Privacy Policy
Effective Date: July 13, 2026
Last Updated: July 13, 2026
Entity: Enid Ltd ("CastReader", "we", "us", or "our")
Service: CastReader mobile apps, browser extensions, website at castreader.com, and production API at api.castreader.ai (collectively, the "Service")
This policy explains what CastReader processes, why it is needed, and the choices available to you. Data handling varies by workflow: some extraction happens on your device, while speech, account, document, explanation, and private voice-cloning features require service processing.
1. What CastReader Does
CastReader provides Read Aloud and Read & Explain workflows for supported webpages, books, PDFs, DOCX and EPUB files, images or screenshots, and pasted text. Its official surfaces include iPhone and iPad, Android, Chrome, Edge, and selected web account or upload workflows.
CastReader does not bypass DRM, paywalls, source permissions, or access controls. You should submit only content you are authorized to access and process.
2. Data We Process
2.1 Account Data
Free browser listening can begin without an account. An email login is required to purchase or manage Pro and to align Pro entitlement across supported surfaces. Depending on the sign-in provider, we may process:
- account ID and provider ID;
- email address;
- display name and profile image supplied by the provider;
- authentication session and security metadata; and
- subscription status and account-to-device links.
We use this data for sign-in, account security, entitlement checks, customer support, and cross-platform Pro consistency. Pro is tied to the login email, not to an anonymous device alone.
2.2 Device and Product Analytics
CastReader may create a random device identifier and process product events such as installation, session start, reading start or end, feature use, navigation to pricing, checkout progress, and errors. Event properties can include app or extension version, source surface, content type, coarse website hostname, funnel identifier, and non-sensitive diagnostic context.
We use this information to operate the Service, diagnose failures, measure product funnels, prevent abuse, and improve supported workflows. We do not intentionally include the full text of your reading content in analytics events.
2.3 Reading and Explanation Content
The content needed for your requested workflow may be processed to extract text, perform OCR, synthesize speech, synchronize highlighting, or generate an explanation. Depending on the surface and source:
- some page extraction or OCR can happen locally on your device;
- text needed for speech is sent to api.castreader.ai;
- uploaded files or library records can be stored when the workflow requires later access, history, progress, or deletion controls; and
- Read & Explain sends the relevant source text and instructions to the configured model service.
CastReader does not turn private user content into public SEO pages by default and does not use private reading content to build a public voice catalog. Availability, storage, and deletion behavior vary by workflow; the product interface and support team can identify the controls available for a particular item.
2.4 Voice Preferences and Private Voice Cloning (Coming Soon)
Preset voice selection, favorites, and recent choices may be stored locally or with the authenticated account, depending on the client.
Private voice cloning is not generally available in the public CastReader experience yet. It is marked Coming soon. Limited approved pre-release testing may use the prepared workflow, and the following terms also describe how the feature is designed to operate when publicly launched. That workflow processes:
- a 3–30 second WAV or FLAC reference recording, up to 4 MB at the public gateway;
- explicit confirmation that the user owns the voice or has the required rights and consent;
- an account-scoped clone ID, lifecycle state, reference hash, consent version, and creation-limit record; and
- generated speech requests made with the owned clone.
For approved pre-release access and the planned public launch, reference audio is encrypted with AES-256-GCM before object storage. Stored reference objects contain ciphertext, and access is checked against the authenticated account. Private clones can be listed, previewed, selected, and deleted by the owning account. They are not added to the public voice catalog or indexed as public pages. The prepared contract allows one successful creation per user in a rolling 24-hour period.
Do not submit another person's voice without the necessary rights and explicit consent. Do not use CastReader to impersonate, deceive, defraud, or falsely attribute speech to another person.
2.5 Payments
Subscription checkout and billing management are handled by Stripe. Stripe processes payment-card and supported payment-method details under its own privacy terms. CastReader receives billing identifiers, plan and subscription status, transaction state, and limited billing contact details needed to provide Pro and support the account. CastReader does not receive or store your full card number.
3. Browser and Mobile Permissions
CastReader requests only permissions needed by the installed surface. Examples include access to the active browser tab for user-initiated extraction, extension storage for settings, microphone access for a user-initiated voice reference recording, and photo or file access when you choose content to import. Operating-system and browser permission screens show the permissions requested by your installed version.
The production TTS and voice services use api.castreader.ai; the canonical website, account, analytics, and billing surfaces use castreader.com.
4. How We Use Data
We process data to:
- provide speech, extraction, highlighting, progress, explanation, account, and private voice features;
- authenticate users and keep Pro entitlement aligned;
- process payments and manage subscriptions;
- secure the Service, enforce rate limits, and prevent fraud or misuse;
- diagnose reliability and compatibility problems;
- answer support requests; and
- comply with legal obligations and enforce our Terms of Service.
We do not sell personal data or private reading content. We do not use private reading content or private cloned voices for advertising.
5. Service Providers
We use service providers for infrastructure, authentication, payments, analytics, speech, and model processing. They receive only the data needed for the requested function and process it under their own terms and our applicable agreements. Key public dependencies include Stripe for payments and the model or infrastructure providers required by the selected speech or explanation workflow.
6. Storage, Retention, and Security
We use HTTPS in transit, access controls, account ownership checks, and operational safeguards appropriate to the workflow. Private voice reference audio is encrypted before object storage. No system is completely secure.
Retention depends on purpose:
- authentication, subscription, consent, security, and transaction records are kept as needed to operate the account and meet legal obligations;
- analytics and operational logs are retained for product, security, and reliability needs;
- uploaded items, histories, and progress records remain according to the workflow and available deletion controls; and
- private cloned voices and their active reference data remain until deleted, the account is closed, or retention is otherwise required for security or legal reasons. Deletion from active systems may not immediately remove encrypted backups.
7. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data. You can also:
- use supported free browser workflows without creating an account;
- sign out or remove an account-device link;
- clear local app or extension storage;
- delete supported uploaded items or private cloned voices through the relevant client;
- manage or cancel a subscription through the account page and Stripe; and
- contact us to request account or privacy assistance.
We may need to verify your identity before completing a request.
8. Children
CastReader is not directed to children under 13, or the minimum age required in the user's jurisdiction, and we do not knowingly create accounts for children who cannot legally consent. Contact us if you believe a child has provided personal data improperly.
9. International Transfers
CastReader and its service providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers.
10. Changes to This Policy
We may update this policy as products, laws, or service providers change. We will publish the updated date here and provide additional notice when required.
11. Contact
For privacy questions or requests:
- Email: support@castreader.com
- Website: https://castreader.com