Privacy Policy
Last updated: August 7, 2026
Introduction
HighlightsHub ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.
Information We Collect
Account Information
When you create an account, we collect:
- Email address – Used for authentication and account recovery
- Display name – Your chosen public username
- Avatar image – Optional profile picture you upload
- Bio – Optional profile description
Content You Create
We store the content you choose to save:
- Books – Title, author, ISBN/ASIN, cover image URL
- Highlights – Text passages you've highlighted from your books
- Notes – Personal notes you attach to highlights
- Tags – Labels you create to organize highlights
- Collections – Groups of highlights you organize
Social Interactions
If you choose to use social features:
- Follows – Users you follow and who follow you
- Likes – Highlights you've liked
- Comments – Comments you post on shared highlights
Book Club Activity
When you create or participate in a club, we store:
- Membership and roles – The clubs you join and whether you are an owner, moderator, or member
- Reading activity – Milestones you mark reached and aggregate progress shown to organizers
- Club content – Shared passages, discussions, replies, book suggestions, and votes
- Club email choices – Organizer reminder defaults, your personal overrides, delivery status, and unsubscribe choices
Club activity is visible to members of that club. Public club identity and summary information may be visible to signed-in readers. Club content remains readable after a plan downgrade; deleting a club removes its club-scoped content.
Subscription and Transaction Information
When a club owner starts or manages a paid plan, we receive and store:
- Billing contact - The email associated with the subscription
- Plan details - Club, plan, price, billing interval, renewal date, and subscription status
- Transaction references - Stripe customer, subscription, invoice, and payment identifiers and payment outcome
Stripe processes payment credentials. HighlightsHub does not receive or store full card or bank-account numbers.
Chrome Extension Data
After you allow extension sync, the extension handles the reading data needed to provide the sync you request:
- Kindle reading data – Book details, highlighted passages, notes, colors, pages, locations, and dates
- Audible reading data – Audiobook details, bookmark notes, chapters, timestamps, locations, and dates
- Sync records – Account-level completion checkpoints plus browser-local progress, temporary tab details, consent, and schedule choices
- First-use progress – The dates when you connect the extension, start and complete your first sync, complete your first import, and first open an imported book. We keep only the milestone date and Kindle or Audible source, not titles, passages, search terms, or browsing history
- Temporary authentication – A short-lived access token kept only in browser session storage while Chrome is open
Manual sync runs only when requested. Scheduled sync is off by default. Compact completion checkpoints are saved to the reader's account; active queues and temporary tab details stay in Chrome. A short-lived access token is stored only for the browser session, and the extension does not read website cookies.
How We Use Your Information
We use your information to:
- Provide and maintain the service
- Enable you to save, organize, and review your highlights
- Sync the Kindle highlights and Audible bookmarks you choose into your HighlightsHub library
- Understand, in aggregate, whether readers can connect the extension and complete a first import
- Allow social features like sharing highlights and following users
- Send account-related emails (password reset, etc.)
- Send club meeting, RSVP, reading-checkpoint, and weekly digest emails you can control or turn off
- Process club subscriptions, maintain billing status, and provide invoices and billing controls
- Maintain the service and respond to support requests
Data Sharing
We do not sell your personal information. We only share data in these cases:
- Public content – Highlights and profile info you choose to make public
- Supabase - Authentication, database, and file storage
- Cloudflare - Hosting, content delivery, and security
- Stripe - Subscription checkout, payment processing, invoices, and the billing portal
- Resend - Transactional account and service email delivery
- Legal requirements – If required by law
Chrome Web Store Limited Use
HighlightsHub's use and transfer of information received from Google Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use extension data only to provide or improve the reading-sync features you choose. We do not sell extension data, use it for advertising or credit decisions, or transfer it except as needed to provide HighlightsHub, protect the service, comply with law, or complete a business transfer subject to this policy.
People do not read your private extension-synced content unless you give permission for a specific support request, access is necessary to investigate abuse or a security incident, the law requires it, or the data has been aggregated and anonymized for internal operations.
Cookies
We use only essential cookies for:
- Authentication – To keep you logged in
- Cookie preferences – To remember your cookie consent choice
We do not use advertising cookies or third-party analytics cookies. See our Cookie Policy for more detail.
Your Rights
You have the right to:
- Access – Download all your data from Settings
- Delete – Permanently delete your account and all data from Settings
- Rectify – Edit your profile and content at any time
- Portability – Export your data in JSON format
- Preferences - Change profile visibility and notification choices in Settings
Depending on where you live, applicable law may provide additional rights, including the right to object to or restrict certain processing. Contact us to make a request. We may need to verify your identity before completing it.
Data Retention
We retain your data as long as your account is active. When you delete your account, personal data you own is permanently removed from our servers within 30 days. Content you contributed to a shared club may be retained where needed to preserve a coherent discussion, with your profile association removed where practical. Club email payloads are removed after 30 days and delivery records after 90 days. Club owners can delete a club and its club-scoped content.
Security
We use industry-standard security measures including encrypted connections (HTTPS), secure password hashing, and row-level security policies to protect your data.
Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the website and, when appropriate, by email or an in-product notice.
Contact Us
If you have questions about this Privacy Policy, please contact us at [email protected].