Privacy Policy: Crunchyroll Companion
Effective date: September 1, 2026
Crunchyroll Companion (“the extension”) is a client-side browser extension that
enhances the Crunchyroll viewing experience. This policy explains what data the
extension handles and where it goes.
Summary: The extension collects no analytics, shows no ads, and has no
tracking. Everything it stores stays on your device unless you opt in to one of
two things: connecting your MyAnimeList account (your data goes directly to
MyAnimeList), or signing in to cloud sync (a copy of your extension data is
stored in a Supabase project run by the developer so it can follow you between
browsers). Both are off until you turn them on.
What the extension stores on your device
All of the following is stored using the browser’s extension storage.
- Settings: your skip toggles, skip method, and playback preferences. These
are saved with
chrome.storage.sync, which means Chrome/Edge syncs them across
browsers where you are signed in to the same browser profile. That sync is
handled by your browser vendor (Google/Microsoft), not by the extension.
- Continue-watching history: a local list of Crunchyroll episodes you have
recently opened (series title, season/episode, thumbnail URL, and timestamps),
used to power the Resume and Continue-watching cards. You can remove
individual entries or clear the whole list at any time from the panel.
- Favorites: the shows you have bookmarked (series title, season, the
show’s page, poster URL, type and episode count, the episode URL you saved
it from, thumbnail URL, and a timestamp). Removed
favorites are kept for up to 30 days as a small “removed” marker so that the
removal can reach your other devices when cloud sync is on.
- Skip statistics: local counters of how much time auto-skip has saved and a
per-day activity count, used for the stats shown on the home dashboard. No
event-level browsing data is recorded.
- Show matches: which MyAnimeList entry each Crunchyroll series was matched
to, so the match does not have to be recomputed every time.
- MyAnimeList authentication tokens: if you connect MyAnimeList, the OAuth
access/refresh tokens are stored locally and used only to talk to MyAnimeList
on your behalf. They are never sent anywhere else and are never included in
cloud sync.
- Cloud sync session: if you sign in to cloud sync, the sign-in session
(access/refresh tokens and the email address of the Google account you used)
is stored locally so the extension can talk to the sync service.
Cloud sync (opt-in)
Cloud sync is off by default. If you choose Sign in with Google in the
panel’s settings, the extension uploads your settings, continue-watching
history, favorites, skip statistics, and show matches to a database hosted on
Supabase that the developer administers, and merges
them with what your other signed-in browsers have uploaded. Nothing else is
uploaded; in particular your MyAnimeList tokens never leave the device.
- Sign-in uses Google OAuth through Supabase Auth. The extension receives your
Google account’s email address and a user id; it does not receive your Google
password or access to anything else in your Google account.
- Data is stored per user and protected by row-level security, so each account
can only read and write its own rows.
- Syncing happens periodically in the background, on startup, shortly after a
local change, and when you press Sync now.
- Sign out in the panel ends syncing and removes the session from the
device. It does not delete the copy already stored on the server; to have
that deleted, contact the developer at the address below.
Network requests the extension makes
- Crunchyroll (
crunchyroll.com, static.crunchyroll.com): reads the
current page’s episode metadata and fetches Crunchyroll’s own public
per-episode skip-timing JSON to know where intros/recaps/credits are.
- MyAnimeList (
myanimelist.net, api.myanimelist.net): public show
details (synopsis, genres, seasons, seasonal rankings, recommendations) are
fetched for the show you are watching using the extension’s own API client
id, with no account involved. Only if you opt in by connecting your
account is it also used to read and update your anime list (episode progress,
status, score) at your request or, with auto-sync enabled, to advance your
progress to the episode you are watching. Progress is only ever moved forward.
- AniList (
graphql.anilist.co): a public, read-only API used to fetch a
show’s characters, staff, and rankings. These requests send only a public
anime identifier. They contain no personal information and no account
data.
- Supabase (the developer’s project on
supabase.co): only if you opt in
to cloud sync, as described above.
What the extension does NOT do
- It does not collect analytics or telemetry.
- It does not contain any tracking, advertising, or fingerprinting code.
- It does not sell or share your data with anyone.
- Outside of opt-in cloud sync, it does not transmit any data to the developer
or to any server the developer controls.
- It does not bypass paywalls, DRM, or advertising. It only automates actions you
can already perform yourself (clicking Skip / Next).
Permissions
- storage: to save your settings, history, favorites, stats, and matches as
described above.
- identity: to perform the MyAnimeList and cloud-sync sign-in flows in a
secure browser window (only used when you connect an account).
- sidePanel: to display the companion UI in the browser side panel.
- alarms: to run the periodic cloud-sync check in the background (it does
nothing while you are signed out).
- Host access to Crunchyroll, MyAnimeList, AniList, and the developer’s
Supabase project: to make the requests described in “Network requests”
above. The extension does not access any other sites.
Data retention and deletion
Data on your device stays there until you delete it: clear items in the panel,
disconnect MyAnimeList (which removes the stored tokens), sign out of cloud
sync (which removes the session), or remove the extension, which deletes all of
its local and browser-synced storage. Cloud-synced data stays on the server
until deleted on request.
Third-party services
Connecting MyAnimeList means your interactions with it are subject to
MyAnimeList’s own privacy policy. Public show details are also retrieved from
AniList; see https://anilist.co/terms. Cloud sync is hosted on Supabase; see
https://supabase.com/privacy. The developer is not affiliated with Crunchyroll,
MyAnimeList, AniList, or Supabase.
Changes
This policy may be updated as the extension evolves; the effective date above
will be revised accordingly.
Questions about this policy, or requests to delete cloud-synced data:
dell@donatoni.dev