Privacy
Everything below can be checked against the product you are using. That is the only kind of privacy policy worth writing.
Version 1.0 · effective 2026-09-12 · what changed
This summary is part of the policy, not a courtesy. It is not a friendly paraphrase kept loosely in step with the real text. If it and the sections below ever disagree, that is a defect in this document — tell us, and the reading that binds us is the one more protective of you.
Grouped by where it comes from. Nothing here is inferred from a third party — we have no data supplier.
Each of these is a use we can point at in the product. There is no fifth purpose held in reserve.
This is the paragraph most people came here to read, so it is the plainest one on the page. A document you import is stored against your account and nobody else’s. It is never pooled with other readers’ content, never shared, never sold, and never used to train any model. Readeroom does not send text you read or import to an outside company for analysis, scoring or training — the systems that process your reading run on our own hardware.
Read-aloud has one reader-controlled exception that needs saying precisely. A local device voice is produced by your browser or operating system on the device. If you choose a device voice marked “needs internet”, your browser or operating system may send the words being spoken to its voice provider under that provider’s privacy terms. Readeroom does not choose that provider, receive that request or receive the resulting audio. You can choose a local voice instead. Readeroom’s persistent audiobooks are made only from rights-cleared shared catalogue books, never from your private imports.
Isolation between accounts is enforced by the database itself, not by the application remembering to filter. Every table holding your data has row-level security forced on, so a query can only ever see rows belonging to the account it is running for. The security page describes the controls, and the gaps.
This is the complete inventory. Essential here means the product cannot do the thing you asked for without it. Everything listed is first-party — set by us, for this site alone. There is no advertising or cross-site tracking cookie in this product at all, so there is none to list.
| Name | Purpose | Type | How long | Party | Essential |
|---|---|---|---|---|---|
better-auth.session_token (your browser will show it prefixed __Secure- over HTTPS) | Signs you in and keeps you signed in. | Cookie — httpOnly, SameSite=Lax, Secure over HTTPS. Not readable by JavaScript. | 24 hours, refreshed while you are actively using the product. | First party | Yes — you cannot be signed in without it. |
readeroom-profile | Remembers which profile you are reading under. | Cookie — signed, httpOnly, SameSite=Lax. Not readable by JavaScript. | 30 days. | First party | Yes — profile selection does not work without it. |
rr-theme | Light or dark, sent with the page request so the first paint already matches your choice instead of flashing the wrong one. | Cookie — readable by JavaScript, SameSite=Lax. | 1 year. | First party | No — a preference. |
rr-theme, rr.scheme | The same appearance choice, kept on the device. rr.scheme is an older name, migrated once and then removed. | Local storage. | Until you clear it. | First party | No — a preference. |
rr-device-voice-v1 | Remembers the device voice you selected for read-aloud on this browser. | Local storage — voice identifier, display name and language only. | Until you choose another voice or clear browser storage. | First party | No — a preference. |
rr.demoToken | A single-use token so that a result from the anonymous speed test can be claimed by your account if you decide to sign up. | Local storage. | Removed as soon as it is claimed. The matching record on our side expires after 48 hours whether or not it is used. | First party | No — the speed test works without it; without it the result cannot be carried into a new account. |
On the checkout page, and only there, we load Stripe’s script so a payment can be taken. It is the only third-party script in the product and it is not loaded anywhere else; what it stores is governed by Stripe’s own privacy policy, not by this page.
So: we use only first-party cookies and local storage required for authentication, security, preferences and functions you asked for. Whether a consent banner is required follows from this inventory and a legal review of the places we operate in — it is not a conclusion we are entitled to reach about ourselves, and you will not find one claimed here either way. Today this table is written and checked by hand against the code; generating it from the code, so it cannot drift, is work we still owe this page.
There is no analytics vendor in this product. When we record how the product is used, the record is first-party: a product_events table in our own PostgreSQL, keyed to a profile identifier.
A profile identifier is not a name, but it is still you. That makes these events pseudonymous personal data, not anonymous data — and an earlier draft of this product’s own documentation called them anonymous, which was wrong. The rules they are held under:
As of this version, nothing in the product writes to that table. The table and its rules exist; the code that would record an event does not. When that changes, this section is where it will be described, and the rules above are the ones it will be built against.
Two service categories Readeroom uses, plus an optional device-voice provider that only your browser or operating system chooses when you select an internet-backed voice.
There is no analytics provider, no advertising network, no data broker, no session recorder and no external model or inference service selected by Readeroom. The optional internet-backed device voice above is controlled by your device. We do not sell personal data, and we do not share it for advertising. If a court or a law requires us to hand something over, we will tell you unless we are forbidden from doing so.
Data-protection requests go to privacy@readeroom.com. We have not appointed a data protection officer and do not claim one.
| Data | How long |
|---|---|
| Account record — email address and your settings | While the account exists. Removed when the account is deleted. |
| Reading measurements — sessions, daily summaries, curriculum and gate state, streaks, mastery records | While the account exists. Never shortened, downgraded or deleted because a payment lapsed — see the measurement history clause in the terms. |
| Highlights, notes and saved vocabulary | Until you delete them, or until the account is deleted. |
| Library items and imported text | Until you delete the item, or the account. Deleting an item removes it from your library immediately and leaves a tombstone — the item’s id and the fact that it was deleted — so the deletion also reaches your other devices. |
| A speed-test result taken without an account | At most 48 hours in a short-lived server cache, and deleted the moment it is claimed by a new account. |
| Usage analytics events | 13 months, then irreversibly aggregated with a minimum cell size of 50 profiles. Anonymous session ids rotate at 24 hours and expire at 90 days. |
| Payment records | Kept as a financial record, append-only, for as long as the law of the operating jurisdiction requires. The laws of New South Wales, Australia, and the courts of New South Wales. Nothing here excludes, restricts or modifies any right you have under the Australian Consumer Law. |
| Backup copies | 30 days. A deletion is immediate in the live system and gone from every backup copy within that window. |
About backups, honestly. When you delete something it is removed from the live system immediately, and the last copy of it disappears when the backup holding it ages out — 30 days at the outside. We will not tell you deletion is instant everywhere, because it is never instant anywhere that keeps backups.
Two things worth saying plainly, because the word “backup” is usually left to do more work than it has earned. The first: these are not separately encrypted. They are held on the same on-premises storage as the live database and inside the same trust boundary, which is not itself encrypted at rest — so encrypting the copy and leaving the original in the clear would be decoration, not protection. That changes the moment a copy leaves this building: any off-site copy will be encrypted before it goes, and until that exists we are not claiming geographic redundancy we do not have. The second: a backup nobody has restored is a hope, not a backup. Ours is restored into an empty database and compared against the original — every table, every column, every access-control rule — and the check is written to fail loudly rather than to reassure.
These work whether or not the law where you live requires them of us. Write to privacy@readeroom.com from the address on the account, and a person answers.
Child profiles are not available yet, so we hold no child profile data today. The database has a place for them, and for a guardian’s recorded consent, but no part of the product creates one — the feature is designed and not built.
Before family profiles are switched on, this page will say exactly what is held for a child profile, who can see it, and what a guardian can and cannot do with it. It will say so first, not afterwards.
This document is versioned. The version and effective date at the top identify it, and they are generated rather than typed, so they cannot say something the release does not.
Superseded versions stay reachable and are linked from the current one — a policy that quietly rewrites itself is not a policy. There is only one version so far, so there is nothing yet to link; this page says that rather than showing you an empty archive.
Privacy and data requests: privacy@readeroom.com. Anything else: help@readeroom.com. Security reports go to security@readeroom.com, and the security page explains what happens next.
The legal entity that operates Readeroom and its registered address: PMOAid Pty Ltd (ACN 654 942 757), trading as Readeroom Level 7, 90 Phillip Street, Parramatta NSW 2150, Australia