Privacy Policy

Last updated: August 7, 2026

1. Introduction

Welcome to Nook ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our reading application and services.

This policy applies to all information collected through our website, mobile application, and any related services, sales, marketing, or events (collectively, the "Services").

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name, and password when you create an account
  • Profile Information: Optional profile details you choose to provide
  • Content: Articles, documents, and reading materials you import into Nook
  • Reading Data: Bookmarks, highlights, notes, and reading progress
  • Payment Information: Billing details processed securely through Stripe
  • Communications: Messages you send to our support team

2.2 Information Collected Automatically

  • Usage Data: How you interact with our Services, including reading patterns and preferences
  • Device Information: Device type, operating system, and browser type
  • Log Data: IP address, access times, and pages viewed
  • Cookies: Session cookies for authentication and preferences

2.3 Browser Extension Data

If you use our browser extension:

Data Sent to Nook Servers

  • Article Content: When you save an article, we extract and send the article text, title, author, and source URL to provide our reading features
  • Subscription Queries: We check your subscription status to display usage limits
  • Detected Article Addresses: When the extension identifies a page as a readable article, we send that page's address and title so we can measure whether our detection is working. This happens when the article is detected, not only when you save it
  • Feature Usage: Which reading tools you use and for how long, together with the address of the page you used them on

Data Stored Locally on Your Device

  • Authentication Data: Your user ID, email, display name, and session tokens are stored locally to keep you signed in
  • Recent Imports: The last 10 articles you imported (title, URL, file ID) are stored locally for quick access

Page Analysis

To detect readable articles, the extension analyzes page structure when you visit websites. This analysis happens on your device and includes checking for article elements, headings, and paragraph content. The page's text and HTML are never sent to our servers unless you choose to save or summarize it. The outcome of the analysis, and the address of the page it ran on, may be sent as described above and below.

Browsing History (On by Default, You Can Turn It Off)

Our article detector can only be improved if we can see the kinds of pages it gets wrong, including the pages it fails to recognise at all. So that we can evaluate and train it, the extension records the address of pages you visit along with the detector's verdict for each one. This is controlled by Help improve article detection in the extension's settings, which is on by default. You can switch it off at any time.

  • What is recorded: the site and path of the page (for example example.com/news/story), whether our detector considered it an article, and which rule decided that
  • We remove query strings. Everything after ? or # is stripped inside your browser before anything is sent, so search terms, access tokens, and session identifiers are not transmitted
  • We never record page content. The text and HTML of a page are only sent if you choose to save or summarize it
  • Private pages are not identified. Pages on local or internal networks are counted only as "private network" with no address recorded, and pages served over plain HTTP or browser-internal pages are skipped entirely
  • You can stop and erase it at any time. Switching the setting off halts collection immediately and deletes what was already collected; you can also delete it without switching off
  • We use it only to improve article detection. It is not used for advertising, is not sold, and is not shared with third parties

What We Do NOT Collect

  • The content, text, or HTML of pages you don't choose to save or summarize
  • Passwords or sensitive form data from other websites
  • Query strings, search terms, or anything else after ? in a page address
  • The addresses of pages on your local or internal network

2.4 Information from Third Parties

  • Google OAuth: If you sign in with Google, we receive your email address and name from your Google account
  • Payment Processors: Stripe provides us with transaction confirmations (not full card numbers)

3. How We Use Your Information

We use your information for the following purposes:

  • Provide, operate, and maintain our Services
  • Process your transactions and manage your subscription
  • Personalize your reading experience and preferences
  • Generate AI-powered summaries and reading aids (processed securely)
  • Sync your reading progress across devices
  • Send you service-related communications
  • Respond to your inquiries and provide customer support
  • Improve and develop new features
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your data based on:

  • Contract Performance: To provide the Services you requested
  • Legitimate Interests: To improve our Services and ensure security
  • Consent: When you opt-in to optional features or marketing
  • Legal Obligation: To comply with applicable laws

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your data with:

  • Service Providers: Third parties that help us operate our Services (hosting, payment processing, analytics)
  • AI Providers: To generate summaries and reading aids (data is processed securely and not stored by providers)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Our Service Providers

  • Supabase: Database and authentication (US-based, GDPR compliant)
  • Stripe: Payment processing (PCI-DSS compliant)
  • Vercel: Hosting infrastructure
  • OpenAI/Anthropic: AI features (data not retained for training)

6. Your Rights

6.1 GDPR Rights (EEA, UK, Switzerland)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a portable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Revoke consent at any time

6.2 CCPA Rights (California Residents)

  • Know: Request disclosure of data collected about you
  • Delete: Request deletion of your personal information
  • Opt-Out: Opt-out of the sale of personal information (we do not sell data)
  • Non-Discrimination: Equal service regardless of exercising rights

6.3 Other US State Rights

Residents of Virginia, Colorado, Connecticut, Utah, and other states with privacy laws have similar rights to access, delete, and correct their data. Contact us to exercise these rights.

7. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Account Data: Until you delete your account
  • Reading Content: Until you delete it or your account
  • Transaction Records: 7 years for tax/legal compliance
  • Analytics Data: Aggregated and anonymized after 24 months

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure authentication with password hashing
  • Regular security audits and monitoring
  • Access controls and employee training
  • Incident response procedures

9. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with all service providers
  • Compliance with applicable data transfer frameworks

10. Cookies and Tracking

We use essential cookies for authentication and functionality. We do not use third-party advertising cookies. You can manage cookies through your browser settings.

11. Children's Privacy

Our Services are not intended for children under 13 (or 16 in the EEA). We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Services. Your continued use after changes constitutes acceptance.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Nook

Email: support@nook.app

You also have the right to lodge a complaint with your local data protection authority.