CurbTube privacy policy

Last updated 2026-08-25

CurbTube upgrades supported media sites with sponsor skips, dislike counts, watchlists, tags, and private shared-stream rooms. It runs in your browser.

CurbSoftware is the controller for this product and the CurbApps account. Questions: curbapps.com/contact.

Local-first by default

Your data lives in a local database inside the extension. Sensitive fields are encrypted with a device or account key, and connected sync encrypts product data before upload. Using CurbTube without a CurbApps account sends no product data anywhere.

What CurbTube does

  • Access to youtube.com: applies the sponsor skips and row fixes you enabled on the page you are watching.
  • Access to HTTP and HTTPS sites: lets a shared room open and reattach YouTube, Vimeo, Twitch, direct video, and HLS sources across different hosts. The media bridge stays dormant until you explicitly choose Attach tab or Open source. Tabs you did not select do not run playback observers or heartbeats.
  • Access to sponsor.ajay.app: fetches public crowd-sourced skip segments for the current video. Only the video ID is sent.
  • Access to returnyoutubedislike.com: fetches the public dislike estimate for the current video. Only the video ID is sent.
  • Declarative net request (Chrome): blocks ad requests locally with a rule list. No request data leaves your browser.
  • Watchlists and tags stay in the local database. Connected sync (premium) uploads them as encrypted envelopes our servers cannot read.
  • Shared rooms send timing, participant roles, and encrypted source or queue envelopes through a Cloudflare Durable Object. Room source details and queue content are not readable by the server.
  • Free rooms are ephemeral and disappear when the room expires. Premium rooms can persist encrypted state for reconnect and device handoff.

If you use a CurbApps account

An account is optional. Creating one at curbapps.com collects your email and authentication data (processed by Supabase) and, if you pay, billing data (processed by Stripe). CurbSoftware never receives your card details.

Connected sync is zero knowledge. Before anything leaves the device it is encrypted with an account encryption key wrapped by a key derived from your master password. Our servers store ciphertext envelopes they cannot read. There is no password reset: if you forget a master password set on a vault, the data cannot be recovered.

Third-party requests

Any outbound requests this product makes are listed in the "What CurbTube does" section above. We do not embed analytics, ad trackers, or fingerprinting scripts.

Changes

If this policy changes, the date above changes with it. Material changes are announced in the product before they take effect.

Other CurbApps

Privacy