Privacy policy
Controller: Ibrahim Mert Küni, support@kunionline.com. Data is stored in the European Union.
What the extension does on your device
Smart Brightness dims and warms web pages locally. It does not read, collect or transmit the
content of the pages you visit, your browsing history, your bookmarks or your form input.
Your settings and per-site preferences are stored by Chrome (chrome.storage)
and, if you have Chrome Sync enabled, synchronised by Google between your own devices. We
never see them.
On each site you visit the extension also writes a single entry named
__smart_brightness_profile__ into that site's own local storage in your browser. It
holds nothing but the current brightness and colour values as numbers — no identifier, no history,
no page content. It exists so the dimming can be applied before the page paints, which is what
prevents a white flash on every navigation. It never leaves your device, is not readable by us,
and you can clear it at any time by clearing site data. Under § 25(2) TTDSG this storage is
strictly necessary to provide the service you explicitly requested by installing the extension,
so it does not require separate consent.
If you never buy anything, the extension never contacts us
The free tier makes no network requests to our servers at all. There is no analytics, no telemetry and no crash reporting.
What we process when you buy Premium or start a trial
- A random device identifier generated on your machine. It is not derived from any hardware or account information and is used to bind your licence to a browser and to enforce the five-device limit.
- Your licence key and its subscription status.
- Your email address, received from our payment provider, used to deliver your licence key, to answer support requests and to let you restore a purchase.
- The extension version and interface language, sent with the request that opens checkout so a fault report can be reproduced against the right build. They are not written to our database.
- Your IP address, used to count requests against the abuse limits that stop licence-key guessing and trial farming. It is held in a short-lived counter and deleted within one hour; it is never linked to your licence or your email address.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and, for the fraud and abuse limits, Art. 6(1)(f) GDPR (legitimate interest in preventing licence abuse).
Payments
Payments are processed by Paddle.com Market Ltd, which is the merchant of record and an independent controller for the payment data you enter. We never see or store your card details. See Paddle's own privacy notice at paddle.com/legal/privacy.
Hosting
Our licence service runs on Cloudflare Workers, with the licence database hosted in the European Union (Western Europe). Cloudflare acts as a processor under a data processing agreement and its standard contractual clauses.
Retention
Subscription records are kept for as long as the licence exists and afterwards for the statutory retention period applicable to commercial records. Device records are deleted when you remove a licence from a browser. Rate-limiting counters are deleted within an hour; webhook records within 90 days.
Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest, by writing to the address above. You also have the right to lodge a complaint with a supervisory authority.
Changes
Material changes are announced on this page before they take effect.