Updated September 10, 2026
Privacy
We do not run advertising or sell your data. We measure public website visits and invitation activity as described in section 07. We also store the text you give Speed Reader, your account if you sign in, billing records if you pay, and the details you submit when requesting a NASC invitation.
01
Who we are
Archerion Labs, in Pasco County, Florida, operates archerionlabs.com and Speed Reader. For anyone reading this under the GDPR, we are the data controller. Write to hello@archerionlabs.com and a person answers.
02
The text you paste
Speed Reader needs your text on the server to render it back to you one word at a time. So we store it, along with the title you give it, its word count, and how far through it you are. That is the whole row.
If you are not on a paid plan, that row is built to disappear. It expires one hour after you create it, and it is marked finished the moment you reach the end. A cleanup job runs every five minutes and deletes anything more than ten minutes past either mark, so the practical ceiling is about an hour and a quarter, usually far less. We keep no copy of our own anywhere else, though see the note on backups in section 10.
On a paid plan the row has no expiry, because the point of paying is a reading history that survives. It stays until you delete it, and every row of your history has a delete control that removes it on the spot.
While a session is live it is locked to your browser by a random secret we set as a cookie. Nobody who guesses the URL can read your text without that secret.
Nearly the same path if you reach Speed Reader through the MCP tool from an AI assistant: whatever text your assistant sends becomes an ordinary session row, and on a free plan it expires an hour after creation like any other. The difference is housekeeping. Your assistant makes the link before you have clicked it, so rather than deleting an unopened one ten minutes after it expires, we hold it for up to a day. That exists so someone on a paid plan who opens the link late still gets the read they paid to keep. It does not make the read openable on a free plan, where the hour is the hour. Once someone claims it, or a day passes, the same cleanup job deletes it. We do not send your text to any AI model. There is no model in this product. The summary line above the reader is arithmetic on the word count, nothing more.
03
Your account
You can use Speed Reader without an account. If you make one, we store your email address. If you sign in with Google, we store the basic profile Google hands back with it. Authentication runs on Supabase, which holds that record for us.
We use it to know which saved sessions are yours and to email you a sign-in link. We do not send marketing.
04
Paying us
Paid plans run through Stripe. Card numbers go to Stripe and never touch our servers. What lands in our database is the Stripe customer and subscription identifier, the status of the subscription, the tier, and when the current period ends. That is enough to know whether to unlock the paid features and nothing more.
Stripe does not push us updates. We ask it, on a schedule and when you open a billing page, and write down the answer. So the only record of your subscription we keep is the one described above, and it is a copy of what Stripe already holds.
Before your first purchase we ask you to accept the terms of service, and we record which version you accepted and when. That record is part of your account and is deleted with it.
05
Your IP address
We never store it. To stop one machine from flooding the service we need to count requests per source, so we run your IP through a keyed one-way hash and count against the hash instead. The key rotates, which means hashes from one period cannot be lined up against another. Those counter rows are deleted after two hours.
Our hosting and database providers see IP addresses in their own transport logs, the way every host on the internet does. That is their retention, under their terms, not a store we keep or query.
06
Cookies
Only the ones that make the thing work. No advertising cookies, no analytics cookies, or persistent analytics identifiers in browser storage. Section 07 describes the separate cookieless measurement.
- sr_session_<id> and sr_api_<id>
- A random secret that proves a reading session belongs to your browser. Contains no identity. Set with HttpOnly and Secure, so page scripts cannot read it. Scoped to that one session.
- sb-<project>-auth-token
- Set by Supabase only after you sign in. It is what keeps you signed in between page loads. Signing out clears it.
07
Counting visits
Our server records the public page requested, a source label or referring hostname, and the time. It does not store IP addresses, browser identifiers or referrer paths in these counter rows. They are deleted after 180 days and cannot identify unique visitors.
We also use PostHog to measure public page views, blog views, clicks to NASC, Show interest clicks, and successful invitation submissions. A browser script sends the public page path, referring hostname, approved campaign labels, basic browser and device type, and event time. Query strings, form contents, account identifiers, private reader pages and session recordings are excluded.
PostHog uses cookieless server hash mode. It receives your IP address and browser user agent as part of the connection and uses them with a daily changing salt to estimate visits. It removes the IP before analytics enrichment. We do not create person profiles or store analytics cookies or persistent browser identifiers. A visitor on two different days may be counted twice. This setup does not provide location maps or IP-based bot filtering.
PostHog processes these events in the United States. The free plan retains events for up to one year. We use them to understand which writing and links lead people to NASC, never for advertising. Browser Do Not Track and Global Privacy Control signals disable this script's collection. Tracker blocking can also stop it; the separate server counter still records page requests.
08
Who else touches it
We use the following providers to operate the site.
- PostHog
- Processes the cookieless website measurements described in section 07.
- Vercel
- Hosts the site and runs the server code.
- Supabase
- The database and the sign-in system. Your sessions and your account record live here.
- Only if you choose Google sign-in. Skip that button and Google is not involved.
- Stripe
- Only if you subscribe. Handles the payment and holds the card details we deliberately never see.
We will also hand over data if a valid legal order requires it. If that ever happens and we are permitted to tell you, we will.
09
Why we are allowed to hold it
Under the GDPR, storing your text and running your account is necessary to give you the service you asked for. Rate limiting is our legitimate interest in keeping the service standing. Billing records are contractual, and we keep the tax-relevant parts as long as the law requires. If you are in the United States, the plain version is that we do not sell or share your personal information for advertising. You can object to measurement or use the browser signals described in section 07.
10
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask for it in a portable format, or object to how we are using it. If you are in the EU or the UK you can also complain to your data protection authority, though we would rather you came to us first.
Deletion you do yourself, without asking us and without waiting. Every row of your reading history has a delete control. Your data lists everything we hold on you and will delete the whole account, the saved reads, and the billing record together. If you are on a paid plan it cancels the subscription first, so deleting cannot leave you paying for an account that no longer exists.
One caveat we would rather state than bury. Deleting removes your data from the live database immediately, but our database host takes a backup every day and keeps each one for seven days. So a copy of something you deleted can sit in a backup until it ages out. We never restore an account or a read from those backups, and after seven days it is gone from them too.
For the rest, a copy of your data or a portable export, email hello@archerionlabs.com and we will answer within thirty days. Those two are not self-serve yet, and we would rather say so than describe a control that does not exist.
11
Where it lives
On servers in the United States. If you are in the EU or the UK, using Speed Reader means your data goes there. Our providers cover that transfer under the European Commission’s standard contractual clauses.
12
Children
Speed Reader is not built for children and we do not knowingly collect anything from anyone under sixteen. If you believe a child has given us data, email us and it comes out.
13
Changes
When this policy changes in substance we change the date at the top and the version identifier below. We do not quietly rewrite history.
privacy-2026-09-10
14
Contact
hello@archerionlabs.com
Archerion Labs, Pasco County, Florida, United States