omit cookies.

Optional saved-page recognition

“Mark pages I've saved and show my highlights on them” is optional. If enabled, Chrome requests access to HTTPS websites. Reader then sends the addresses of HTTPS pages you visit, including pages you have not saved, through your configured Connect route to query your selected collection. It retrieves matching saved highlights and may read page text to display them. This is not merely an on-device browser comparison. Turning the feature off stops these background lookups and requests removal of the optional website permission.

Connection and local browser data

The extension keeps Connect authorization state, the selected collection, preferences and interrupted-write recovery information in Chrome's extension-local storage. Signing keys and application identity are held in the extension's IndexedDB databases. Recovery data can include identifiers, addresses and pending changes. Draft text and selected passages are kept in extension session storage and cleaned up when their tab closes. This implementation does not use Chrome's synchronized storage for those drafts.

Connect grants are sensitive credentials used to access only collections you authorize. Extension API requests do not use ambient Connect portal cookies. The separate Connect approval website handles its own sign-in.

Where data goes

The production extension contacts connect.mdbase.dev for authorization and collection operations. Depending on your collection, records and files are handled by a hosted collection service or your own connector, with a cloud relay where applicable. Not all traffic remains on your computer. The Connect privacy pagedescribes account, routing and hosted-collection handling.

For a collection served from your computer, you may separately allow direct access to the connector on your own device. This is optional; Chrome controls the localhost and local-network permissions. Websites you capture and DOI registries have their own privacy practices.

Purposes, service providers and sharing

Reader uses this information to prepare and save sources, look up citation metadata, store annotations, access an authorized collection, recover interrupted writes and, if enabled, recognize saved pages. Connect processes account and grant details, routing metadata and bounded usage counts needed to operate the service; its operator report uses aggregate counts rather than returning individual records or page contents.

Production Connect and its hosted provider run on Render with managed PostgreSQL. Hosted files are stored as opaque objects in Cloudflare R2; the hosted provider handles authorized record and file operations. Render provides database recovery, and encrypted logical database backup artifacts are retained through GitHub Actions. Account email may be delivered through Resend. DOI registries receive a DOI when a lookup is made, and the original website serves content or a PDF when you choose to capture it. These providers may process the network and operational information necessary to provide those services. The extension does not contain an advertising or third-party analytics SDK. We do not sell user data, use or transfer it for purposes unrelated to Reader's stated function, or use or transfer it to determine creditworthiness or for lending. Transfers to service providers and DOI registries are limited to the functions described above.

Our use of information received from Google APIs adheres to theChrome Web Store User Data Policy, including the Limited Use requirements.

Retention and controls

  • Saved sources, files and annotations remain in the selected collection until removed using the collection's controls. Removing the extension does not delete them.
  • Session drafts are temporary. Local preferences, authorization and recovery state can persist across browser restarts.
  • Turn off saved-page recognition in extension Settings to stop background address lookups and request removal of website access.
  • Settings → Disconnect this browser → Disconnect and clear local data removes extension-local state, session drafts and IndexedDB credentials after confirmation. It also requests removal of optional website and local-connector permissions. Finish pending saves first: a write already sent may still complete, and recovery information is discarded.
  • Clearing this browser does not revoke server-side grants or delete collection content, and does not affect other browsers. Highlights already drawn on an open page may remain until it is reloaded. Revoke Reader's application access in Connect and remove records/files in your collection using its controls. Revocation for a connector-backed collection can remain pending until that connector confirms it.

Connect deletes expired authorization and usage rows that are no longer needed, generally after about 13 months. Other account, grant and audit information can be retained while needed for service, security or legal purposes. Hosted file deletion may first leave retained versions and backups that are removed through maintenance or backup expiry; deletion from all recovery copies is not immediate. The provider and Render may retain operational logs. The Connect account-deletion pageexplains account-level controls and exceptions; local collection files on your own computers are not removed by deleting an account.

Contact and changes

For privacy questions or requests, contactCallum Alpass at callum@mdbase.dev. Changes to this policy will be posted at this address with an updated effective date.

Effective date: 27 September 2026.

mdbase

Typed Markdown collections.

ProductAppsConnectDownloads
DevelopersSDKRuntimeSpecification
ProjectSupportSecurityStatusGitHubPrivacyAccount deletionTerms