← Back to Lumotext

Privacy Policy

Updated 24 September 2026

Lumotext reads things aloud. There are three ways to use it — a browser extension, a web app, and an iOS app — and this policy describes exactly what each one stores and what it sends. They differ in one way worth stating up front: the extension works with no account at all, while the web app and the iOS app each require a free one, because both open onto a library that has to belong to you rather than to one browser on one machine.

The short version

The extension, signed out — which is its default: Lumotext has no analytics. It makes no network requests to us or to anyone else — the only requests it makes on its own go to the site you are already on: the page's icon, to show in the player, and on Google Docs the document's own plain-text export from Google, because Docs draws the document as a picture and that export is the text. Nothing you read is collected, transmitted or sold by us.

The web app, signed out: it works without an account — paste or type something and listen. Nothing is uploaded, nothing is stored on our side, and your voice, speed and highlighting settings stay in your own browser. An account is only asked for when you reach for something that needs one: saving to a library, importing a file, or reading above 2×.

The web app, signed in: reading still happens entirely inside your browser — the text you listen to is never uploaded to us. What the account holds is your email address, the documents you deliberately save to your library, your reading settings, and one number: how many words you have had read aloud. That is the whole of it.

The extension, signed in: Lumotext syncs that one number — the running count of words you've had it read aloud — to your account, so it's visible in the web app regardless of which of the two you used to read. Signing in and out both happen in the web app, never in the extension itself; the extension only ever receives a copy of the session needed to report that count. No page content, no URL, no title, and no browsing history is ever included.

The iOS app: it needs an account, and it is the surface that sends the least — no analytics of any kind, no advertising identifier, no tracking. Reading happens on the phone, using the voices already installed on it. Apart from your own account, the only things it ever contacts are the sites you point it at yourself. It has its own section below.

Five things deserve their own sections, and they're below: the iOS app, what the account itself holds, the companies we rely on to run the service, the words-read sync above, and some of the voices your browser offers being synthesised online by the browser vendor.

Your account, and why the web app asks for one

The web app keeps a library: documents you save, and where you stopped in each. That has to live somewhere other than one browser on one machine, or it would not survive a new device, a cleared cache, or the extension and the web app being two different programs. An account is what makes a library yours rather than that browser's, so the web app asks for one before it opens.

What we hold for an account:

  • Your email address — the only thing you are asked for. There is no password: signing in sends a one-time link to that address. We use it to identify your account and to send those links. We do not send marketing email, and we do not share or sell the address.
  • If you sign in with Google instead — Google tells us your email address, your name and the address of your Google profile picture, and gives us an identifier for your Google account. That is the whole of what Google sends; we ask it for nothing beyond your basic profile and email, and we never receive your Google password or gain any access to your Gmail, Drive or other Google data. The name and picture are stored on your account record but are not shown anywhere in the app today — only the email is used. Using Google is optional; the email link works just as well.
  • The documents you save — their title, text, any tags you add, and, for a page saved from the extension or added by its address in the iOS app, that address. These are the ones you press Save on. Nothing you merely read is stored.
  • The original PDF, if you ask for it — when you save a PDF, the web app offers to keep the file itself alongside the text it pulled out of it. That is what lets you reopen it later as the document it actually is, pages and layout intact, rather than only its text. It is a tick box at the moment you save, it applies to that one file, and unticking it means only the text is uploaded. A kept file is stored privately: it is never public, never given a shareable address, and is reachable only through a link that is made when you open it and expires about a minute later. You can see how much you are storing in the account panel, and the file is deleted when you delete the document. EPUBs are text-only either way.
  • Your reading settings and your place — voice, speed, highlighting choices, and how far through each saved document you got.
  • One number — the running count of words read aloud, described below.
  • Which plan you are on — currently "free" for everyone, along with its status and renewal date. Lumotext does not charge for anything yet and we take no payment details; these fields exist so that paid plans can be added later without altering your account.

We do not log what you read — no analytics tool ever sees document content, page text, or anything you have Lumotext read aloud. The web app uses Google Analytics to see aggregate usage of the site itself (which pages get visited, roughly how many people use it) — see below. The extension has none of this, signed in or out, and runs no analytics or advertising of any kind.

Deleting it: deleting a document removes it, along with the original file if one was kept. To delete the whole account, open the account panel in the web app and choose Delete account. It is immediate and it is final: your sign-in record, your saved documents, your settings and your word count are all removed together, and there is no undo and no recovery window. You do not need to ask us, and nothing is retained afterwards beyond what the law requires us to keep.

The extension needs none of this. Used signed out — its default — it has no account and sends nothing to us.

The companies we rely on

Lumotext is a small operation and does not run its own datacentre. A handful of companies are involved in running it, and each sees only what its job requires. None of them is given your reading, your saved documents, or your account data for their own purposes.

  • Supabase — hosts the database your account and library live in, handles signing in, and sends the sign-in link emails. Everything described in the section above is stored there, on servers in the United States.
  • Cloudflare Turnstile — the "verify you're human" checkbox on the sign-in and waitlist forms. It exists because those forms can be submitted without an account, which makes them the obvious thing for a bot to hammer. To make that judgement Cloudflare receives your IP address and signals about your browser, under Cloudflare's privacy policy. Turnstile does not use cookies to track people across sites. We see only its yes-or-no answer.
  • Google — only if you choose "Continue with Google", and only for that sign-in, as described above.
  • An icon service — web app only. When your library shows the icon of a site a page was saved from, the web app asks an icon service for that icon. The only thing that service receives is the address of the site; never your documents, your account, or anything you have read. The extension and the iOS app do not use it — they request the icon from the source instead.
  • Google Analytics — web app only; the extension cannot load remote scripts at all, so it has no analytics regardless of sign-in state. It sees which pages of lumotext.com get visited and ordinary visitor information (device, browser, approximate location from IP), the same as any website's traffic analytics. It never sees the text of what you read, your saved documents, or your email address. Google's own policy governs what it does with that data: policies.google.com/privacy.

We do not sell or rent personal information to anyone, and we have never done so.

The mobile waitlist

The web app does not work well on phones — mobile browsers rarely offer a voice worth listening to — so when it can't find a usable one it offers to email you when that changes. On iPhone the iOS app is that answer, and the list now exists for everyone else. If you enter an address there we store that address, a note of which form it came from, and the browser's user-agent string — kept only to tell one kind of device from another, and because it is what lets us spot a flood of fake signups. This is separate from having an account, and the only email it will ever be used for is the one it was collected for. To be removed from it, write to privacy@lumotext.com.

The iOS app

The iOS app is the third way to use Lumotext and the one that sends the least. It carries no analytics — none of the site analytics described above runs in it — no advertising identifier, and no tracking of any kind. Apart from your own account, the only things it ever contacts are the sites you point it at yourself.

It needs an account, because it opens onto your library. Everything under Your account above applies to it, with one addition:

  • If you sign in with Apple — Apple gives us an identifier for your Apple account and, on the first sign-in only, your email address and name. If you choose Hide My Email, what reaches us is a relay address that forwards to you; we never see your real address and we cannot ask for it. As with Google, this is optional — the email link works just as well.

Saving a link. You can give the app a web address and it will save that page to your library. The app fetches the page from the site itself, the same way a browser would: it is not sent to us, to a reader service, or to anything in between. It is fetched without cookies and without any browser session, so a page behind a sign-in will not come through — which is the trade for never touching one. Nothing is kept unless you press Save, and what is saved is what is saved for any other document: title, text, and the address it came from.

Site icons. When a saved page shows the icon of the site it came from, that icon is requested from the source — the site's own address — and nothing about you, your library or your account goes with the request.

Dictation. You can speak a document instead of typing it. This uses the microphone and Apple's speech recognition, and the app requires the on-device mode: the audio becomes text on your phone and is never sent to Apple's servers, or to us. The microphone is live only while you are dictating, nothing is recorded or kept, and what it produces is text you can edit before anything is saved. If your phone cannot do recognition on-device, dictation is unavailable rather than falling back to sending audio away.

Your settings — voice, speed, text size, highlight colour, light or dark — are stored on the phone. Your place in each saved document syncs to your account, so a listen you start on the phone continues on the web.

PDFs and files you import are read on the phone. As in the web app, the text is what is saved; an original file is only kept if you ask for it, under the same terms described above.

What Lumotext stores, and where

In the extension, everything is stored locally by your browser, using the standard extension storage API. None of it is transmitted to the developer.

Settings (storage.sync) — your chosen voice, language filter, reading speed, highlight preferences, whether to read footers and menus, whether to keep reading while the tab is hidden, and whether hover-to-read and click-to-read are switched on. If you have browser profile sync switched on, your browser syncs these between your own devices the same way it syncs bookmarks. That transfer is handled by your browser and its account, not by Lumotext.

Reading positions (storage.local) — so you can pick up where you left off. For each page you have listened to, Lumotext records the page URL and title, how far through it you were, and when. This never leaves your computer. Selecting "Start over" on the resume prompt deletes that page's entry. Clearing the extension's storage, or uninstalling it, deletes all of them.

Lumotext does not read, store or transmit form fields, passwords, cookies, or the content of pages beyond turning visible text into speech in the moment you ask it to.

The caveat: words-read sync (only if you sign in)

Signing in happens in the companion web app, never in the extension — there is no password field there and never will be. Once you're signed in, the web app hands the extension a copy of that session (an access token, tied to your account) so the extension can report to the same running count the web app shows. This happens over a private browser-to-extension channel restricted to the web app's own address; no other website can reach the extension this way.

While signed in, the extension:

Signing out — from the web app's account page, or from the extension's toolbar popup — clears that stored session immediately and stops any further sending. It also revokes the session everywhere it was used, not just on this device.

If you never sign in to the extension, none of this section applies to it: it sends nothing anywhere, exactly as described above. Signing in is required for the web app, and optional for the extension.

The caveat: online voices

Lumotext does not synthesise speech itself. It hands text to the speech engine your browser already provides (speechSynthesis) and that engine decides how to produce the audio. Which engine you get depends on the voice you choose:

Lumotext labels these in the voice picker under the group heading Natural (online) so the choice is visible rather than buried. If you want nothing to leave your machine, pick a voice from the Premium, Enhanced or Standard groups.

Permissions, and why each is needed

Saving a page to your library (only if you sign in, and only when you press Save): the "Save to your library" button sends that one page's title, address and readable text to your own library in the web app, so you can listen to it later there. This happens only when you press the button, never automatically, and never while signed out. It is the one exception to "no page content, no URL, no title" above — and it is your choice, per page.

The words-read sync feature adds no new permission: it uses the access already granted to the extension's own background script, restricted on our end to our own web app's address (externally_connectable in the manifest — the browser enforces that no other site can use this channel).

Limited Use

Lumotext's handling of user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:

In the extension signed out, these commitments cost nothing extra to keep: it sends nothing to us or to any third party, so there is nothing to transfer, sell, advertise against, or read. Signed in, the only thing that ever leaves the device is the integer described above, plus any page you deliberately press Save on.

Your rights over what we hold

Everything we hold about you is visible in the web app: your library is the documents, the account panel shows your email, your plan and your word count. You can edit or delete any document, and delete the entire account, yourself, at any time — see above. If you would like a copy of your data in a portable form, or you want something corrected that you cannot change yourself, write to privacy@lumotext.com and we will deal with it within 30 days.

Depending on where you live you may have further rights over your personal information — to access it, correct it, delete it, object to its use, or complain to a regulator. Lumotext is operated from the United States and your data is stored there. The same address above reaches us for any of these.

Children

The extension collects no personal information from anyone, including children.

The web app is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child under 13 has created one, write to privacy@lumotext.com and we will delete the account and its contents.

Changes

If this policy ever changes, the new version will be published here and the date above will be updated.

Contact

Questions about this policy: privacy@lumotext.com.