Privacy Policy
- Your books stay in your browser on your own device. We never upload book files or covers.
- An account is optional. Only if you sign in do we store your reading records (positions, highlights, notes…) so they can sync between your devices.
- Some features you choose to use — translation, dictionary lookup, text-to-speech, cloud import — send the relevant text or request to that service.
- No ads, no analytics or tracking, and we don't sell or share your data for advertising.
1. Data stored only on your device
Without an account, everything stays in your browser's local storage on this device:
- Book files you add, and covers generated from them
- Reading positions, highlights, notes, bookmarks, notebooks, reviews and tags
- Settings, cached translations and reading statistics
- API keys you enter for translation or text-to-speech services — stored encrypted, and never uploaded to Polypage servers or included in sync
This data is not sent to us. It's removed when you delete it in the app or remove the extension.
2. Account and sync (optional)
If you create an account and sign in, we process:
| Data | Purpose |
|---|---|
| Email address and password (stored as a secure hash by our authentication provider) | Sign-in and account security; the email is also used to send a verification code. |
| Library records: book title, author, format and tags (not the file or cover) | Showing the same library on your other devices. |
| Reading positions, highlights (including the highlighted text), notes, bookmarks, notebooks, reviews and settings | Syncing your reading between devices. |
| Subscription status (once paid plans exist) | Enabling paid features you've purchased. |
Not uploaded: book files, covers, API keys, and translation caches. When you delete an item, a small deletion marker is kept so your other devices remove it too.
3. Services that receive data when you use a feature
These requests are sent directly from your browser to the service you use, only when you use that feature. Each service handles the data under its own privacy policy.
| Feature | What is sent | To whom |
|---|---|---|
| Translation (selection or inline) | The text being translated and the target language | Google Translate (default, no key needed), or Microsoft Translator / DeepL using your own API key |
| Text-to-speech | The text being read | Your browser's speech engine (some browser voices are online voices provided by the browser vendor), or Google Cloud Text-to-Speech / Microsoft Azure Speech using your own API key |
| Dictionary search | The selected word or phrase | The dictionary websites you have enabled (Google Search by default). In card mode the page is loaded in the background, so that site may set its own cookies. |
| Wikipedia lookup | The selected text | Wikipedia |
| Adding a book without a cover or author | The book's title or ISBN | Google Books API, to find a cover and author |
| Cloud import | Sign-in through the provider's own page; read-only access to list and download the files you choose | Google Drive, Dropbox, Microsoft OneDrive, or the WebDAV server you enter |
| Custom font from a URL | A request for that font file | The address you enter |
Sign-in tokens for cloud import are kept only in memory while the extension is open. Saved WebDAV server addresses and user names are stored on your device; passwords are stored encrypted, like API keys.
4. Service providers we use
- Supabase — database and authentication for accounts and sync.
- Resend — sending sign-up verification emails.
- Cloudflare — hosting this website (polypage.app).
- Google Play — payment processing, once paid plans become available through the Android app. We receive only purchase status, not your payment details.
These providers may process data on servers outside your country.
5. How long we keep data
- Synced data is kept while your account exists, until you delete it.
- If you ask us to delete your account, we delete your account and synced data within 30 days, except where the law requires us to keep something longer.
- Data on your device stays until you delete it or remove the extension.
6. Your choices and rights
- Use Polypage without an account — nothing about your reading leaves your device except through the features in section 3.
- Export your annotations at any time (Markdown, plain text or JSON).
- Delete individual books and records in the app; deletions sync to your other devices.
- Request access to, correction of, or deletion of your account data by contacting us (section 9).
7. Browser permissions
- Storage — keeping your books and records on your device.
- Identity — signing in to Google Drive, Dropbox or OneDrive for cloud import.
- Context menus — the Polypage items in the right-click menu.
- Scripting, and optional site access — reading dictionary pages for dictionary cards, and connecting to the WebDAV server or font address you enter. Site access is requested per site, only when you add one.
- Font settings — listing fonts installed on your computer for the font menu.
- Access to specific service addresses — our sync server and the translation, text-to-speech and cloud storage services listed in section 3, so those features can work from inside the extension.
8. Children
Polypage isn't directed at children under 14, and we don't knowingly collect their personal data.
9. Contact and privacy officer
Privacy officer: vill
Email: contact@polypage.app
10. Changes to this policy
We'll update this page when our practices change and revise the effective date above. For significant changes, we'll also let you know in the extension.