Privacy Policy

Last updated: September 5, 2026.

Back to home

Who controls your data

mread-it is a read-it-later and feed reader application. mread-it is the data controller for account data and saved reading data. For privacy requests, contact privacy@mread-it.app.

Data we process

We process the data needed to run the service:

  • Account data, including email, optional name, password hash, account dates and API token status.
  • Saved reading data, including URLs, titles, excerpts, authors, images and reading state.
  • Feed data, including feed URLs, titles, fetch metadata and refresh errors.
  • Article cache data, including extracted HTML or Markdown when the reader fetches article content.
  • Browser extension clips, including the page URL, title, canonical URL, selected text and visible page HTML that you explicitly choose to save.
  • Optional Kindle imports, including book identifiers, titles, authors, highlight text, notes, locations and colors read from Kindle Notebook after you enable synchronization.
  • Article extraction reports you submit, including your optional comment, account identity, article details, submission time, user agent, browser, operating system, device category, app display mode, viewport dimensions, language and time zone. Administrators use these reports to investigate and fix reading problems. Reports are included in your account export and deleted when the associated item or your account is deleted.
  • Minimal reader activity, including action type, timestamp, origin, disposition and a technical item reference. It excludes content, titles, URLs, email addresses and tag labels.
  • Local browser preferences, such as theme and reader display settings.
  • Anonymous essential browser telemetry, limited to sanitized error types and stacks, route templates, device class and aggregate performance measurements. It excludes account identity, concrete URLs, query strings, referrers, request headers, saved content, DOM recording, behavioral autocapture and session replay.
  • Security and operational logs, such as user id, item id, feed id, URLs, request errors and technical events.
  • Short-lived security data for authentication abuse prevention, including hashed network identifiers and hashed password-reset tokens. Raw IP addresses and reset tokens are not stored in these security tables.

Why we process data

  • To create and authenticate your account.
  • To save, display, search, export and delete your articles and feeds.
  • To refresh RSS/Atom feeds and fetch article content you request.
  • To receive pages and URLs that you explicitly save with the browser extension.
  • To import Kindle highlights and notes when you enable automatic synchronization.
  • To secure the service, prevent abuse and diagnose failures.
  • To measure aggregate reader activation, retention and feature adoption without user profiles or leaderboards.

Legal bases

Where GDPR applies, we rely on contract necessity to provide the service, legitimate interests for security and reliability, legal obligation where applicable, and consent only for optional features that require it. Where LGPD applies, we rely on equivalent legal bases including contract execution, legitimate interest, legal obligation and consent where needed.

Cookies and local storage

The app uses essential authentication cookies to keep you signed in. It also stores reader preferences in your browser local storage. These are used for service functionality, not advertising. If analytics, marketing or other non-essential trackers are added, they must be disabled until you consent.

The browser extension stores its configured mread-it origin, extension API token, synchronization setting, progress checkpoints and recent status messages in the browser's extension-local storage. The token is sent only to the configured mread-it origin as an authorization credential. It is never sent to Amazon.

Browser extension controls

Saving a URL sends its address and title to the configured mread-it app. Clipping a full page additionally sends the visible page HTML, selected text and canonical URL. These actions happen only when you use the extension button, context menu or keyboard shortcut.

Kindle synchronization is off by default. Enabling it asks the browser for access to Kindle Notebook and the configured mread-it origin. While enabled, the extension opens a temporary inactive Notebook tab on browser startup and approximately every six hours, reads the available books and annotations, and uploads them to mread-it. You can disable synchronization at any time. Disabling it stops future imports but does not delete content already imported; you can delete that content or your account in mread-it.

Amazon passwords and cookies remain in the browser and are not uploaded to mread-it. The extension does not sell data, use it for advertising, or collect unrelated browsing activity.

Third parties

The service may use infrastructure providers for hosting, Postgres database storage and optional Cloudflare R2 image caching. It also contacts external websites when you add feeds, save pages, refresh feeds or proxy reader images. Data may be processed in the region configured by the deployment operator. Those external websites may receive network request data such as IP address and user agent.

Cloudflare Email Service delivers transactional account-recovery messages. Passwords selected during sign-up or recovery are screened against Have I Been Pwned using a partial hash-prefix query; the password itself and its complete hash are not sent to that service.

The optional Kindle integration contacts Amazon's Kindle Notebook at read.amazon.com using your existing browser session. Amazon receives the ordinary network information associated with those requests. The extension sends the resulting book and annotation data only to your configured mread-it app.

When DZone blocks direct server-side article extraction, the app sends the public article URL to Jina AI Reader to retrieve readable article content. Jina AI receives the article URL and ordinary network request data; it does not receive your mread-it account identity or credentials.

Retention

Account, feed and saved item data is kept while your account exists. Identifiable reader activity is kept for up to 13 months and is deleted when your account is deleted. Anonymous daily product aggregates may be kept for up to 25 months. Deleted items are removed from the application database. Cached media may remain in infrastructure caches until cache expiry or deletion jobs remove it. Expired password-reset records and authentication rate-limit identifiers are removed after no more than 24 hours. Anonymous essential browser telemetry and operational logs are retained as long as needed for security and reliability.

Your rights

Depending on your jurisdiction, you may request access, correction, portability, deletion, restriction, objection, information about data sharing and withdrawal of consent. The settings page provides data export and account deletion controls. For requests that are not covered by those controls, contact privacy@mread-it.app.

Security

Passwords are stored using versioned, salted Argon2id hashes, and extension API tokens are stored as hashes. A password reset signs out all devices and revokes the extension API token. API tokens are shown only when rotated and should be kept secret. Rotate your token from Settings if it may have been exposed.

Browser extension limited use

Information received through browser extension permissions is used only to provide or improve the user-facing clipping and Kindle import features. It is not transferred for advertising, credit assessment or data brokerage. Human access is limited to explicit support consent, security investigation, legal obligations, or aggregated and anonymized internal operations. This use complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.