Privacy Policy

Last updated July 21, 2026

The short version

Who we are

Squirrel Reader is made by Swiftfox Software, and Swiftfox Software is the data controller for the personal data described here. You can reach us at support@squirrelreader.com.

This policy covers the Squirrel Reader apps (iOS today, and Android when it ships), the Squirrel Reader Chrome extension, the share extensions, and the squirrelreader.com website.

What we collect

We collect what a read-it-later app needs to be a read-it-later app, and not much else.

Account information

When you create an account we store your email address and your sign-in credentials — a password hash if you use email sign-in, or an identity token if you use Sign in with Apple or Google. You can optionally add a display name. We also store your subscription tier (free or premium) and your app preferences, such as reader defaults and your Kindle settings.

Your library

Everything you save becomes part of your library, stored under your account:

All of this is protected by per-user access rules on the server: your library is readable only by you.

Your whole library is also mirrored into a database on your device, so saving, reading, searching, tagging, and highlighting all work offline. That on-device copy — including downloaded podcast and video files, your search index, and reader preferences — stays on your device and is never uploaded. The one exception is files you explicitly add to your library: EPUBs and PDFs you upload are, by design, stored on our server so they can sync to your other devices (see “Uploaded files” below).

On-device AI: summaries, key points, questions, Ask, and transcripts

On iOS 26 and later, Squirrel Reader can summarize an article, pull out its key points, suggest questions worth thinking about, answer questions about it in a chat (“Ask”), and transcribe podcast episodes — all using Apple’s on-device models. The article text and audio never leave your device for this — no cloud AI service is involved, and transcription works on the downloaded audio file, not the microphone. Only the resulting text of a summary, key points, or questions is uploaded:

If you’d rather not contribute a transcript to the pool, don’t run transcription on that episode.

Article images

When you save an article, we copy its images (up to 20 per article, plus a thumbnail) to our own storage so they load reliably and work offline. These copies are stored at unguessable, content-hashed URLs, but the URLs themselves are publicly readable — anyone who somehow obtained the exact URL could load the image. The images are copies of pictures that were already on the public web, and they’re deleted when you delete your account, but we’d rather you know how they’re hosted.

Uploaded files (EPUB & PDF)

If you upload an EPUB or PDF — or open one with Squirrel Reader from Files or Mail — the file itself is stored on our server so your books and documents can sync to your other devices. Uploaded files live in a private storage area readable only by you; unlike article images, there are no public URLs for the files themselves. When you delete an uploaded item, the file is removed from our storage within moments (which also frees your storage quota), and deleting your account removes every uploaded file along with the rest of your data.

Two related details:

Send to Kindle

If you use Send to Kindle (a Premium feature), we store your @kindle.com address and your auto-send preference. Each send converts the article to an EPUB and emails it to your Kindle address. We keep a server-side log of each send attempt — the Kindle address, whether it succeeded, any error, the file size, and a timestamp — which we use to enforce a fair-use limit of 25 sends per day. Only you (and our server) can see your send log.

Imports

If you import from Pocket, Instapaper, or Omnivore, your export file is uploaded and parsed on our server to recreate your items and tags. The raw export file is processed in memory and not stored — only the resulting library items are kept. (This applies to library-import files; EPUB and PDF files you upload as reading material are stored so they can sync — see “Uploaded files” above.)

Clipboard

The app can offer to save a URL from your clipboard. It checks whether the clipboard contains a URL using the iOS privacy-safe API (which doesn’t read the contents and doesn’t trigger the paste notification). The actual clipboard value is read only when you tap the save button, and nothing is stored unless you save the link. The clipboard is never read in the background.

Sessions on your device

Your sign-in session (access and refresh tokens) is stored locally on your device: in the app’s storage, in the iOS Keychain (so the share extension can save links), in app-private storage on Android when the Android app ships, and in the Chrome extension’s local extension storage. Sessions never leave your device except to authenticate with our backend.

How saving actually works

Two details worth knowing:

What we don’t collect

This list is verified against our codebase, not just our intentions:

Services we rely on

We use a small set of service providers (subprocessors) to run Squirrel Reader. Each receives only what it needs:

ServiceWhat it doesWhat it receives
SupabaseOur backend: authentication, database, file storage, and sync.Your account data and library content, as described above.
RevenueCatSubscription management for Premium.A pseudonymous identifier (your account UUID) and App Store purchase information. No email, no library content.
ResendSends our transactional email: account emails (verification, password reset, and similar) and Send-to-Kindle deliveries.Your email address (or Kindle address) and, for Kindle sends, the article as an EPUB attachment.
LoopsOur marketing contact list (e.g., a welcome email).Your email, name, account UUID, and subscription tier — added after you confirm your email, and deleted when you delete your account.
AppleSign in with Apple, App Store billing, and the public iTunes Search API that powers podcast search.Sign-in and purchases are handled by Apple under Apple’s terms. Podcast searches send your search terms and country code to Apple’s public directory — no account identifiers attached.
GoogleOptional Sign in with Google.The standard OAuth sign-in flow; no Google SDK is embedded in the app.

We don’t sell your personal data, and we don’t share it with anyone beyond the providers above.

Your rights and your data

We extend GDPR-style rights to everyone, not just users in the EU:

Retention: items you delete are soft-deleted first (so deletions can sync across your devices), then permanently purged from our servers after 30 days. Account deletion removes everything immediately.

To exercise any of these rights, use the in-app tools or email support@squirrelreader.com.

Where your data lives

Our infrastructure (Supabase) is hosted in the United States, and we operate it to GDPR standards for everyone, everywhere. If you’re in the EU or UK, transfers to the US are covered by our providers’ standard contractual clauses.

Children

Squirrel Reader is for readers aged 13 and up. It is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we’ll delete it.

Changes to this policy

If we change how we handle your data, we’ll update this page and the date at the top. We won’t quietly bury anything meaningful — the whole point of this policy is that there’s not much to bury.

Contact

Swiftfox Software support@squirrelreader.com

We store your reading, not your data — squirrels hoard acorns, not secrets.