Privacy Policy
This policy explains what data ToneReader collects, why, and how it is protected.
Last updated: June 2026
1. Who we are
ToneReader ("we", "our", "the service") is a web application for reading and studying tonal languages. If you have questions about this policy, visit our support page.
2. Data we collect
Account information. When you sign in via OAuth (Google, GitHub, or similar), we receive your email address, display name, and profile picture from the provider. We store only what is needed to identify your account.
Content you create. Documents you upload or paste, folders you create, and flashcards you save are stored on our servers so you can access them across devices. This content is associated with your account and is not accessible to other users.
Usage data. We track aggregate counts — characters processed, flashcards created, audio requests made — to enforce free-tier limits and prevent abuse. We also store your spaced-repetition review history (grades and scheduling state) to power the SM-2 algorithm.
Preferences. Timezone and day-end hour settings you configure are stored to provide accurate streak calculations.
Billing data. Payments are processed by Stripe. ToneReader never sees or stores your card number or full billing address. Stripe shares only a customer ID, subscription status, and renewal date with us.
Technical data. Standard web-server logs may include your IP address, browser type, and request timestamps. These are used for debugging and security and are not linked to your account in any persistent way.
3. How we use your data
- To operate the service — authenticate you, store and retrieve your content, and compute flashcard schedules.
- To enforce subscription limits and process payments.
- To generate audio: words you request are sent to Microsoft Azure TTS and the resulting audio is cached on Cloudflare R2. The text of your request is not retained by Azure beyond the duration of the API call.
- To look up dictionary definitions: words you click are sent to the Wiktionary REST API. No account information is shared with Wikimedia.
- To improve the service: aggregate, anonymized usage patterns (e.g., which languages are most used) may inform product decisions. We do not run third-party analytics SDKs.
We do not sell your data. We do not use your data for advertising.
4. Third-party processors
We share data with the following sub-processors only to the extent necessary to operate the service:
| Processor | Purpose | Data shared |
|---|---|---|
| Neon (Postgres) | Database hosting | All stored user data |
| Stripe | Payment processing | Email, billing info |
| Microsoft Azure | Text-to-speech (Pro) | Words/phrases requested |
| Cloudflare R2 | Audio file storage | Generated audio files |
| Wikimedia Foundation | Dictionary lookups | Words/phrases looked up |
5. Cookies and session storage
ToneReader uses a single session cookie to keep you signed in. No advertising or tracking cookies are set. We do not use fingerprinting techniques.
6. Data retention
Your data is retained for as long as your account is active. If you delete your account, all personal data (documents, flashcards, account information) is permanently deleted from our database within 30 days. Anonymized aggregate statistics (e.g., total user counts) may be retained indefinitely.
Cached audio files associated with your requests may persist on Cloudflare R2 beyond account deletion; these files contain no personal information — only the text of the word or phrase.
7. Your rights
Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, use our support page from the address associated with your account. We will respond within 30 days.
EU/EEA users (GDPR). Our legal basis for processing your data is the performance of a contract (providing the service you signed up for) and our legitimate interest in operating a secure, functioning service. You have the right to lodge a complaint with your national data protection authority.
California users (CCPA). We do not sell personal information. You have the right to know what data we hold, to request deletion, and to opt out of any future sale (which we do not currently conduct).
8. Security
All data is transmitted over HTTPS. Database access is restricted to the application server. OAuth tokens are never stored server-side — only the derived user ID and profile information are persisted. Stripe handles all payment card data in their PCI-compliant environment.
9. Children
ToneReader is not directed at children under 13. If you believe a child under 13 has created an account, contact us via our support page and we will delete the account promptly.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app. Continued use of ToneReader after changes take effect constitutes acceptance of the revised policy.