Privacy
Last updated 9 September 2026
Screenshots never leave your computer
When you capture a region, Second Read takes a picture of the visible tab, crops it to your selection, reads the text, and discards the image. All of that happens inside your browser. The image is never uploaded, never stored, and never sent to us or anyone else. There is no copy of it to request, subpoena, or leak.
When the page already contains the text as text, no screenshot is taken at all.
What we store
If you sign in, we store on our database:
- the text you captured, including any edits you make
- the page address, page title, and site icon it came from
- whether the text was read from the page, from pixels, or imported
- any tags you add, and when the passage was saved and last shown to you
- your email address, used to sign you in and to send digests if you enable them
If you do not sign in, all of this stays on your device and we hold nothing.
Signing in with Google
You can sign in with a code sent to your email, or with Google. Choosing Google opens Google's own sign-in window; we never see your password, and Google returns exactly one thing to us — your email address, used for the same two purposes as above.
We do not request or receive access to your Gmail, Drive, contacts, calendar, or anything else in your Google account, and we cannot read them. Revoking Second Read under your Google account permissions ends this at any time.
Who can read your saves
Only you. Access is enforced by the database itself: every row is bound to the account that created it, and a request carrying a different account's credentials returns nothing. This is not a check in our application code that could be bypassed by a bug in it.
What we do not do
- We do not sell or share your data with anyone.
- We do not use your saved text for advertising or to train models.
- The extension does not track your browsing. It sees only the pages you capture from.
- We do not run analytics that record the contents of a save.
Analytics on this website
This website uses Google Analytics to count visits: which pages are read, roughly which country a visit came from, and which link led here. It runs on secondread.cc and nowhere else.
The extension reports nothing to it. No saved passage, no page you captured from, and nothing from your library is ever sent to Google. If you would rather not be counted, any content blocker will stop it and nothing on this site depends on it working.
Services we rely on
Supabase stores the database and handles sign-in. Resend delivers sign-in codes and digest emails. Vercel hosts this website. Google Analytics counts visits to it. Each receives only what it needs to do that job.
If you connect Telegram, Telegram carries your digests and anything you send to the bot to be saved. Messages you send it become saves in your library, so treat that chat as you would the extension. Sending a link to a post on X makes one request to X's public embed endpoint to read that post's text; it identifies nobody and carries nothing about you.
Amazon is not on this list, because we send them nothing. Connecting Kindle reads a page in your own browser under your own session, the same as opening it yourself. No account of ours is involved and no data of yours passes through us on the way.
Bringing highlights in
From Kindle. Amazon publishes no export and no interface for highlights; the only place they exist away from the device is your own notebook page at read.amazon.com. If you connect Kindle, the extension opens that page in your browser, using the Amazon session you are already signed in with, reads the highlights it finds, and closes it again. It happens entirely on your machine. We never see your Amazon password, never receive a token, and have no access to your Amazon account ourselves. Nothing about your Amazon account, your orders, or your reading is sent to us — only the highlights from the books you tick, which are then stored exactly like anything else you save.
That permission covers read.amazon.com and nothing else, it is only requested if you ask to connect Kindle, and you can withdraw it at any time from your browser's extensions page. Declining it does not affect anything else in Second Read.
From a file. A Readwise export, or a Second Read file you left with, is read by your own browser on the settings page. It is not uploaded. Nothing is sent anywhere until you have seen which books it contains and chosen; if you change your mind, the file never leaves your machine at all.
Leaving
You can export everything you have saved as Markdown or JSON at any time, from your library, without asking us. Deleting your account removes your saves from the database.
Permissions the extension asks for
- Access to the current tab, granted only at the moment you press the shortcut, so it can screenshot what you are looking at. It does not have standing access to every site you visit.
- Storage, to keep your saves on the device so capture works offline and the new tab loads instantly. Without a size limit, because a Kindle library can run to thousands of passages and the default is about ten megabytes.
- New tab page, to show you a saved passage. You can turn this off in the extension.
- Search, only if you switch on the optional search box for the new tab. Replacing the new tab page takes Chrome's own search box away and there is no way to keep it, so this draws one. What you type is handed to whichever search engine you have already set as your default, exactly as the address bar would. It does not pass through us and we never see it.
- Notifications, to tell you when a Kindle import has finished. A first import can run for ten minutes or more and you should not have to sit and watch it. Nothing else sends you a notification.
- read.amazon.com, optional and only asked for if you choose to connect Kindle. It is one address, not a category of site, and it is the only way to reach highlights Amazon will not otherwise export. Withdraw it any time from your browser's extensions page.
Limited use of the data we receive
Second Read's use of information received from Google APIs, and of any data collected through the Chrome extension, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:
- We use your data only to provide and improve the single purpose of this extension: saving text you read and bringing it back to you.
- We do not transfer your data to third parties except to run the service itself.
- We do not use your data for advertising, personalisation, or to train machine learning models.
- No human reads your saved text, except you.
How long we keep it
Your saves are kept until you delete them or delete your account. There is no expiry and no archive we hold on to afterwards. Deleting your account removes your saves from the database, and we keep no backup copy to restore from. Delivery logs for digests record only whether a send succeeded, never its contents, and are discarded after 90 days.
Children
Second Read is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will remove it.
Scope and contact
This policy covers the Second Read Chrome extension and the website at secondread.cc, which share one account and one set of data.
Questions, corrections, or a request to delete your data: hello@secondread.cc
If this policy changes materially, we will say so by email before the change takes effect rather than quietly editing this page.
Second Read