Privacy Policy
Last updated 28 July 2026
What we collect, why we collect it, who else sees it, and how to get a copy or have it erased.
Controller
The data controller is [legal entity name], [registered address]. Privacy questions: [privacy@yourdomain].
What we collect
- Account — name, email address, hashed password, sign-up date. Lawful basis: performance of a contract.
- Your content — saved items, reading history, translations and drafts, Ask conversations, OCR uploads. Contract.
- AI usage records — which feature you used, when, which model, and token counts. We do not store the text of your prompts in these records. Lawful basis: legitimate interest in enforcing usage limits and understanding cost.
- Anonymous usage — for signed-out visitors we store a salted hash of your IP address plus a random cookie value, solely to apply the free-tier limit. It is not linked to an identity.
- Billing — handled by Stripe. We store a customer reference and subscription status; we never see your card number. Contract and legal obligation.
- Server logs — IP address, request path, timestamp, retained briefly for security and debugging. Legitimate interest.
What we do not do
We do not sell your data, we do not serve advertising, and we do not use your reading history or conversations to build advertising profiles. We do not train models on your content.
Sub-processors
Providers who process data on our behalf, each under a data-processing agreement:
- Hetzner Online GmbH (Germany) — hosting and database storage
- Stripe — payment processing and subscription billing
- Brevo — transactional email (verification, password reset, billing notices)
- [your model providers, e.g. OpenAI, Anthropic] — process the text you send to Ask, Translate, and OCR
- Dharmamitra — OCR, when you use that provider
Some providers are outside the EEA. Transfers rely on Standard Contractual Clauses or an adequacy decision.
AI features specifically
When you use Ask, Translate, or OCR, the text you submit — along with relevant passages from the corpus — is sent to a model provider to generate a response. Providers may retain it briefly for abuse monitoring under their own terms. Do not paste anything into these features that you would not want processed by a third party.
How long we keep things
Account data and your content: until you delete them or close your account. AI usage records: 24 months. Server logs: 30 days. Billing records: as long as tax law requires, typically 7–10 years.
Your rights
You can access, correct, export, erase, restrict, or object to processing of your data, and lodge a complaint with your supervisory authority.
Two of these are self-service from your account page: Download a copy gives you everything as JSON, and Delete this account erases it. For anything else, write to us and we will respond within 30 days.
Cookies
We use a session cookie to keep you signed in, and — for signed-out visitors only — a random identifier used with your IP address to apply the free usage limit. Both are strictly necessary, so no consent banner is required. We do not use advertising or analytics cookies.
Security
Traffic is encrypted in transit. Passwords are hashed. Database access is restricted to the application. Backups are encrypted and stored separately. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.
Changes
We will post material changes here and, where they affect you meaningfully, notify you by email.