Legal
Privacy Policy
Last updated August 6, 2026
Overview
SubSync syncs Substack subscribers into your email service provider (currently Kit). This policy explains what we collect, why we need it, and how the Chrome extension fits in. By using SubSync you agree to this policy.
Who we are
SubSync is operated as a standalone product at subsync.app. For privacy questions, contact privacy@subsync.app.
Data we collect
- Account data — email address, name/avatar if you sign in with Google, and session identifiers needed to keep you logged in.
- Publication metadata — Substack publication title, URL, logo, and role, discovered when you connect the extension.
- Subscriber records — email, name (if present), subscription tier/flags, and timestamps fetched from Substack so we can deliver them to Kit and avoid duplicates.
- Provider credentials — Kit OAuth OAuth tokens you connect, encrypted at rest on our servers. These never leave our backend and are never sent to the browser extension.
- Sync operational data — sync configs, watermarks, run history, delivery status, and extension pairing tokens (we store a hash of the token, not the raw secret after minting).
Chrome extension
The SubSync extension runs in your browser. It uses your existing Substack session (cookies) to call Substack's own authenticated APIs, then forwards raw subscriber pages to SubSync over HTTPS with a pairing token.
- storage — stores only the pairing token and lightweight UI hints (e.g. last poll time).
- alarms — schedules periodic sync polls (~every 30 minutes).
- cookies — reads Substack session cookies so publication-scoped API calls can authenticate as you. Cookie values are not logged or uploaded as a separate dataset.
- Host access —
*.substack.comto fetch subscribers; SubSync app origins to talk to our API.
The extension does not hold Kit credentials, does not transform subscriber data for delivery, and does not share data with any product other than SubSync.
How we use data
- Authenticate you and keep your account secure
- Fetch Substack subscribers you asked us to sync
- Deliver those subscribers to Kit according to your mapping
- Deduplicate, retry failed deliveries, and show sync history
- Operate, debug, and improve the service
We do not sell subscriber lists, use them for advertising, or contact your subscribers on your behalf.
Third parties
- Supabase / Postgres — database hosting for account and sync data
- Kit — destination ESP; receives subscribers you choose to sync
- Google — optional sign-in
- Resend — optional magic-link email delivery for sign-in
- Substack — source of subscriber data, accessed via your own browser session through the extension
Retention & deletion
We keep account and sync data while your account is active. You can disconnect Kit, revoke extension pairing tokens, and disable syncs in Settings. To delete your account and associated subscriber ledger data, email privacy@subsync.app. We will process deletion requests within a reasonable period unless we must retain limited records for legal or security reasons.
Security
Provider credentials are encrypted at rest with application-layer encryption. Extension traffic to SubSync uses HTTPS and a bearer pairing token. Sessions for the web app use Auth.js. No method of transmission or storage is perfectly secure; we take commercially reasonable steps to protect your data.
Children
SubSync is intended for adults operating Substack publications and email lists. We do not knowingly collect personal information from children under 13.
Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do. Continued use of SubSync after an update means you accept the revised policy.
Contact
Questions or requests: privacy@subsync.app.