Privacy policy
How READANYTHING LTD collects, uses and protects your personal data under UK law. Effective 11 June 2026.
1. Who we are
READANYTHING LTD is the data controller for personal data processed through readanything.io. We are registered with the Information Commissioner's Office (ICO). Contact our data lead at [email protected].
2. What we collect and why
The personal data we process, the source, the purpose and our lawful basis under UK GDPR:
| Data | Source | Purpose | Lawful basis |
|---|---|---|---|
| Account email and auth data | Clerk | Provide your account and login | Contract |
| Payment details | Stripe | Take payment for paid plans | Contract |
| Uploaded files and extracted text | Your upload (then OpenAI) | Perform the OCR, summary, translation or transfer you requested | Contract |
| IP address | Your request | Rate limiting, security, fraud prevention | Legitimate interests |
| Cookieless analytics | Plausible | Aggregate, anonymous usage statistics | Legitimate interests |
Card numbers are handled by Stripe, our PCI-DSS-compliant payment processor; we do not store full card details. Uploaded documents may themselves contain other people's personal data, which we process on your behalf to provide the Service.
3. AI processing, stated plainly
Our AI features (OCR, summarise, translate) send the text of your document to a third-party AI provider to perform the task. We do not use your content to train any model, and our transfer feature does not send your files to any AI model at all. Our providers' standard terms state that API content is not used to train their models by default.
4. Who we share data with (sub-processors)
We use carefully chosen processors under written data-processing terms: Cloudflare (hosting, storage, edge), Clerk (accounts and login), Stripe (payments), OpenAI (OCR, summarisation and translation models), Resend (transactional email), and Plausible (cookieless analytics). We do not sell your personal data.
5. International transfers
Some processors are based outside the UK. Where they are, we rely on the UK Extension to the EU-US Data Privacy Framework where the processor is certified (including Cloudflare, Clerk and Stripe), and on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses where they are not (including OpenAI), supported by a transfer risk assessment.
6. How long we keep it
We keep account and billing data for as long as you have an account and then for the periods required by tax and accounting law. We minimise document data: uploaded files and results are not kept longer than needed to provide the Service; transferred files are deleted automatically on link expiry. At the model level, OpenAI deletes API content within about 30 days (or retains nothing on zero-retention endpoints).
7. Security
We protect personal data with encryption in transit and at rest, access controls, least-privilege credentials and the measures set out in our security overview. No method is perfectly secure, but we take appropriate technical and organisational measures and review them.
8. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where we rely on it. To exercise any right, email [email protected]; we will respond within one calendar month (extendable for complex requests, with notice). We will pass on erasure requests to our processors.
9. Cookies
We use only strictly-necessary cookies for login and security, and cookieless analytics (Plausible), so we do not currently require a cookie-consent banner. If we ever add non-essential cookies or advertising, we will introduce a compliant consent banner first, with “reject” as easy as “accept”.
10. Children
The Service is not intended for children under 16, and we do not knowingly collect their data.
11. Complaints
If you are unhappy with how we handle your data you can complain to us at [email protected], and you have the right to complain to the Information Commissioner's Office (ico.org.uk).
12. Changes
We may update this policy; material changes will be notified on the site.
Last updated 11 June 2026.