Privacy Policy

GetReadVault Privacy Policy

Author: juwencheng Effective date: 2026-08-01 Last updated: 2026-09-11

Note: This policy is for the GetReadVault website, Chrome / Edge extension store listings, and user support. It is not legal advice. You may have additional rights under the mandatory laws of your location.

1. Who we are

GetReadVault is a webpage highlighting and excerpt tool. It helps you save selected text while reading, add notes and tags, and review captures inside the browser extension. Local capture stays free forever. Upgrade to Pro when you need multi-device or cross-browser cloud sync.

Contact:

  • Website: https://getreadvault.com
  • Support email: support@getreadvault.com

2. Scope

This Privacy Policy applies to:

  • the GetReadVault browser extension (currently for Google Chrome and Microsoft Edge; other browsers, if released later, follow the shipped product);
  • the GetReadVault web service (accounts, subscriptions, sync, feedback, and support);
  • customer support communications related to those services.

It does not apply to third-party websites, browser stores, OAuth providers, payment platforms, or pages you visit. Those parties process data under their own policies.

3. Information we collect

3.1 Account information

When you sign in or create an account, we may collect email address, display name, avatar URL, third-party login provider (such as Google or Apple), email used for one-time login codes (the code itself is stored only as a short-lived hash), password hash (we do not store passwords in plaintext), user ID, authentication status, and subscription status.

We use this for login, identity, cloud sync, subscription management, security, and support.

3.2 Content you actively save

When you use highlights, notes, comments, tags, or cloud sync, we may process webpage text you actively select and save; notes, comments, and tags; page title and URL; anchor data used to restore highlights (such as XPath, offsets, and context snippets); and saved/updated/sync timestamps.

Without sign-in or Pro cloud sync, this content mainly stays in your local browser. With Pro cloud sync enabled, it is synced to GetReadVault Cloud for access across supported devices and browsers.

3.3 Reading-time records

When you are signed in and entitled to Pro cloud sync, the extension automatically records time spent on visible tabs and uploads it to GetReadVault for in-account reading stats. There is no separate “turn off reading time” setting today. To stop uploads, sign out, drop Pro, or uninstall the extension.

Each record may include page URL, page title, date, and duration in seconds. Only time while document.visibilityState === 'visible' is counted. Background or non-visible pages are not counted. Sites you disable in the sidebar also stop highlighting and stop reading-time recording.

If you are not signed in or do not have Pro, reading-time records are not uploaded to our servers. A content script still runs on pages you visit so highlights can be restored; that does not mean we upload the page’s HTML.

3.4 Feedback and support information

When you contact us, we may collect issue description, page URL/title, browser type and extension version, contact email, and related support conversation content.

3.5 Local storage and browser permissions

GetReadVault uses browser storage and extension capabilities, including:

  • IndexedDB for local highlights, tags, comments, and sync state;
  • unlimitedStorage for on-device quota only (not cloud quota);
  • local extension storage for tokens, language and preferences, sync timestamps, OAuth temporary state, and the site-blocklist cache;
  • website cookies / local storage on getreadvault.com for the login token and UI language;
  • content scripts on pages you visit, for the selection toolbar, restoring saved highlights, and co-reading overlays—these scripts do not upload full page HTML;
  • context menu, sidebar, and tabs permissions for core workflows.

If you sign in, domains you disable may sync with your account so highlighting stays off on other devices.

We do not collect your full browsing history for advertising and do not bulk-scrape or upload page bodies when you are not using highlight, co-reading, feedback, or (Pro) reading-time features. A content script must run on pages you visit to restore highlights in place; that is not the same as reading or storing the entire page.

3.6 Payment and subscription information

If you purchase a Pro subscription, payment providers (such as Stripe, PayPal, or WeChat Pay) may process payment methods, billing, and transactions. GetReadVault generally does not store full card numbers or WeChat payment passwords, but may store subscription status, plan type, billing cycle, provider customer/subscription/transaction/merchant order IDs, and refund/cancellation/invoice status.

3.7 Login codes

When you request an email login code, we process your email address and store a hash of the one-time code, its expiry, and failed-attempt count. Codes are short-lived (typically 15 minutes) and are invalidated after a successful login or too many failed attempts. We do not log codes in plaintext.

3.8 Co-reading rooms

If you host or join a co-reading room, we may process the room ID, invite token, page URL locked to the room, member user IDs and display names, and in-room highlights and comments. This content is shown only to members of that room—it is not a public annotation layer. Only Pro users can host a room; invited members do not need Pro. Room annotations are separate from personal-library cloud sync: a Free member’s room marks are not turned into their personal synced highlights.

3.9 Bring-your-own-key (BYOK) AI (experimental)

If you configure an AI connection, we may process:

  • the third-party API key you submit (stored encrypted on our servers; plaintext is not returned in API responses);
  • the vendor, API host, and model name you choose;
  • prompts, excerpt snippets, and model replies from conversations you start (stored in your AI conversation history).

We forward requests to the AI host you configure (for example an OpenAI-compatible endpoint or DeepSeek). Those providers process data under their own policies. We do not use BYOK conversations for advertising profiles, and we do not share your key with other users.

3.10 Security logs

To prevent abuse and debug sign-in issues, we may record IP address, User-Agent, action type, and time for security-related events (for example admin access or unusual login activity). Hosting and server access logs may also include IP and request metadata, retained as needed for operations and security.

3.11 Email

We send login codes, password resets, subscription, and service notices through our email provider (currently Amazon SES). Admins may also send product or marketing email to registered users; every marketing message includes an unsubscribe link. Transactional mail (codes, security, and billing) is not covered by the marketing unsubscribe.

4. How we use information

We use information to provide highlighting and local library features; send and verify email login codes; provide cloud sync and visible-tab reading-time stats for eligible Pro users; show room highlights, comments, and display names to co-reading members; encrypt and proxy BYOK AI requests to the host you configure; identify entitlements; handle support; send service notices and optional product email; improve reliability; prevent abuse; and meet legal or compliance obligations.

5. How we share information

We do not sell personal information. We share or process data only when necessary with cloud/hosting providers, OAuth providers (such as Google or Apple), payment providers (Stripe, PayPal, WeChat Pay, as you use them), our email provider (Amazon SES), the AI host you configure if you use BYOK AI, or when required by law.

6. Data retention and deletion

  • Local data: stored in your browser; delete via clearing extension/browser data or uninstalling.
  • Cloud-synced captures: retained until you delete items, we delete the account at your request, or law requires retention.
  • Login-code hashes: typically expire within 15 minutes.
  • BYOK API keys and AI conversations: retained until you delete the connection/session, we delete the account, or law requires retention.
  • Subscription/transaction records: may be retained for finance, tax, risk, or legal reasons.
  • Support, feedback, and security logs: usually retained for a reasonable period after resolution.

There is no in-app one-click account deletion today. To request account or cloud data deletion, email support@getreadvault.com. We will process requests within a reasonable time unless retention is legally required.

7. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete account or cloud data, request a copy of data we hold about you (where features and law allow), cancel a subscription or disable sync (reading-time uploads stop when Pro sync is not entitled), unsubscribe from marketing email (codes, security, and billing mail still send), delete saved BYOK keys and AI conversations, object to or restrict certain processing, and withdraw consent.

You may also use the product without signing in (local capture only). Clearing browser data or uninstalling may erase local data. Reading-time recording has no separate toggle today.

8. Data security

We use reasonable safeguards such as HTTPS for cloud APIs, account-level isolation, limited internal access, and careful handling of login credentials. No internet service is perfectly secure—please protect your devices and accounts.

9. International transfers

Services, servers, vendors, and users may be in different countries. By using the service, you understand information may be transferred or processed outside your location. We use reasonable safeguards as required by applicable law.

10. Children's privacy

GetReadVault is not intended for children under 13 or the minimum age required by local law. Contact us to delete information if a child has provided personal data.

11. Third-party webpages

Content scripts may run on pages you visit to provide highlighting. We do not control third-party page content or privacy practices.

12. Changes to this policy

We may update this policy. For material changes, we will provide reasonable notice via the website, in-product messages, email, or store listing notes. Continued use means you accept the updated policy.

13. Contact us

  • Support email: support@getreadvault.com
  • Website: https://getreadvault.com