Privacy Policy
Last updated: August 19, 2026
AllReads lets you save articles and documents to a clean reader and listen to them. This policy covers the AllReads website (allreads.net) and the AllReads browser extension. It is short on purpose.
1. Information we collect
- Your email address and password when you create an account. Passwords are hashed by our auth provider and are never visible to us.
- The content you save — the address, title, and readable text of pages you clip, files you upload, and emails you forward to your AllReads address.
- What you create in the app — highlights, notes, tags, folders, and your reading and listening progress.
- Your own AI provider key, if you choose to add one. It is encrypted at rest and used only to generate the audio you ask for.
- How much you listen, if you use the AllReads voices — a running count of words for the current billing month, so we can apply the fair-use limit. It is a number, not a list of what you listened to.
- Basic technical logs and anonymous, cookie-free page-view counts, so we can keep the service running and see which pages people visit. The demo at allreads.net/text-to-speech is the one place we set a cookie of our own — see section 6.
2. How we use it
To save your articles, show them in the reader, read them aloud when you ask, keep you signed in, apply the listening limit that comes with your plan, take payment if you subscribe, and answer your emails. That is the whole list.
We do not sell your data, share it with advertisers, or use your saved content to train AI models. We do not use it for credit, lending, or anything unrelated to reading and listening.
3. The browser extension
Single purpose. The AllReads extension does one thing: it saves the page you are on to your AllReads library so you can read or listen to it. Everything below exists to serve that.
It only reads a page when you tell it to — by clicking the AllReads icon, using a keyboard shortcut, or the right-click menu. It does not watch your browsing, and it does not collect pages in the background. It reads your AllReads sign-in cookie so saved pages land in your library, and touches cookies for no other site.
Here is every permission it asks for, and why:
- activeTab — to read the title and article text of the tab you are looking at, at the moment you ask us to save or read it.
- scripting — to place the AllReads player and save button into the page, and to pull out the readable text.
- storage — to remember your settings and keep you signed in. This stays on your device.
- contextMenus— to put “Save to AllReads” in your right-click menu.
- Access to websites — you can save from any site, so the extension cannot know in advance which ones you will use. Access is broad; the actual reading only happens on the tab you act on.
Uninstall it any time from your browser’s extensions page and it stops having any access at all.
5. The AllReads voices
If you listen with the voices included in your plan, rather than with your own API key, the text of what you are listening to is sent to a voice server we operate ourselves. No third party sees it. The text is not kept after the audio is made.
The audio is cached.Making speech takes real time on that server, so the audio it produces is stored and reused. Each piece is filed under a fingerprint of the words it reads — not under your name, your account, or the document it came from — which means two people listening to the same paragraph are served the same recording. Cached audio carries nothing that identifies who asked for it, and it is deleted on a schedule.
This applies only to the AllReads voices. Audio made with your own key is never cached or shared, because you paid for it.
6. Trying AllReads without an account
The demo at allreads.net/text-to-speech works without signing in, so it has to recognise a visitor some other way to keep the free reading from being drained by scripts. For that we store, for one day:
- A cookie on your browser, holding a random identifier and nothing else.
- A scrambled version of your IP address. We shorten it first, then put it through a one-way hash, so what is stored cannot be turned back into an address.
- A rough description of your device, taken from the headers your browser already sends with every request. It is deliberately not a fingerprint: we do not probe your device, read your fonts, or draw to a hidden canvas.
Text you paste into the demo is read by the same voice server described above, and its audio may be cached in the same way. Nothing you try in the demo is saved to a library, and closing the tab ends it. All of this expires within a day.
7. Security
Everything travels over HTTPS, and sensitive values like your stored API key are encrypted at rest. No system is perfect, but we treat your library as private.
8. Your data, your call
Delete any saved item from your library whenever you want. Delete your whole account from settings, or email us and we will do it. You can ask for a copy of your data, ask us to correct it, or remove the extension from your browser at any time. We keep your information while your account is active and remove it after deletion, except where the law says we must keep records.
9. Children
AllReads is not for children under 13, and we do not knowingly collect their information.
10. Changes
If this policy changes we will update the date at the top, and tell you directly if the change is a significant one.
11. Contact
Questions, or want your data deleted? Email allreadshq@gmail.com and a human will reply.