MembersDigital Craft Workshop
Lathe for Substack

Privacy policy

Last updated: 23 September 2026 · Operator: Daniel Rusnok, Digital Craft Workshop · Contact: daniel.rusnok@gmail.com

What Lathe does

Lathe is a Chrome extension that adds features to substack.com and medium.com: read/unread markers and flags in Substack Chat, AI summaries of posts, promo Note ideas and Medium crossposts. It runs in your browser with your existing Substack session.

Data Lathe stores

  • Your Digital Craft Workshop account email and an access token for the members hub, to check which plan you have. Stored in the extension’s local storage and on our members hub (members.digitalcraftworkshop.com).
  • Your AI provider API key (Anthropic or OpenAI), if you add one. Stored only in the extension’s local storage on your device. It is never sent to us or to anyone except the provider you chose.
  • Preferences and small caches (settings, read/unread overrides, generated summaries and note ideas for 24 hours). Stored only on your device.
  • Your subscriber list, only if you run a publication and use a gift form: Lathe reads names and emails of your own subscribers from your Substack dashboard to autocomplete the recipient. The list stays in the browser's memory for 15 minutes and never reaches our servers.
  • Chat flags (which color you gave which chat thread). Stored with Chrome sync, so they appear in your other Chrome browsers signed in to the same Google account. They never reach our servers.

Data Lathe sends

  • To Substack (substack.com): requests made with your own logged-in session to read your posts and inbox state, exactly as the Substack website does.
  • To Anthropic or OpenAI, only when you ask for a summary or note ideas: the text of that post, with your own API key. Their privacy policies apply to that request.
  • To our members hub: your access token, to check your plan, and usage events: which Lathe feature you used (for example “summary” or “Medium crosspost”), whether it worked, a short error code and the extension version. Usage events never contain post text, page addresses, what you read or write on Substack, or your API key. Turn them off in the extension settings → Account → Share usage stats. We keep them for 180 days.
  • To Medium (medium.com), only when you start a crosspost: the post you chose is pasted into a new Medium draft in your browser.

What Lathe never does

  • It never reads or stores your Substack or Medium password or cookies.
  • It never posts, publishes, sends messages or subscribes on your behalf. You always click the final button yourself.
  • It does not sell or share data, show ads, or use third-party analytics or tracking.

Your controls

Remove your AI key or disconnect your account in the extension settings at any time. Revoke connected browsers on the members hub. Uninstalling the extension deletes everything it stored locally. To delete your members hub account, email daniel.rusnok@gmail.com.

Chrome Web Store user data policy

Lathe’s use of information received from Google APIs and the Chrome Web Store adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.