Privacy Policy
Last updated 26 September 2026. Mundane Read is a registered business name of Creditcrest Technologies Pty Ltd (ACN 702 318 778, ABN 80 702 318 778). Write to support@mundaneread.com about anything below.
There is no advertising on this site, ever, and nothing described below is sold or shared with anyone for advertising purposes — that is a property of the product, not a setting that could change.
1. What we collect
| Data | When | Why |
|---|---|---|
| Email address | Free reader account signup, or API payg
checkout | Identifies your account; for API accounts, shared with Stripe to process billing. |
Signed session cookie (mr_reader) | After reader signup | Proves you are signed in. Contains your email and an issue timestamp, signed so it cannot be forged, but not encrypted — do not treat it as a secret channel. |
| Sign-in codes (hashed) | Each time you sign in | Checks the code you type. We store a keyed hash of the code, never the code itself, and delete it after a day. |
| Front-page preferences | When you save them in Settings | The sections, places and indicator limits your front page opens with. Delete them with "Reset" in Settings. |
Display cookie (mr_signed_in) | After signing in | Tells the page to show "Settings" instead of "Sign in". Contains only "1". |
Anonymous cookie (mr_anon) | Reading without an account | A random id with no other meaning, used only to count today's articles against the 12-a-day cap. Not linked to an email address or any other identity. |
| API key (hashed) | API account creation | Authenticates API calls. We store a SHA-256 hash, not the key itself — the full key is shown once and cannot be recovered by us either. |
| Usage records | Every API call | Which product, how many words, which
day — needed to bill payg accounts correctly and to enforce the free
tier's quota. |
| Daily Brief email | If you turn it on in Settings | Your address, and the date the last one was sent so you get one a morning. Every email has a one-click unsubscribe. |
| Stories you follow | When you press Follow on a story | Your address and the story, so we can email you when another newsroom files on it. Every one of those emails unsubscribes in one click, without signing in. |
| Accuracy labels | If you label paragraphs | Your answers, stored under a one-way hash of your email so each person counts once; never shown with your address. |
| Your location | If you press "Use my location" on Local | Used in your browser to find the nearest town. It is never sent to us. |
| Stories you have opened, and subjects you have folded away | As you read, and if you use Not today | Kept in your browser's own storage so a story you have read can be marked and a subject you muted stays muted. Never sent to us, not linked to any account, and not shared between your devices. Clearing your browser data clears them; so does Unmute everything, for the muted subjects. |
| Extension subscription status | When you subscribe | Whether your subscription is active, its plan and renewal date, and Stripe's customer id, so the extension can be unlocked. Updated by Stripe when anything changes. |
| Extension sign-in tokens (hashed) | When you connect an extension | Lets the extension ask whether your account is subscribed. We store a SHA-256 hash, the browser and system it was connected from (“Safari on macOS”, worked out from the connecting page; the full browser string is not kept), and the last day it was used; a connected extension checks in at least once a week. That is how Settings lists your browsers and how a subscription is kept to one person in up to three browsers. When a browser is disconnected we keep the record, and why, for 30 days. The extension sends only the token: not the pages you read, not their addresses, not its weekly count, which stays on your device. Disconnect any browser in Settings. |
| Nothing, for the extension's article lookups | When the extension shows its panel on an article | To show the readings we publish for an article, the extension turns the page's address into a SHA-256 fingerprint in your browser and sends us only its first four characters, which one address in every 65,536 shares. We answer with the articles we hold under those four characters and the extension picks the match on your device. The address itself is never sent, the request carries no token or cookie, and we keep nothing from it. |
| Payment details | API payg checkout or extension subscription | Collected and stored by Stripe directly; we never receive or store card numbers. |
Your rights
Download everything we hold about you, or delete your account, from Settings (Your data, Delete account). For anything else, including a correction, email support@mundaneread.com. We follow the Australian Privacy Principles and reply within 30 days.
2. What we do not collect
No password (reader accounts do not have one). No tracking pixels, no third-party analytics, no advertising identifiers. The anonymous reading cookie is not used for anything beyond the daily count and is never combined with an email address.
3. Retention
A reader session cookie is valid for 90 days from signup and is not renewed by reading — after 90 days, sign in again. An hourly job deletes what is past its use: anonymous daily-read counts after two days, sign-in codes after one, records of failed sign-ins once they can no longer lock anything, and an extension connection that has not been used in 180 days. API usage records are kept for as long as the account is active, for billing history and disputes. Everything held against a reader account is deleted when the account is, from Settings.
4. Sharing
Cloudflare hosts the site and receives the ordinary details of every request (your IP address and browser) to serve it. The site's typeface is served from our own domain, so no font service sees your visit. Account emails are sent through Resend, which receives your email address and the message.
Stripe processes payments and receives the billing information needed to do that (email, and whatever payment details you give Stripe directly — never us). We do not sell, rent, or share reader or account data with anyone else, including for advertising, because there is no advertising on this product to share it with.
5. Your rights
Email privacy@mundaneread.com from the address on the account to have it and its data deleted, or to ask what is held against it. For a reader account this simply means clearing the record of your email; the session cookie itself already expires in your own browser and can be cleared immediately by signing out. For an API account, deletion also revokes any active keys and cancels the underlying Stripe subscription.
6. Children
This service is not directed at children under 13, and we do not knowingly collect an email address from anyone under that age.
7. Changes
We will update the date at the top of this page when this policy changes, and describe the change in plain terms rather than only in the diff.