Privacy Policy

Last updated: 7 October 2026

Readbird is a reading app: it collects articles from the feeds you subscribe to, saves what you want to keep, and stores your highlights and notes. This page explains exactly what is stored, where, and who else can see it.

Short version: your data is stored on servers in the European Union, is readable only by your own account, is never sold, and can be exported or deleted by you at any moment without contacting support. There is no advertising in Readbird; product analytics never sees the contents of what you read or write and can be switched off in the Privacy Centre.

Who is responsible

Readbird is an independent project run by an individual — Sergio Rozum (Germany); the full provider identification is on the Impressum page. There is no company behind it and no data-processing on behalf of third parties. For any privacy question you can write directly to the address at the bottom of this page. A data protection officer has not been appointed, because the law does not require one here.

What data is stored

Readbird stores only what the app needs to work:

  • Account: your email address. If you sign in with Google, Google also passes your name and profile picture — nothing else. Readbird never receives your Google password.
  • Your library: feed subscriptions, folders, saved articles and links, read/unread state, labels, highlights, notes and any images you attach to notes.
  • Settings: reading preferences, theme, language, sorting, filter rules — synchronised between your devices so the app looks the same everywhere.
  • Article content: titles, summaries, publication dates and, for articles you open, the extracted full text. This is public content of the sites you subscribe to, stored once and shared by all readers of that feed.
  • Technical data needed to deliver the service: your IP address is seen by the hosting providers listed below while a request is being served, as it is for any website.

Browser extension

If you install the Readbird browser extension, it acts only when you click its icon or its context-menu entry — there is no background sending and no browsing history is collected.

  • What is sent: the address of the page you save (including its query string) and, for the page you are viewing, its HTML as your browser displays it. This may contain whatever that page shows you. The data goes to Readbird’s servers in the EU (Supabase) together with your session token; the extracted text is stored in Cloudflare R2.
  • What is stored in the extension: a separate Readbird sign-in session issued to the extension when you are signed in on readbird.app (never your password), kept only in the extension’s local browser storage.
  • What is not done: no automatic or background capture, no tracking of other pages, no sale or sharing with third parties.
  • Limited Use: Readbird’s use of data received through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. The data is used only to save the page and show it to you; it is passed only to the processors named in this policy, is never used for advertising, and is not read by people except with your consent, for security purposes or where the law requires it.

What Readbird does NOT do

  • No advertising, no ad networks, no advertising identifiers.
  • No advertising trackers and no third-party tracking. Product analytics (PostHog, see below) counts events and lengths — never the contents of articles, notes, highlights or searches — and stops with one switch in the Privacy Centre.
  • Your reading data is never sold, rented or shared for marketing.
  • No public profiles or share links: saved articles, notes and highlights are private to your account. The only exception is a note to which you yourself invite co-authors: they see that note and nothing else.
  • No third-party cookies. On your device Readbird stores only what the service you asked for strictly needs (§ 25(2) no. 2 TDDDG): your session, your settings, offline copies of your library and images (local database and cache), and — if you add them — your own Gemini key and, if you allow push, a device token. A pseudonymous analytics identifier is stored only after your consent (§ 25(1) TDDDG).
  • One first-party cookie, rb_app=1 (strictly necessary, no personal data, kept for one year): it only tells our server to open the app instead of the welcome page when you visit readbird.app. Deleting it simply shows the welcome page again.

Where the data is stored, and who processes it

Readbird uses a small number of providers, each for one clearly defined job:

  • Supabase (database and authentication) — project hosted in the EU (Frankfurt). Stores your account, library and settings.
  • Cloudflare (website hosting, CDN and R2 object storage) — serves readbird.app and stores extracted article texts.
  • Images from our own address — preview frames of YouTube videos and website icons of feeds are downloaded by our server and served from feeds.readbird.app (Cloudflare). Until you allow YouTube in the Privacy Centre, your browser therefore does not contact Google or YouTube for them; our server fetches them itself, without any information about you. Preview frames are kept for at most 30 days and are then deleted or refreshed; if a video is no longer available, its copy is deleted. Legal basis: our legitimate interest in showing feeds without connecting your browser to Google (Art. 6(1)(f) GDPR). Rights holders can ask us to remove a copy at support@readbird.app.
  • Cloudflare Web Analytics (page speed and visit statistics) — only if you switch on “Analytics” in the Privacy Centre (your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG). A small script from Cloudflare then measures how fast pages load and reports page views, country, browser and device type — without cookies and without browser fingerprinting; we only see aggregate numbers. Without your consent the script is not loaded at all. You can withdraw consent at any time in the Privacy Centre; the script is then no longer loaded.
  • Cloudflare Turnstile (bot protection on the sign-in form) — checks that the form is filled in by a person; Cloudflare receives the technical data of that request. Legal basis: our legitimate interest in protection against abuse, Art. 6(1)(f) GDPR.
  • Visit counter on the landing page (our own) — when you open readbird.app, our server counts the visit using only what arrives with the request anyway: the domain of the page you came from, campaign labels in the link (utm_source, utm_medium, utm_campaign), whether the page was opened inside another app, the type of device (phone, tablet or computer) and the country, which our hosting provider Cloudflare derives from the connection. In our database we keep only a daily total per combination — no IP address, no browser name or version, no full address, no time of day and no identifier. Nothing is stored on or read from your device, the totals are not linked to any account, and we keep nothing that would let us single out an individual visitor. Legal basis: our legitimate interest in knowing where visitors come from (Art. 6(1)(f) GDPR).
  • Google — only if you choose “Sign in with Google”. Google tells Readbird your email, name and profile picture.
  • Push notifications — only if you allow them. In the Android app they are delivered through Google Firebase Cloud Messaging, in the browser through the push service of your browser vendor. We store a device token or push endpoint with its keys and the browser identifier; legal basis Art. 6(1)(b) GDPR (the notifications you asked for). They are removed when you turn notifications off or delete your account.
  • Microsoft Azure Translator — receives the text of an article only at the moment you press “translate”, translates it and returns the result. Nothing is sent automatically.
  • Resend (delivery of service emails) — sends the emails Readbird itself has to send you: sign-up confirmation, password reset and confirmation of an email change. Resend receives the recipient address and the message and keeps delivery logs for 30 days. Messages are sent from an EU region (Ireland); the account and log data of the service are stored in the USA (see below).
  • Google Gemini — only if you add your own Gemini API key in Settings and then open the “Transcript” tab of a video, use the search summary or ask a question about a video. Your device then sends the request to Google; the key stays on your device and the request does not pass through our servers. For a search summary the found articles are sent, and your own notes and highlights only after a separate confirmation.
  • Google Lens — only when you yourself tap the Google Lens action on a photo: the address of that photo is then passed to Google.
  • Images in articles — your device loads them directly from the publisher’s server, which therefore sees your IP address. For offline mode the app can also preload such images in the background.
  • Sentry (error diagnostics, EU region) — receives a technical error report when something breaks. Session Replay and performance tracing are switched off, so the contents of your screen are not transmitted. Reports include the browser and operating system name and version (from the User-Agent), but neither your IP address nor account identifiers, and are deleted automatically after at most 90 days. Sentry keeps a public list of its own subprocessors at sentry.io/legal/subprocessors. Where an error report reads information from your device, this is strictly necessary to provide a stable and secure service (§ 25(2) no. 2 TDDDG); legal basis: Art. 6(1)(f) GDPR.
  • PostHog (product analytics, EU Cloud) — receives pseudonymised events about how the app is used: which sections are opened, how long an article was read, where people get stuck. Never the contents of articles, notes, highlights or search queries — only lengths, counters and flags. Events reach PostHog by two routes, and both only with your consent (Art. 6(1)(a) GDPR): you must have switched on “Analytics” in the Privacy Centre. From your device: the events of your own use. From our server: a small set of events about actions you take after you gave consent (saving an article, creating a note or highlight, subscribing to a feed, sending a report), keyed to your account identifier. Switching “Analytics” off in the Privacy Centre stops BOTH routes and withdraws your consent (Art. 7(3) GDPR). From your IP address PostHog determines an approximate location (country, region, city, postcode and approximate coordinates); the IP address itself is discarded and not stored with the events. Events are deleted after 12 months; if you withdraw your consent or delete your account, we also delete the events linked to your account ID at PostHog, within 30 days at the latest. Session recording, autocapture and heatmaps are not used at all: Readbird sends every event explicitly, without their SDK.
  • YouTube — when an article contains an embedded video, the player is loaded from YouTube and YouTube sees that request, exactly as on any site with an embedded video.

Feedback and support

There are two ways to write to us, and they collect different amounts of data. Inside the app, “Report a problem” attaches your account so we can follow up; the public form at /contact needs no account at all, and only the message itself is required — name and email are optional, and without them the message is not linked to any person.

What we process: the text you write (up to 4,000 characters), the category, the contact details you choose to give, and technical context such as app version, platform, language and the screen involved. We do not store your IP address: to stop spam the form keeps only a salted, irreversible hash of it, and that hash is erased after 7 days.

Legal basis: Art. 6(1)(b) GDPR for handling your support request, and Art. 6(1)(f) GDPR for evaluating ideas and improving Readbird — you may object at any time under Art. 21 GDPR. Messages sent through the public form are deleted after 24 months at the latest.

Please do not put other people’s personal data or particularly sensitive information into the message. If you delete your account, reports you sent from inside the app remain as anonymous records — your account link is removed, but the text stays, because a report may concern a complaint that has to outlive the account.

Transfers outside the EU

Your library — articles, highlights, notes, settings — is stored on servers in the European Union (Frankfurt). Some of the providers above are US companies, so a limited technical slice of data can reach the United States:

The legal basis for these transfers is the EU-US Data Privacy Framework — an adequacy decision of the European Commission (Art. 45 GDPR). Should it ever be invalidated, the providers below fall back to the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). We review this section whenever the legal situation changes.

  • Cloudflare, Inc. (USA) — serves the website, stores extracted article texts (R2) and, only with your consent, processes page-speed and visit statistics (Web Analytics, cookie-free). Certified under the Data Privacy Framework, with Standard Contractual Clauses on top.
  • Google (Ireland / USA) — only in the moments described above: signing in with Google, loading an embedded YouTube player, push delivery in the Android app (Firebase Cloud Messaging), Google Lens on your tap, or Gemini with your own key. Google LLC is certified under the Data Privacy Framework.
  • Microsoft (Azure Translator) — the text of an article you chose to translate. Certified under the Data Privacy Framework, with Standard Contractual Clauses on top.
  • Resend, Inc. (USA) — delivers Readbird’s service emails (sign-up confirmation, password reset, email change). Messages are sent from an EU region (Ireland); the account data and delivery logs are stored in the USA. Certified under the Data Privacy Framework, with Standard Contractual Clauses incorporated into its Data Processing Addendum.
  • Supabase — your data is stored in Frankfurt (EU). Our contract partner is Supabase Pte. Ltd (Singapore); should the company or its affiliates access data from outside the EU (for example, for technical support), the Standard Contractual Clauses in its Data Processing Addendum apply.
  • PostHog, Inc. (USA) — the events themselves stay in the EU Cloud (Frankfurt); only technical metadata of our account is processed in the USA. PostHog participates in the Data Privacy Framework; Standard Contractual Clauses apply as a fallback under its Data Processing Addendum.
  • Sentry (Functional Software, Inc., USA) — the error reports themselves stay in Frankfurt (EU); only technical metadata of our developer account is processed in the USA. Sentry relies on the Data Privacy Framework, with Standard Contractual Clauses applying automatically if it lapses.

Legal basis and purpose (GDPR)

  • Performing the service you asked for — Art. 6(1)(b) GDPR: account, subscriptions, saved articles, notes, synchronisation of settings.
  • Legitimate interest — Art. 6(1)(f) GDPR: keeping the service secure and diagnosing errors; delivering the app and its images quickly and reliably through a content delivery network (Cloudflare, without cookies or scripts of its own); protection against abuse at sign-in (Turnstile). You may object at any time under Art. 21 GDPR by writing to support@readbird.app.
  • Legitimate interest — Art. 6(1)(f) GDPR: an internal count of the days on which you used Readbird (read, saved, wrote a note or highlight, subscribed), so that we know how many people actually use it and how often to refresh your feeds (feeds nobody has opened for a long time are refreshed less often). Only your account identifier and the date are stored — no contents; the data stays in our database in the EU, is not passed to anyone, and is deleted after 400 days or together with your account. Switching “Analytics” off removes you from our usage statistics; the days themselves are still stored for the refresh rate. To object under Art. 21 GDPR, write to support@readbird.app.
  • Consent — Art. 6(1)(a) GDPR: optional features you switch on yourself, such as translating an article with an external service, embedded players from other platforms, or product analytics.

How long data is kept

Your account data is kept until you delete it. Deleting your account removes your library, notes, highlights, settings and the account itself immediately and irreversibly.

Article records from public feeds are cleaned up automatically after a retention period, independently of individual accounts.

Product analytics at PostHog: events are deleted after 12 months; on withdrawal of consent or deletion of your account they are deleted earlier (see above).

Your rights

Under the GDPR you can access, correct, export, restrict or delete your data, and object to its processing. Two of these are built into the app and need no request:

  • Export: Settings → “Download my data” gives you everything in JSON and Markdown.
  • Deletion: Settings → “Delete account”, or the public page /delete-account.
  • Withdrawal of consent: you may withdraw any consent at any time with effect for the future (Art. 7(3) GDPR), for example in the Privacy Centre.
  • You also have the right to complain to a data protection authority in your country.

Children

Readbird is not directed at children under 16.

Changes to this policy

If the way Readbird handles data changes, this page is updated together with the change, and the date at the top of the page changes with it. The German version of this policy is authoritative; the translations are provided for convenience.

Contact

Questions about privacy, export or deletion: support@readbird.app

← Back to login