Privacy Policy

Last updated: August 19, 2026

SimpleReads is a nonprofit educational reading, note-taking, and research platform designed to help students stay focused while reading online and organize information across multiple sources.

We take privacy seriously, especially because SimpleReads may be used by students and in educational environments.

Quick summary: SimpleReads collects and processes information only as needed to provide, secure, maintain, and improve the service. We do not sell personal information. We do not use student notes or Google Workspace data to create advertising profiles, and we do not use Google Workspace API data for advertising.
✅ Google Sign-In
✅ Encrypted cloud storage
✅ No selling data
✅ No targeted advertising
✅ Data deletion requests

1. What This Privacy Policy Covers

This Privacy Policy applies to simplereads.org , the SimpleReads Chrome browser extension, and related SimpleReads services and features.

This policy explains what information SimpleReads accesses and collects, how that information is used, where information may be stored, how Google user data is handled, how data is protected, when information may be shared, and how users may request deletion of their data.


2. Information We Access and Collect

Google Account and Authentication Information

SimpleReads uses Google OAuth and Google Sign-In functionality to authenticate users.

When you sign in with Google, SimpleReads may receive basic Google account profile information made available under the permissions you approve. This may include:

  • Your name.
  • Your email address.
  • Google account identifiers.
  • Basic Google profile information, such as a profile image, when returned by Google.

SimpleReads uses this information to authenticate your account, determine whether you are authorized to use SimpleReads, and provide the service.

SimpleReads does not receive or store your Google account password.

Authentication Tokens and Local Session Information

After Google authorization, SimpleReads may temporarily store your Google OAuth access token and basic account information in Chrome extension local storage on your device so that SimpleReads can maintain your authenticated session and make authorized Google API requests.

When you sign out of SimpleReads, the extension removes locally stored account and token information and attempts to revoke the associated Google authorization token.

Notes and Research Content

SimpleReads allows users to create, edit, organize, and delete notes while reading online.

Saved note information may include:

  • The text or content of the note.
  • The source webpage URL associated with the note.
  • The time the note was created or updated.
  • The page scroll position associated with the note.
  • The SimpleReads or Google document associated with the note, including a document identifier and title.
  • An internal user identifier used to associate the note with the appropriate SimpleReads user.

Saved notes may be stored in Google Cloud Firestore so that users can access and manage their SimpleReads content.

SimpleReads stores source URLs in connection with notes so users can preserve the context and source of their research. The current SimpleReads application does not use these URLs to build advertising profiles.

Draft Notes and Browser Storage

Notes that have not yet been added to a saved SimpleReads document may be temporarily stored in browser local storage on the user's device.

A draft note may include information such as:

  • Note content.
  • Source webpage URL.
  • Timestamp.
  • Page scroll position.
  • Draft status.

After draft notes are successfully added to a document, SimpleReads clears those draft notes from its local draft storage.

School, Organization, and Account Authorization Information

SimpleReads uses authorization records to determine whether a user is permitted to access the service.

SimpleReads may process information such as:

  • User email address.
  • Email domain.
  • Authorization status.
  • Authorization start and end dates, where applicable.
  • Last-login information for authorized accounts.
  • Access-request status and request timestamp.

Schools and organizations may be authorized by email domain. When a domain is approved, SimpleReads uses the domain portion of a user's Google email address to determine whether that user is eligible for access.

This allows eligible students and staff to use an approved school or organization Google account without SimpleReads manually approving every account individually.

Access Requests

If a user is not already authorized, SimpleReads may allow the user to request access.

When an access request is submitted, SimpleReads may store the user's email address, a pending request status, and the date or time the request was submitted.

SimpleReads Administrative Information

The current SimpleReads administrative dashboard is used for account, domain, and access management.

The administrative dashboard displays account information such as a user's name and email address for access-management purposes.

The current administrative dashboard does not display users' note content or general browsing history.


3. Google Drive and Google Docs Integration

SimpleReads integrates with Google Drive and Google Docs so users can organize SimpleReads notes into Google documents.

Google API access is used to provide user-facing SimpleReads features and to perform actions initiated through the SimpleReads application.

The SimpleReads Google Drive Folder

SimpleReads searches the user's Google Drive for a folder named SimpleReads.

If a SimpleReads folder does not already exist, SimpleReads may create the folder in the user's Google Drive.

The folder is used to organize Google Docs created or managed through SimpleReads.

Google Drive Metadata

SimpleReads requests Google Drive metadata access so the application can locate the SimpleReads folder and identify Google Docs associated with that folder.

The current SimpleReads implementation uses Drive metadata to retrieve information such as:

  • Google Drive file or folder identifiers.
  • Google Drive file or folder names.

SimpleReads uses this information to locate the SimpleReads folder and display Google Docs from that folder in the SimpleReads My Documents interface.

The https://www.googleapis.com/auth/drive.metadata.readonly permission is a Google Drive metadata permission and may authorize visibility into Drive file metadata. The current SimpleReads application uses this access to locate the SimpleReads folder and retrieve identifiers and names needed for its document-management features.

This metadata permission does not itself provide file-content access. Google Docs content is accessed separately through the Google Docs permission described below.

Creating and Managing Google Drive Files

At the user's direction, SimpleReads may create and manage Google Drive files used with SimpleReads.

SimpleReads may:

  • Create the SimpleReads Google Drive folder.
  • Create Google Docs inside the SimpleReads folder.
  • Rename Google Docs managed through SimpleReads.
  • Delete a Google Doc when the user intentionally requests deletion through SimpleReads.

These actions are performed to provide SimpleReads' user-facing document-management functionality.

Google Docs Content

When a user intentionally creates, opens, edits, or synchronizes a Google Doc through SimpleReads, SimpleReads may read and modify the contents of that Google Doc as necessary to perform the requested action.

SimpleReads may use the Google Docs API to:

  • Read a Google Doc's structure and text so SimpleReads can determine where associated notes and source information are located.
  • Insert source webpage URLs into the Google Doc.
  • Insert note content into the Google Doc.
  • Apply basic text and paragraph formatting to inserted SimpleReads content.
  • Update synchronized note content after the user edits a note.
  • Remove or replace synchronized content when the user edits or deletes associated information.

SimpleReads reads Google Doc content as needed to perform these synchronization operations. The current application does not intentionally store a complete copy of a user's Google Doc in Cloud Firestore simply because the document was read through the Google Docs API.

SimpleReads does not use Google Docs content for advertising, advertising profiles, or unrelated purposes.


4. Google OAuth Permissions Requested by SimpleReads

The current SimpleReads Chrome extension requests the following Google OAuth scopes:

Google Account Email

https://www.googleapis.com/auth/userinfo.email

Used to receive the user's Google email address for authentication and SimpleReads account-authorization purposes.

Google Account Profile

https://www.googleapis.com/auth/userinfo.profile

Used to receive basic Google profile information used by SimpleReads during authentication and within the user experience.

Google Docs

https://www.googleapis.com/auth/documents

Used to access and modify Google Docs when required for SimpleReads' user-facing note and document synchronization functionality.

This includes reading document content and using Google Docs update operations to insert, update, format, or remove SimpleReads content at the user's direction.

Google Drive Metadata

https://www.googleapis.com/auth/drive.metadata.readonly

Used by the current SimpleReads implementation to locate the SimpleReads Google Drive folder and retrieve identifiers and names for Google Docs contained within that folder so those documents can be displayed and managed in SimpleReads.

Google Drive File Access

https://www.googleapis.com/auth/drive.file

Used to create and manage Google Drive files and folders used with SimpleReads, including creating the SimpleReads folder, creating Google Docs, and performing user-requested management actions on SimpleReads files.

SimpleReads uses Google API permissions only to provide or support user-facing SimpleReads functionality.


5. How We Use Information

SimpleReads uses information described in this policy for purposes including:

  • Authenticating users through Google.
  • Determining whether a user is authorized to access SimpleReads.
  • Verifying access through approved school or organization domains.
  • Processing user access requests.
  • Providing and maintaining the SimpleReads note-taking experience.
  • Saving and retrieving notes associated with a user's account.
  • Associating notes with source webpages and scroll positions so users can preserve research context.
  • Creating and managing the user's SimpleReads folder in Google Drive.
  • Displaying Google Docs associated with the SimpleReads folder.
  • Creating, reading, updating, renaming, and deleting user-directed SimpleReads Google Docs.
  • Synchronizing user-created notes with Google Docs.
  • Maintaining user authentication sessions.
  • Protecting SimpleReads against unauthorized access or misuse.
  • Responding to support, privacy, and deletion requests.
  • Complying with applicable legal obligations.

6. Data Security and Protection

SimpleReads uses technical and organizational safeguards designed to protect personal information and Google user data from unauthorized access, disclosure, alteration, or loss.

Encryption in Transit

SimpleReads relies on secure HTTPS connections when communicating with Google APIs and Firebase services.

Google Firebase and Cloud Firestore protect supported network communications using HTTPS and Transport Layer Security (TLS).

Encryption at Rest

SimpleReads uses Google Cloud Firestore for application data storage.

Cloud Firestore automatically encrypts stored data at rest using encryption provided and managed by Google Cloud unless a different supported encryption configuration is selected.

Google Authentication

SimpleReads uses Google's OAuth authentication mechanisms. SimpleReads does not receive or store users' Google account passwords.

Google OAuth access tokens used by the Chrome extension may be stored locally within Chrome extension storage for the duration of the authenticated session.

Account and Domain Access Controls

SimpleReads checks authorization records before providing access to protected application functionality.

Access may be granted based on an individually authorized account or an approved school or organization email domain.

Administrative Access

Administrative access to SimpleReads systems and account data is limited to authorized individuals who require access to operate, maintain, secure, or support SimpleReads.

SimpleReads does not permit routine human access to Google Workspace API data for unrelated purposes.

No Absolute Security Guarantee

No internet-based service or method of electronic storage can be guaranteed to be completely secure. Although SimpleReads uses safeguards designed to protect information, SimpleReads cannot guarantee absolute security.


7. Sharing and Disclosure

SimpleReads does not sell personal information or Google user data.

Information may be processed or disclosed only in limited circumstances such as the following:

  • Google and Firebase Services: SimpleReads uses Google APIs, Google Drive, Google Docs, Firebase, and Cloud Firestore to provide application functionality. Information may be transmitted to or processed by these Google services as necessary to provide the user-requested features.
  • Service Providers: Information may be processed by service providers acting on behalf of SimpleReads when necessary to operate, maintain, or secure the service and only for the permitted purpose.
  • Security: Information may be accessed or disclosed when reasonably necessary to investigate misuse, fraud, security incidents, or threats to the SimpleReads service or its users.
  • Legal Requirements: SimpleReads may disclose information when required by applicable law, regulation, legal process, or a valid request from a public authority.

Human Access to Google Workspace Data

SimpleReads does not allow humans to read Google Workspace API user data except where such access is permitted under applicable Google policies, such as when a user has provided appropriate consent for a specific purpose, when access is necessary for security or abuse investigation, or when required by applicable law.


8. Google API Services User Data Policy and Limited Use

SimpleReads' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google Workspace API data is used only to provide or improve appropriate user-facing SimpleReads functionality.


9. What We Do Not Do With Google User Data

SimpleReads does not use Google Workspace API data for:

  • Selling personal information or Google user data.
  • Targeted advertising.
  • Personalized or interest-based advertising.
  • Advertising retargeting.
  • Creating advertising profiles.
  • Selling information to data brokers or information resellers.
  • Determining creditworthiness or for lending purposes.
  • Training, creating, or improving generalized artificial intelligence or machine-learning models.
  • Unrelated surveillance or monitoring.

10. Data Retention and Deletion

Account and Authorization Information

Account and authorization information may be retained while a SimpleReads account remains active, while access authorization remains necessary, or as otherwise reasonably required to provide and secure the service.

Notes and Research Information

Saved notes and associated information may remain stored while the user's SimpleReads account is active so the user can continue accessing and managing their research.

Draft Notes

Unsaved draft notes may be stored locally in the user's browser. SimpleReads clears its local draft-note list after those notes are successfully added to a saved document.

Google Drive and Google Docs

Google Docs created through SimpleReads are stored in the user's own Google Drive.

Removing data from SimpleReads does not necessarily delete a Google Doc from the user's Google Drive unless the user specifically uses a SimpleReads feature that deletes that Google Drive file or the user deletes the file directly through Google.

Deletion Requests

Users may request deletion of their SimpleReads account and associated SimpleReads-stored information at any time by contacting:

simplereadsinc@gmail.com

Upon a verified account-deletion request, SimpleReads will delete applicable account information and SimpleReads-stored Google user data from active SimpleReads databases within 30 days, except where retention is required by law or reasonably necessary for security, fraud prevention, or other legitimate operational purposes.

Where applicable, temporary residual copies may remain for a limited period in service-provider backup or logging systems until those systems complete their normal retention or deletion cycle.

Revoking Google Access

Users may revoke SimpleReads' access to their Google Account through their Google Account security and third-party permissions settings.

SimpleReads also attempts to revoke its Google OAuth token when a user signs out through the SimpleReads extension.

Revoking Google authorization prevents future authorized access to Google APIs but does not necessarily delete information already stored in SimpleReads or Google Docs already created in the user's Google Drive.

To request deletion of SimpleReads-stored data, contact simplereadsinc@gmail.com .


11. Browser Permissions and Local Storage

The SimpleReads Chrome extension uses browser permissions and browser storage required to provide extension functionality.

This may include Chrome extension local storage and webpage local storage for:

  • Authentication session information.
  • Basic Google profile information.
  • Extension settings and preferences.
  • Temporary draft notes.
  • Information needed to return a user to the location on a page associated with a note.

SimpleReads may access the URL of the active webpage as part of its note-taking and source-context functionality.

SimpleReads does not use this information to create advertising profiles.


12. Cookies

SimpleReads.org or related SimpleReads services may use cookies, local storage, or similar browser technologies when necessary for essential functionality.

SimpleReads does not use third-party advertising cookies to create behavioral advertising profiles.


13. Students and Educational Use

SimpleReads is designed for educational use and may be used by students, including minors.

We seek to minimize personal information collected from students and process information only as reasonably necessary to provide SimpleReads functionality, authenticate users, manage authorized access, maintain research content, provide Google integrations, and protect the service.

Schools and educational organizations considering deployment of SimpleReads should review this Privacy Policy and SimpleReads' privacy and security practices before enabling student access.

Additional consent, privacy, contractual, or data-protection requirements may apply depending on a student's age, location, school, and applicable law.

This Privacy Policy should not be interpreted as a claim that SimpleReads automatically satisfies every school, district, state, federal, or international student-data requirement.

SimpleReads is willing to work with participating educational organizations to address applicable privacy and security requirements for a deployment.

A parent, guardian, school, or student with questions regarding personal information or deletion may contact simplereadsinc@gmail.com .


14. User Choices and Control

Users have choices regarding their information and Google account access.

  • Users choose whether to authorize SimpleReads to access their Google Account.
  • Users may revoke SimpleReads' Google authorization through their Google Account.
  • Users may sign out through the SimpleReads extension.
  • Users decide when to create SimpleReads notes.
  • Users decide when to create or add notes to a Google Doc.
  • Users may rename or delete supported SimpleReads documents through the available application controls.
  • Users may request deletion of SimpleReads-stored account data.
  • Users may contact SimpleReads with privacy or data questions.

15. Changes to This Privacy Policy

SimpleReads may update this Privacy Policy when the product, technology, legal obligations, or data practices change.

When this Privacy Policy is updated, the Last updated date at the top of this page will be changed to reflect the effective date of the revision.

If a change materially affects how SimpleReads accesses, uses, stores, protects, or shares Google user data, SimpleReads will update its disclosures and obtain additional user consent where required before using Google user data for a materially different purpose.


16. Contact SimpleReads

If you have questions about this Privacy Policy, Google user data, SimpleReads security practices, account information, or a data-deletion request, please contact:

Email: simplereadsinc@gmail.com

Website: simplereads.org