1. Introduction
Welcome to Readdit Later, a Chrome extension designed to help you save, organize, and enhance your Reddit experience. This Privacy Policy explains how we collect, use, store, and protect your information when you use our extension and its features.
Data Controller: Readdit Later is operated by Sanjhai Prakash B, an individual sole proprietor based in Tiruchirappalli, Tamil Nadu, India ("we," "us," or "our"). We determine how and why your personal data is processed. For any privacy question, data-access request, or to exercise your data-protection rights, contact us at sanjhaiprakash18@gmail.com.
Transparency First: Readdit Later uses both local browser storage and secure server storage. This policy clearly explains what data is stored where, why we store it, and how you can control or delete it at any time.
2. Information We Collect
2.1 Account Information
When you use Readdit Later, we collect:
- Email Address: Used for subscription management, account recovery, and the emails you choose to receive (collected when you complete a purchase or when you enter it in the extension, for example to turn on the weekly digest)
- Reddit Username: Automatically detected from your Reddit browsing session to identify your account and enable cross-device data sync
- Name: If provided to our payment processor at checkout, your name is shared with us and stored with your account (see Section 2.3)
2.2 Reddit Content
We access and process:
- Saved Posts: Titles, content, URLs, subreddit names, scores, and metadata
- Saved Comments: Comments you have saved on Reddit, including comment text, author, subreddit, and parent post context
- User Labels: AI-generated or custom labels you assign to posts
- Personal Notes: Notes you add to saved posts
- Read Status: Which posts you have marked as read or unread
- Reminders: Reminder dates and settings you attach to saved posts
2.3 Subscription and Billing Information
- Subscription status, tier, and expiration dates
- Payment provider IDs (Dodo Payments customer/subscription IDs)
- Billing details received from Dodo Payments, including your name, email address, phone number, and billing address (street, city, state, postal code, country)
- Payment method type (e.g., card, wallet) — but never your card number, CVV, or bank credentials
- Trial usage tracking
- First installation date
2.4 Usage Analytics (First-Party Only)
To understand which features are used and improve the product, the extension sends usage events to our own server. Each batch of events is sent with your Reddit username and, if you have given us one, your email address (used only to look up your plan; it is not stored with the events). Each stored event contains:
- An event name and category (for example: session start/end, page viewed, feature used, search performed, export completed, filter or sort changed, upgrade screen opened, checkout started)
- Your plan tier and a timestamp
- Small event details, such as the export format and post count, the number of search results and the length of a search query (not the query itself), the filter or sort option chosen, session duration, and, when you open a post, that post's Reddit ID and subreddit
Usage events do not include the text of your saved posts, notes, or extension search queries. One exception: when an AI tool connected through the remote MCP connector (Section 5) runs a search that returns no results, we log that search query (up to 200 characters) so we can improve search quality. We do not use any third-party analytics or tracking services (no external trackers).
In addition, our server uses your IP address transiently to rate-limit requests and prevent abuse. We do not store IP addresses in our database, but our hosting provider (Vercel) may record them in its own request logs for a limited period under its retention policy (see Section 12.2).
2.5 Emails and the Weekly Digest
If you give us your email address and keep the weekly digest turned on, the extension uploads the title, subreddit, permalink, score, and a short text preview (up to about 500 characters) of your saved posts to our server so we can build your digest email. Nothing is uploaded for the digest until you have provided an email address and the digest is on.
Digest and reminder-style emails (such as the weekly digest and "forgotten gems" resurfacing emails) may include AI-generated summaries of those posts. We also send account emails (for example, a welcome email, purchase and cancellation confirmations, payment-failure notices, and, if you turn it on, scheduled export files). You can turn the digest off in the extension settings or unsubscribe using the link in any email. We keep a log of emails sent to you (recipient address, email type, subject, and delivery status) to avoid duplicate sends.
2.6 Feedback, Surveys, and Uninstall Survey
- In-app feedback: If you answer an in-app survey, rate an AI Chat Agent reply, or reply to an in-app support prompt, your answers are sent to our server together with your Reddit username and, if known, your email address and basic usage context (such as your plan and number of saved posts).
- Uninstall survey: When you uninstall the extension, Chrome opens a feedback page (hosted on GitHub Pages). The page address includes your Reddit username, plan, extension version, and approximate usage (number of saved posts and days since install). If you choose to submit the form, your answers, those details, any email you type in, and your browser's user agent are sent to our server and to Web3Forms, a form-delivery service that emails them to us. If you close the page without submitting, nothing is sent.
2.7 What We Do NOT Collect
- Your Reddit password or login credentials
- Private messages or direct communications
- Posts you have not explicitly saved
- Your browsing history outside of Reddit
- Precise geolocation or device fingerprinting (note: we do receive the billing address you provide to our payment processor — see Sections 2.3 and 8.4)
- Your credit card number, CVV, or bank account credentials (handled entirely by Dodo Payments)
3. Server-Side Data Storage
Important: Server Storage Disclosure. Unlike purely local extensions, Readdit Later stores certain data on our secure servers (Supabase) to enable premium features like cross-device sync and persistent data storage.
3.1 What Data is Stored on Our Servers
The following data is stored in our Supabase database:
User Accounts Table:
- Email address (unique identifier)
- Reddit username (for cross-device sync)
- Name (if shared by the payment processor)
- Subscription status, tier, and expiration dates
- Dodo Payments customer and subscription IDs
- Trial usage tracking (whether trial was used)
- Account creation and update timestamps
- First installation date
User Labels Table:
- Reddit username (to link labels to your account)
- Reddit post IDs
- AI-generated or custom labels (stored as JSON array)
- Creation and update timestamps
User Notes Table:
- Reddit username
- Reddit post IDs
- Your personal notes for each post
- Creation and update timestamps
User Read Status Table:
- Reddit username
- Reddit post IDs
- Read/unread status (boolean)
- Creation and update timestamps
User Reminders Table:
- Reddit username
- Reddit post IDs
- Reminder date and time
- Creation and update timestamps
Usage Analytics Table:
- Reddit username and plan tier
- Usage event names, categories, small event details, and timestamps (see Section 2.4)
- No saved-post text, notes, or extension search queries (zero-result MCP search queries excepted, see Section 2.4)
AI Chat and Agent Data:
- Reddit username
- Your recent AI Chat Agent messages and the agent's replies, and saved conversations (title and messages), so your chat history follows you across devices and reinstalls
- Agent settings you create, such as a reading goal, playbook, and review queue
- AI results we cache to avoid regenerating them, such as summaries, sentiment results, and categories
- Watchdog topics you set up, which are matched against your own saved posts, and your email address if you have provided one so matches can be emailed to you
Weekly Digest Posts (only with an email address and the digest turned on):
- Reddit username
- Post IDs, titles, subreddit names, permalinks, scores, and a short text preview (up to about 500 characters)
Email Preferences and Email Log:
- Whether the digest is on, whether you have unsubscribed, and your scheduled-export settings
- A record of each email sent to you (recipient address, email type, subject, delivery status)
Feedback and Survey Responses:
- Your answers to in-app surveys, AI reply ratings, in-app support replies, and the uninstall survey (see Section 2.6)
Shared Collections (only if you share one):
- If you create a public share link for a collection, the collection name, the posts in it, and your Reddit username and email (if known) are stored; the collection name and posts can be viewed by anyone with the link
Device Security Keys:
- When you install or update the extension, it receives a random security key that proves requests to our server come from your own browser, so nobody else can access your data just by knowing your Reddit username
- We store only a one-way hash (fingerprint) of each key, never the key itself, together with your Reddit username and the dates it was created and last used
- Each browser or device you use gets its own key; keys are deleted when you delete your account
Payment & Webhook Logs:
- Subscription lifecycle events (created, renewed, cancelled, payment succeeded/failed)
- The billing details received from Dodo Payments — your name, email address, phone number, and billing address
- Payment method type, payment/subscription IDs, amount, and currency
- Used to verify subscriptions, keep your access accurate, and handle payment disputes
Cloud Backup (paid plans only):
- Your Reddit username (used to key your backup)
- Your saved posts and comments (titles, content, URLs, subreddit names, scores, and metadata)
- A per-post deletion flag and timestamps
Saved Posts (Server-Side Search Index):
- Reddit username (used as the key for this index)
- Reddit post IDs
- Post title and post body text (selftext), stored in plaintext up to approximately 4,000 characters
- Subreddit, author, URL, permalink, flair, domain, score, and comment count
- A numeric embedding (vector) generated from the post to enable semantic search
- Labels, notes, read status, and collection assignments associated with those posts
- This index powers AI-powered / natural-language search, the AI Chat Agent, and AI Tools (MCP) access. When you connect an AI tool via MCP, a randomly generated access token authenticates that tool to this index; the token controls access, while the underlying post data is stored keyed to your Reddit username. This is a plaintext copy, separate from and in addition to the cloud backup described in Section 4.
3.2 Why We Store Data on Servers
Server storage enables:
- Cross-Device Sync: Access your labels, notes, and read status across multiple browsers and computers
- Encrypted Cloud Backup (paid plans): On paid plans, automatically back up your saved posts (encrypted in transit and at rest) so they survive browser resets, reinstalls, or device changes
- Data Persistence: Retain your organization data even if you reinstall the extension
- Account Recovery: Automatically restore your data when signing in with your Reddit username
- Subscription Management: Verify premium features, manage billing, and resolve payment disputes
3.3 What is NOT Stored on Servers
These remain local to your browser only:
- Extension settings and preferences
- AI embeddings cache
- Local search history
Note: Your saved post content may be stored on our server in two ways: on paid plans, it is backed up so your library can be recovered after a reinstall or on a new device (see Section 4); and, when you use our AI-powered search, the AI Chat Agent, or AI Tools (MCP) access, it is stored as a plaintext search index keyed to your Reddit username (the "Saved Posts" index in Section 3.1) so those features can search and reason over your saves. Both stores are encrypted in transit and at rest, but neither is end-to-end (zero-knowledge) encrypted.
4. Encrypted Cloud Backup (Paid Plans)
Paid Feature: Cloud backup is available on paid plans. When your subscription is active, your saved posts are backed up to our server (encrypted in transit and at rest) so your library can be restored after an extension reinstall or on a new device. On free plans, saved posts are kept locally in your browser and are not backed up to our server.
4.1 What It Does
On paid plans, Readdit Later backs up your saved posts and comments to our server. This ensures your library survives browser resets, extension reinstalls, or device changes without requiring you to manually export and re-import your data.
4.2 How It Works
- 1.Your saved posts are stored in our Supabase database, keyed by your Reddit username
- 2.Each post is stored as its own record so it can be restored accurately
- 3.For paid users, backups run automatically after each sync (scrape) and after each save-click
- 4.When you reinstall the extension or set it up on a new device, your library is restored from this backup
4.3 How Your Data Is Protected
Your backup is encrypted in transit (HTTPS/TLS) and encrypted at rest in our database, with row-level security. It is not end-to-end (zero-knowledge) encrypted, however: because our AI features (semantic search, tagging, and AI-tool access) need to read your saves, our servers can access the stored post content. We do not sell your data or share it with third parties except the infrastructure providers required to operate the service.
4.4 What is Backed Up
- Your saved post and comment data (titles, content, URLs, subreddit names, scores, and metadata)
4.5 Managing and Deleting Your Backup
You are in control of cloud backup at all times:
- Turn it off: Toggle "Cloud Backup" off in the extension's Privacy & Data settings to stop backing up your saves to our server.
- Delete it: Click "Delete Cloud Backup" in the same settings to permanently remove your backed-up posts from our server. This does not affect your local library on this device or your account.
- Delete everything: Deleting your account also permanently removes your cloud backup along with all your other server-stored data.
5. AI Tools Integration (MCP)
Readdit Later supports MCP (Model Context Protocol), an open standard that lets AI assistants connect to external tools. There are two separate ways to connect your saves to AI tools, with very different privacy characteristics: a remote connector (uses our server, opt-in sync) and a local MCP server (runs entirely on your own computer, no server involved).
Opt-in Feature: The remote connector is optional and available on paid plans. No AI tool can reach your saves through it until you create your private connector link in the extension (the "Create my private link" button).
5.1 Remote Connector — What It Does
The remote connector lets AI tools that support remote MCP servers — such as Claude (web, desktop, and mobile) via custom connectors — search and read your saves from anywhere, and organize them when you ask. It works over the Saved Posts search index on our server (Section 3.1), which the extension keeps up to date so these AI tools can access your saves on your behalf.
5.2 How It Works
- 1.You click "Create my private link" in the extension's AI tools section
- 2.A randomly generated access token is created to authenticate AI-tool access (it expires after 90 days)
- 3.If some of your saves are already in your cloud backup but not yet in the Saved Posts search index, they are copied into the index so the connector can see them right away
- 4.You copy a unique URL and paste it into your AI tool's configuration
- 5.The AI tool connects to our server using that URL to read your saves and, when you ask it to, make changes to your library (see Section 5.4)
5.3 What Data is Synced
The remote connector can access the following data from our Saved Posts search index (Section 3.1):
- Post titles, subreddit names, author names, URLs, permalinks, and scores
- Post body text (selftext), stored in plaintext up to approximately 4,000 characters
- Your labels, notes, and read/unread status
- Collection names and which posts belong to them
Your email address and Reddit OAuth session are never included. Note that this saved-post data is stored keyed to your Reddit username (see Section 3.1); the MCP access token controls who can reach it, but it is not stored anonymously.
5.4 Data Security
- Encrypted in transit: All sync data is transmitted over HTTPS/TLS
- Encrypted at rest: Server data is stored on Supabase (AWS infrastructure with encryption at rest)
- Access token: Your MCP access token is randomly generated and authenticates AI-tool access. The token itself is not your Reddit username, but our server maps it to your account to return your saves — the underlying post data is stored keyed to your Reddit username (see Section 3.1)
- Read and write access: AI tools connecting through the remote URL can read your saves and, when you ask them to, change your library: add or remove labels, add notes, mark posts read or unread, and delete posts from your Readdit Later library. These changes are made to your server-stored data and may be reflected in the extension. Deleting a post from your library does not unsave it on Reddit, and the AI tool is asked to show you which posts it will delete and get your confirmation first. Only connect AI tools you trust, and review destructive requests before confirming them in your AI tool. (The local MCP server, described in Section 5.7, offers similar actions on your own machine only.)
5.5 Data Retention
- The Saved Posts search index is kept on our server until you delete your account (Section 11) or ask us to delete it
- We do not currently run an automatic inactivity cleanup for this data. If you stop using the extension, delete your account or email us at sanjhaiprakash18@gmail.com and we will remove it
5.6 Disconnect and Delete
You can cut off an AI tool's access at any time with "Turn off this link and make a new one" in the extension, which immediately deactivates your old access token. Access also ends automatically when the token expires (after 90 days) or when your paid plan ends. Turning off the link does not delete the Saved Posts search index, because it also powers AI search and the AI Chat Agent; to remove it, delete your account (Section 11) or email us.
5.7 Local MCP Server (No Server Involved)
Separately from the remote connector, Readdit Later offers a local MCP server (npx readdit-later-mcp) for AI tools that run on your computer, such as Claude Desktop and Cursor.
- Runs entirely on your machine: The local server connects to the extension through a local connection on your own computer (127.0.0.1). Your data is read directly from your browser and is never sent to our servers or any external service through this connection.
- Read-write by design: Unlike the remote connector, the local MCP server can also act on your library when your AI tool requests it — applying labels, managing collections, adding notes, marking posts read, deleting posts from your library, and exporting to CSV or Markdown. These actions run locally and only when you ask your AI tool to perform them.
- Fully under your control: Stop the local server or close your AI tool at any time to end access. Nothing persists outside your own machine.
6. AI Features and Data Processing
AI Features Information: Our AI-powered features process your post content to provide summaries, sentiment analysis, and auto-labeling. Post content is sent to our server and then to AI providers (OpenRouter/OpenAI/Anthropic) for processing. Semantic search and the AI Chat Agent operate over the server-side Saved Posts search index described in Section 3.1.
6.1 AI-Powered Features
- AI Summaries: Automatic post summarization using GPT-4o-mini
- Sentiment Analysis: Emotion and tone detection
- Auto-Labeling: Automatic categorization
- Natural Language Search: Semantic search using embeddings
- Subreddit Analysis: Community insights
- AI Chat Agent: Conversational assistant for searching, organizing, and managing saved posts using Anthropic's Claude model
6.2 AI Data Flow
When you use AI features:
- 1.Post content is sent from your browser to our server (reddit-later-server.vercel.app)
- 2.Our server sanitizes and processes the request
- 3.Content is sent to OpenRouter API (using OpenAI's GPT-4o-mini model)
- 4.AI response is returned through our server to your browser
- 5.We do not ask AI providers to store your content; how they handle it is governed by their own policies (Section 8.3). Our server may keep the results (such as summaries, sentiment results, and categories) so they do not need to be regenerated
The weekly digest and related emails may also send the titles and short previews of your saved posts to an AI provider to write summaries for the email (Section 2.5).
6.3 Data Minimization
To protect your privacy:
- Long posts are truncated (max 2000-4000 characters depending on feature)
- Personal identifiers are removed when possible
- Only necessary context is sent (title, subreddit, content)
- Your Reddit username is sent to our server for credit tracking and subscription verification, but is not forwarded to third-party AI providers
6.4 AI Chat History
Conversations with the AI Chat Agent are stored in your browser's local storage (for up to 30 days) to maintain chat continuity. They are also stored on our servers so your chat history syncs across devices and survives a reinstall: your most recent messages and the agent's replies, plus any conversations you save (with their titles), are kept in our database keyed to your Reddit username. You can delete or rename saved conversations in the extension. Server-stored chat history is kept until you delete it or delete your account, at which point it is removed (Section 11).
7. How We Use Your Information
7.1 Core Extension Functions
- Display and organize your saved Reddit posts
- Synchronize labels, notes, and read status across devices
- Provide search and filtering capabilities
- Manage subscription and premium features
- Send the weekly digest and other emails described in Section 2.5
7.2 Subscription Management
- Verify premium subscription status
- Process trial activations
- Handle subscription renewals and cancellations
- Link accounts for automatic restoration after reinstall
- Verify payments and respond to payment disputes or chargebacks
7.3 AI Enhancement
- Generate summaries of lengthy posts
- Analyze sentiment and emotional tone
- Automatically categorize and label posts
- Provide semantic search capabilities
7.4 Product Improvement
- Analyze first-party feature-usage events to understand which features are valuable
- Identify and fix errors and performance issues
8. Third-Party Services
8.1 Reddit
We interact with Reddit through browser-native capture:
Browser-Native Capture
- When you visit your Reddit saved posts page, the extension reads your saved posts using your existing logged-in Reddit session — either from the page content your browser renders, or by requesting Reddit's own saved-posts JSON listing (the same data Reddit's website loads for you). These requests rely solely on your existing session; no Reddit API keys, OAuth apps, or additional credentials are involved
- Your Reddit username is automatically detected from your logged-in Reddit session — no login or credentials are required by the extension
- The extension stores your saved posts locally over time. Regular syncs accumulate older posts so your library can grow beyond Reddit's ~1,000-item display limit as older items are captured before they fall off
- This method uses your existing logged-in browser session and is functionally equivalent to you viewing and scrolling through your own saved posts
All Reddit interactions are governed by Reddit's Privacy Policy.
8.2 Supabase (Database Storage)
We use Supabase for secure database storage:
- PostgreSQL database for user accounts and synced data
- Encrypted connections (HTTPS/TLS)
- Row-level security policies
- Regular automated backups
Governed by Supabase's Privacy Policy.
8.3 AI Services
- OpenRouter API: Gateway for accessing AI models; post content, chat messages, and search queries you send to AI features are forwarded through it
- OpenAI (GPT-4o-mini and embedding models): Text analysis, summarization, generation, and the embeddings used for semantic search
- Anthropic (Claude): AI Chat Agent conversations and tool-assisted post management
- Processing: Via our secure server (reddit-later-server.vercel.app)
Governed by OpenRouter's Privacy Policy, OpenAI's Privacy Policy, and Anthropic's Privacy Policy.
8.4 Payment Processing
- Dodo Payments: Handles all payment processing
- We never see or store your card number, CVV, or bank credentials
- We do receive and store the billing details Dodo shares with us — your name, email address, phone number, and billing address — in our payment and webhook logs, used to verify subscriptions and handle payment disputes
Governed by Dodo Payments' Privacy Policy.
8.5 Notion Integration (Optional)
If you enable Notion integration:
- OAuth authentication with Notion required
- The one-time OAuth sign-in step passes through our server so that our Notion app credentials stay private; your Notion access token is returned to your browser and stored there, not on our servers
- Data exported directly from your browser to Notion
- No saved-post data passes through our servers during export
- Revocable through Notion's integration settings
8.6 Crisp (Support Chat, Optional)
The extension dashboard includes an optional support chat provided by Crisp, loaded as an embedded frame. It is only active when you open the chat panel. Any information you type into the support chat is processed by Crisp and governed by Crisp's Privacy Policy. We do not send your saved posts, labels, or notes to Crisp.
8.7 Vercel (Hosting)
Our server (reddit-later-server.vercel.app) runs on Vercel. All requests from the extension to our server, including the data described in this policy, pass through Vercel's infrastructure, and Vercel may keep request logs (which can include IP addresses) under its own retention policy. Governed by Vercel's Privacy Policy.
8.8 Resend (Email Delivery)
We use Resend to send our emails (the weekly digest, account and billing emails, and scheduled export files). Resend receives your email address and the content of each email, which may include titles and previews of your saved posts. Governed by Resend's Privacy Policy.
8.9 Web3Forms and GitHub Pages (Uninstall Survey)
The uninstall feedback page is hosted on GitHub Pages. If you submit it, your answers and the details listed in Section 2.6 are sent to Web3Forms, a form-delivery service that emails them to us, as well as to our own server. Governed by Web3Forms' Privacy Policy and GitHub's Privacy Statement.
9. Data Storage and Security
9.1 Security Measures
- Encryption in Transit: All data transmission uses HTTPS/TLS
- Database Security: Supabase provides encrypted-at-rest storage and row-level security
- Session-Based Auth: Reddit username detected from your browsing session, no passwords stored
- Content Security Policy: Prevents unauthorized script execution
- Rate Limiting: API request throttling prevents abuse
- Minimal Permissions: Only necessary browser permissions requested
9.2 Data Access Control
- Server access restricted to service roles only
- No manual access to user data without explicit request
- All database operations logged for security auditing
- Regular security updates and monitoring
10. Your Rights and Data Control
10.1 Access Your Data
- View Locally: All stored information accessible through extension interface
- Export Data: Download your labels, notes, and posts in JSON/CSV format
- Server Data: Request complete copy of your server-stored data
10.2 Modify Your Data
- Edit or remove labels and notes at any time
- Change privacy and feature preferences
- Update account email or disconnect your account
- Delete specific posts or categories
10.3 Control Third-Party Access
- Reddit: Log out of reddit.com to disconnect the extension from your Reddit account
- Notion: Disconnect integration through Notion settings
- AI Features: Can be disabled in extension settings
- AI Tools (MCP): Turn off your remote connector link from the extension at any time; stop the local MCP server whenever you choose
- Emails: Turn off the weekly digest in the extension settings, or use the unsubscribe link in any email
- Cloud Backup: Turn cloud backup on or off, or permanently delete it from our server, in the extension's Privacy & Data settings (deleting your account also removes it)
11. Data Deletion and Account Removal
Right to Erasure (GDPR Article 17): You have the right to request complete deletion of all your personal data from our servers at any time, for any reason.
11.1 How to Delete Your Data
You can delete your data in two ways:
Option 1: Through the Extension
- 1.Open Readdit Later extension
- 2.Go to Settings → Privacy & Data
- 3.Click "Delete My Data" button
- 4.Confirm deletion (irreversible action)
- 5.Your server-stored data is permanently deleted, normally immediately
Option 2: Contact Us Directly
- 1.Email: sanjhaiprakash18@gmail.com
- 2.Subject: "Data Deletion Request - Readdit Later"
- 3.Include your Reddit username or email address
- 4.We will process your request within 30 days
11.2 What Gets Deleted
When you delete your data, we permanently remove:
- Your user account record (email, Reddit username, name)
- All subscription information, including stored billing details and payment/webhook logs (except minimal records we are legally required to keep — see Section 11.3)
- All synced labels, notes, reminders, and read status
- Your Saved Posts search index (titles, body text, metadata, and embeddings)
- All cloud backup data
- All AI Tools (MCP) access tokens
- Your AI Chat Agent history, saved conversations, and agent data (goal, playbook, review queue)
- Your weekly digest posts and Watchdogs
- Uninstall survey responses linked to your username
- All usage analytics events linked to your username
To also remove cached AI results, in-app feedback and survey answers, or copies of uninstall survey responses that Web3Forms has already emailed to us, email us and we will delete them. Request logs held by our hosting provider (Vercel) expire under its own retention policy.
11.3 What Remains
- Local Data: Data stored in your browser remains until you uninstall the extension or clear browser data
- Anonymized Analytics: Aggregate usage statistics (no personal identifiers)
- Legal Records: Minimal billing records may be retained for tax/legal compliance (typically 7 years)
11.4 Data Export Before Deletion
Before deleting your data, you can:
- Export all your labels and notes as JSON/CSV
- Download a complete copy of your server-stored data
- Save your data locally or transfer to another service
12. Data Retention
12.1 Active Account Data
- User Accounts: Retained until you delete your account or ask us to delete it (we do not currently delete accounts automatically after cancellation)
- Synced Data: Labels, notes, reminders, and read status retained indefinitely while account is active
- Cloud Backup: Retained while your account is active; deleted when you delete it (via the settings control) or delete your account
- Saved Posts Search Index: Retained while your account is active to power search and AI features; deleted when you delete your account
- Payment & Webhook Logs: Retained while your account is active and for a limited period afterward to handle disputes; minimal billing records kept per legal requirements (see 12.3)
- AI Tools (MCP) Access Tokens: Deactivated when you turn off your link or after 90 days; deleted when you delete your account
- AI Chat History, Agent Data, Digest Posts, Watchdogs, Usage Analytics, and Survey Responses: Retained until you delete them (where the extension offers a control) or delete your account
- Inactive Accounts: We do not currently delete inactive accounts automatically. If you stop using Readdit Later, delete your account from the extension or email sanjhaiprakash18@gmail.com and we will remove your data
12.2 Temporary Data
- AI Processing: We do not ask AI providers to retain your content; their retention is governed by their own policies (Section 8.3)
- Server Logs: We do not store IP addresses in our database. Our hosting provider (Vercel) may keep request logs, which can include IP addresses, for a limited period under its own retention policy
- Cache Data: Cached AI results are kept so they do not need to be regenerated; email us to have yours deleted
12.3 Legal Retention
- Financial Records: Subscription payment records retained for 7 years (tax compliance)
- Legal Disputes: Data may be retained if involved in legal proceedings
13. Children's Privacy
Readdit Later is not intended for children under 13 years of age. Since the extension requires a Reddit account, users must meet Reddit's minimum age requirements (13+ in most jurisdictions, 16+ in some regions). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
14. Policy Updates
We may update this Privacy Policy to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
- Industry best practices
14.1 Notification of Changes
- The "Last Updated" date will be revised
- Significant changes highlighted in extension update notes
- In-app notification for material privacy changes
- Email notification for major changes (if email provided)
14.2 Your Consent
- Continued use after updates constitutes acceptance
- Material changes may require explicit re-consent
- You can always request clarification via email
15. Contact Information
Privacy Questions & Data Requests
For privacy questions, data access requests, deletion requests, or concerns:
Data Controller: Sanjhai Prakash B (sole proprietor), Tiruchirappalli, Tamil Nadu, India
Email: sanjhaiprakash18@gmail.com
Subject Line: "Readdit Later Privacy Inquiry"
Response Time: Within 72 hours for inquiries, 30 days for deletion requests
For Data Deletion Requests, include:
- Your Reddit username or email address
- Specific data you want deleted (or "all data")
- Confirmation that you understand deletion is irreversible
Technical Details
Chrome Permissions Explained
Our extension requests these specific Chrome permissions:
- storage: Store your data and preferences locally
- unlimitedStorage: Allow large save libraries to be cached locally without hitting browser storage caps
- tabs: Open Reddit links and manage extension interface
- alarms: Schedule background synchronization and auto-export
- sidePanel: Display extension interface in Chrome's side panel
- notifications: Show completion notifications for sync and auto-export
- downloads: Save your exported files (CSV, JSON, Markdown, etc.) to your computer
Host Permissions
We request access to these domains:
- https://www.reddit.com/*: Read saved posts from your Reddit browsing session and detect your username
- https://reddit-later-server.vercel.app/*: Our server for AI processing and data sync
- https://api.notion.com/*: Optional Notion integration
- https://api.openai.com/*: AI features (via our server)
- https://openrouter.ai/*: Alternative AI models (via our server)
- https://www.redditstatic.com/*: Load Reddit static assets and images
- https://styles.redditmedia.com/*: Load Reddit stylesheets and media
- https://*.thumbs.redditmedia.com/*: Display Reddit thumbnail images
- https://preview.redd.it/*: Display Reddit image previews
- https://i.redd.it/*: Display Reddit-hosted images
- https://imgur.com/* and https://i.imgur.com/*: Display Imgur images embedded in saved posts
- http://127.0.0.1:52849/*: Local connection between the extension and the optional local MCP server — this traffic never leaves your computer
Legal Compliance
GDPR Compliance (European Users)
Under the General Data Protection Regulation (GDPR), you have:
- Right to Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to certain processing activities
- Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority
International Data Transfers
We are based in India, and the third-party providers we use to operate Readdit Later are located in other countries, primarily the United States. Your information may therefore be transferred to, stored, and processed outside your country of residence, including in jurisdictions that may not offer the same level of data protection as your own. In particular:
- Supabase (database, cross-device sync, and cloud backup) — hosted on Amazon Web Services infrastructure in the United States
- Vercel (our application/API server) — United States
- OpenRouter, OpenAI, and Anthropic (AI processing) — United States
- Resend (email delivery) — United States
- Dodo Payments (payments), Crisp (support chat), Web3Forms and GitHub Pages (uninstall survey), and Notion (only if you connect it) — these providers may process data outside your country under their own policies
Where we transfer the personal data of users in the European Economic Area or the United Kingdom to countries without an adequacy decision, we rely on appropriate safeguards — such as the Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) incorporated into our providers' data-processing terms — together with those providers' technical and organizational security measures. To request more information about these safeguards, contact us at sanjhaiprakash18@gmail.com.
CCPA Compliance (California Users)
Under the California Consumer Privacy Act (CCPA), you have:
- Right to Know: What personal information we collect
- Right to Delete: Request deletion of your information
- Right to Opt-Out: Opt out of data "sales" (we do not sell data)
- Right to Non-Discrimination: Equal service regardless of privacy choices
Data Processing Legal Basis
We process your data based on:
- Contract Performance: Providing the extension service and premium features
- Legitimate Interest: Improving service quality and security, including first-party usage analytics and preventing payment fraud
- Consent: AI features, AI Tools (MCP) access, the weekly digest and other optional emails, surveys you choose to submit, and optional integrations
- Legal Obligation: Compliance with tax and financial regulations
Transparency Commitment: We believe in complete transparency about data collection. This policy honestly discloses all data we collect, where it is stored, and how you can control it. We will never sell your personal data to third parties.
Acknowledgments
By using Readdit Later, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. Your use of premium features (AI processing, cross-device sync) constitutes consent for the server-side data storage described in this policy. If you disagree with any part of this policy, you may discontinue use and request data deletion.
Questions about this page? Email us at sanjhaiprakash18@gmail.com.
Read our Terms of Service