Privacy Policy
Last updated: 27 August 2026
Subshack is a Chrome extension for Substack creators. It reads your own Notes statistics to show you what works, helps you draft better Notes and replies, and lets you reuse your own published articles. This policy explains exactly what data Subshack handles, where it goes, and what we will never do with it.
Who we are
Subshack is published by 404-DEV, INC. For any question about this policy or your data, contact us at contact@404-dev.com.
What Subshack does
The published extension does two things: it collects the performance of your own Notes and articles so it can be analysed on your device, and it audits a public Substack profile you point it at. Beyond that, Subshack analyses your own Notes and drafts content — reply suggestions, Notes, and article-template fills. You review, edit, and publish everything yourself. Subshack never posts, follows, likes, restacks, or subscribes on your behalf, never auto-inserts a mention, and never automates any public engagement. Requests to Substack are throttled to a human pace and only read data you already have access to.
Messages and group chats (Chat)
Not in the published extension yet. The features described in this section are built but are not part of the version available on the Chrome Web Store — they cannot be reached or switched on there. They are documented here so this policy stays ahead of what ships, and this paragraph will be removed when they are released.
The Chat tab is the one place where Subshack can act without a click, and only if you switch it on — it is off by default. When enabled, it reads your Substack direct messages to draft an answer. In its default mode the draft simply waits for you. If you explicitly choose Send automatically, Subshack sends that reply from your account after a random delay, within the quiet hours and the daily cap you set. It never sends a public Note, reply or restack on your behalf, and you can turn it off at any time. The conversation text is sent to our AI provider to write the reply, exactly like the rest of the generation described below.
The same tab can share one link across the Substack group chats you already belong to. Subshack reads those chats to find where your link already is — so it does not post twice — and reads each group’s published house rules; groups whose rules forbid self-promotion are set aside and Subshack refuses to post there. Posting happens one group at a time, on your click by default. An automatic queue exists behind an explicit setting, spaced at random and capped per day. Subshack still never publishes a Note, an article or a restack, and never follows or subscribes for you.
Campaign Mode links
Campaign Mode runs directly on supported Substack pages, Facebook Groups, Reddit communities and X. It lets you choose a campaign and copy a link to the campaign’s destination URL, with campaign parameters describing where you plan to share it. The page you are visiting is never substituted for that destination.
Campaigns are stored in your private Subshack account. When, and only when, you press Copy link, we store the campaign, destination URL, platform, context type and stable context id, a readable community name when available, the source page URL without query parameters or fragments, the UTM parameters and the creation date. This lets the same campaign and context reuse one link instead of creating duplicates. A snapshot of the active campaign is also kept in Chrome local storage so Campaign Mode survives a browser restart.
Campaign Mode does not read or store the text of posts, Notes, chats or private messages. Substack Inbox and X Messages are excluded from context detection. Opening or navigating a supported page prepares only its URL-derived context and stores nothing on our servers until you click Copy link.
How Subshack reads your Substack data
When you start a synchronization, Subshack calls Substack from your browser, using your own logged-in session, to read data about your Notes. Your Substack session cookie stays in your browser: it is never sent to us or to anyone else. These Substack endpoints are internal and undocumented; they can change or break at any time, which may interrupt synchronization.
Public profiles of people who engage with you
Substack does not include a bio in the like, restack or reply payloads. To tell you which of your known readers is genuinely connected to the topic you are writing about, Subshack can read the public profile of the people who engaged with your Notes organically or subscribed through them — substack.com/api/v1/user/<handle>/public_profile, the same data anyone sees on their public page (bio, publication, follower count). These requests are sent without your session cookie, are throttled, run at most once a month per person, and the result stays on your device.
These profiles are used only to show you who engages with your content. They stay on your device: they are not sent to our servers by synchronization, enrichment, or any automatic process — the one exception is the assistant, and only when you ask it a question about your audience (see The assistant below, including which fields are never sent).
Data stored on your device
The following is stored in your browser (Chrome local storage). It stays on your device unless you turn on Backup to your Subshack account, which is described in its own section below and is off unless you turn it on:
- Your editable prompts and generation settings.
- Your publication and identity settings (used to fill in variables).
- Your local library of your own published articles (titles, URLs, summaries).
- Your Notes and their statistics: text, publication date, impressions, likes, replies, restacks, new free and paid subscribers, profile visits, and the traffic-source and audience breakdowns Substack reports for each Note.
- Snapshots of those metrics taken at each synchronization, so Subshack can show how a Note evolves over time.
- Labels computed for each Note: content type, topics, hook, call to action, and growth mechanism (organic, community/networking, reciprocal), plus any correction you make by hand.
- People Substack exposes on your Notes — those who liked, restacked or replied to them, and those who subscribed through them: their public Substack identity (id, display name, handle when available, avatar, publication) and their interactions with your Notes. This is third-party data about other creators. It is stored on your device and used only to show you who engages with your content; it is sent to our servers only if you ask the assistant a question about your audience, and then only the fields listed under The assistant below.
- Which people you mentioned from the composer, so Subshack avoids suggesting them again too soon.
- A local log of AI calls (operation, duration, sizes) — never the text of your drafts.
- An anonymous, randomly-generated identifier used only for aggregated analytics.
You can delete all of it at any time — see Your choices below.
Backup to your Subshack account (optional, off by default)
Everything listed above is computed and kept on your device. That has one consequence: nothing can read it when your browser is closed — not the web dashboard, not the AI connector (MCP) you may have connected to Claude or ChatGPT, not any agent acting on your behalf.
You can therefore choose to back that data up to a private account on our servers. This setting lives in the extension, under Settings › Sync. It is off unless you turn it on, and turning it on is an explicit action — installing, synchronizing or linking a browser never enables it.
When, and only when, you turn it on, each synchronization also sends:
- Your Notes and their statistics, and the snapshots taken at each sync.
- Your published articles with their statistics, traffic sources and headline tests.
- The labels computed for each Note (content type, topics, hook, call to action, growth mechanism), including the corrections you made by hand.
- The public Substack profiles of people who liked, restacked or replied to your Notes.
- Your subscriber list as Substack shows it to you, including e-mail addresses, and which of them opened each of your e-mails.
This copy is private to your account. It is never shared with other users, never sold, and never used to train any model. Turning the setting off stops any further upload; to remove the copy already stored, use Delete my Subshack data in the extension, which deletes the server-side copy as well as the local one.
Data sent to an AI provider
Three features send data off your device, and only these three:
- Generating or rewriting a draft. When you explicitly click a generate or improve action, the extension sends the text you are working on and your prompt/settings to our backend at saas-maker.com, which asks an AI model for the draft and returns it. Nothing is sent while you type.
- Classifying your Notes. During synchronization, the text of your own Notes (up to 2 000 characters each, in batches) is sent to our API at www.subshack.pro, which asks an AI model to label them (content type, topics, hook, call to action, growth mechanism) and returns only those labels. The model never receives your statistics, your audience, or anyone’s identity — performance is computed on your device.
- The assistant. When you ask it a question, the extension sends your question, the conversation so far, and a summary of your account (counts and metrics, no identities) to our API at www.subshack.pro. Depending on the question, it then sends only the slices of data needed to answer it — see the next section.
All three go through OpenAI as the model provider, are used only to return your result, are not used to train models, are not sold, and are not used to build advertising profiles. We do not store your conversations or your drafts on our servers. You can turn all three off in Settings → Sync & export → Disable AI features; Subshack then runs fully locally, with rule-based classification only.
Your audience data stays on your device
Your subscriber list, per-Note and per-article statistics, and which subscribers opened each e-mail are read from your own publication during synchronization and kept on this device only — never uploaded to our servers, never shared, never sold, never used for advertising.
The assistant
The assistant answers questions about your own account. It is the only part of Subshack that can send information about other people off your device, so it asks for your explicit agreement the first time you open it, and does nothing until you agree.
What it can send, and only when the question requires it:
- Metrics and counts computed on your device — impressions, subscribers, replies, comparisons between formats or topics.
- The text of your own Notes — an extract when listing them, the full text when you ask about one in particular.
- For audience questions only: the display name, handle and publication name of people who engaged with you, their public follower and subscriber counts, and how they interacted with your Notes.
What it never sends, by design and enforced by an automated test: the text of anyone’s replies, their profile photo, or their bio. Your conversation is kept on your device and can be cleared from the panel at any time.
People who are not Subshack users
The people named above are Substack creators and readers who interacted with your Notes. They are not Subshack users and have not agreed to anything with us. We handle their data on the following basis:
- Why. Only to answer a question you asked about your own audience. We have a legitimate interest in providing that answer; we do not profile these people, contact them, or use their data for anything else.
- What. Only what Substack already shows publicly on their profile — never their private messages, and never the text they wrote in reply to you.
- How long. Not stored on our servers at all. It is sent to answer one question and is not retained afterwards. The copy on your device is deleted when you delete your Subshack data.
- Removal. If you are one of these people and want your data removed from a Subshack user’s device, contact us — see below. Note the underlying data comes from Substack, where you control what your profile shows publicly.
Analytics
To understand which features are useful and improve the product, Subshack sends anonymous, aggregated usage events (for example: a suggestion was generated) to PostHog (EU region, eu.i.posthog.com). These events are tied to the anonymous identifier described above — never to your name, email, or Substack account — and contain no personal content.
One exception, and we want to be precise about it. Extension events also carry a publication fingerprint: the first 16 characters of a SHA-256 hash of your public Substack handle. Your handle itself never leaves your device. We use it for one thing — counting one creator once, instead of counting a new person every time the extension is reinstalled. Because Substack handles are public, this fingerprint is pseudonymous rather than anonymous: someone holding a list of handles could match it back. It is never used to contact you or to build a profile.
On the subshack.pro website, the same anonymous events record the pages you visit and how you got there: the referring site (for example substack.com) and any campaign parameters in the link you clicked (utm_source and the like). This tells us which links bring people in. We use no advertising or cross-site tracking cookies, and we do not build a profile of you across other websites.
The website sets a first-party cookie. It holds the anonymous identifier and nothing else, and it is what lets us tell a returning reader from a new one instead of counting the same person twice. Website analytics are served from subshack.pro/ph-relay, our own domain, and forwarded to PostHog in the EU — so that privacy tools blocking third-party domains do not silently break our page counts. Same data, same processor, one less broken measurement.
We record website sessions. On subshack.pro (not in the extension) we capture a replay of the page as you saw it — clicks, scrolling, navigation — to find where the site confuses people. Everything you type is masked: form fields are never recorded. Replays are stored by PostHog in the EU and are used only to fix the site. If you sign in, this and the events above are linked to your account id — never your email address — so that we can count one person once across devices.
What we never do
- We never post, follow, like, restack, or message for you.
- We never sell or rent your data.
- We never use your data to determine creditworthiness or for lending.
- We never use or transfer your data for any purpose unrelated to Subshack’s single purpose.
- We show no ads.
Your choices
- Delete everything: Settings → Sync & export → Delete my Subshack data removes your Notes and statistics, snapshots, classifications, audience, contacts, mention history, article library, promotion history, cached profile audits, assistant conversations and AI usage log from this device. Your prompts and settings are kept.
- Clear the assistant: the Clear button in the assistant panel deletes that conversation from your device on its own.
- Turn off AI: Settings → Sync & export → Disable AI features stops all generation and classification requests.
- Never synchronize: synchronization only runs when you start it, or on the daily schedule you enable yourself.
- Uninstalling the extension removes all data stored on your device.
If you are a Substack creator whose public identity appeared in someone’s Subshack audience and you want it removed, that data lives on that person’s device; contact us and we will explain how to have it cleared. For anything else, email contact@404-dev.com.
Data retention
On-device data persists until you clear it or uninstall the extension. Content sent to generate a suggestion is processed to return your result and is not used to build a profile of you. Analytics events are retained in aggregate to measure product usage.
Children
Subshack is intended for Substack creators and is not directed to children under 13.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected on this page with a new “Last updated” date.
Contact
404-DEV, INC. — contact@404-dev.com