This policy explains how Abhay Srivatsa, the individual operator of Readspace, handles information across Readspace’s hosted services, applications, and browser extensions, and how those practices differ when you use a self-hosted instance.
1. Scope
This Privacy Policy describes how Abhay Srivatsa, the individual operator of Readspace (“Readspace,” “we,” “us,” or “our”), handles personal information when you use the Readspace website, hosted web application, mobile applications, browser extensions, support channels, and related cloud services (collectively, the “Services”).
For a self-hosted Readspace instance, the person or organization operating that instance controls the information processed by it. Section 8 explains this distinction. This policy does not govern third-party websites, publishers, feeds, or services that Readspace links to.
2. Information we collect
Information you provide
- Account information: your email address, account identifier, authentication information, plan, and account settings.
- Library and reading data: feeds and newsletters you follow; saved articles; folders; tags; notes; highlights; reading status and history; priorities; preferences; and related content metadata.
- Newsletter data: when you send a newsletter to your personal Readspace address, we process the recipient token, sender email and display name, subject, email body, and relevant list-unsubscribe or archive URL. We store the subject as the article title, a sanitized HTML body, a short excerpt, sender information, and the relevant list URL when available. The raw email is parsed in transit and is not intentionally retained by Readspace after processing.
- Communications: your name, email address, message, and referral source if you contact us through our website, plus information you send in support requests.
Information collected when you use the Services
- Device and log information: IP address, browser or app type, device model, operating system, timestamps, request and error logs, crash details, performance data, and identifiers associated with an account, session, or installation.
- Usage information: pages or features used and interactions with the hosted web application. We use anonymous product analytics to capture page views, URLs, and product interactions; we do not identify users to our analytics provider. Self-hosted builds do not enable our hosted analytics configuration.
- Local data: cookies, browser storage, extension storage, and on-device caches used for authentication, settings, offline reading, and synchronization.
Browser extension data
When you ask the extension to save a page or follow a feed, it may access and send the active page’s URL, title, metadata, feed details, and relevant page content to the Readspace instance you selected. It also stores settings and authentication state locally. Readspace does not use the extension to record your general browsing history or monitor unrelated tabs in the background.
Payments
If you buy a subscription, we and our commerce providers receive transaction identifiers, product or plan information, entitlement status, renewal and cancellation events, and limited billing details. Payment credentials are collected by the payment or app-store provider; Readspace does not store complete payment-card numbers.
Content fetched from third parties
To retrieve feeds, newsletters, articles, images, or page metadata, Readspace may request content from a URL you provide or a source you follow. The source may receive ordinary request information, such as our server’s IP address and request headers. Content made available through Readspace remains subject to the source’s own terms and privacy practices.
3. How we use information
We use information to:
- create and secure accounts, authenticate sessions, and prevent fraud or abuse;
- fetch, organize, display, search, synchronize, and preserve your reading library across devices;
- provide features you request or automations you choose to enable, including content extraction, summaries, translation, highlights, digests, recommendations, and other AI-assisted tools;
- process subscriptions and maintain plan entitlements;
- send service, security, support, and transactional messages;
- diagnose crashes, improve reliability, understand feature use, and develop the Services; and
- comply with law, enforce our Terms, and protect Readspace, our users, and others.
When you request an AI feature—or enable an automated AI feature in the future—relevant article text, metadata, preferences, and instructions may be sent to Google’s paid Gemini API to generate the result. Readspace does not use your private library content to train general-purpose AI models. Under Google’s terms for paid Gemini services, Google does not use submitted prompts or responses to improve its products, although it may retain them for a limited period for abuse monitoring and legally required disclosures.
4. Legal bases for processing
Where data-protection law requires a legal basis, we rely on: performance of our contract with you to provide requested Services; our legitimate interests in operating, securing, and improving Readspace; your consent where requested, such as for optional device permissions; and compliance with legal obligations. You may withdraw consent at any time, without affecting earlier processing.
6. Data retention
We keep personal information for as long as reasonably necessary to provide the Services, fulfill the purposes described here, comply with legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and plan. For example, product data generally remains while your account is active; logs, analytics, caches, and older article content may be deleted or de-identified on shorter schedules; and transaction records may be retained for tax, accounting, and fraud-prevention requirements.
When you delete your cloud account through Settings → Delete my account in the mobile app, Readspace immediately deletes your authentication account and associated data from its production database. Deleted information may remain in restricted backups until those backups are overwritten under routine retention schedules. Diagnostic records already sent to Sentry may remain until their routine expiration, and transaction or entitlement records held by Polar, RevenueCat, Apple, or Google may remain under their legal and operational retention requirements. Anonymous PostHog events cannot reliably be connected to an account for account-specific deletion.
7. Your choices and rights
You can update many settings in Readspace and delete your account through Settings → Delete my account in the mobile app. You can currently export your feed subscriptions—including feed URLs and titles—as an OPML file. Readspace does not currently provide a full export of reading history, saved content, notes, or other account data. You may contact us to request access to, correction of, or deletion of your personal information.
Depending on where you live, you may have rights to object to or restrict processing, withdraw consent, receive portable data, appeal a denied request, or complain to a data-protection authority. We may need to verify your identity before completing a request. Authorized agents may submit requests where local law permits. We will not discriminate against you for exercising applicable privacy rights.
Readspace does not currently sell or share personal information for targeted advertising. If that changes, we will update this policy and provide any controls required by law.
8. Self-hosted instances
If you self-host Readspace, your instance’s operator—not Readspace’s hosted-service operator—determines how that instance collects, stores, secures, retains, and shares data. Readspace’s Supabase stack, database, storage, search, and caching services run on the infrastructure selected by the instance operator rather than through Supabase’s hosted cloud service. The open-source deployment does not enable Readspace’s hosted PostHog analytics or cloud-mobile Sentry configuration by default. However, an administrator may configure integrations, telemetry, logs, AI providers, email delivery, backups, or other services independently.
If you use a Readspace app or extension with a self-hosted server, content and credentials are sent to the server address you configure. Direct privacy questions about that instance to its administrator.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport where supported, access controls, and service monitoring. No storage or transmission system is completely secure, so we cannot guarantee absolute security. You are responsible for protecting your credentials and for securing any instance you operate.
10. International transfers
Readspace and its providers may process information in countries other than the one where you live. Where required, we use recognized safeguards for international transfers. Privacy protections and government-access rules may differ between countries.
11. Children’s privacy
The Services are intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a person under 18 has provided personal information to Readspace, and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this policy as the Services or law changes. We will post the revised policy and update the date above. If a change materially affects your rights, we will provide additional notice when required.
13. Contact us
Readspace is operated by Abhay Srivatsa in Texas, United States. For privacy questions or requests, email support@readspace.ai. You can also use our contact page.