Privacy Policy

Last updated: 2026-06-20

1. Controller

This Readfine instance is operated by Jakub Libík, reachable at [email protected]. The operator is the data controller within the meaning of the GDPR.

2. Data we collect

Data Purpose Legal basis
Email address Account identification, password reset, briefing emails Art. 6(1)(b) GDPR
Display name Personalisation of the interface Art. 6(1)(b) GDPR
Password (bcrypt hash) Authentication Art. 6(1)(b) GDPR
Feed subscriptions & reading history Providing the reader service, AI features Art. 6(1)(b) GDPR
Timezone preference Date/time display and scheduled briefings Art. 6(1)(b) GDPR
IP address & user-agent Security, abuse prevention (server logs) Art. 6(1)(f) GDPR

We do not collect analytics, advertising data, or sell data to third parties.

3. AI features

AI features (article summaries, briefings, scoring, chat) are optional and can be enabled or disabled in Settings → AI. To use them you provide your own API key for the AI provider of your choice (Anthropic, OpenAI, or Google). Your key is stored encrypted, is used only to make requests on your behalf, and can be deleted at any time.

When you use these features, article content (and, for chat, your messages) is sent to the AI provider you configured. Under the standard paid API terms of Anthropic, OpenAI and Google, your content is not used to train their models. Exception: Google's free Gemini API tier may use your prompts and the generated responses to improve Google's products. To keep your content out of training, use a paid Gemini key or another provider.

4. Cookies

This service uses a single session cookie to keep you signed in. This cookie is strictly necessary for the service to function and does not require your consent (Art. 5(3) ePrivacy Directive; GDPR Art. 6(1)(b)). No tracking, analytics, or advertising cookies are used.

5. Data retention

Your data is stored for as long as your account is active. When you delete your account, all personal data (feeds, articles, labels, filters, briefing history) is permanently deleted immediately. Server logs may be retained for up to 30 days for security purposes.

6. Your rights

Under GDPR you have the right to:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data (via Settings → Profile).
  • Erasure: delete your account and all data (via Settings → Profile → Danger zone).
  • Portability: export feed subscriptions via Settings → Feeds → Export OPML.
  • Object: object to processing based on legitimate interest.

To exercise rights not available in the interface, contact [email protected]. You also have the right to lodge a complaint with your local supervisory authority.

7. Contact

Jakub Libík
[email protected]