Skimora is a Chrome extension for faster, more focused reading (bionic bolding, autopace, deep reading time, and retention tools). This policy explains what data the extension handles, where it lives, and what we (and the extension) do with it.

The short version

  • Everything is stored locally on your device. Skimora uses your browser's local storage (chrome.storage.local) and an IndexedDB database. No reading data, highlights, summaries, stats, or settings are uploaded to any server.
  • No account is required. You can use the core bionic-bolding feature forever without signing up, logging in, or providing any personal information.
  • One optional network call. The only time Skimora talks to the network is to activate and re-check a license key. That request goes to a Supabase Edge Function we operate, and contains only the license key you typed and a random device id that Skimora made on this install (see below). A license works on up to 3 devices at a time.
  • No standing access to the sites you visit. Skimora does not run in the background on your pages. Its reading script is injected into a single tab, only at the moment you invoke Skimora from its toolbar button.
  • No analytics, no advertising, no third-party tracking, no data resale. We do not embed any remote code and the extension performs no telemetry.

Data stored on your device

DataWhereWhy
Settings / preferenceschrome.storage.localRemember your choices (theme, bolding, toggles)
Deep reading blocks and daily totals (start/end time, focused minutes)IndexedDBShow today's focused reading, your year heatmap, weekly summary and personal best
Highlights and end-of-article summariesIndexedDBLet you review and export what you saved
Imported document text, rendered pages, bionified chaptersIndexedDB (cached)Let you re-open PDFs/EPUBs and export bionified EPUBs
Validated license record (including the key you entered, and the licence our server signed for this install)chrome.storage.localKeep you unlocked offline after first activation
A random device idchrome.storage.localCount this install as one of your license's 3 devices

None of the above leaves your machine except the license key and the random device id, in the license request described below. Document bytes you import are cached locally so the extension works offline; they are never transmitted.

The one network request (license activation)

When you enter a license key in the Activate screen, Skimora sends that key to a Supabase Edge Function we operate, for validation. The response is a validation result plus the license record and a licence signed by our server, which proves the licence is genuine. They are cached locally so the extension keeps working without a connection. We do not receive or store any information about the pages you read, your highlights, your stats, or your browsing history.

The request contains two things: the key you submitted, and a random device id. Skimora makes that id once, on this install, with the browser's random number generator. It is not a hardware or browser identifier, it says nothing about you or your computer, and it is deleted when you remove the extension (so a reinstall counts as a new device). Its only use is the device limit: a license works on up to 3 devices at a time.

On our server we keep, for each license key: its status, the device ids using it (up to 3) with the date each was added, when its devices were last reset, and the id of the payment it was bought with (from Dodo Payments, who handle checkout), so that a refund can switch that key off. Our server may also ask Dodo Payments, who issued your key, whether it is still valid; that request contains only the key. We do not receive your card details. If you activate your key on a 4th device, Skimora first asks you to confirm; if you do, the other 3 are signed out and this device takes their place. That reset can be done once every 24 hours. Each device's reading stats and highlights stay on that device either way.

At no point does Skimora read, collect, or transmit:

  • the URLs you visit or the content of web pages,
  • anything about your device beyond the random id described above,
  • your highlights, summaries, or reading statistics,
  • any personally identifiable information,
  • any data from sites other than the Supabase endpoint above.

Permissions and what they are used for

PermissionUse
activeTabAccess to the one tab you are on, granted at the moment you click the Skimora toolbar button, and only then
scriptingInject the reading script into that tab on demand, so bolding and pacing can transform its text
offscreenPlay focus audio in a hidden document so it survives the popup closing
alarmsPeriodically re-check an activated license key (see below)
storageSave settings and cached license locally
downloadsSave your exported highlights/summaries and bionified EPUBs to your device

Skimora requests no host permissions and installs no always-on content script. It cannot read a page until you invoke it there. When you do, the injected script transforms text inside your browser and never sends it anywhere.

Because an activated license is cached so it keeps working offline, the alarms permission is used to re-validate the key periodically against the endpoint above. That request contains only the key and the random device id; it is the same call described earlier.

Your controls

  • Export: highlights, summaries, and documents can be exported (Markdown, JSON, or EPUB) directly to your device via the Downloads API.
  • Review and delete: the Settings and Manage Storage screens let you inspect, back up, and remove stored data. Nothing is deleted without your explicit confirmation.
  • Reset: you can reset all preferences to defaults from Settings.
  • Uninstall: removing the extension deletes its local storage and database.
  • Device ids on our server: they stay attached to your license key until the key's devices are reset. To have them removed sooner, email [email protected] with your license key.

Children

Skimora does not knowingly collect personal data from anyone. It requires no account, and the only things it stores remotely are license keys and the random device ids described above, so it collects no personal data from children.

Changes

If this policy changes, the new version will be noted by the "last updated" date above and, where relevant, within the extension.

This website

This website sets no cookies, runs no analytics and loads no third-party scripts, fonts or trackers. Payments are handled by Dodo Payments on their own checkout page. Skimora does not see or store your card details. We receive what is needed to issue and support your license.

After you pay, Dodo sends you back to our thank-you page with your license key in the address, so the page can show it to you. It is read in your browser only, taken out of the address straight away, and never stored or sent anywhere.

Contact

For privacy questions, email [email protected].