Privacy Policy
Last updated: 27 August 2026
This policy covers the chapter browser extension and the service it talks to at api.dativ.us. Throughout, "we" means Dativus LLC, contactable at contact@chapter.dativ.us.
The short version
The extension needs an account, so we hold your email address. Drawing markers on a video means asking our service about that video, so we learn which supported videos you open. Because a subscription is sold for one household, we also keep a coarse count of how many networks each account is used from. If you subscribe, our payment provider takes the money and we keep the billing record. We run no advertising and no third-party analytics, we build no profiles, and we sell your data to nobody.
What we collect
Your account
- Email address, and a password if you create an account with one. Passwords are hashed and never stored in a form we can read or recover.
- Google account email, if you choose "Continue with Google". Our service brokers the sign-in; Google returns your address and a confirmation that it succeeded.
- Subscription status, which decides whether we serve you chapter data.
- A record of each email we send you and what became of it - delivered, bounced, or refused - kept against your address, so we can tell when mail to you is failing and can avoid locking you out over something as ordinary as a full mailbox.
- The description your browser sends of itself at sign-up: the "user agent" line naming your browser and operating system, kept so that a burst of accounts made by one script is distinguishable from a burst of real people. Nothing reads it today and no decision about you comes from it.
We use these to sign you in, to keep you signed in, to tell you when your account needs attention (email verification, password resets, a failed delivery to your address), and to decide whether to serve chapter data.
Which videos you open
When you open a supported video page, the extension sends us the identifier of that video, taken from the page URL, to receive its chapter markers. The request is authenticated, so it is associated with your account and we can tell which supported videos you have opened.
We use that to serve markers, to keep the service running, and in aggregate to decide which events to process next. Never for advertising, and never combined with data from anywhere else.
The extension runs only on the Paramount+ pages named in its manifest. It cannot see, and never receives, your browsing anywhere else.
How much the extension is used
For each day your account is active we store the day, how many times the extension asked for markers, and the time of the most recent of those requests. That time is overwritten by each new request, so it marks one moment per day rather than your viewing hours. We do not record what you watched.
Your subscription
Paddle takes the payment and tells us what happened. We keep the identifier Paddle uses for you as a customer, so an incoming payment reaches the right account; your subscription's identifier and when it expires, which is what we check before serving chapter data; and Paddle's notifications about your subscription as they arrive, which carry your billing name, address and email as Paddle holds them. Tax law obliges us to keep those notifications, so when you delete your account we strip the name, address, email and business details out of them and keep the amounts and dates. The customer identifier is deleted outright.
A free trial is one per person. To hold to that we check your email address, and the payment method behind the trial, against trials already taken; if either has been used for a trial before, the trial is cancelled automatically and we keep a note of that decision. This affects trials only, and never a subscription you have paid for.
Where you connect from
Any service you connect to receives the address your device connects from; it is how the reply finds its way back. What we do with ours:
- At sign-in, we store the address as it arrived, alongside that sign-in, so we can rate-limit sign-in attempts and recognise a session as belonging to a device rather than to whoever holds a copied token. This is the only place we keep a full address, and it lives exactly as long as the sign-in does.
- At sign-up, we store a scrambled, one-way form of it that cannot be turned back into an address, so we can tell whether many accounts are being created from one place. Never the address itself.
- When the extension fetches markers, we cut the address down to the network block it belongs to - roughly "this home" or "this office", never "this machine" - and scramble that. Beside it we keep the country, the public number saying which internet provider routes that block, the date, how many times the extension asked for markers, and the time of the most recent of those requests. One row per account, per day, per network.
That last one is the sharing census, and it is there because a subscription is sold for one household. It holds no address, no city, and no record of which video was watched from which network. Its time is the last request of that day, overwritten each time, so a row marks one moment rather than a trail. A row can place your account on a network, in a country, at a time. It cannot place you at an address or a street.
Nothing about your account is decided from any of this. There is no device limit, no automatic suspension, nothing that costs you access, and nothing that triggers a message to you. The counts are read in aggregate, on an internal page, to tell us whether sharing happens at all, and will never be used to judge an individual account. If that ever changes, we will say so here first.
We do not use any of it for advertising, we do not look up where you are beyond the country, and we do not combine it with data from anywhere else.
Missing-video reports
If a supported video has no chapter data, the extension offers a button to report it. Pressing it sends the video identifier, the page URL, the series name, the episode title, the video's duration, and the extension's version number. Those last four come from the page's own public metadata. The report is attributed to your account so we do not count one person twice, and so we can tell you when it has been processed. Nothing is sent unless you press the button.
What we do not collect
- No advertising identifiers, and no third-party analytics, tracking or advertising of any kind. The extension itself contacts two hosts:
api.dativ.us, and Google's sign-in pages if you choose that option. Pressing Subscribe opens a tab on our own site which loads Paddle's checkout script - a third host, reached only on that press and never in the background. - No payment card details. Paddle takes the payment on its own pages; card numbers reach neither us nor the extension.
- No video, audio, screen contents, or keystrokes.
- No contents of any page outside the supported Paramount+ paths.
- No location beyond the country your network is registered in. No city-level lookups, and the extension never asks your browser where you are.
What is stored on your own device
Neither of these is ever transmitted:
- A session token, in extension storage, so you stay signed in between browser restarts. Signing out deletes it, and so does uninstalling.
- Your display preferences - chapter view on or off, the history stack lock, markers on the standard time bar - in the page's local storage. Your browser keeps these against the Paramount+ site rather than against the extension, so they outlive an uninstall; clearing that site's data in your browser settings removes them.
Who else sees it
- Cloudflare, our hosting and database provider, which runs the service and stores the records described above.
- Resend, our email provider, which delivers verification, password-reset and notification emails to your address.
- Paddle, our payment provider and the merchant of record for your purchase, which runs the checkout and the subscription page. Your email address and what you bought reach them; your card details go to them and never to us.
- Google, only if you use Google sign-in, and only to the extent of that sign-in.
Otherwise we disclose personal data only where the law requires it, and we will tell you when we are permitted to. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
How long we keep it
- Account information: as long as the account exists. When you delete your account your identity - email address, name, password, sign-in tokens - is erased at once, and is gone from backups within 3 months.
- Usage counts: up to 400 days. They survive account closure, because what is left no longer identifies you and removing it would change figures for periods that have already passed.
- Billing records: 7 years, which is what tax and accounting law requires of us. We remove the personal details when you delete your account and keep the financial facts.
- Anti-abuse records: 3 years, so that one person cannot take repeated free trials. They outlive the account, but the readable parts - your address in normalised form and your browser's description of itself - are erased when you delete it, leaving a scrambled code and a date.
- Sign-in addresses: the life of that sign-in, and no longer. Signing out, resetting your password, or deleting your account removes the record on the spot. A sign-in left alone expires by itself after a week without use, and a sweep deletes it within a day of that, so the address is gone about eight days after you last used the extension, with nothing left to delete on request.
- The network counts above: 60 days, then deleted automatically. They are deleted outright rather than anonymised when you delete your account, because no figure depends on them surviving.
- Operational records - the requests the extension makes, and our own notes of what failed or was refused: as long as we need them to operate, secure and debug the service. Deleting your account unlinks these from you rather than removing them.
- Email delivery records: for as long as we operate the service. They are not removed when you delete your account, and they hold your address and what our email provider told us about each message sent to it.
- Missing-video reports: as long as they are useful for prioritising processing. When you delete your account we strip the report of everything about you and keep what it says about the video.
- The fact that an account was deleted, and when: as long as we operate the service, so that we can show we acted on your request.
Your choices and rights
You can:
- Sign out at any time from the extension's popup, which deletes the session token from your device and ends the session on our side.
- Request a copy of your data, a correction, or deletion of your account by writing to contact@chapter.dativ.us. We will respond within 7 days.
- Uninstall the extension, which stops all data collection immediately and removes everything it stored locally. That does not by itself delete your account - ask us if you want that too.
We extend these rights to everyone who uses the extension, wherever you live, rather than only to people covered by a particular law: access, correction, deletion, a portable copy of your data, and objection to or restriction of processing. You may also withdraw from the service entirely at any time by asking us to delete your account.
If you are in the European Economic Area or the United Kingdom, you additionally have the right to complain to your national data protection authority, and we are required to tell you the legal basis on which we process each thing:
| What | Legal basis |
|---|---|
| Email address, password, subscription status | Performance of our contract with you (Art. 6(1)(b)). |
| Video identifiers sent to fetch chapter markers | Performance of our contract with you (Art. 6(1)(b)). |
| Missing-video reports | Performance of our contract with you (Art. 6(1)(b)); you initiate each one. |
| Taking payment and managing your subscription | Performance of our contract with you (Art. 6(1)(b)). |
| Keeping billing records for 7 years | Compliance with our legal obligations under tax and accounting law (Art. 6(1)(c)). |
| Keeping records to run, secure and debug the service, and deciding in aggregate which events to process next | Our legitimate interests in operating and improving the service (Art. 6(1)(f)), balanced against the limited and non-sensitive nature of what we hold. |
| Counting how much the service is used | Our legitimate interests in knowing how many people use the service, and in sizing and operating it (Art. 6(1)(f)). It never leaves our own systems and is never used to make a decision about you individually. |
| Your address at sign-in, and the scrambled form and browser description kept at sign-up | Our legitimate interests in securing the service against automated sign-in attempts and bulk account creation (Art. 6(1)(f)). |
| Counting how many networks a subscription is used from | Our legitimate interests in preventing our subscriptions being shared beyond one household, and in understanding the scale of it (Art. 6(1)(f)). We reduce the address to a network and scramble it before storing, keep it 60 days, read it only in aggregate, and make no decision about any individual account from it. You can object to this processing at any time by writing to us. |
| Verification, password-reset and account notification emails | Performance of our contract with you (Art. 6(1)(b)). We send no marketing email. |
Where your data goes. We are a United States company, and Cloudflare and Resend process data in the United States. Where personal data of European Economic Area or United Kingdom users is transferred there, we rely on the transfer safeguards in our agreements with those providers, including the European Commission's Standard Contractual Clauses, and you can ask us for details. Paddle is the merchant of record for your payment and processes it under its own terms.
You are not subject to any automated decision-making that produces legal or similarly significant effects.
If you are a California resident: we do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. The rights listed above are available to you.
Children
The extension is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, write to contact@chapter.dativ.us and we will delete it.
Security
Traffic between the extension and our service is encrypted in transit. Chapter data requests carry a short-lived access token rather than your long-lived session token, and no part of the extension that runs inside a web page ever holds a credential. Passwords are stored hashed. No system is perfectly secure, but we treat account data as the sensitive thing it is.
Changes
If we change this policy we will post the new version here and change the date at the top. If a change significantly affects you - we start using your information for a new purpose, we begin collecting a new kind of information, or someone new receives it - we will email you before it takes effect.
Contact
contact@chapter.dativ.us - questions, requests, and complaints all land in the same place.