Toread

Privacy policy

Last updated 13 September 2026

Toread saves the pages you choose so you can read them later. This policy covers toread.app, the Toread browser extension (Chrome, Brave, Arc, Dia, Edge and Firefox) and Toread for Raycast. The short version: we only handle what you save and what it takes to run your account. There are no ads, no analytics or tracking scripts, and we never sell or rent your data.

What we collect

  • Your account. Your email address, used to send sign-in codes. Codes are stored encrypted and expire after five minutes. Signing in sets one cookie, your session; it is the only cookie Toread uses.
  • Your library. The links and files you save, the copy of each page Toread fetches from the link, and what is made from it: text, translations, summaries, categories and tags. Also your highlights, notes, folders and settings.
  • Your subscription. If you subscribe to Plus or Pro, payment is handled by Stripe. We keep your plan, its status and billing period, and Stripe’s customer and subscription ids. We never see or store card details.
  • On your device. Conveniences such as reading progress and panel sizes are kept in your browser’s local storage and never sent to us.

The browser extension

The extension only acts when you click its button or press its shortcut.

  • When you open it, it reads the address and title of the tab you are on, using the browser’s activeTab permission, and asks Toread whether that address is already in your library. Nothing is saved.
  • When you press Save, it sends that address and the folder you picked. Toread’s servers then fetch the page.
  • It stores, in the extension’s own local storage, the connection token Toread gives it when you connect and the folder you used last.
  • It never reads the content of the pages you visit, records your browsing history, runs on pages by itself, or talks to any server other than toread.app.

Its permissions are activeTab (the current tab’s address and title, only after you click), storage (the token and last folder), identity (the window where you approve the connection on toread.app) and access to toread.app.

For each connected browser we keep a name such as “Chrome on macOS”, taken from the browser at the moment you connect, when it was connected and last used, and how many saves it made. The token itself is stored only as a one-way hash.

Toread for Raycast

Raycast uses an API key you create in Settings → Extensions and store in Raycast. When you run Save Tab it reads the address and title of your browser’s frontmost tab, and sends the address only when you save. Save Link sends the address you enter. Recent Saves lists your newest saves.

How we use it

Only to provide Toread: saving and processing what you choose, showing you your library, sending sign-in codes, and running your subscription. We do not use your data for advertising, sell it, build profiles from it, use it to determine creditworthiness or for lending, or use it for anything unrelated to Toread.

Who else processes it

  • Cloudflare runs Toread: the servers, the database, file storage, sending sign-in emails, and turning PDFs into text.
  • An AI model provider receives the text of each page you save to translate, summarise and classify it: the provider behind the model your plan or your settings use, which may be Anthropic, OpenAI, Google, DeepSeek, xAI, Mistral, Groq, OpenRouter or Vercel AI Gateway. It receives the page text, not your email address.
  • Stripe handles checkout, payments and invoices if you subscribe.

We share data with no one else, except where the law requires it.

Keeping and deleting your data

We keep your data while your account exists. You can delete any item, delete every item in Settings → Data, disconnect any browser or revoke any key in Settings → Extensions, and delete your account in Settings → Account, which removes your items, highlights, notes, settings and connections and cancels a subscription. Toread stores one copy of a page’s contents for everyone who saved it, so a copy another reader still has saved stays in storage after you delete yours.

Security

Everything travels over HTTPS. Sign-in codes are encrypted, connection tokens and keys are stored only as hashes, and every request for your data is checked against your account.

Children

Toread is not directed at children under 13, and we do not knowingly collect their data.

Changes and contact

If this policy changes, the date at the top changes with it. Questions or requests about your data: privacy@toread.app.