Privacy Policy
LeanRead is a product of LightCode ("we", "us"). This policy explains what we collect, why, and what your choices are. The short version: LeanRead is local-first — your documents stay on your device unless you choose AI compression or cloud sync — and we do not sell your data or show ads.
1. What we collect
Account data. If you create an account: your email address and authentication data, managed by Supabase (our database and login provider).
Synced content. If you sign in and use cloud sync: the sources, citations, notes, and reading workspaces you choose to sync, stored so they follow you across devices.
AI compression input. If you use AI compression: the text you submit is sent to our AI provider (currently OpenAI) to generate the compressed version. We do not use your text to train models, and we do not permit our provider to do so under its API terms.
Early-access requests. If you fill out the form on leanread.io: name, email, reading interest, and message, so we can respond and manage the beta.
Billing. Subscriptions are processed by Paddle, our merchant of record. Paddle collects your payment details directly — we never see your card number. We store your subscription status and Paddle identifiers to grant paid features.
Server logs. Standard technical logs (IP address, request time) for security and abuse prevention, retained briefly.
2. What stays on your device
Documents you read, local compression results, and settings live in your browser's local storage. Uploaded files are processed to extract text and are not retained on the server. If you never sign in, your reading data never leaves your device except as described for AI compression.
3. Cookies
LeanRead uses only essential cookies — the ones that keep you signed in. We use no advertising or analytics cookies, so we do not show a cookie consent banner. Paddle's checkout sets cookies needed for payment and fraud prevention.
4. Service providers
We share data only with the providers needed to run the Service: Supabase (database, authentication), Paddle (payments, as merchant of record), OpenAI (AI compression, only when you use it), Resend (transactional email), and Cloudflare (networking and security). Each receives only what its function requires.
5. Your rights
You can export your sources and citations from the app at any time. You can ask us to access, correct, or delete your account data by emailing [email protected]; deletion removes your account and synced content within 30 days, except records we must keep for tax or legal reasons (held by Paddle). EU/UK residents have the rights provided by GDPR; California residents have the rights provided by the CCPA.
6. Data security and retention
Data is encrypted in transit, access is restricted by row-level security so each account can only reach its own data, and we keep regular backups. We retain account data while your account is active and delete it on request as described above.
7. Children
LeanRead is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
8. Changes
We will announce material changes to this policy by email or in the app before they take effect.
9. Contact
LightCode · lightcode.us · [email protected]