Loading...

Fingerprint data flow

Three workflows, three different data boundaries.

Listening for your position, volunteering public coverage, and asking SINK to process a private screening asset are not the same operation. This page keeps those boundaries explicit.

Viewer phone sync

Input
A short microphone window after the viewer starts sync
Sent to SINK
The selected title/variant request and ordinary request metadata. The derived reference catalog is downloaded to the phone.
Not uploaded
Raw microphone audio and the phone's query fingerprint in ordinary production use
Retention
Audio and the query are transient on-device. Downloaded references use a bounded local cache.

Opt-in extension contribution

Input
Decoded audio from the active playback tab, after current consent
Sent to SINK
Derived landmark pairs, playback position, title, service/language variant, format version, and temporary account attribution for integrity controls
Not uploaded
Raw tab audio
Retention
Accepted measurements remain in the shared catalog. Withdrawal permanently removes account attribution and rotates to a different random key per title/variant.

Authorized hosted screening

Input
Organizer-authorized source audio or video for an exact version
Sent to SINK
The source file, project/version metadata, processing status, integrity information, and derived private artifacts
Not uploaded
Nothing: this is explicitly an upload workflow and requires rights authorization.
Retention
Source media is deleted after successful processing; failed work may retain it for retry for up to 24 hours. Private derivatives remain while authorized.

Derived does not mean anonymous

Fingerprints are compact features used for alignment rather than playable audio files, but they can still be sensitive. Public contributions are initially associated with an account for integrity controls. On withdrawal, SINK removes that association and assigns a different random identity per title/variant so consensus survives without creating a cross-title history. Private exact-cut fingerprints remain contract-scoped and revocable.

Controls and deletion

Future extension contributions can be disabled, and the account link on accepted public measurements can be permanently removed from extension settings. Accepted de-identified catalog measurements remain; debug captures and rejected or failed staging data are deleted. Account holders can start account deletion in app or on the web. Screening organizers can withdraw authorization and request private-version teardown under the hosted-screening workflow.

Start or request account deletion

Separate extension disclosure

Helping identify an unfamiliar playback page

Fingerprint contribution is not the extension's only page-processing feature. On unidentified or broadly supported playback pages, SINK may transmit page URL and player/title metadata to resolve what is playing. When structured signals are insufficient, the extension can also send a bounded, whitespace-collapsed excerpt of visible page text plus privacy-redacted URL and embed hints to SINK's content-identification endpoint. It does not send raw page HTML for this step.

Extension error reports may include the current page URL, extension version, browser user agent, error message, stack, and related diagnostic fields. A page URL can contain browsing or account-related information, so this diagnostic flow is disclosed separately from the local-audio claim.

Related policies

Data-flow summary reviewed August 11, 2026. The Privacy Policy controls if this summary and the policy differ.