Privacy Policy

How CastReader handles account, reading, voice, cloud-storage, analytics, and payment data across its mobile apps, browser extensions, and website.

Effective Date: August 26, 2026

Last Updated: August 26, 2026

Entity: Enid Ltd ("CastReader", "we", "us", or "our")

Service: CastReader mobile apps, browser extensions, website at castreader.com, and production API at api.castreader.ai (collectively, the "Service")

This policy explains what CastReader processes, why it is needed, and the choices available to you. Data handling varies by workflow: some extraction happens on your device, while speech, account, document, explanation, and private voice-cloning features require service processing.

1. What CastReader Does

CastReader provides Read Aloud and Read & Explain workflows for supported webpages, books, PDFs, DOCX and EPUB files, images or screenshots, and pasted text. Documents can be imported from your device or, if you choose to connect an account, from a cloud storage service such as Google Drive, Dropbox, or Microsoft OneDrive. Its official surfaces include iPhone and iPad, Android, Chrome, Edge, and selected web account or upload workflows.

CastReader does not bypass DRM, paywalls, source permissions, or access controls. You should submit only content you are authorized to access and process.

2. Data We Process

2.1 Account Data

Free browser listening can begin without an account. An email login is required to purchase or manage Pro and to align Pro entitlement across supported surfaces. Depending on the sign-in provider, we may process:

  • account ID and provider ID;
  • email address;
  • display name and profile image supplied by the provider;
  • authentication session and security metadata; and
  • subscription status and account-to-device links.

We use this data for sign-in, account security, entitlement checks, customer support, and cross-platform Pro consistency. Pro is tied to the login email, not to an anonymous device alone.

2.2 Device and Product Analytics

CastReader may create a random device identifier and process product events such as installation, session start, reading start or end, feature use, navigation to pricing, checkout progress, and errors. Event properties can include app or extension version, source surface, content type, coarse website hostname, funnel identifier, and non-sensitive diagnostic context.

We use this information to operate the Service, diagnose failures, measure product funnels, prevent abuse, and improve supported workflows. We do not intentionally include the full text of your reading content in analytics events.

Data obtained through Google APIs is excluded from this section. Google Drive file contents, file names, file identifiers, folder paths, search terms, and Drive account identifiers are never sent to analytics, funnel measurement, or growth metrics. See §2.6.

2.3 Reading and Explanation Content

The content needed for your requested workflow may be processed to extract text, perform OCR, synthesize speech, synchronize highlighting, or generate an explanation. Depending on the surface and source:

  • some page extraction or OCR can happen locally on your device;
  • text needed for speech is sent to api.castreader.ai;
  • uploaded files or library records can be stored when the workflow requires later access, history, progress, or deletion controls; and
  • Read & Explain sends the relevant source text and instructions to the configured model service.

CastReader does not turn private user content into public SEO pages by default and does not use private reading content to build a public voice catalog. Availability, storage, and deletion behavior vary by workflow; the product interface and support team can identify the controls available for a particular item.

2.4 Voice Preferences and Private Voice Cloning

Preset voice selection, favorites, and recent choices may be stored locally or with the authenticated account, depending on the client.

Private voice cloning is available through the dedicated web tool after sign-in. Every signed-in Free and Pro member can create multiple private voices and hear each server-set fixed preview; arbitrary-text generation, Read Aloud, and Explain use require Pro, including a valid trialing subscription, and share 120 minutes (7,200 seconds) per membership-month allowance window. The workflow processes:

  • a 3–30 second reference captured directly from the browser microphone; the public flow does not accept an existing audio-file upload;
  • explicit confirmation that the user owns the voice or has the required rights and consent;
  • an account-scoped clone ID, lifecycle state, reference hash, and consent version; and
  • generated speech requests made with the owned clone or an accepted Voice Gift.

Reference audio is encrypted with AES-256-GCM before object storage. Stored reference objects contain ciphertext, and access is checked against the authenticated account. Private clones can be listed, previewed, selected, and deleted by the owning account. They are not added to the public voice catalog or indexed as public pages. Creation, deletion, and fixed previews do not consume the 120-minute application allowance; deleting one voice does not affect the other voices. Usage records count successful generated-audio duration and protect idempotent requests from duplicate charges; failed, cancelled, timed-out, or quality-rejected generation does not consume the allowance, and cached replay is not charged again.

Global and China users, sign-ins, accounts, databases, object storage, and compute routes are fully isolated. Voice data and entitlements do not sync between regions.

Voice Gift lets the living voice owner authorize one named email to use the clone for private personal text-to-speech. The owner chooses a 7, 30, or 90 day expiry and privately sends the invitation link. CastReader stores a one-way recipient-email hash, a masked email, a one-way invitation-token hash, the consent version, the expiry, and lifecycle timestamps; the recipient account ID is stored after acceptance. Acceptance requires a signed-in account whose email matches the invitation. The owner can revoke the grant, the recipient can remove it, and deleting the source voice revokes its grants. Voice Gift does not make the clone public, searchable, or available in the public voice catalog.

A signed-in requester can also create a 30-day private request asking one named living person to record and authorize their own voice. CastReader stores one-way hashes and masked forms of the requester and invitee emails, a one-way request-token hash, related account IDs, the personal-TTS purpose, request expiry, acceptance, fulfillment or cancellation timestamps, and the completed grant ID when applicable. The invitee must sign in with the exact invited email. Accepting the request does not itself share a voice: the invitee must create or select their own clone, choose a 7, 30, or 90 day grant, and explicitly confirm the final authorization. The requester never becomes the owner of the clone.

CastReader does not currently support posthumous voice recreation. Do not upload recordings of a deceased person or attempt to recreate their voice. A family relationship, possession of an old recording, or a general recording release does not substitute for the specific consent that such a workflow would require.

Do not submit another person's voice without the necessary rights and explicit consent. Do not use CastReader to impersonate, deceive, defraud, or falsely attribute speech to another person.

2.5 Payments

Subscription checkout and billing management are handled by Stripe. Stripe processes payment-card and supported payment-method details under its own privacy terms. CastReader receives billing identifiers, plan and subscription status, transaction state, and limited billing contact details needed to provide Pro and support the account. CastReader does not receive or store your full card number.

2.6 Google Drive Data (Limited Use)

Connecting Google Drive is optional and is never required to use CastReader. When you choose to connect it, CastReader requests the https://www.googleapis.com/auth/drive.readonly scope for one purpose only: to let you browse and search your Drive inside CastReader, select a document, and open it for Read Aloud or Read & Explain.

CastReader's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, for data obtained through Google APIs:

  • We use it only to provide and improve the user-facing browsing, import, reading, highlighting, and explanation features you explicitly request.
  • We do not use it for advertising, retargeting, or any form of personalized or targeted advertising.
  • We do not use it to develop, improve, or train generalized or non-personalized AI or machine learning models.
  • We do not sell it, and we do not use it for product analytics, funnel measurement, growth metrics, marketing, or profiling.
  • We transfer it only as necessary to provide the feature you requested — the text of the document you opened is sent to our speech and explanation processors to produce audio and explanations for that document — or to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit prior consent. These processors are contractually prohibited from using the data to train their own models or for any purpose other than serving your request.
  • Humans do not read your Google Drive data, except with your explicit consent for a specific support request you initiate, for security purposes such as investigating abuse, or where required by law. Where such access is needed, we use aggregated or de-identified data whenever possible.

CastReader requests read-only access. It never creates, modifies, renames, moves, deletes, or uploads files in your Google Drive, and it does not perform background synchronization, indexing, or automatic scanning of your Drive.

CastReader does not store the original bytes of your Google Drive files on its servers. A Drive item in your CastReader library is stored on your device as a reference (the connected account, file identifier, and revision) plus basic metadata such as the title; when you reopen it, the file is downloaded again from Google Drive to your device.

You can disconnect Google Drive at any time inside CastReader, which revokes the grant and deletes the stored tokens and cached metadata on your device. You can also revoke CastReader's access at any time at myaccount.google.com/permissions.

3. Browser and Mobile Permissions

CastReader requests only permissions needed by the installed surface. Examples include access to the active browser tab for user-initiated extraction, extension storage for settings, microphone access for a user-initiated voice reference recording, and photo or file access when you choose content to import. Operating-system and browser permission screens show the permissions requested by your installed version.

The production TTS and voice services use api.castreader.ai; the canonical website, account, analytics, and billing surfaces use castreader.com.

4. How We Use Data

We process data to:

  • provide speech, extraction, highlighting, progress, explanation, account, and private voice features;
  • authenticate users and keep Pro entitlement aligned;
  • process payments and manage subscriptions;
  • secure the Service, enforce rate limits, and prevent fraud or misuse;
  • diagnose reliability and compatibility problems;
  • answer support requests; and
  • comply with legal obligations and enforce our Terms of Service.

We do not sell personal data or private reading content. We do not use private reading content or private cloned voices for advertising.

The uses listed in this section describe CastReader data generally. Data obtained from Google APIs is governed by the narrower Limited Use terms in §2.6, which take precedence over this section wherever the two differ.

5. Service Providers

We use service providers for infrastructure, authentication, payments, analytics, speech, and model processing. They receive only the data needed for the requested function and process it under their own terms and our applicable agreements. Key public dependencies include Stripe for payments and the model or infrastructure providers required by the selected speech or explanation workflow.

Data obtained from Google APIs is shared only with the speech and explanation processors needed to fulfill the request you made for that specific document, as described in §2.6. It is not shared with analytics, advertising, or marketing providers.

6. Storage, Retention, and Security

We use HTTPS in transit, access controls, account ownership checks, and operational safeguards appropriate to the workflow. Private voice reference audio is encrypted before object storage. No system is completely secure.

Retention depends on purpose:

  • authentication, subscription, consent, security, and transaction records are kept as needed to operate the account and meet legal obligations;
  • analytics and operational logs are retained for product, security, and reliability needs;
  • uploaded items, histories, and progress records remain according to the workflow and available deletion controls; and
  • private cloned voices and their active reference data remain until deleted, the account is closed, or retention is otherwise required for security or legal reasons. Deletion from active systems may not immediately remove encrypted backups;
  • Voice Gift grant and request records remain through their active lifecycle and as needed for consent, security, abuse prevention, and legal obligations. Cancellation, revocation, recipient removal, expiry, or source-voice deletion ends the applicable active access even when the consent record must be retained; and
  • Google Drive access and refresh tokens are stored on your device only and are deleted when you disconnect Google Drive, when the grant is revoked, or when you delete the app. Original Drive file bytes are not retained on our servers; the copy downloaded for reading is held in a protected temporary location on your device.

7. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data. You can also:

  • use supported free browser workflows without creating an account;
  • sign out or remove an account-device link;
  • clear local app or extension storage;
  • delete supported uploaded items or private cloned voices through the relevant client;
  • cancel an unfinished voice request, revoke a Voice Gift you created, or remove a Voice Gift you received through the voice-cloning web tool;
  • disconnect a connected cloud storage account in the app, or revoke CastReader's Google access at myaccount.google.com/permissions;
  • manage or cancel a subscription through the account page and Stripe; and
  • contact us to request account or privacy assistance.

We may need to verify your identity before completing a request.

8. Children

CastReader is not directed to children under 13, or the minimum age required in the user's jurisdiction, and we do not knowingly create accounts for children who cannot legally consent. Contact us if you believe a child has provided personal data improperly.

9. International Transfers

CastReader and its service providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers.

10. Changes to This Policy

We may update this policy as products, laws, or service providers change. We will publish the updated date here and provide additional notice when required.

11. Contact

For privacy questions or requests: