Skip to content

Privacy Policy

Last updated September 2, 2026

This Privacy Policy explains how Moderok (“Moderok”, “we”, “our”) collects, uses, and shares information when you use our analytics platform for browser extensions (the “Service”), available at moderok.dev.

Who this policy applies to

Moderok has two types of users:

  • Developers who sign up for a Moderok account and install our SDK in their browser extensions.
  • End users of browser extensions that have integrated the Moderok SDK.

Different sections below apply to each group. If you are an end user and want to know what a specific extension is collecting, please contact the developer of that extension.

Information we collect from developers

When you create a Moderok account, we collect:

  • Your name, email address, and profile image from the sign-in provider you choose.
  • Information about the extensions (“apps”) you register in Moderok, including app name and Chrome Web Store ID.
  • Billing information, which is processed and stored by our payment processor. We do not store your full payment card details on our servers.
  • Basic session information when you use the dashboard.
  • Usage information about how you interact with our websites and dashboard, collected using cookies and similar technologies (see “Cookies and similar technologies” below).

Information the Moderok SDK collects from end users

When a developer installs the Moderok SDK into their browser extension, the SDK collects extension usage data to help the developer understand how their extension is used. The SDK collects:

  • A randomly generated analytics profile identifier that can be recovered through the browser’s sync storage and that Moderok does not automatically associate with a name or email address.
  • Events that the extension explicitly chooses to track, along with any properties the developer chooses to attach.
  • Lifecycle events such as install, update, and daily ping.
  • Technical context: SDK version, extension ID and version, browser name and version, operating system, locale, and the extension surface that emitted the event (such as the background worker, popup, or options page).
  • Optional: uncaught errors and error metadata (if the developer has enabled error tracking).

The SDK does not automatically add names, email addresses, cookies from other sites, browsing history, or page contents to analytics events. Developers control the custom event properties they send. As with any web request, our infrastructure receives the source IP address; it is used for security and rate limiting and may remain in access logs for up to one month, but it is not added to the analytics event shown in the dashboard.

How we use information

  • To provide, maintain, and improve the Moderok Service.
  • To display analytics to developers in their Moderok dashboard.
  • To process payments and manage subscriptions.
  • To respond to support requests and communicate about the Service.
  • To detect, prevent, and address technical issues, abuse, and security incidents.

How we share information

We do not sell personal information. We share information only with:

  • Our payment processor for billing and subscription management.
  • Your chosen sign-in provider when you authenticate.
  • Our cloud infrastructure provider, which stores data in data centers in the United States.
  • Our website analytics provider for website and product usage analytics, either with your consent or in cookieless mode.
  • Legal authorities when required by law, subpoena, or to protect our rights.

Data retention

  • Event data collected by the SDK is retained for up to 2 years, after which it is automatically deleted.
  • Developer account data is retained for as long as the account is active, and for a reasonable period after deletion for billing and legal compliance.
  • Subscription and billing records are retained for the period required by applicable tax and accounting law.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, email us at admin@moderok.dev. We will respond within a reasonable time and in accordance with applicable law. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

Cookies and similar technologies

We store one strictly necessary cookie, mk_consent, on .moderok.dev for up to 12 months, to remember whether you accepted or declined analytics. We also store one first-party cookie, mk_attrib, on .moderok.dev for up to 30 days; it records the page you first arrived on, the site that referred you, and any utm parameters in the address. It contains no identifier and is used only to understand which pages lead to signups. The Moderok dashboard additionally sets first-party cookies for authentication and session management. With your consent, we use a third-party analytics service to understand how our websites are used; accepting stores that service’s first-party cookie and local storage entries in your browser. Before you make a choice, and if you decline, analytics runs in cookieless mode: it stores nothing in your browser and counts the visit using a rotating, privacy-preserving server-side hash that we do not use to identify you. You can change your choice at any time using “Cookie settings” in the footer. We do not use third-party advertising cookies.

Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Legal bases for processing

Where data protection law requires a legal basis, we rely on: performance of a contract for account, app, and billing data needed to provide the Service; our legitimate interests in keeping the Service secure, rate limited, and working as intended; your consent for optional website analytics; and compliance with legal obligations for tax and accounting records. Where Moderok processes SDK event data on a developer’s behalf, that developer is responsible for the legal basis for their own collection.

International transfers

We host the Service in data centers in the United States, and some of our providers are based there. Where we transfer personal data from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) together with the technical and organizational measures described in this policy.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of the Service after an update constitutes acceptance of the updated policy.

Contact us

If you have questions about this Privacy Policy or our data practices, email us at admin@moderok.dev.