ReadHalo

PRIVACY POLICY

Privacy, in plain words.

What is processed, why it is needed, and the controls available to you.

Prepared for launch review ·

What this covers.

This draft describes the public website, ReadHalo apps and browser extensions, and the account and cloud-voice services. A webpage you read, your operating system, and Apple or Razorpay’s checkout also have their own privacy practices.

Operator and privacy contact: awaiting owner confirmation. The legal operator, business address and monitored privacy contact must be added here before this policy takes effect. See contact status.

What ReadHalo processes.

Public website visits
The static site has no analytics scripts, advertising pixels, forms or application cookies. Cloudflare delivers the site and may process connection data such as your IP address and request details for delivery and security. The reading preview plays bundled, prerecorded samples and sends no text to a speech service.
Account and sign-in
Email address, account ID, profile name and any profile details supplied by an enabled sign-in provider; session cookies, IP address, browser information, verification records and rate-limit records. These support sign-in, account security and abuse prevention. Google or Apple sign-in appears only when configured. Email verification is delivered through ZeptoMail.
Connected devices and access
Device-session credentials, account connection records, plan, trial expiry, character usage and paid-access dates. These authorize cloud voices and share your allowance across devices. Native credentials are stored in the device Keychain; browser credentials use extension storage.
Text and audio
The reader extracts text from the page for playback. With device voices, ReadHalo does not send that text to its cloud speech service; the device’s speech engine handles it. With cloud voices, text chunks, voice and speed are sent through ReadHalo’s Cloudflare service to DeepInfra to generate audio and word timings. Upcoming chunks may be prepared before you hear them. Do not use cloud voices for content you do not want sent to those services.
Payments
Subscription and transaction identifiers, account-to-purchase links, status, amounts, paid periods and refund or dispute events. Apple and Razorpay handle checkout details under their own policies. ReadHalo does not collect card numbers in its own payment form.
Local preferences and support
Voice, speed, site preferences and downloaded audio are stored locally by the app or extension. If you contact support, the information you choose to send will be used to investigate your request.

Services involved.

The implementation uses Cloudflare for hosting, account storage and request handling; ZeptoMail for sign-in emails; DeepInfra for cloud speech; and Apple and Razorpay for their respective purchases. Optional Google and Apple sign-in also exchanges identity information with the selected provider.

Cloud audio and word timings may be reused for matching speech requests from other authorized users. Cache keys use a hash of the speech inputs; that does not make the audio or spoken content anonymous.

Provider retention, processing locations, international transfer arrangements and contractual safeguards must be confirmed before launch. This draft makes no promise that providers do not retain inputs or use them for model improvement.

Storage and deletion.

Cloud speech responses are configured for a server cache lifetime of up to 24 hours; actual availability can be shorter. The extension’s downloaded-audio cache is configured to expire entries after 30 days and is size-limited. Expired local records are removed during cache access or cleanup, so expiry is not a promise of physical erasure at an exact time. In private browsing, the extension keeps audio in memory instead of its persistent cache. Cloud requests can still use the server cache.

Account deletion removes the stored profile and access record and revokes connected access. It retains an opaque account identifier and security/revocation records to prevent old requests from recreating access. Billing ownership, transaction, entitlement and event records also remain. There is no implemented automatic purge schedule for these retained records.

Account deletion does not remotely erase downloaded audio on every device, remove shared server cache entries immediately, or delete records held independently by payment and infrastructure providers. Use Clear downloaded audio in ReadHalo settings to remove local recordings.

Retention periods for retained account and billing data, verification/rate-limit records, logs, backups and support correspondence are awaiting owner confirmation. No fixed deletion deadline is promised by this draft.

Your choices and requests.

You can use device voices without a ReadHalo account, choose whether to use cloud voices, change extension permissions in your browser, clear downloaded audio, sign out, or delete your account. Signing out of the account website is separate from signing out of a connected app or extension. Sign out on all devices revokes connected device access.

Follow the account deletion instructions. A contact route for access, correction, export, deletion and other privacy requests must be verified before public launch. Applicable rights and the process for exercising them will be finalized for the launch jurisdictions.

Policy status and changes.

This is a review draft, not an effective policy. The operator must confirm the lawful purposes/bases, age eligibility, privacy-request process, disclosures and retention schedule before publishing an effective date. Future material changes should be communicated through the service and reflected on this page.