← ReadFlow home

Privacy

Owner review draft: Add the operating entity, a monitored privacy contact, and confirmed provider retention details before treating this page as final.

Last updated: September 24, 2026.

ReadFlow turns documents and public web pages into a reading view with optional browser text-to-speech. This page describes the data the current app handles.

Information ReadFlow handles

Listening and error reports

Scanned PDF OCR runs in your browser. ReadFlow downloads OCR worker and language-model files from its configured asset host when OCR is first used. The source PDF image is processed locally by the browser; recognized document text is then saved according to your browser-only or signed-in cloud-sync choice described above.

Bookmarks, sentence highlights, notes, and document tags are stored with the document. Signed-in documents sync these items to your private account. Selecting “Available offline” saves an additional account-scoped document and source-file copy in this browser. Removing the offline copy or deleting the account removes it from this browser. Signing out removes the offline copies for that account from this device.

Speech playback uses the browser's built-in speech engine. ReadFlow does not send document text or audio to a ReadFlow speech service. Speech processing by the browser or operating system follows that provider's own settings and privacy practices.

For reliability, the app can report a fixed error category and timestamp to ReadFlow's Cloudflare endpoint. It does not send the error message, stack trace, page URL, account ID, document title, or document text. Cloudflare processes the network request and may handle technical request data under its own policies. Reports are limited in the browser and at the endpoint.

Service providers

Supabase provides authentication, database, and private file storage. Cloudflare hosts the website and runs its web-link and monitoring endpoints. Google provides sign-in and the user-selected Drive import flow. These providers process data as needed to provide their services and under their own terms and privacy notices.

Security and retention

Account documents and PDF files are stored in a private bucket with account-scoped access policies. ReadFlow uses account-scoped database policies for documents and reading progress. No system can promise perfect security; protect your sign-in account and devices.

You can export account documents and progress from the library. Deleting your account removes its active database rows, private Storage files, and ReadFlow browser copies on the current device. Supabase provider backups may retain copies until their applicable backup retention period ends. The project plan and configured retention window have not yet been confirmed for this draft.

Your choices

You can use ReadFlow without signing in and keep documents only in the browser. Sign in to sync. Use “Export my data” to download an archive. “Delete account” permanently removes the account and its cloud data and clears pending or duplicate copies associated with the account in this browser. Local-only documents that were never added to the account remain in the browser and can be removed individually.

Contact and owner details

Operating entity: [Owner to add]. Privacy contact: [Owner to add a monitored email address]. Support: see the support page.