Same Page

Privacy policy

Last updated 28 August 2026 · Applies to the Same Page Chrome extension and this website.

Same Page is built and operated by Nick White, an independent developer, who is the data controller for the information described here. Questions, requests, and deletion requests go to nwhite.dev@gmail.com.

1. What we collect and why

Data Why it is needed When it is collected
Email address and password To create your account and sign you in. Passwords are handled by our authentication provider and stored only as a salted hash — we never see or store your password. When you sign up or sign in.
Username So friends can find you and so your name appears on the comments you send. When you sign up.
Friend list and friend requests To let you send comments to specific people. When you add or accept a friend.
Comment content, emoji reactions, and replies This is the product: your comment is delivered to the friend you chose and shown to them on the matching episode. When you send a comment or reply.
A still frame of the Netflix player (screenshot) So your comment has visual context — the friend sees the moment you were reacting to. Only when you click the Same Page comment button in the player. See section 2.
Show, season, episode, and playback timestamp To pin a comment to the exact moment and to hold it back until your friend reaches that episode. This is what makes the extension spoiler-safe. When you send a comment.
Show, season, and episode titles and artwork Stored once as a shared catalogue so conversations can be labelled and illustrated. When you send the first comment about a given episode.
Read state (whether a comment or reply has been seen) To show unread counts. When you open a conversation.

We do not collect your browsing history, your Netflix viewing history, your Netflix account details, page content from other websites, your location, or any advertising or analytics identifiers. Same Page contains no analytics SDK, no ad network, and no tracking pixels. The extension only runs on netflix.com — it has no access to any other site you visit.

2. Screenshots — exactly when and what

The short version

  • A screenshot is taken only at the moment you click the Same Page comment button inside the Netflix player. Nothing is captured while you are just watching, and nothing is captured on any other website.
  • What is captured is the visible area of that Netflix tab — the video frame you were on. Netflix's own on-screen controls and subtitles are hidden before the capture.
  • The captured frame is shown to you inside the message box before you send anything. If you close the box instead of sending, the image is discarded and never leaves your computer.
  • It is uploaded and stored only when you press send, and only the friend you chose (and you) are shown it in the app.

Technically this uses Chrome's tab-capture capability, restricted by the extension's manifest to Netflix pages only, and invoked once per click. It is not a continuous or background recording, and there is no screen, microphone, camera, or audio capture of any kind.

Because a screenshot is a picture of your screen, anything else visible in the Netflix tab at that moment — for example a profile name in the Netflix UI — will be part of the image you send. The preview in the message box is there so you can check before sending.

3. Where your data is stored

Accounts, comments, friend lists, the episode catalogue, and uploaded screenshots are stored in a Postgres database and file storage operated by Supabase, which acts as our hosting provider (sub-processor). Data is held in the region of our Supabase project and protected by row-level security rules so that a comment is readable only by its sender and its recipient.

Uploaded screenshot files are served from a storage bucket over a URL containing your account identifier, the conversation identifier, and a timestamp. Anyone who is given that exact URL can view that image, so treat a screenshot URL as you would any unlisted link.

On your own computer, the extension keeps a copy of your signed-in user record and friend list in Chrome's local extension storage, so the overlay works without signing in again. Signing out clears it.

This website is static and hosted on Vercel. It sets no cookies and runs no analytics; Vercel may log ordinary request data such as IP address for security and operational purposes.

4. Who your data is shared with

Comments and their screenshots are shared with exactly one person: the friend you address them to. Your username is visible to people you are friends with or who search for your username to send a request.

Beyond that, we do not sell, rent, or trade your data, do not share it with advertisers or data brokers, and do not use it to train machine learning models. The only third parties involved are the hosting providers named in section 3, acting on our instructions. We may disclose data if legally required to do so.

5. How long we keep it

6. Your choices and rights

If you are in the UK or EEA, you also have the rights to object to or restrict processing and to data portability, and you may complain to your local data protection authority. Our legal basis for processing is performance of a contract with you (running the service) and your consent for the screenshot attached to a comment.

7. Security

All traffic between the extension and our backend uses HTTPS. Access to comments is enforced per-row in the database, not just in the app. Passwords are hashed by our authentication provider. No system is perfect; if you believe you have found a vulnerability, please email us rather than disclosing it publicly.

8. Children

Same Page is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.

9. Limited use

Our use of data received through Chrome extension APIs complies with the Chrome Web Store Limited Use requirements: the data is used only to provide and improve the features described above, is not transferred to third parties except as set out in section 3, is not sold, and is not used for advertising, credit assessment, or lending purposes.

10. Changes

If our data practices change, this page is updated and the date at the top changes with it. Material changes will also be noted in the extension's Chrome Web Store release notes.

11. Contact

Nick White, independent developer — nwhite.dev@gmail.com