Privacy Policy
What Legato Reader sends, stores, and shares — and what it never touches.
Effective 2026-10-01 · Yeonsol Kim
Legato Reader reads a web page aloud only when you ask it to. It has no advertising, no analytics SDK, no tracking, and no third-party trackers of any kind. This page describes exactly what leaves your device when you press Narrate.
The short version
- The extension reads a page only when you start a narration. It does not watch your browsing, and it does not run in the background on pages you never narrate.
- To make audio, the text of that one page is sent to our server and from there to our speech provider. There is no way to synthesise speech without transmitting the text.
- We store the script and audio we produce, plus the page title and URL — not the page's original text.
- Sign in with Apple gives us an opaque identifier and, only if you choose, an email address. We never see your Apple ID password or payment details.
- You can delete everything from inside the app, permanently, without contacting us.
What we collect
| Data | Why | How long |
|---|---|---|
Apple account identifier (the opaque sub from Sign in with Apple) |
To have an account at all: to attach your subscription and your monthly allowance to you. | Until you delete your account. |
| Email address — only if you chose to share it when signing in (it may be an Apple private relay address) | Service notices and replying to support requests. We do not send marketing email. | Until you delete your account. |
| Subscription state: the product you bought, its expiry, and Apple's original transaction identifier | To know which plan and allowance you are entitled to, and to honour renewals, expiries, and refunds Apple tells us about. | Until you delete your account. |
| For each page you narrate: its title and URL | To label the item in your listen-later list and in your usage history. | Until you delete your account. |
| The narration script and the audio file we generate from that page | So playback works, so you can replay a page you already spent an article on, and so a page someone has already narrated does not have to be paid for and generated twice. | 180 days after it was last played, then deleted. |
| A SHA-256 fingerprint of the page text (not the text itself) | It is the cache key. It cannot be turned back into the page. | With the audio, above. |
| Usage records: which narration, when, whether it was served from cache, and what it counted against your allowance | To enforce the monthly allowance and to investigate billing disputes. | 400 days. |
| Ordinary server logs: IP address, timestamp, endpoint, response code | Security, abuse prevention, and debugging. They are not joined to your reading history for any other purpose. | 30 days. |
What we deliberately do not collect
- Your browsing history. The extension is granted access to web pages so that it can read the one you are on, but it transmits nothing until you press Narrate.
- The original text of the page. It is processed to produce the script and then discarded; only the derived script and audio are kept.
- Advertising, analytics, or device identifiers. There is no SDK of that kind in the app or the extension.
- Payment information. Subscriptions are sold by Apple. We receive an entitlement, never a card number.
Who else sees your data
Our speech and language provider
The extracted text of the page you narrate is sent to OpenAI, which produces the narration script and synthesises the speech. Under their API terms this content is not used to train their models and is retained only briefly for abuse monitoring. See https://openai.com/enterprise-privacy.
Apple
Apple handles sign-in and all payments, and notifies our server when a subscription renews, lapses, or is refunded. Apple's handling of that data is governed by Apple's own privacy policy.
Hosting
Our servers and audio storage run on Fly.io (application), Neon (database), and Cloudflare R2 (audio and script storage), in the United States — application and database — and the Asia-Pacific region for stored audio. They process data only to run the service.
We do not sell your data, and we do not share it with anyone else — no advertisers, no data brokers, no analytics companies. We will disclose data if a valid legal order compels us to, and we will tell you unless we are legally prohibited from doing so.
The shared cache — please read this one
To keep the price down, narrations are cached by a fingerprint of the page text. If another subscriber later narrates a page whose text is byte-for-byte identical to one already narrated, they are served the existing audio instead of paying to generate it again. Playback still requires that the requester's own account has narrated or saved that page.
The practical consequence: a page you narrate is stored on our server as a script and an audio file. That is fine for public articles, which is what Legato Reader is for. Do not use it on pages containing confidential or personal information — a private document, an internal wiki, a medical or financial record. If you do, contact support@legatoreader.com and we will delete that item.
Your choices and rights
- See what we hold. The app shows your plan, your usage, and your saved list, and can export a machine-readable copy of your entire record.
- Delete everything. Settings → Delete account in the app removes your account, your saved list, and your usage history immediately and permanently. It does not cancel your Apple subscription — do that in Settings → Apple Account → Subscriptions.
- Delete one item. Remove it from your saved list, or email us for anything else.
- Object, correct, or restrict. Wherever the GDPR, the CCPA, or Korea's PIPA applies to you, those rights apply here; write to us and we will act within 30 days.
- Stop entirely. Turn the extension off in Safari's settings and nothing further is ever transmitted.
Security
Everything travels over TLS. Session tokens are signed, expire, and can be revoked by signing out. Audio is served only to a signed-in account that narrated or saved that page. No system is perfect; if you find a weakness, please write to support@legatoreader.com and we will credit you.
Children
Legato Reader is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
International transfers
We are based in the Republic of Korea, and our providers process data in the United States — application and database — and the Asia-Pacific region for stored audio. Using the service involves transferring your data there under standard contractual protections.
Changes
If we change this policy in a way that matters, we will raise it in the app before the change takes effect, and the date at the top will change. Past versions are available on request.
Contact
Yeonsol Kim
support@legatoreader.com