Effective: September 28, 2026 · Last updated: September 29, 2026
MobileReady — Privacy Policy
MobileReady has two parts: this website (webmobileready.com, including accounts and billing) and the MobileReady browser extension, which previews websites inside realistic, simulated device frames. They handle data differently, so this policy covers them in two separate sections. What the website collects does not describe what the extension collects, and vice versa.
Website and account data
The website does collect and process some personal data. This section lists what it handles and who processes it.
Accounts and sign-in
When you create an account we store your email address, a securely hashed password (if you use email sign-up), and optionally a display name and avatar URL. You can also sign in with Google; in that case Google shares your email address and basic profile details with us to create or match your account. Password-reset and sign-up confirmation emails are sent to your email address.
Authentication and the account database are provided by Supabase (through Lovable Cloud). Sign-in sessions are stored in your browser's localStorage so you stay logged in.
Subscriptions and billing
Payments are processed by Stripe through Stripe Checkout and the Stripe billing portal. Full payment-card details are entered on Stripe's pages and handled by Stripe; MobileReady never receives or stores your card number, and does not store card brand or last four digits.
When you start checkout we send Stripe your account email and internal user ID. From Stripe we retain:
- your Stripe customer ID and subscription ID,
- plan, price ID, price, currency, billing interval, status, current billing period and cancellation dates,
- invoice records: amount, currency, description, and links to Stripe-hosted invoice/PDF pages.
Stripe notifies us of subscription and invoice changes via verified webhooks.
Devices, pairing and usage counts
If you pair the extension with your account, we store each device's random device ID, device token, a name and coarse browser/OS labels, and when it was last seen. Pairing codes are stored with their expiry time. We keep a daily count of screenshots per account to enforce plan limits (a number only — never the screenshots). You can remove devices from your account page.
For security and abuse prevention, pairing and plan-check requests are logged with the action, result, device ID, pairing code, plan and seat information, and the requesting IP address and browser user-agent. You can view your own entries through your account.
Contact form and newsletter
Contact form: your name, email, optional company and message are emailed to our team inbox and a confirmation is emailed to you. The message is not stored in our database; we keep a delivery log (template name, recipient email, status, time).
Newsletter / notify signup: we store your email, the page it came from, and whether you're subscribed, and send one confirmation email. Emails sent by the website (account, contact, newsletter) are delivered by Lovable's email service, which also maintains an unsubscribe/suppression list.
Website analytics, hosting and logs
The website is hosted on Lovable, which provides built-in website analytics. It records page views and aggregate visit information such as pages visited, referring site, device type (desktop/mobile/tablet), country, and visit duration. We use it to understand traffic in aggregate. We do not add any third-party advertising or tracking scripts to the website.
As with any web service, our hosting and backend providers process technical request data (such as IP address and user-agent) to deliver pages, operate the service and keep it secure.
Cookies and browser storage (website)
- localStorage: your sign-in session.
- sessionStorage: a short-lived flag used to recover from failed page loads.
- We do not set advertising cookies.
Website processors
- Supabase (via Lovable Cloud) — authentication, database and backend functions; receives account, subscription, device and log data described above.
- Stripe — payments and billing; receives your email, user ID and payment details you enter.
- Google — only if you choose Google sign-in; handles your Google authentication.
- Lovable — website hosting, analytics and email delivery; receives request data, analytics events and email recipients/content.
We do not sell personal data.
Browser extension data
This section describes only the extension. The website analytics and account collection above do not apply to the extension itself.
The short version
- A free, unpaired user who never runs the PageSpeed feature and has turned telemetry off transmits no data at all from the extension. Everything happens locally in your browser.
- The extension can send optional, pseudonymous product-usage telemetry (described below) that you can turn off. It does not use third-party analytics, tracking, or error-reporting services.
- The extension does not collect your browsing history, keystrokes, form data, or the content of the pages you view.
- Screenshots and inspected styles are created on your device and are shared only if you choose to save or copy them.
What the extension handles
1. Licensing / subscription (only if you connect a paid plan). Pairing is optional. When you redeem a 6-digit pairing code, the extension sends to our licensing provider (Supabase):
- a random
device_idthe extension generates (not derived from your hardware or any personal identifier), - the pairing code you entered,
- a durable
device_tokenreturned by the server on subsequent checks, - coarse technical labels to name the device on your account (e.g. "Chrome 126", "macOS").
It then checks your plan periodically (about weekly) by sending only the device_id + device_token. The server returns your plan and your account email; the email is stored locally to display in the account panel and is never transmitted anywhere by the extension. If you never pair, none of this occurs. (Server-side logging of these requests is described in the website section above.)
2. Performance measurement (opt-in). When you click Measure performance in Webpage Specs, the extension sends the URL of the page you are testing (not its contents) to the Google PageSpeed Insights API to retrieve a performance score. This happens only on that click.
3. Local settings. Your preferences, the pairing token, the cached plan, and a daily screenshot counter are stored in your browser's local extension storage. They are not synced to any account and never leave your device.
Product-usage telemetry
To understand which features help people and to improve the product, the extension can send a small set of pseudonymous usage events to MobileReady. You can turn this off at any time in the extension's settings; when it is off, no telemetry events are sent.
- Events: extension activated, first simulation, device switched, screenshot captured, upgrade prompt viewed, checkout started, D1 and D7 return visits.
- Details sent with events: browser type, extension version, plan tier, device category (for example phone or tablet), capture mode and whether it was HD, and the name of the feature behind an upgrade prompt.
- Identifier: a random installation ID generated by MobileReady. If you are signed in, events may be linked to your account so we can understand plan usage; your identity is never placed inside the event details.
- Purchases: completed checkouts are recorded from Stripe's verified notification (plan, amount, currency and Stripe transaction ID).
- Never collected: page URLs, page titles, website content, screenshots, CSS values, email addresses, pairing codes, device tokens, passwords, browsing history, keystrokes, form input, or raw error text.
- Processor: Supabase stores these events. Retention: events are deleted after 6 months.
What the extension never does
- No advertising trackers, tracking pixels, fingerprinting, or error reporting; the only usage data is the optional telemetry described above.
- No collection of browsing history, page content, keystrokes, or form input.
- The only third parties that ever receive data from the extension are Supabase (licensing if you pair, and optional telemetry) and Google PageSpeed Insights (a URL, if you click Measure performance).
- No remote code: all extension code is bundled at build time.
Retention, rights and other terms
These apply to both the website and the extension.
Retention
- Account, subscription, invoice, device and usage records are kept while your account exists.
- Security/pairing logs, email delivery logs and newsletter records are kept until removed.
- Extension data lives in your browser until you disconnect your plan, clear the extension's storage, or uninstall. Removing a device on the website invalidates it server-side.
- Stripe retains payment records under its own policies and legal obligations.
Your choices and rights
You can update your profile and remove devices from your account page, and manage or cancel your subscription through the Stripe billing portal. There is currently no self-service account deletion; to request access, correction, export or deletion of your data, or to unsubscribe, contact us below and we will respond as required by applicable law. Newsletter and notification emails include an unsubscribe link.
International processing
Our providers may process data in countries other than your own, including the United States. By using the website you understand that your data may be transferred to and processed in those locations.
Security
Account data is protected with access controls so users can read only their own records; payment webhooks are signature-verified; and card data is handled only by Stripe. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children
MobileReady is a professional tool and is not directed to children. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the product changes. We will revise the "Last updated" date above when we do.
Contact
Questions or data requests: email info@kentonwd.com or use the contact page.