Privacy Policy
Privacy Policy — Read For Me: Text to Speech
Last updated: 2026-10-06
Read For Me reads web page paragraphs aloud. This policy explains exactly what data the extension handles, where it goes, and how to remove it.
Summary
- Signed out, nothing leaves your device except the paragraph text you ask to have read, sent directly to the text-to-speech provider *you* configured.
- Signing in is optional. It is only needed for the premium plan, and you can sign in with Google or with an email address and password.
- Reporting a problem is opt-in and manual. Nothing about a page is uploaded unless you open Report an issue, read what it will send, and press Send report.
- We do not use analytics, telemetry, advertising, or tracking of any kind.
- We do not sell your data, and we do not share it except with the providers needed to deliver a feature you explicitly used.
What data is collected
Data that never leaves your device
| Data | Why | Where it is stored |
|---|---|---|
| Your API keys for text-to-speech providers | To call the provider you chose | chrome.storage.local, readable only by the extension's own pages and background worker. Never injected into web pages and never synced. |
| Your preferences (provider, voice, speed, disabled sites, tone and language settings, cloud-sync target) | To remember how you like the extension to behave | chrome.storage.local |
| Generated audio and its transcript | To replay a paragraph instantly and to build ZIP and video exports | The website's own IndexedDB, in that site's origin |
Data sent off your device
| Data | Sent to | Why | When |
|---|---|---|---|
| Paragraph text | The text-to-speech provider you configured (for example OpenAI, Microsoft Azure, ElevenLabs, Google Cloud, or a custom endpoint) | To synthesize the audio you asked for | Only when you press play, or when you start a batch generation |
| Paragraph text | The Read For Me API | To synthesize audio using your premium credits, or to detect the paragraph's tone | Only on the premium plan, and only when the corresponding feature is switched on |
| Email address and, for Google sign-in, your name, profile picture URL and Google account ID | The Read For Me API | To create and identify your account | Only when you sign in |
| A one-way hash of your password, if you choose to set one | The Read For Me API | To verify you at sign-in. Your password itself is never stored or transmitted after the initial request, and it is hashed with a per-password salt (PBKDF2-HMAC-SHA256). | Only when you set or change a password |
| Your email address and a six-digit confirmation or reset code, if you set a password | Resend (our email delivery provider) | To deliver the code that confirms your address or resets your password | Only when you sign up, or ask for a password reset |
| Subscription status and credit balance | The Read For Me API | To know which features you can use and how many credits remain | While signed in |
| Generated audio, its transcript, page title, page URL, site origin, and the paragraph's position in the article | The Read For Me API, or your own Google Drive | To sync your library so it is available on your other devices | Only when you enable cloud sync and press Sync now, or switch on upload-as-you-go |
| An issue report: your description, the page URL, title, origin, language and metadata, the page's visible text and HTML source, its resource list, and up to three audio files found on the page | The Read For Me API | To reproduce and fix the problem you reported. The page snapshot and audio are what make a page-specific bug diagnosable without a follow-up round trip. | Only when you open Report an issue, enter a description, and press Send report. Nothing is collected before that. |
We do not collect your browsing history, we do not read pages you have not asked the extension to act on, and we do not record which pages you visit.
How data is stored
- On your device: settings and API keys in
chrome.storage.local; generated audio in each website's own IndexedDB. Clearing a site's data in Chrome, pressing Clear cache for this site, or uninstalling the extension removes this. - On our servers (premium only): your account record, subscription status, an append-only credit ledger, and — if you enable cloud sync — the audio you uploaded with its transcript and page metadata, held in Cloudflare R2 storage and a Cloudflare D1 database.
- In your Google Drive (premium, optional): if you choose Google Drive as your sync target, audio is written directly from your browser to your own Drive. It does not pass through our servers.
How data is used
Each item is used only for the feature it belongs to:
- Paragraph text — to produce the audio you requested, and (on premium, if you enable it) to choose a speaking tone appropriate to the passage.
- Account details — to sign you in and to attach your plan and credits to the right account. If you set a password, only a salted hash of it is stored, and the password itself is never retained. One-time confirmation and reset codes are stored only as a salted hash and expire after ten minutes.
- Failed-attempt counters — to slow down password guessing against your account, we count failed sign-in, code and code-request attempts per account and per source IP address. These counters are short-lived and hold no other information.
- Credit ledger and usage records — to meter premium usage accurately and to show you your remaining balance.
- Synced audio and transcripts — to restore your library on another device.
- Issue reports — to reproduce and fix the problem you described. A report is kept for as long as it is useful for that, and it is stored as one database row plus the page snapshot and page audio it carried. Reports are accepted without an account (a report is often about the page *or* the sign-in flow misbehaving), and filing them is rate limited per account or per IP address so the storage cannot be used as free file hosting. You can file a report from a page where you have disabled reading, because "the extension does nothing here" is itself a problem worth reporting.
Tone detection stores no text
When tone detection is enabled, the API stores only a SHA-256 hash of the paragraph and the tone it classified, so the same paragraph is never classified twice. The paragraph text itself is not retained for this purpose.
Third-party services
| Service | Purpose | Their policy |
|---|---|---|
| Google Sign-In | Optional account sign-in with Google | https://policies.google.com/privacy |
| Resend | Delivering the confirmation and password-reset codes for email + password sign-in | https://resend.com/legal/privacy-policy |
| Google Drive (only if you choose it as your sync target) | Storing your audio in your own Drive | https://policies.google.com/privacy |
| Cloudflare (Workers, D1, R2) | Hosting the premium API and storing synced audio | https://www.cloudflare.com/privacypolicy/ |
| Stripe | Processing premium subscription payments. We never see or store your card details. | https://stripe.com/privacy |
| Your chosen text-to-speech provider | Converting text into speech | Depends on the provider you configure |
Data sharing
We do not sell your data. We do not share it with advertisers or data brokers. We share data only with the services listed above, and only as needed to deliver the feature you used, plus where we are legally required to do so.
Audio stored in your own Google Drive is governed by your agreement with Google, not by us. We cannot read files in your Drive other than the ones the extension created — the extension requests the narrow drive.file permission, which grants access only to files it creates itself.
Data retention and deletion
- Local data is kept until you clear it. Each site's cache is removed by Clear cache for this site, by clearing that site's data in Chrome, or by uninstalling the extension.
- Server-side data is kept while your account exists. Issue reports are kept for as long as they are useful for fixing the reported problem.
- A report you filed while signed out has no account attached, so the account controls cannot reach it. Ask us to remove it at privacy@readforme-tts.com and include the page URL you reported.
- You are in control. In the extension's settings, Account → Export my data downloads your account details, synced clips, issue reports, credit ledger and usage records as JSON. Account → Delete account and data permanently deletes your synced audio and your issue reports (including their page snapshots and page audio) from storage, and erases your credit ledger, usage records, sessions and subscription association.
- A minimal record (your Google account identifier, or your email address for a password account, plus the fact that the one-time trial was claimed) is retained after deletion so that deleting and re-registering cannot be used to claim the trial repeatedly. Your password hash, pending codes and failed-attempt counters are deleted along with the rest of the account. No audio, transcript, ledger or personal profile data is retained.
- Cancelling a subscription does not delete your account; your plan simply lapses at the end of the paid period.
Children
This extension is not directed at children and we do not knowingly collect data from children.
Changes to this policy
If our data practices change, we will update this policy and revise the date at the top. Material changes will also be noted in the extension's Chrome Web Store listing under version history.
Contact
Questions about this policy, or a request to see or delete your data: privacy@readforme-tts.com. Questions about the extension itself can go to support@readforme-tts.com, or through the form at https://readforme-tts.com/contact.