Privacy policy
Same Page is built and operated by Nick White, an independent developer, who is the data controller for the information described here. Questions, requests, and deletion requests go to nwhite.dev@gmail.com.
1. What we collect and why
| Data | Why it is needed | When it is collected |
|---|---|---|
| Email address and password | To create your account and sign you in. Passwords are handled by our authentication provider and stored only as a salted hash — we never see or store your password. | When you sign up or sign in. |
| Username | So friends can find you and so your name appears on the comments you send. | When you sign up. |
| Friend list and friend requests | To let you send comments to specific people. | When you add or accept a friend. |
| Comment content, emoji reactions, and replies | This is the product: your comment is delivered to the friend you chose and shown to them on the matching episode. | When you send a comment or reply. |
| A still frame of the Netflix player (screenshot) | So your comment has visual context — the friend sees the moment you were reacting to. | Only when you click the Same Page comment button in the player. See section 2. |
| Show, season, episode, and playback timestamp | To pin a comment to the exact moment and to hold it back until your friend reaches that episode. This is what makes the extension spoiler-safe. | When you send a comment. |
| Show, season, and episode titles and artwork | Stored once as a shared catalogue so conversations can be labelled and illustrated. | When you send the first comment about a given episode. |
| Read state (whether a comment or reply has been seen) | To show unread counts. | When you open a conversation. |
We do not collect your browsing history, your Netflix
viewing history, your Netflix account details, page content from other
websites, your location, or any advertising or analytics identifiers.
Same Page contains no analytics SDK, no ad network, and no tracking
pixels. The extension only runs on netflix.com — it has
no access to any other site you visit.
2. Screenshots — exactly when and what
The short version
- A screenshot is taken only at the moment you click the Same Page comment button inside the Netflix player. Nothing is captured while you are just watching, and nothing is captured on any other website.
- What is captured is the visible area of that Netflix tab — the video frame you were on. Netflix's own on-screen controls and subtitles are hidden before the capture.
- The captured frame is shown to you inside the message box before you send anything. If you close the box instead of sending, the image is discarded and never leaves your computer.
- It is uploaded and stored only when you press send, and only the friend you chose (and you) are shown it in the app.
Technically this uses Chrome's tab-capture capability, restricted by the extension's manifest to Netflix pages only, and invoked once per click. It is not a continuous or background recording, and there is no screen, microphone, camera, or audio capture of any kind.
Because a screenshot is a picture of your screen, anything else visible in the Netflix tab at that moment — for example a profile name in the Netflix UI — will be part of the image you send. The preview in the message box is there so you can check before sending.
3. Where your data is stored
Accounts, comments, friend lists, the episode catalogue, and uploaded screenshots are stored in a Postgres database and file storage operated by Supabase, which acts as our hosting provider (sub-processor). Data is held in the region of our Supabase project and protected by row-level security rules so that a comment is readable only by its sender and its recipient.
Uploaded screenshot files are served from a storage bucket over a URL containing your account identifier, the conversation identifier, and a timestamp. Anyone who is given that exact URL can view that image, so treat a screenshot URL as you would any unlisted link.
On your own computer, the extension keeps a copy of your signed-in user record and friend list in Chrome's local extension storage, so the overlay works without signing in again. Signing out clears it.
This website is static and hosted on Vercel. It sets no cookies and runs no analytics; Vercel may log ordinary request data such as IP address for security and operational purposes.
4. Who your data is shared with
Comments and their screenshots are shared with exactly one person: the friend you address them to. Your username is visible to people you are friends with or who search for your username to send a request.
Beyond that, we do not sell, rent, or trade your data, do not share it with advertisers or data brokers, and do not use it to train machine learning models. The only third parties involved are the hosting providers named in section 3, acting on our instructions. We may disclose data if legally required to do so.
5. How long we keep it
- Comments, replies, and screenshots are kept until you or your friend delete them, or until either account is deleted.
- Your account record is kept until you ask us to delete it.
- Deleting your account deletes your account row, your friendships, your conversations and comments, and your uploaded screenshots. Copies already delivered to a friend's conversation are removed with the conversation.
- The shared episode catalogue (show and episode titles and artwork) is not personal data and is retained.
6. Your choices and rights
- Don't send it. No comment or screenshot is uploaded unless you press send.
- Access and export. Email us and we will send you a copy of the data held about you.
- Correction. Email us to correct your username or email address.
- Deletion. Email us from your registered address and we will delete your account and associated data, normally within 30 days.
- Uninstalling the extension removes its local storage from your browser but does not by itself delete your server-side account — ask us for deletion as above.
If you are in the UK or EEA, you also have the rights to object to or restrict processing and to data portability, and you may complain to your local data protection authority. Our legal basis for processing is performance of a contract with you (running the service) and your consent for the screenshot attached to a comment.
7. Security
All traffic between the extension and our backend uses HTTPS. Access to comments is enforced per-row in the database, not just in the app. Passwords are hashed by our authentication provider. No system is perfect; if you believe you have found a vulnerability, please email us rather than disclosing it publicly.
8. Children
Same Page is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
9. Limited use
Our use of data received through Chrome extension APIs complies with the Chrome Web Store Limited Use requirements: the data is used only to provide and improve the features described above, is not transferred to third parties except as set out in section 3, is not sold, and is not used for advertising, credit assessment, or lending purposes.
10. Changes
If our data practices change, this page is updated and the date at the top changes with it. Material changes will also be noted in the extension's Chrome Web Store release notes.
11. Contact
Nick White, independent developer — nwhite.dev@gmail.com