Privacy Policy
Lullula ("Lullula", "we", "us") is a browser extension and a companion web service that read web pages, Google Docs, PDFs, and EPUB documents aloud using text-to-speech, with optional AI-generated summaries, and keep what you save for later listening. Our mobile app is not released yet; where this policy mentions the mobile app, it describes how the app will handle your data once it is available. This policy explains what data we collect, how it is used, and the choices you have.
Lullula is an independent software project operated by a small team — the "we" in this policy and the controllers of the personal data it describes. For any privacy question or request, contact support@lullula.io.
1. Data we collect
We collect data to provide reading and account features, and, when you allow the optional measurement described below, to compare player designs:
- Document content you choose to have read. Built-in voices — your browser's in the extension and the web app, and your phone's in the mobile app once it is released — are provided by that browser's or phone's own speech engine, which may process the text on your device or with its provider (some browsers' online voices work that way). Lullula receives nothing from that speech engine. When you use a premium AI voice, the text extracted from the current web page, Google Doc, PDF, or EPUB is sent to our service to generate speech audio, and on to the speech provider named in §3. Summaries work differently: when the reading player appears on a page, a summary is generated automatically unless you turn summaries off (see §7), so that page's text goes to our service and on to one of the AI providers in §3 without you asking each time. Two smaller jobs send short pieces of a page to the same AI provider: working out what language the text is in (up to 500 characters) when your browser cannot, and working out which part of a page holds the article (a compact outline of the page, including its address). The outline is made as a page opens, before the player appears, so it can be sent for a page where the player then does not appear. Beyond that, we do not read pages you never open the player on. For Google Docs, the extension reads the document's text through the Google session already signed in to your browser (the document's mobile view); it never changes the document or its sharing settings.
-
Screenshots of pages that looked covered (extension versions 1.0.0 to 1.7.1,
signed-in users only). These versions contained a check for when you were signed in
and, as a page opened, part of its article appeared to be covered on screen — by a paywall, a
pop-up, or sometimes only a sticky banner or chat button. Without you pressing play, it first
sent the page's address in a generalised form (the scheme and domain, plus short section
names from the path such as
/news, which can include a username; titles, numbers and ids replaced, and nothing after?or#) to our service to ask whether we already had a result for it. If we did not, it tried to take a screenshot of the visible part of the browser window. In Chrome and Edge the browser refused, so no screenshot was ever taken there; only the address was sent. In Firefox the screenshot could be taken. It was reduced to at most 800 pixels on its longest side and sent with that address to our service. Until 19 September 2026 our service had no place for it and discarded it unused; from 19 September 2026 our service passed it on to DeepSeek's vision model (see §3). A screenshot shows whatever was on screen, which can include personal information. Because of a fault, if such a page was loading in a tab you were not looking at, the screenshot showed the tab you were looking at instead. Screenshots were not taken on a short list of banking, payment and sign-in sites (such as Chase, Bank of America, PayPal, and the Google, Microsoft, Okta and Apple sign-in pages), onlocalhostand private IPv4 addresses, or on our web app — but, because of the same fault, that list was checked against the page that asked, not the tab captured. Nothing was sent while you were signed out. On 27 September 2026 our service stopped these checks: it now gives every version the same answer without seeing the page, so they no longer try to take screenshots — except if our service fails to answer at that moment, and a screenshot sent then is discarded unread and never passed on. Versions after 1.7.1 do not take screenshots. See §6 for what was kept. - Account and authentication data. If you sign in, we process your email address and an authentication token issued for your Lullula account.
- Reading history for signed-in users. When you start playback while signed in, we store the page or document title, address (URL), favicon when available, content type, playback progress and duration, reading position, and a short text excerpt (up to 80 characters) around that position. This lets your history and resume position sync across devices. We record only content you choose to play; we do not monitor unrelated pages or your general browsing activity.
-
Items you save to Listen later. When you press Listen
later in the extension's player, these are stored with your account: the page or
document title; its address (URL) when it is an ordinary web address (
httporhttps— local files and browser pages are saved without one); the text as it is read aloud; the text's language; and the site name, description, image address and icon address when the page provides them. When you add a page by its address instead — by starring it in the web app's history, or from the mobile app once it is released — our server fetches that page to get its text and stores the same things. With a premium subscription we send the saved text to our speech provider (Microsoft Azure, §3) ahead of time and keep the audio it returns on Amazon Web Services (§3), so the item is ready to play on any device you sign in to. Without one, nothing is prepared ahead of time: when you play the item, its text is downloaded to your devices and read by the device's own speech engine — your browser's in the web app, and your phone's in the mobile app once it is released, which may keep a copy on your phone so you can listen offline. A premium item whose audio cannot be prepared (for example, once the month's premium allowance is used up) is saved all the same and plays with the device's own voice. Extension versions up to 1.7.1 have a Bookmark star in the player instead of Listen later: it saves only the page's title and address, nothing is prepared ahead of time, and our server fetches the page's text, and stores it the same way, the first time you play the item. If you are signed in, each time the player appears on a page, the extension (every version) also sends that page's address to our service to check whether you have already saved it; we use the address only to answer and do not store it, and our request logs leave it out. - Settings and preferences. If you are signed in, the voice you pick for each language and your list of blocked sites are synced to your account, so they follow you to other computers. Other settings — reading speed, volume, theme and feature toggles — are stored by your browser and follow your browser profile through the browser's own sync, not through your Lullula account.
- Equations on web pages. When a page you have Lullula read contains mathematical notation (MathML or LaTeX), the extension sends each formula — not the rest of the page — to our service, which turns it into spoken words, whichever voice is reading. We keep those spoken words, keyed by a fingerprint of the formula and not linked to you or the page, so the same formula is not converted twice (see §6).
-
Player design measurement (optional, in experiment-capable extension releases).
This is off by default and requires an explicit choice inside Lullula; your website
cookie choice does not enable it. If you allow it, we compare the player designs bundled
with the extension and their reliability using a random installation identifier
(
experimentUnitId), an exposure identifier (exposureId), event identifiers, optional existing install/trial identifiers, client version and browser, coarse installation cohort, document type and expanded/minimized mode. The reports describe selected actions in Lullula's player, attempted starts and their latency/outcome, listening duration and closing reason, and summary/save/recovery outcomes. Random attempt identifiers connect starts to results; reading and session identifiers connect reports of the same reading. These areexperiment_assignment,experiment_exposure,experiment_action,experiment_play_attempt,experiment_play_attempt_resultandexperiment_playbackevents sent to our own service (api.lullula.io). They contain no page address, title, page or selection text, summary text, audio, voice-provider key, authentication token, email, location or free-form error message. They are not general monitoring of website clicks, typing, scrolling or network traffic. Existing verified trial/install records can link these identifiers to your account, so we do not describe these optional records as anonymous. After consent, the extension can also request a versioned JSON configuration from our service; this selects only code already bundled in the extension, not remote executable code. Releases without this capability do not perform this measurement. See §6 for retention and §7 for your controls. -
Anonymous identifiers and usage events. Before you sign in, we
generate a random identifier to provide a limited free trial. It is not linked to your
identity. When the extension is first installed it also generates a random install
identifier (
install_id). The extension uses the two to send a few small events to our own server (api.lullula.io): that it was installed (install_confirmed, with the store it came from asinstall_store: Chrome, Edge, Firefox or other), and that audio actually played for ten seconds or a reading reached its end (playback_success, with whether it was a web page, a PDF or an EPUB). A single reading normally sends more than oneplayback_successreport, and not for just one reason: one once its audio has sounded for ten seconds or the reading reaches its natural end, a second if you keep listening past three minutes of it, and a third when the reading ends, saying how. (A 30-minute gap in listening also starts a new session and can add still more reports, by letting the ten-second one fire again for a reading you come back to — but going quiet that long is the least common of the three reasons, and its absence does not mean only one report was sent.) Every report of the same reading carries the same random, per-reading identifier (reading_id), which is never linked to a page's address, its title, its text, or any other content, and the milliseconds of audio that have actually sounded in that reading so far, added up across any pauses (listened_ms) — so the reports are snapshots of one reading, not separate readings. The report that closes a reading also says why it ended, from a fixed list (outcome: it reached its natural end, you stopped it, its tab closed, another reading replaced it, your quota ran out, or it errored) — the sentence you see in the reader explaining why a reading stopped is not sent; only which of these fixed reasons it was. None ofreading_id,listened_msoroutcomecarries a page's address, a title, page text, or an email address. Every event carries a random event id, the time it happened and the extension's version string; playback events also carry a random session id (session_id) that is replaced after 30 minutes without listening. The welcome page the extension opens after installing has the install identifier in its address for a moment; the page removes it before Google Analytics or the Meta Pixel can read it. On that page the extension also reads the marketing site'svm_aid,vm_acqandvm_firstcookies (§4), if you have them, and sends them once with the install event, so we can tell which campaign or website led to the install. If you later sign in, our server records once that the trial identifier was linked to your account (account_linked, with your account id and the extension's version). Versions of the extension before 1.7.1 send simpler counts instead: that it was installed, the first time you play something, and at most one "used today" signal per day, the install count carrying the page name from thevm_srccookie (§4). None of these events contains the address or title of a page you read, its content, your email address or any audio.
We do not collect health data, payment card data (see §5), personal communications, or precise location. We do not monitor sites you do not ask Lullula to read or build a general browsing profile. The Lullula browser extension and web app contain no third-party analytics or tracking SDKs; our marketing site uses analytics governed by the consent rules in §4.
2. How we use data
- To convert the content you select into spoken audio.
- To generate optional summaries of that content.
- To authenticate you and provide subscription features.
- To save and sync your preferences.
- To save and sync your reading history, progress, and resume position.
- With your optional in-extension consent, to compare bundled player designs and listening/start/recovery outcomes and improve the reading interface.
- Until 27 September 2026, to check whether a page's text could be read when part of it looked covered on screen, so the player was not offered on a page it could not read (see the screenshots item in §1).
- To keep the items you save to Listen later, prepare their audio ahead of time on premium plans, and play them on the devices you sign in to.
- To fill the web app's Discover page. Today it lists stories from the front page of Hacker News, leaving out any you dismiss (we keep the address of each story you dismiss with your account, so it stays hidden); your reading history plays no part in it. Personalised suggestions are not switched on yet. When they are, a suggestion will be drawn only from public web pages that at least two other readers have also played, and your own history will decide what is shown to you and will never be shown to anyone else.
We do not use your data to build advertising profiles, and we do not sell or rent your data to third parties. We also do not use the text or documents you submit to train AI models of our own. What each provider says about training on the data we send them differs, and §3 states it provider by provider: Microsoft Azure and OpenAI say they do not, Alibaba Cloud says it will not without a separate consent we do not give, and DeepSeek publishes no such exclusion for its API.
3. Sharing and sub-processors
We share data only with service providers that help us deliver the product, and only as needed to provide it:
- Microsoft Azure (Azure AI Speech) — the text you choose to have read is sent to Azure's text-to-speech service to generate the audio; on premium plans, so is the text of each item you save to Listen later, ahead of time. Microsoft processes it to synthesize speech and does not use it to train its models.
- DeepSeek — one of three services that may generate an AI summary, and, from 19 to 27 September 2026, the service that checked screenshots Firefox could take of pages that looked covered (see §1). Its privacy policy lists training and improving its models among the purposes it processes data for, and neither it nor the terms governing its API publishes an exclusion for API traffic or a retention period. DeepSeek processes and stores data in the People's Republic of China, so summary text it handles is transferred there, as was any screenshot it received (see §1).
- Alibaba Cloud (Model Studio) — may generate an AI summary. We use its international service: Alibaba's documentation says request data is stored in the region it is sent to, which for us is Singapore, and that the model runs on nodes outside the Chinese mainland — though its terms allow it to process content in any country where it or its sub-contractors have facilities. Its terms also state that it will not use the content to develop or improve the models on Model Studio without our separate consent, which we do not give. It publishes no retention period.
- OpenAI — may generate an AI summary. OpenAI states that data sent to its API is not used to train its models. It keeps API inputs for up to 30 days for abuse monitoring, where authorized OpenAI employees and specialist contractors under confidentiality obligations may review them. We use OpenAI's standard API rather than a region-pinned one, so this data may be processed in the United States or in other countries where OpenAI operates.
- Your own text-to-speech provider (optional) — if you connect ElevenLabs, an OpenAI-compatible endpoint, Microsoft Azure Speech, Google Cloud Text-to-Speech, Amazon Polly or Alibaba Cloud Model Studio (Qwen-TTS, in the Singapore or Beijing region you choose) in the extension's settings with your own API key or access key, the text you play with one of that provider's voices is sent from your browser straight to that provider, under its own terms and privacy policy, with your key. The key is stored only in your browser. Our servers never receive the key, and the requests for those voices' audio do not pass through us. The rest of this policy still applies whichever voice reads: if you are signed in, the page you play is added to your reading history, and the page's text is sent for a summary whenever one is made (both in §1). Disconnecting the provider in settings removes the key.
- Google (Sign in with Google) — if you choose to sign in with Google, the sign-in button on the web app is served by Google and Google receives your choice to use it; we receive your Google account's email address and name to create or match your account. Google's own privacy policy governs what it does with that sign-in.
- Apple (Sign in with Apple, in the mobile app once it is released) — our iOS app will offer Sign in with Apple once it is released; the extension and the web app do not offer it. If you choose it, Apple handles the sign-in and tells us your Apple account's email address (or the relay address Apple creates if you choose to hide yours), whether Apple has verified it, an identifier for your Apple account that is specific to Lullula, and, the first time you sign in, the name you choose to share, so we can create or match your account. We also keep a token Apple issues for that sign-in, so that deleting your Lullula account can also remove Lullula from your Apple account's sign-in settings. Apple's own privacy policy governs what it does with that sign-in.
- Amazon Web Services — our backend, database (including the sentence cache described in §6 and the text of items you save to Listen later), and the audio files generated from your text (cached clips, and the audio prepared for saved items) are hosted on AWS in the United States. Original PDFs and EPUBs that you explicitly save to your cloud library are also stored privately on AWS, as described in the cloud-library section. When a PDF page is a scan rather than text, an image of that page may also go to AWS Textract, in the same account, to recover the words so they can be read aloud.
- Mathpix — may receive an image of a single PDF page when that page is a scan that has to be turned into text, and receives an image of a single equation when a PDF contains mathematical notation, so that either can be read aloud. Neither carries your account identifier, the file name, or the page address. Mathpix is in the United States.
-
Hugging Face (extension versions 1.5.0 to 1.7.1) — the first time one of
these versions needs to recognize the text of a scanned PDF page in your browser, it
downloads its text-recognition model (about 30 MB) from Hugging Face
(
huggingface.co) and keeps it in your browser for later use. Like any website, Hugging Face sees your IP address and browser details when the files are downloaded; no document content, page address or account information is sent with the download. Versions 1.8.0 and later download the same model from our own site (lullula.io) instead. - Sentry — receives error reports from our backend so we can find and fix failures. A report carries the error, the request method, the path of our own endpoint that failed, and your account or trial identifier. Before a report leaves our servers we remove the request body, query parameters, sign-in credentials and cookies, so the text you sent to be read or summarized is not in it, and the page you are reading appears at most as its website's domain name, never as a full address. Sentry processes this data in the United States.
- Resend — sends our transactional email (sign-in verification, receipts, feedback notifications).
- ImprovMX — forwards email you send to our support address to the developer's mailbox.
- Payment processor (Stripe) — subscription payments are handled by Stripe in the Lullula web app. The extension itself does not collect or process payment card details.
-
Website analytics — our marketing site (
lullula.io) uses Google Analytics 4 (cookie-based, and gated by consent where consent is required) to understand site usage. The Lullula web app itself contains no analytics service. See §4.
Any of those three may handle a given summary. Which one does depends on which services are reachable at the time: it is not something you choose, and it is not shown to you. We keep a record of which service handled each summary, alongside your account or trial identifier. Text you send for a summary goes to these three and no others — we will not add a fourth without naming it here first, and we treat that as a material change under §10.
Between them, the providers above process data in the United States, the People's Republic of China, and Singapore, so text you have read aloud or summarized may be transferred outside the country you are in, and screenshots Firefox could take with extension versions 1.0.0 to 1.7.1 (see §1) went to the People's Republic of China from 19 to 27 September 2026.
These providers process data on our behalf. We do not transfer your data to anyone for their independent use; note, though, that DeepSeek's own policy lists training its models among the purposes it processes data for (see its entry above).
4. Cookies and analytics
Our marketing site (lullula.io) uses two third-party measurement services —
one to understand how the site is used, and one, on two pages only, to measure our own
ads — and a first-party attribution record of its own that goes only to our server. This
applies to the marketing site only — the Lullula web app and the browser extension contain
no analytics or tracking SDKs.
- Google Analytics 4 — uses cookies. In the EEA, the United Kingdom and Switzerland it does nothing until you accept: we use Google Consent Mode v2, so until then Google Analytics stores no analytics data on your device and sets no cookies (it may send anonymous, cookie-less signals). Elsewhere it starts when the page loads, and the banner's Reject stops it. Either way we enable analytics storage only; advertising signals stay disabled, so we build no advertising profiles.
-
Meta Pixel — on two pages only: the landing page our Facebook ads point
to (
/get) and the welcome page the extension opens after installing (/welcome). In the EEA, the United Kingdom and Switzerland it starts only after you accept; until then it is fetched but never started, so it sends nothing and sets no cookies. Elsewhere it starts when the page loads, and the banner's Reject stops it. Once running, it tells Meta that the page was viewed, that a store link was clicked, and that the welcome page opened after an install — so we can see which of our ads led to installs. It sends no name, email or account information. Meta sets its_fbpand_fbccookies for this and handles them under Meta's privacy policy. You can withdraw consent at any time from "Cookie preferences" in the footer, and control how Meta uses this data in your Facebook ad settings. -
First-party attribution (
vm_aid,vm_acq,vm_first) — unless analytics consent is withheld (in the EEA, the United Kingdom and Switzerland that means only after you accept; elsewhere, until you reject), the marketing site sets three cookies of its own onlullula.ioand sends two events to our own server (api.lullula.io):vm_aid— a random visitor identifier, kept for 180 days. It is not linked to your name or email, and the welcome page never sets it.vm_acq— your most recent visit that came from a campaign link or from another website, kept for 7 days: the campaign labels in the link (utm_source,utm_medium,utm_campaign,utm_content, a placement idcid, the page variant) and the referring site's host name, such aswww.reddit.com. It holds campaign labels and a referrer host only — never a full address, a page title or anything you typed. A visit you make directly leaves it unchanged.vm_first— where your first such visit came from and when, kept for 180 days and never overwritten.vm_sid— not a cookie: a random session id in your browser's session storage for that tab, replaced after 30 minutes without a page view and gone when the tab closes.
landing_view(a page of the site loaded; never sent from the welcome page) andstore_click(you clicked one of our store links). Each carriesvm_aid, the session id, a random event id, the time, the version of the site's script and, if you have one, thevm_acqrecord or, once that has expired, thevm_firstrecord. They are sent without cookies attached and are never shared with third parties. If you install the extension, its welcome page reads the three cookies once and sends them with the install event (§1). Rejecting, or withdrawing consent later, deletes all three cookies and the session id, so a later install is not linked to your visits. -
First-party attribution cookie (
vm_src) — set by the marketing site when you click an install or sign-up link, unless analytics consent is withheld: in the EEA, the United Kingdom and Switzerland that means it is set only after you accept, and elsewhere only until you reject. It holds the page you were on (and campaign name, if any) — no identifiers — and expires after 30 days. If you then create an account, that page name is stored with the account. If you install the extension, it reads the page name once, on the welcome page it opens after installing, and stores it with its anonymous install count. Either way, we learn which of our pages convince people to try Lullula. It is never shared with third parties. It is kept only while versions of the extension before 1.7.1 are still in use, and will then be removed. - Store link tags — when you follow one of our links to the Chrome Web Store, Firefox Add-ons or Microsoft Edge Add-ons, the marketing site adds the name of the page you were on to that link, so the store's own statistics can show which of our pages sent you. If you have opted in to analytics, it also adds the name of the site that referred you to us, such as a search engine. No identifiers are added. What the store does with the visit is covered by that store's own privacy policy.
Your control. A banner asks for your choice on your first visit to the
marketing site, and you can change or withdraw that choice at any time using the
"Cookie preferences" link in the site footer. When it applies matters:
in the EEA, the United Kingdom and Switzerland nothing described in this section runs
until you accept, and we tell those places apart by reading your browser's own time-zone
setting — there is no lookup of your IP address and nothing is sent anywhere to work it
out. Everywhere else, analytics starts with the page and the banner is how you turn it
off. Whenever you decline, Google Analytics sets no cookies, the Meta Pixel never starts,
no vm_src, vm_aid, vm_acq or vm_first
cookie is set (and the last three are deleted if you already had them), no
landing_view or store_click event is sent, no analytics data is
stored on your device, and store links carry only the page name. The choice itself, accept
or reject, is kept in a vm_consent cookie on lullula.io for 180
days, so the banner does not ask again on every page.
5. Payments
Subscriptions are purchased through the Lullula web app using Stripe. Card numbers and payment details are entered into and handled by Stripe directly; the extension never receives or stores them.
Original files in your library
When cloud file saving is available and you choose Save later, Save a PDF or EPUB, Upload original file, or Save a copy from the source, we upload the complete original PDF or EPUB and its filename to private Amazon Web Services storage in the United States. Opening a file by itself does not upload its original. Saving requires sign-in. An older text-only item needs an accessible source or a one-time original-file upload; extracted text cannot recreate a lost original.
Identical files may share one stored copy. Each account has its own private ownership; sharing storage never lets another user open your library. We retain an original while it has a saved library reference. Deleting your last reference releases your storage allowance immediately and queues physical deletion when no other account still owns that copy. Account deletion removes your ownership and queues the same cleanup. Failed storage deletions are retried and monitored. Temporary abandoned uploads expire automatically. A download link already issued can remain usable for up to five minutes.
Original file storage is separate from speech audio retention. File-only saves do not start paid speech or OCR just to store the original.
A failed attempt to open a saved file reports its collection identifier to our server so we can verify ownership and count reader failures. Operational monitoring uses aggregate counts and byte totals. Storage-loss and cleanup alerts sent to Sentry contain only counts or internal storage identifiers, never filenames, file fingerprints, document text, source addresses, or signed download links.
6. Data retention
- Optional player experiment records. Experiment reports and conflict records are retained for 90 days after our service receives them. Deleting your account removes experiment units linked through verified trial/install records; unlinked records expire through retention rather than an assumed account connection. A one-way hash of a deleted linked unit is kept for the same retention period to prevent delayed reports from recreating it. In your browser, pending experiment reports are limited to 500 events and 48 hours and are cleared when you turn measurement off. The local consent, installation identifier and assignment remain in extension storage until that storage is cleared or the extension is removed, so changing consent does not assign you a new player group. These rules do not change the retention of ordinary product events or the other data described in this policy.
- Narrated text and audio. When a premium AI voice reads to you, we keep the text of each sentence together with the audio generated for it, so a later request for exactly the same sentence, voice and settings is answered from this cache instead of being generated again. The cache is not linked to your account or trial identifier — it answers anyone who asks for the same sentence — so deleting a reading-history entry or your account does not remove it. Instead, each cached sentence and its audio are deleted automatically within 90 days of being created. Saving an item to Listen later, or preparing its audio, adds nothing to this cache: saved items are kept with your account, as described below.
- Spoken equations. The spoken words we make from a formula on a web page (§1) are kept without an expiry date, keyed by a fingerprint of the formula. They are not linked to you, your account or the page, so they cannot be traced back to what you read.
- Screenshots of covered pages (extension versions 1.0.0 to 1.7.1). We did not store the screenshots Firefox could send: each was discarded (before 19 September 2026) or passed to DeepSeek for one check and then discarded by us, and our logs never contained one. DeepSeek may have kept what it received from 19 to 27 September 2026: it publishes no retention period, and its policy lists training its models among its purposes (see §3). Had DeepSeek answered a check, we would have kept its result — the generalised page address described in §1, what kind of page it was, whether its text was readable, how many times the result was looked up, and when — not linked to your account. No result was ever stored. The extension kept a copy of recent results in your browser for up to 3 days; later versions delete it when they update.
- Summary text. Text sent for summarization is retained by whichever provider handled it, under that provider's own policy (see §3): OpenAI states up to about 30 days, while DeepSeek and Alibaba Cloud publish no retention period. We keep the generated summary, and a one-way fingerprint of the text it was made from so that a repeat request need not be sent out again, while your account is active; these are stored with your account rather than with your reading history.
- Listen later. A saved item — its title, address, text and details — is kept until you delete the item or your account. Audio prepared for a saved item is deleted automatically within 90 days of being created; after that the item plays with your device's voice, and its audio is prepared again if you ask for it. Once the mobile app is released, the copy of the text it keeps on your phone is removed when you sign out of it.
- Reading history. Reading-history entries and resume positions are retained while your account is active. You can delete individual entries or clear your reading history. When you delete your account, this data is deleted or anonymized.
- Account data is retained while your account is active. When you delete your account, associated personal data is deleted or anonymized.
- Locally stored settings remain on your device until you remove the extension or clear its storage.
7. Your choices and rights
- Optional player design measurement. An experiment-capable installation or update shows a focused consent screen inside the extension if you have not answered its current consent version. Both allow and off choices appear on that screen; opening or closing it does not grant consent. You can change the choice in the extension's General settings. New pages can participate after you allow measurement. Turning it off clears pending experiment reports and stops experiment measurement without stopping reading or ordinary product analytics. A reading that crossed opt-out stays outside later measurement even if you allow it again, so opted-out audio is not counted. Turning it off cannot recall a request already dispatched and does not delete reports already received; their retention and account-deletion rules are in §6.
- Access/deletion. You may request access to or deletion of your account data by contacting us at support@lullula.io.
- Turn off AI summaries. Summaries are the main thing that sends a page's text to the AI providers in §3, and they run automatically. Turning off "Show Summary" in the extension's General settings stops that; premium voices still send the text you play to the speech provider. Built-in browser voices, and phone voices in the mobile app once it is released, are your browser's or phone's own speech engine, which may process the text on the device or with its provider; Lullula receives nothing from that speech engine.
- Delete saved items. Removing an item from Listen later in the web app (or, once it is released, the mobile app) deletes its saved text and any audio prepared for it. Deleting your account deletes your saved items with it.
- Sign out. Signing out removes the stored authentication token from your device.
- Uninstall. Removing the extension deletes its locally stored data.
- Depending on your location, you may have additional rights (e.g., under GDPR or CCPA), including the right to access, correct, delete, or restrict processing of your personal data.
8. Security
We use industry-standard measures, including encryption in transit (HTTPS), to protect your data. No method of transmission or storage is completely secure, but we work to protect your information against unauthorized access.
9. Children
Lullula is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect personal data from them.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through in-product notice.
11. Contact
Questions or requests: support@lullula.io.