Privacy policy
Effective 21 July 2026. This policy covers the ReadSpeak mobile app, website, and backend service.
Data processed
- The photo, image, PDF, office, presentation, spreadsheet, RTF, or text document you deliberately submit and the text extracted from it.
- A random signed device ID, broad phone model/type, date and time, source file type, target language, credits used and remaining, subscription state, and spending total.
- Store purchase and subscription events supplied by Apple, Google, and RevenueCat.
- Technical security data normally present in server logs, such as IP address and request errors.
Why and where it is processed
Submitted content is used only to provide OCR, translation, and speech. It may be processed by contracted infrastructure and AI/speech providers, currently including Google Gemini (primary document processing), Mistral AI (document-processing fallback), Microsoft Azure/Edge speech services, RevenueCat, Apple, and Google. Connections use HTTPS.
Retention
- OCR, translation, speech, and result caches: normally no more than 15 minutes and always size-limited.
- A multi-page upload is held in an owner-bound, size-limited server-memory session for no more than 30 minutes so you can choose to read later pages. It is not written to the application database.
- Office-format conversion uses a random temporary directory that is deleted immediately after conversion, including when conversion fails.
- Scan-event metadata: 30 days. It does not contain the document image or extracted text.
- User action logs: 90 days.
- Phone model/type: cleared after 90 days without activity.
- Payment and accounting records: up to seven years, or longer only when legally required.
Access and deletion requests
ReadSpeak does not currently create a username/password account. You can still request access to or deletion of operational data associated with the Phone ID shown at the bottom of the app's Settings screen. Email privacy@readspeak.net with that Phone ID. After reasonable verification, operational records are erased. Financial records that must be retained are disconnected from the Phone ID and kept under a new random anonymous reference.
Deleting app data or reinstalling the app may remove the local token, so copy the Phone ID before doing so if you want to make a request.
Security and choices
Device requests use signed tokens. Administrative access requires a long secret, a time-based MFA code, and an expiring session. You may stop processing at any time by not submitting another document and may uninstall the app.
Contact
Privacy: privacy@readspeak.net
Support: support@readspeak.net