Privacy Policy

Effective date: October 5, 2026 · Applies to the Polypage browser extension and polypage.app

In short

1. Data stored only on your device

Without an account, everything stays in your browser's local storage on this device:

This data is not sent to us. It's removed when you delete it in the app or remove the extension.

2. Account and sync (optional)

If you create an account and sign in, we process:

DataPurpose
Email address and password (stored as a secure hash by our authentication provider)Sign-in and account security; the email is also used to send a verification code.
Library records: book title, author, format and tags (not the file or cover)Showing the same library on your other devices.
Reading positions, highlights (including the highlighted text), notes, bookmarks, notebooks, reviews and settingsSyncing your reading between devices.
Subscription status (once paid plans exist)Enabling paid features you've purchased.

Not uploaded: book files, covers, API keys, and translation caches. When you delete an item, a small deletion marker is kept so your other devices remove it too.

3. Services that receive data when you use a feature

These requests are sent directly from your browser to the service you use, only when you use that feature. Each service handles the data under its own privacy policy.

FeatureWhat is sentTo whom
Translation (selection or inline)The text being translated and the target languageGoogle Translate (default, no key needed), or Microsoft Translator / DeepL using your own API key
Text-to-speechThe text being readYour browser's speech engine (some browser voices are online voices provided by the browser vendor), or Google Cloud Text-to-Speech / Microsoft Azure Speech using your own API key
Dictionary searchThe selected word or phraseThe dictionary websites you have enabled (Google Search by default). In card mode the page is loaded in the background, so that site may set its own cookies.
Wikipedia lookupThe selected textWikipedia
Adding a book without a cover or authorThe book's title or ISBNGoogle Books API, to find a cover and author
Cloud importSign-in through the provider's own page; read-only access to list and download the files you chooseGoogle Drive, Dropbox, Microsoft OneDrive, or the WebDAV server you enter
Custom font from a URLA request for that font fileThe address you enter

Sign-in tokens for cloud import are kept only in memory while the extension is open. Saved WebDAV server addresses and user names are stored on your device; passwords are stored encrypted, like API keys.

4. Service providers we use

These providers may process data on servers outside your country.

5. How long we keep data

6. Your choices and rights

7. Browser permissions

8. Children

Polypage isn't directed at children under 14, and we don't knowingly collect their personal data.

9. Contact and privacy officer

Privacy officer: vill
Email: contact@polypage.app

10. Changes to this policy

We'll update this page when our practices change and revise the effective date above. For significant changes, we'll also let you know in the extension.