Privacy Policy

Core reading and editing are local-first. Optional AI only receives document context when you choose to use it.

Effective August 3, 2026 · Readlet 2.3 and Companion 2.4

No ads or data sale

Readlet does not sell personal information, build advertising profiles, or include tracking inside the extension.

Local-first core

PDF rendering, OCR, annotations, forms, signatures, and exports run on your device.

AI only when requested

Prompts and relevant document context go through the local companion to your ChatGPT account only after you ask.

Everything you need to know

1 Introduction

Readlet is a PDF reading and editing workspace available as a web app and Chrome extension. Its core reader is designed to work on your device. Readlet AI is optional and uses a separately installed local companion.

The short version: ordinary reading, OCR, editing, form filling, signatures, and export happen locally. If you use Readlet AI, the question and the document context needed to answer it are sent through Readlet Companion to OpenAI under the ChatGPT account you connect. Readlet does not run an advertising profile or sell personal information.

2 Information We Collect

Readlet does not require a Readlet account. The app keeps the following information on your device so its features can work.

What Readlet does not do

No hidden business model
Sell personal information
Build advertising profiles
Track unrelated browsing activity
Run in-extension advertising analytics
Use data for credit decisions
Read files you have not opened

Stored on your device

Locally on your device
Reading history and position
Preferences and recent documents
AI chat history and diagnostics
Vault entries and saved signatures

Local data can be cleared from Readlet or your browser. The vault can be protected with a passcode; without one, it is stored locally without vault encryption. Exported backups are plain files, so keep them somewhere safe.

3 How We Use Information

Readlet uses information in two distinct ways:

  • Core PDF features: PDF rendering, OCR, search, annotations, forms, signatures, page operations, and export run in your browser.
  • Remote PDF loading: When you open a PDF from the web, Readlet requests it from the website hosting it. That site receives the normal request information, such as your IP address and browser headers.
  • Optional Readlet AI: When you ask a question, Readlet sends your prompt and relevant document text, page images or visual crops, recent conversation context, and any form values needed for the requested action to the local companion. The companion passes that request to OpenAI using your connected ChatGPT account.
  • Companion updates: Readlet checks a public GitHub release manifest to tell you when a newer companion is available.

Readlet AI does not run merely because the sidebar is visible. It sends document context only after you make an AI request or approve an AI-assisted form action.

4 Data Storage

Readlet stores product state in browser storage and IndexedDB. This may include:

  • Appearance, zoom, and reading preferences
  • Recent-document history, page position, and cached local files
  • Locally saved AI chats and generated chat titles
  • Diagnostics used for troubleshooting
  • Vault entries, profiles, and signature images

You can clear this information from Readlet or through browser settings. Uninstalling the extension normally removes its browser storage. A passcode encrypts the vault at rest; other local Readlet data is not presented as encrypted storage. Vault exports are unencrypted JSON files by design.

5 Third-Party Services

Readlet interacts with third parties only where a feature requires it:

  • OpenAI: Optional Readlet AI requests are handled through your ChatGPT account. Readlet does not ask you to enter your ChatGPT password into the extension. OpenAI's privacy policy applies to that processing.
  • Document hosts: Opening a remote PDF contacts the website that serves that file.
  • GitHub: Companion update checks and downloads use public GitHub release files. GitHub receives normal request metadata under its privacy statement.
  • Hosting and store analytics: This website is hosted by GitHub Pages, and the Chrome Web Store may provide aggregate listing and installation information. Readlet itself does not include advertising or cross-site tracking. Google's privacy policy applies to Chrome and the Chrome Web Store.

6 Permissions Explained

Readlet requires a few Chrome permissions to work properly. Here's exactly what each one does and why we need it:

webNavigation

Lets us know when you're opening a PDF so we can display it in Readlet instead of Chrome's basic viewer.

webRequest

Helps us detect PDFs that don't have ".pdf" in the URL. Some websites serve PDFs without obvious filenames, so we check the file type to catch these.

activeTab

Gives Readlet access to your current tab when you click our icon, so you can open PDFs with a single click.

scripting

Allows Readlet to inspect the active page after you click the extension, so it can locate a PDF embedded in that page.

storage

Keeps your preferences, reading history, local chat history, and vault on this device.

nativeMessaging

Connects to Readlet Companion on your computer when you choose to use Readlet AI. The reader works without the companion.

Access to websites

Allows Readlet to load and display PDFs from any website. Without this, browser security would block us from showing PDFs hosted on external sites.

These permissions support PDF detection, loading, local settings, page integration, and the optional companion. Readlet does not use them to build a history of unrelated browsing.

7 Data Security

Readlet reduces exposure by keeping its core workflow local:

  • Local core: Rendering, OCR, editing, forms, and signatures do not require a Readlet cloud account.
  • Optional vault encryption: Setting a vault passcode protects vault contents at rest using browser cryptography.
  • Scoped AI use: Only context required for a request is selected for Readlet AI, and the companion runs locally.
  • Diagnostic redaction: Readlet attempts to remove common sensitive patterns from downloadable diagnostics, but you should still review a diagnostic file before sharing it.

No software can promise absolute security. Keep Chrome and Readlet up to date, protect your device account, and use a vault passcode for sensitive saved information.

8 Children's Privacy

Readlet is a general-purpose PDF tool and is not directed to children under 13. A parent, guardian, school, or organisation should decide whether optional AI processing is appropriate for a child and should review OpenAI's applicable terms.

If you believe a child has provided information through Readlet in a way that requires action, contact us using the details below.

9 Chrome Web Store Compliance

In accordance with Chrome Web Store Developer Program Policies:

No Sale of Data: We do not sell or transfer user data to third parties for any purpose.
Product functionality only: Information accessed is used to load, read, edit, search, or answer a request about the PDF you opened.
No Creditworthiness Use: User data is not used for creditworthiness or lending purposes.

10 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or for legal reasons.

  • The "Last Updated" date will be revised when changes are made
  • Significant changes will be noted in the Chrome Web Store listing
  • We encourage you to review this policy periodically

Continued use of Readlet after changes indicates acceptance of the updated policy.

11 Contact Information

If you have questions about this Privacy Policy or our data practices, we're happy to help.

Questions? We're Here to Help

Have questions about privacy or how Readlet handles your data? Drop us a line.

or find us at
Developer codernoel
Website codernoel.com