Privacy Policy
Privacy Policy
Effective Date: April 4, 2026 Last Updated: July 14, 2026 Entity: Enid Ltd ("us", "we", or "our") Service: CastReader iOS and Android apps, browser extension, and the CastReader websites at castreader.ai and castreader.com (collectively, the "Service")
This Privacy Policy explains what data CastReader collects, how we use it, and the choices you have. We designed CastReader with privacy in mind — text extraction and OCR happen locally where supported, and we collect only what is necessary to operate and improve the Service.
What changed in the July 2026 update: This policy now covers the iOS and Android apps and describes first-party product analytics, mobile sign-in, and App Store / Google Play subscriptions. Analytics never contains the text, images, file names, titles, URLs, email addresses, or raw errors from content you read.
1. What CastReader Does
CastReader is a browser extension with two main features:
Read Aloud (TTS). When you click the extension icon:
- Text extraction happens locally in your browser — the extension reads the page's DOM to find the article content. No page content is sent to our servers for extraction.
- For Kindle Cloud Reader, the extension uses local OCR (tesseract-wasm running inside your browser) to read rendered page images. OCR processing is entirely local — no images or book content are uploaded for reading.
- For WeRead (微信读书), the extension reads chapter data from the page's existing API responses within your browser. No additional network requests are made to WeRead's servers.
- Text-to-speech conversion: extracted text is sent to our TTS API server (
api.castreader.ai) to generate audio. This is the only step of Read Aloud where page content leaves your browser.
AI Explain (解读). When you click Explain, the relevant page text — and, on pages that cannot be annotated directly (e.g. canvas-rendered books), a screenshot of the visible reading area — is sent to our Explain server (quickread.castreader.ai) where a large language model generates a guided explanation and on-page annotations, and our TTS generates the narration. This happens only when you explicitly click Explain, never in the background.
2. Data We Collect
2.1 Account Data (optional — only if you sign in)
CastReader works without an account. If you choose to sign in, we use Google Sign-In or Sign in with Apple and store:
- Your name, email address, and profile picture as provided by Google
- An account identifier, your subscription status/plan, and which app or extension device IDs you have linked
We do not receive or store your Google or Apple password. We do not access your Google Drive, Gmail, contacts, iCloud content, or other unrelated account data.
2.2 Payments (Pro)
Web payments are processed by Stripe; iOS and Android in-app subscriptions are processed by Apple and Google Play. Your payment credentials go directly to the payment provider — we never see or store your full payment credentials. We receive and store the product, subscription status, and purchase result needed to operate Pro access, provide support, prevent fraud, and understand conversion. Billing records are retained as required for accounting and tax purposes.
2.3 Usage Metering (free-tier quotas)
To operate the free tier fairly, our server keeps per-device daily counters: seconds of audio listened (free listening time) and number of AI Explain runs. These counters are keyed to a random device ID, reset daily, and contain no page or document content.
2.4 Content Sent for Processing
- Read Aloud: extracted text is sent to
api.castreader.aisolely to generate the audio response. It is processed in memory, not used for training or advertising, and not shared with third parties. - AI Explain: the page text (and screenshot, where applicable) is sent to
quickread.castreader.aisolely to generate the explanation. It is not used for training and not retained after processing; transient server logs are deleted within 30 days. - Mobile capture/import: camera and photo OCR runs on the device. Text from the resulting document is sent only when you request Read Aloud or AI Explain. Product analytics does not receive that text or image.
- Share / Send to Phone: if you use these features, the content you choose to share is stored only as long as needed to provide the feature. Live sessions expire automatically; shared pages can be deleted by you.
2.5 Product Usage Analytics
We collect first-party product analytics to understand feature usage, reliability, and free-to-Pro conversion. Each event can contain:
- Device and account identifiers: a randomly generated UUID stored locally in the app or extension, and an account ID if you are signed in. This lets us join sessions across features and, for signed-in users, across devices.
- Event type and controlled properties: app session, content import result, Read Aloud and Explain starts/milestones/results, paywall display, and purchase result; plus platform/app version, coarse content source/format/language, voice ID, speed, count/length buckets, latency, playback duration, completion bucket, and controlled error stage/code.
- Session identifiers: random IDs for the app session and for a content, reading, explanation, or purchase attempt. These are used to reconstruct an aggregate funnel and are not advertising identifiers.
Product analytics does NOT collect: document/page text, OCR text, screenshots or images, file names, titles, URLs, referrers, email addresses, passwords or form data, advertising identifiers, raw errors, or server response bodies. IP addresses are not stored in analytics event properties; they may appear in standard server access logs, which are deleted after 30 days. We do not sell analytics data or use it for cross-company tracking or advertising.
2.6 Extension Settings
Your preferences (voice, speed, language, highlight color) are stored locally using the browser's or operating system's app storage.
2.7 Websites
On castreader.ai and castreader.com we use privacy-focused, cookie-free web analytics (Plausible) for aggregate traffic statistics. Signing in on castreader.com sets the cookies required for your login session.
3. Browser Extension Permissions
| Permission | Purpose |
|---|---|
activeTab | Read the current page's DOM to extract article text when you click the extension |
storage | Store your settings, device ID, and quota/announcement flags locally |
scripting | Inject the highlight overlay and content scripts for special sites (Kindle, WeRead) |
contextMenus | "Read selected text" in the right-click menu |
alarms | Periodic analytics queue flush in the background service worker |
offscreen | Run tesseract-wasm OCR locally for Kindle text extraction |
Host access incl. <all_urls> | Two uses: reading the page you ask CastReader to read (content scripts), and captureVisibleTab screenshots only when you click Explain on pages that cannot be annotated directly. CastReader never reads or captures pages in the background. |
4. Data We Do NOT Collect
- No browsing history: we do not track which pages you visit. The extension only acts on a page when you invoke it.
- No page content storage: text sent for TTS/Explain is processed and discarded, not banked.
- No advertising: no ads, no ad networks, no sale or rental of data to anyone.
- No third-party tracking: no Google Analytics, no Facebook Pixel.
- No payment credentials: card/Alipay details live only at Stripe.
5. Data Storage and Security
- Local data (settings, device ID) lives in
chrome.storage.local, sandboxed from websites. - All transmission is over HTTPS.
- Account and subscription records are stored in our database with access restricted to the operators of the Service.
6. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
CastReader TTS API (api.castreader.ai) | Convert text to speech | Extracted text of the content you play |
CastReader Explain server (quickread.castreader.ai) | Generate AI explanations | Page text (and screenshot where applicable) of the content you Explain |
| Google / Apple sign-in | Optional account login | Name, email, avatar where provided, and account identifier |
| Stripe / Apple / Google Play | Payment processing | Payment details go directly to the provider; we receive product and subscription status |
| Plausible Analytics (websites only) | Cookie-free traffic stats | Anonymous page views, no PII |
7. Children's Privacy
CastReader does not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction). If you believe a child has provided personal information to us, contact us and we will delete it.
8. Your Rights and Choices
- Use without an account: all free features work without signing in.
- Delete your account: contact us at the email below and we will delete your account data and unlink your devices within 30 days (subscription records may be retained where required by law).
- Cancel your subscription: anytime via "Manage subscription & billing" (Stripe billing portal); access continues to the end of the paid period.
- Reset local data: clear the extension's storage or clear/uninstall the mobile app to delete locally stored settings, queue data, and the random device ID.
- Control analytics requests: extension users may block
castreader.ai/api/eventswith a content blocker. Mobile users may contact us to request deletion of analytics associated with their account or device ID. - Uninstall: removing the extension or app deletes its locally stored data; server-side retention and deletion are described below.
If you are in the EEA, UK, or California and have a data request, contact us and we will respond within 30 days.
9. Data Retention
- Analytics events: up to 12 months, then deleted.
- TTS / Explain content: not retained after processing (transient logs ≤ 30 days).
- Daily usage counters: rolling daily rows; superseded days have no content value and are periodically pruned.
- Account data: until you delete your account.
- Subscription/billing records: as required for accounting, tax, and fraud prevention.
- Share pages / live sessions: until deleted by you, or automatically (live sessions expire within 24 hours; shared pages after 90 days of inactivity).
10. International Data Transfers
Our servers are located in the United States, Singapore, and Hong Kong. By using the Service you consent to processing in these locations. Data is protected by the same safeguards regardless of where it is processed.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes are posted on this page with an updated "Last Updated" date; significant changes are also noted in the extension's store changelog.
12. Contact Us
- Email: support@castreader.ai
- Websites: https://castreader.ai · https://castreader.com