mutualfit — Extension Watch
Privacy Policy
Last updated 16 September 2026.
This policy describes what mutualfit.ai collects, who else processes it, where that processing happens, and what you can ask to have done with it. It describes the site as it works today, not as it is planned to work.
What the paid product does, so the rest of this page makes sense
Extension Watch is a subscription at USD $29 per month. It records one snapshot per day of a subscriber’s Chrome extension — install count, star rating, review count, version, and a hash of the requested permissions — and the same daily snapshot for up to 5 competitor extensions the subscriber names. It displays the accumulated days as a chart.
Daily recording began on 16 September 2026. A chart is only as long as the time since that date, and past values cannot be backfilled, because the Chrome Web Store publishes only current values. An early subscriber is buying the start of a record, not a record they can read immediately.
Alerts when a tracked number moves — a rating drop, an install drop, a permission change — are not built. The snapshots those alerts would read from are being recorded now; the alerting itself is unfinished.
Who operates this site
Extension Watch is operated by an individual sole proprietor based in mainland China. Contact is by email at [email protected]. Creem acts as Merchant of Record and is the seller of record for every purchase.
That email address is the only contact channel, and it is the address to use for privacy requests, support, refunds and cancellation.
There is no analytics and no tracking of any kind
This is stated first because it removes most of what a privacy policy usually has to explain. On any page of mutualfit.ai there is:
- no analytics script
- no tracking pixel
- no advertising cookie
- no third-party tracker of any kind
Nothing is stored in your browser except what keeps you signed in after you sign in. Email is transactional only — no marketing email is sent. Card details are never seen or stored by mutualfit.
What is collected
Using the free tools
The Chrome extension permission lookup, the WordPress plugin maintenance status pages and the aggregate research reports need no account. Using them collects nothing about you beyond the standard web server logs described below, which Cloudflare records as part of serving the site.
Creating an account
Authentication runs on Supabase. It stores your email address and an auth session. If you set a password, it is hashed by Supabase. Magic-link sign-in stores no password at all.
Subscribing and using Extension Watch
The application database, Supabase Postgres, stores your user id, your email address, your subscription status, the list of extensions you have chosen to track, and alert records — the table the unfinished alerting feature would write to.
Payment is taken by Creem. Card details are never seen or stored by mutualfit. From Creem, the operator receives only your customer email, your subscription status, and Creem customer and subscription identifiers.
Emailing support
Mail sent to [email protected] is forwarded by Cloudflare Email Routing to the operator. Your email address and whatever you write in the message are part of that mail.
Server logs
The site is hosted on Cloudflare Pages. Cloudflare processes standard web server logs, including IP address and user agent, as part of serving the site. These logs are produced by the hosting layer, not by any script on the page.
Sub-processors
These four companies process data on the operator’s behalf. There are no others.
| Sub-processor | Role | What it handles | Where |
|---|---|---|---|
| Supabase | Authentication and application database | Email address, auth session, hashed password when one is set; user id, subscription status, tracked extension list, alert records | United States (US East) |
| Creem | Payments, acting as Merchant of Record and seller of record for every purchase | Takes the payment, handles VAT and invoicing. Holds the card details; mutualfit never sees or stores them. Returns only customer email, subscription status, and Creem customer and subscription identifiers | Not stated here |
| Resend | Outbound transactional email, sending from [email protected] | The recipient address and the contents of the message it is asked to send. Transactional only; no marketing email is sent | Processing region not established, so none is stated |
| Cloudflare | Hosting (Cloudflare Pages) and inbound mail forwarding (Email Routing) | Standard web server logs, including IP address and user agent. Forwards mail sent to [email protected] | Not stated here |
Where your data is processed
The operator is an individual in mainland China. The processors listed above are in the United States. Your account data therefore sits on United States infrastructure and is accessed from mainland China. That is stated here as a plain fact you should know before you create an account.
No formal transfer mechanism has been executed for this. There are no Standard Contractual Clauses in place, no adequacy decision is being relied on, and there is no Data Privacy Framework certification. If that arrangement is not acceptable to you, the honest advice is not to create an account.
Data about software, not about visitors
The extension and plugin listings shown on this site are collected from public Chrome Web Store pages and the official WordPress.org API. That is data about published software — install counts, ratings, versions, requested permissions, maintenance status — and it is not data about the people who visit this site. It is not joined to any visitor or account.
How long data is kept
Account data is kept while the account exists, and is deleted on request. No fixed retention period has been set. Rather than invent a number, this policy says what is true: there is no schedule, and deletion happens when you ask for it or when the account is closed.
What deletion does not reach
Deleting your account removes what the operator controls: your record in Supabase auth and in the Postgres database, including your email address, subscription status, tracked extension list and alert records. Two things sit outside that and cannot be deleted on request:
- Cloudflare’s web server logs, which are produced and held by Cloudflare as part of serving the site.
- Creem’s transaction and tax records. Creem is the seller of record and keeps the records it needs for invoicing and VAT. The operator cannot remove them.
Any claim that deletion removes every trace of you would be false, so it is not made here.
Your rights
You can ask for any of the following:
- Access — a copy of the data held about you.
- Rectification — correction of data that is wrong.
- Erasure — deletion of your data, subject to the limits in the section above.
- Portability — your data in a form you can take elsewhere.
- Objection — objection to processing.
- Complaint — the right to complain to a data protection authority.
Requests go to [email protected]. They are answered as quickly as the operator can, with a target of 30 days. That is a target, set against the fact that this is one person, and no shorter window is promised.
Cancelling and closing your account
There is no self-serve cancellation link yet. Cancellation is by emailing [email protected], and it is honoured immediately on receipt, stopping the next charge. Ask in the same email if you also want your account data deleted, and it will be deleted, within the limits described above.
Changes to this policy
If what the site does changes, this page is updated and the date at the top of it changes with it. The date at the top is the date of the current version.
Contact
Privacy questions, rights requests, support and cancellation all go to the same address: [email protected].