Skimora Privacy Policy
Last updated 25 September 2026
Skimora is a Chrome extension for faster, more focused reading (bionic bolding, autopace, deep reading time, and retention tools). This policy explains what data the extension handles, where it lives, and what we (and the extension) do with it.
The short version
- Everything is stored locally on your device. Skimora uses your browser's
local storage (
chrome.storage.local) and an IndexedDB database. No reading data, highlights, summaries, stats, or settings are uploaded to any server. - No account is required. You can use the core bionic-bolding feature forever without signing up, logging in, or providing any personal information.
- One optional network call. The only time Skimora talks to the network is to activate and re-check a license key. That request goes to a Supabase Edge Function we operate, and contains only the license key you typed and a random device id that Skimora made on this install (see below). A license works on up to 3 devices at a time.
- No standing access to the sites you visit. Skimora does not run in the background on your pages. Its reading script is injected into a single tab, only at the moment you invoke Skimora from its toolbar button.
- No analytics, no advertising, no third-party tracking, no data resale. We do not embed any remote code and the extension performs no telemetry.
Data stored on your device
| Data | Where | Why |
|---|---|---|
| Settings / preferences | chrome.storage.local | Remember your choices (theme, bolding, toggles) |
| Deep reading blocks and daily totals (start/end time, focused minutes) | IndexedDB | Show today's focused reading, your year heatmap, weekly summary and personal best |
| Highlights and end-of-article summaries | IndexedDB | Let you review and export what you saved |
| Imported document text, rendered pages, bionified chapters | IndexedDB (cached) | Let you re-open PDFs/EPUBs and export bionified EPUBs |
| Validated license record (including the key you entered, and the licence our server signed for this install) | chrome.storage.local | Keep you unlocked offline after first activation |
| A random device id | chrome.storage.local | Count this install as one of your license's 3 devices |
None of the above leaves your machine except the license key and the random device id, in the license request described below. Document bytes you import are cached locally so the extension works offline; they are never transmitted.
The one network request (license activation)
When you enter a license key in the Activate screen, Skimora sends that key to a Supabase Edge Function we operate, for validation. The response is a validation result plus the license record and a licence signed by our server, which proves the licence is genuine. They are cached locally so the extension keeps working without a connection. We do not receive or store any information about the pages you read, your highlights, your stats, or your browsing history.
The request contains two things: the key you submitted, and a random device id. Skimora makes that id once, on this install, with the browser's random number generator. It is not a hardware or browser identifier, it says nothing about you or your computer, and it is deleted when you remove the extension (so a reinstall counts as a new device). Its only use is the device limit: a license works on up to 3 devices at a time.
On our server we keep, for each license key: its status, the device ids using it (up to 3) with the date each was added, when its devices were last reset, and the id of the payment it was bought with (from Dodo Payments, who handle checkout), so that a refund can switch that key off. Our server may also ask Dodo Payments, who issued your key, whether it is still valid; that request contains only the key. We do not receive your card details. If you activate your key on a 4th device, Skimora first asks you to confirm; if you do, the other 3 are signed out and this device takes their place. That reset can be done once every 24 hours. Each device's reading stats and highlights stay on that device either way.
At no point does Skimora read, collect, or transmit:
- the URLs you visit or the content of web pages,
- anything about your device beyond the random id described above,
- your highlights, summaries, or reading statistics,
- any personally identifiable information,
- any data from sites other than the Supabase endpoint above.
Permissions and what they are used for
| Permission | Use |
|---|---|
activeTab | Access to the one tab you are on, granted at the moment you click the Skimora toolbar button, and only then |
scripting | Inject the reading script into that tab on demand, so bolding and pacing can transform its text |
offscreen | Play focus audio in a hidden document so it survives the popup closing |
alarms | Periodically re-check an activated license key (see below) |
storage | Save settings and cached license locally |
downloads | Save your exported highlights/summaries and bionified EPUBs to your device |
Skimora requests no host permissions and installs no always-on content script. It cannot read a page until you invoke it there. When you do, the injected script transforms text inside your browser and never sends it anywhere.
Because an activated license is cached so it keeps working offline, the alarms
permission is used to re-validate the key periodically against the endpoint above. That request
contains only the key and the random device id; it is the same call described earlier.
Your controls
- Export: highlights, summaries, and documents can be exported (Markdown, JSON, or EPUB) directly to your device via the Downloads API.
- Review and delete: the Settings and Manage Storage screens let you inspect, back up, and remove stored data. Nothing is deleted without your explicit confirmation.
- Reset: you can reset all preferences to defaults from Settings.
- Uninstall: removing the extension deletes its local storage and database.
- Device ids on our server: they stay attached to your license key until the key's devices are reset. To have them removed sooner, email [email protected] with your license key.
Children
Skimora does not knowingly collect personal data from anyone. It requires no account, and the only things it stores remotely are license keys and the random device ids described above, so it collects no personal data from children.
Changes
If this policy changes, the new version will be noted by the "last updated" date above and, where relevant, within the extension.
This website
This website sets no cookies, runs no analytics and loads no third-party scripts, fonts or trackers. Payments are handled by Dodo Payments on their own checkout page. Skimora does not see or store your card details. We receive what is needed to issue and support your license.
After you pay, Dodo sends you back to our thank-you page with your license key in the address, so the page can show it to you. It is read in your browser only, taken out of the address straight away, and never stored or sent anywhere.
Contact
For privacy questions, email [email protected].