⚡ subshack

Privacy Policy

Last updated: 27 August 2026

Subshack is a Chrome extension for Substack creators. It reads your own Notes statistics to show you what works, helps you draft better Notes and replies, and lets you reuse your own published articles. This policy explains exactly what data Subshack handles, where it goes, and what we will never do with it.

Who we are

Subshack is published by 404-DEV, INC. For any question about this policy or your data, contact us at contact@404-dev.com.

What Subshack does

The published extension does two things: it collects the performance of your own Notes and articles so it can be analysed on your device, and it audits a public Substack profile you point it at. Beyond that, Subshack analyses your own Notes and drafts content — reply suggestions, Notes, and article-template fills. You review, edit, and publish everything yourself. Subshack never posts, follows, likes, restacks, or subscribes on your behalf, never auto-inserts a mention, and never automates any public engagement. Requests to Substack are throttled to a human pace and only read data you already have access to.

Messages and group chats (Chat)

Not in the published extension yet. The features described in this section are built but are not part of the version available on the Chrome Web Store — they cannot be reached or switched on there. They are documented here so this policy stays ahead of what ships, and this paragraph will be removed when they are released.

The Chat tab is the one place where Subshack can act without a click, and only if you switch it on — it is off by default. When enabled, it reads your Substack direct messages to draft an answer. In its default mode the draft simply waits for you. If you explicitly choose Send automatically, Subshack sends that reply from your account after a random delay, within the quiet hours and the daily cap you set. It never sends a public Note, reply or restack on your behalf, and you can turn it off at any time. The conversation text is sent to our AI provider to write the reply, exactly like the rest of the generation described below.

The same tab can share one link across the Substack group chats you already belong to. Subshack reads those chats to find where your link already is — so it does not post twice — and reads each group’s published house rules; groups whose rules forbid self-promotion are set aside and Subshack refuses to post there. Posting happens one group at a time, on your click by default. An automatic queue exists behind an explicit setting, spaced at random and capped per day. Subshack still never publishes a Note, an article or a restack, and never follows or subscribes for you.

Campaign Mode links

Campaign Mode runs directly on supported Substack pages, Facebook Groups, Reddit communities and X. It lets you choose a campaign and copy a link to the campaign’s destination URL, with campaign parameters describing where you plan to share it. The page you are visiting is never substituted for that destination.

Campaigns are stored in your private Subshack account. When, and only when, you press Copy link, we store the campaign, destination URL, platform, context type and stable context id, a readable community name when available, the source page URL without query parameters or fragments, the UTM parameters and the creation date. This lets the same campaign and context reuse one link instead of creating duplicates. A snapshot of the active campaign is also kept in Chrome local storage so Campaign Mode survives a browser restart.

Campaign Mode does not read or store the text of posts, Notes, chats or private messages. Substack Inbox and X Messages are excluded from context detection. Opening or navigating a supported page prepares only its URL-derived context and stores nothing on our servers until you click Copy link.

How Subshack reads your Substack data

When you start a synchronization, Subshack calls Substack from your browser, using your own logged-in session, to read data about your Notes. Your Substack session cookie stays in your browser: it is never sent to us or to anyone else. These Substack endpoints are internal and undocumented; they can change or break at any time, which may interrupt synchronization.

Public profiles of people who engage with you

Substack does not include a bio in the like, restack or reply payloads. To tell you which of your known readers is genuinely connected to the topic you are writing about, Subshack can read the public profile of the people who engaged with your Notes organically or subscribed through them — substack.com/api/v1/user/<handle>/public_profile, the same data anyone sees on their public page (bio, publication, follower count). These requests are sent without your session cookie, are throttled, run at most once a month per person, and the result stays on your device.

These profiles are used only to show you who engages with your content. They stay on your device: they are not sent to our servers by synchronization, enrichment, or any automatic process — the one exception is the assistant, and only when you ask it a question about your audience (see The assistant below, including which fields are never sent).

Data stored on your device

The following is stored in your browser (Chrome local storage). It stays on your device unless you turn on Backup to your Subshack account, which is described in its own section below and is off unless you turn it on:

You can delete all of it at any time — see Your choices below.

Backup to your Subshack account (optional, off by default)

Everything listed above is computed and kept on your device. That has one consequence: nothing can read it when your browser is closed — not the web dashboard, not the AI connector (MCP) you may have connected to Claude or ChatGPT, not any agent acting on your behalf.

You can therefore choose to back that data up to a private account on our servers. This setting lives in the extension, under Settings › Sync. It is off unless you turn it on, and turning it on is an explicit action — installing, synchronizing or linking a browser never enables it.

When, and only when, you turn it on, each synchronization also sends:

This copy is private to your account. It is never shared with other users, never sold, and never used to train any model. Turning the setting off stops any further upload; to remove the copy already stored, use Delete my Subshack data in the extension, which deletes the server-side copy as well as the local one.

Data sent to an AI provider

Three features send data off your device, and only these three:

All three go through OpenAI as the model provider, are used only to return your result, are not used to train models, are not sold, and are not used to build advertising profiles. We do not store your conversations or your drafts on our servers. You can turn all three off in Settings → Sync & export → Disable AI features; Subshack then runs fully locally, with rule-based classification only.

Your audience data stays on your device

Your subscriber list, per-Note and per-article statistics, and which subscribers opened each e-mail are read from your own publication during synchronization and kept on this device only — never uploaded to our servers, never shared, never sold, never used for advertising.

The assistant

The assistant answers questions about your own account. It is the only part of Subshack that can send information about other people off your device, so it asks for your explicit agreement the first time you open it, and does nothing until you agree.

What it can send, and only when the question requires it:

What it never sends, by design and enforced by an automated test: the text of anyone’s replies, their profile photo, or their bio. Your conversation is kept on your device and can be cleared from the panel at any time.

People who are not Subshack users

The people named above are Substack creators and readers who interacted with your Notes. They are not Subshack users and have not agreed to anything with us. We handle their data on the following basis:

Analytics

To understand which features are useful and improve the product, Subshack sends anonymous, aggregated usage events (for example: a suggestion was generated) to PostHog (EU region, eu.i.posthog.com). These events are tied to the anonymous identifier described above — never to your name, email, or Substack account — and contain no personal content.

One exception, and we want to be precise about it. Extension events also carry a publication fingerprint: the first 16 characters of a SHA-256 hash of your public Substack handle. Your handle itself never leaves your device. We use it for one thing — counting one creator once, instead of counting a new person every time the extension is reinstalled. Because Substack handles are public, this fingerprint is pseudonymous rather than anonymous: someone holding a list of handles could match it back. It is never used to contact you or to build a profile.

On the subshack.pro website, the same anonymous events record the pages you visit and how you got there: the referring site (for example substack.com) and any campaign parameters in the link you clicked (utm_source and the like). This tells us which links bring people in. We use no advertising or cross-site tracking cookies, and we do not build a profile of you across other websites.

The website sets a first-party cookie. It holds the anonymous identifier and nothing else, and it is what lets us tell a returning reader from a new one instead of counting the same person twice. Website analytics are served from subshack.pro/ph-relay, our own domain, and forwarded to PostHog in the EU — so that privacy tools blocking third-party domains do not silently break our page counts. Same data, same processor, one less broken measurement.

We record website sessions. On subshack.pro (not in the extension) we capture a replay of the page as you saw it — clicks, scrolling, navigation — to find where the site confuses people. Everything you type is masked: form fields are never recorded. Replays are stored by PostHog in the EU and are used only to fix the site. If you sign in, this and the events above are linked to your account id — never your email address — so that we can count one person once across devices.

What we never do

Your choices

If you are a Substack creator whose public identity appeared in someone’s Subshack audience and you want it removed, that data lives on that person’s device; contact us and we will explain how to have it cleared. For anything else, email contact@404-dev.com.

Data retention

On-device data persists until you clear it or uninstall the extension. Content sent to generate a suggestion is processed to return your result and is not used to build a profile of you. Analytics events are retained in aggregate to measure product usage.

Children

Subshack is intended for Substack creators and is not directed to children under 13.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected on this page with a new “Last updated” date.

Contact

404-DEV, INC. — contact@404-dev.com

← Back to Subshack