Privacy Policy
Read the web without being followed.
Ratdolt collects only what it needs to compose a public page, protect the service and respond when you ask for help. It does not sell personal data or use advertising trackers.
Effective August 11, 2026
Who is responsible
The person or entity operating Ratdolt and ratdolt.com is the controller of personal data described in this policy. Privacy questions and rights requests may be sent to get@ratdolt.com.
Data Ratdolt processes
- Addresses and public page content. The URL you submit, the HTML and public images needed to compose it, source metadata and the resulting publication.
- Selected-text captures. Plain text you deliberately paste, its public source URL and optional title/author. Ratdolt turns it into inert semantic HTML; the website cannot read another tab, source-site cookies, passwords, hidden elements or form values.
- Account, Library and collaboration data. Your account email, profile, saved publications, settings, collections, research and provider connections. When someone invites you to a shared reading or private collection, Ratdolt keeps the invited email, role, expiration and acceptance state privately. A collection invite is claimed only by a signed-in account whose current email is confirmed and matches; its owner alone can see that roster. Anyone with an unlisted shared-reading link can read the public username/name, highlights and note you deliberately contribute, but cannot see either invitation roster or email addresses. If you add a birthday to profile settings, the complete date remains owner-only. A separate unchecked-by-default choice may publish its month and day on an already public profile; the anonymous response never includes the birth year. Making the profile private also disables that birthday display while retaining the private date. When an owner reads an active saved publication, Ratdolt may keep its furthest five-decimal page fraction and last-opened time. It does not store a per-page scroll trail or copy page text into that progress record.
- Manual bookmarks and saving preferences. When you choose Save for later, Ratdolt stores the normalized address and the title, description, author, source type, cover, favourite, archive state, visibility, collections and tags you deliberately provide. If you ask it to remember those choices, the organization defaults are stored with your account.
- Reading, Composer and narration defaults. If you explicitly promote a Composer setup, Ratdolt stores bounded document theme, light/dark control-panel choice, typography, display, accessibility—including reading-ruler colour, opacity, height and position—and bounded scoped-CSS preferences locally and, when signed in, with your account. An explicit narration action stores only the browser-voice name, bounded rate and pitch used as a starting point for new Composer and PDF readings. An explicit translation action stores only the selected BCP 47 source- and target-language codes as a starting point for new translations; it never stores translated document or selection text. Custom CSS is sanitized before it is applied. A named device font or browser voice is only a text preference; its file is never uploaded, and saving narration does not upload PDF bytes or text. URL routing stores only the normalized domain, wildcard or bounded regex pattern plus its Reader/Composer and content-mode choices. Ratdolt tests that preference when you deliberately submit a public URL to the website; it does not read or retain a history of unrelated browser tabs. The global destination palette filters its fixed internal links only in page memory and discards the query when it closes; Ratdolt does not record those keystrokes. Auto-scroll direction and bounded speed may be stored as defaults, but active motion is never restored from synced data. Ratdolt checks local translation support only when you ask it to translate. Choosing the separately labelled Google Translate fallback opens that provider directly, so the provider receives the text and normal browser request data at that moment.
- Composer content repair. Text corrections, block formatting and the identities of blocks you remove are reversible fields in that source snapshot's private Composer workspace. The visual deletion mode, its current focus and its single-step Undo control are temporary interface state and are not synchronized. Removing a Composer block does not alter Reader, the source snapshot or its canonical PDF; restoring one removes only that private hidden-block instruction.
- Citation artifacts. Composer derives the five citation styles from metadata already present in the recovered source snapshot. Copying a bibliography, downloading its HTML or Word-compatible DOC, and printing or saving it as PDF happen in your browser; those actions create no citation request or additional Ratdolt record. Opening Cite from a saved publication only navigates to that source's existing private Composer workspace; it does not create a duplicate citation record. Optional title, author, publication and date corrections persist inside that private source workspace, never rewrite the immutable source and are removed from a frozen collaborative share. The files remain wherever you choose to save them.
- Unified material index. Ratdolt searches owner-scoped bookmark collection, publication, image, private cloud PDF, note and highlight fields and returns bounded metadata or excerpts to the All Materials page. A collection result exposes its name, icon, parent context and bounded counts—not another taxonomy or its members' private content. Private collection membership can link publication, saved-image and account-PDF bookmark IDs; notes and highlights remain outside that relationship. Ratdolt stores one owner-only relative order for those account-backed members. Collection collaborators and anonymous/public views receive only the separate publication order, not private image/PDF IDs or positions. Device-only PDF names, tags and collection IDs are read from IndexedDB and merged by the browser; their bytes and local position do not enter the account index. Moving a bookmark between folders sends only its closed material type, account object ID and the two owner collection IDs; unrelated memberships are preserved. A material filter sends only the repeated owner tag IDs selected in the URL; the owner-only projection requires every selected tag before counting, sorting or paginating. Device-only PDFs apply the same match-all rule in this browser. Tag View groups only the material page already returned to the browser, makes no additional request and may display one object in each of its matching tag groups; the page's headline continues to count unique objects. After two typed characters, autocomplete sends the bounded query to that same owner-only index and returns at most eight titles, short descriptions, contexts and canonical first-party links with private caching disabled. Device-only PDF names are matched after the response inside this browser and never enter that request.
- Saved images and attributed covers. Web images you deliberately preserve and bitmap files you upload are stored in a private image bucket with their title, alternative text, tags and source metadata. Choosing one as a bookmark cover creates only an owner-checked reference; it does not duplicate the image or make the storage object public. If you deliberately search Unsplash, Ratdolt sends the bounded search phrase to Unsplash and displays its hotlinked results. Choosing one stores its photo ID, CDN URL and photographer name/username for attribution; Ratdolt does not store the API key or provider download endpoint. The same search can select a public profile cover after you publish that profile. A visitor's browser then requests the image directly from Unsplash while Ratdolt displays linked photographer credit. Returning the profile to private clears either uploaded or remote cover identity.
- Private file-storage usage. Ratdolt totals the byte counts already recorded for your preserved images, explicitly saved cloud PDFs, permanent source snapshots and portable HTML editions. The owner-only account response contains the aggregate plus those three category totals; it contains no storage path, signed URL, file body or another account's usage. Device-only PDFs, note text and ordinary Library metadata do not enter this file allowance.
- Portable-edition recovery. If a one-file edition cannot preserve every guarded stylesheet, font or image, a service-only queue keeps the publication/version identity, owner ID, private object paths and retry timestamps for up to seven days. No browser visitor or anonymous projection can read that queue. A recovered file replaces the indexed edition only when it contains the same resource set with more resources embedded; the former private object is removed after the quota-checked commit.
- Offline device shelf. When you choose “Keep on this device” or import a Ratdolt one-file HTML edition, that complete file plus bounded title, source address, immutable version, fidelity label, byte count, declared resource counts, SHA-256 digest and saved time enter IndexedDB in the current browser profile. Ratdolt caps one file at 70 MB, the shelf at 20 files and its own logical allowance at 500 MB. The service worker caches only the public
/offlineand/offline/pdfshells, versioned application assets, house fonts/brand files and the labelled sample. The PDF shell explicitly warms the newly loaded bundled PDF.js chunks, worker and annotated-export runtime through that same static allowlist; PDF bytes and annotations remain in their separate local IndexedDB stores and never enter Cache Storage. The worker explicitly excludes account, billing, checkout, Composer, Library, Research, share and every API route. A local copy is not account sync, is not encrypted by Ratdolt, survives sign-out and remains readable to anyone using that browser profile until you remove it or the browser clears storage. Imported files must carry Ratdolt's deny-by-default archive policy and contain no active controls. Current content-addressed account responses expose an RFC 9530 digest that is verified before the write; legacy files are fingerprinted locally. Missing or digest-failing rows remain visible for explicit recovery and a failed quota write does not delete the prior commit. Asking the browser for persistent storage is separate and may be refused; downloading the one-file HTML remains the independent backup. The PDF shelf compares bounded SHA-256 metadata, file and workspace keys before it lists a document. It does not present metadata whose bytes are missing; it can reopen byte records whose metadata disappeared only after their digest verifies, and keeps a bounded research-only identity so re-importing the exact PDF can restore its notes. An encrypted PDF's password exists only in its controlled password field and PDF.js opening callback: an incorrect value is cleared, no value enters a request, cookie, Web Storage or IndexedDB, and reopening the retained file asks for it again. Workspace writes are serialized and compare their update time inside the same IndexedDB transaction so an older asynchronous save cannot replace newer research. The displayed usage/quota are browser estimates for the whole Ratdolt origin, not an account allowance. Persistent-storage permission reduces automatic eviction risk but cannot prevent browser, operating-system or user deletion. - Profile following. When signed in, you may follow an already public profile. Ratdolt stores the two internal profile IDs and creation time in a table with no anonymous or authenticated Data API grants. Public profiles expose aggregate follower/following counts, never either roster. Your Following feed is computed for your account and contains only objects whose profile and object are still public. Unfollowing deletes the relationship. Making a profile private removes all inbound follows so a later public transition cannot silently restore its former audience.
- Reading Commons search and continuation. Public and Following searches run against the complete current least-data projection, not a browser-cached result window. A continuation token contains its public feed/search boundary, snapshot time, update time, public handle and source URL or collection slug. It contains no account or object UUID, email, snapshot path, note or research data. Ratdolt rechecks both profile and object visibility on every page, so a withdrawn object stays absent.
- Unlisted collection access links. Creating or rotating link access generates a 256-bit secret in the application and stores only its SHA-256 digest with the owner and collection IDs. The raw secret is revealed in the browser URL fragment, removed from the address after display and never becomes a collection query parameter. Anyone holding the resulting URL can read the owner's public handle, collection name/description/icon and at most 500 owner-ordered web, saved-image and account-PDF bookmarks. A saved file may remain private everywhere else: its access URL combines this collection bearer with a separate opaque file token, rechecks exact same-owner membership and serves only signature/digest-verified bytes; PDFs are forced downloads. The response omits account/object IDs, storage paths, snapshots, PDF workspaces, highlights, notes, private covers, other memberships, research and the collaborator roster. The collection remains absent from the public profile and Reading Commons; rotating or disabling the link, changing visibility or removing a file invalidates the corresponding old access path.
- Public collection hierarchy. A public collection page can display a parent breadcrumb and direct-child folders from the same bounded public-profile projection. Ratdolt returns a parent slug only when the parent belongs to the same account and the profile, child and parent are each independently public. If a public child sits below a private parent, anonymous readers see the child as a root; the private parent's name, slug, ID and relationship remain undisclosed.
- Public image and PDF collection bookmarks. A saved image or account PDF remains private unless you separately publish the file, at least one containing collection and your profile. The anonymous collection projection contains bounded display metadata and one opaque public token; it contains no account or object UUID, storage path, PDF digest or annotation workspace, tags, private memberships or research. Each delivery rechecks all three public choices. Images must still match their inert bitmap signature and complete stored digest. PDFs must still match their complete digest and are sent as downloads under a sandboxed, non-cacheable response; the browser research workspace never becomes public. Removing any public choice stops delivery. Moving the file itself from Public to Private also rotates its token, so republishing cannot silently restore the former address. A public collection embed may render the same bounded row and triple-gated first-party image, or offer the same download-only PDF address, in the owner's mixed bookmark order. The embed receives no extra grant or private rank. The public profile and profile embed may show each eligible file once when at least one public collection keeps that same triple consent alive; they do not disclose which collection granted eligibility. Unlisted collection links, Reading Commons copy actions and collaborator projections do not receive these file bytes.
- Service and security data. Ordinary request information such as IP address, user agent, timestamps, requested route, error details and rate-limit state.
- Aggregate audience data. Page views and limited technical context such as route, referrer, country, browser, device and operating system, measured by Vercel Web Analytics without cookies or persistent visitor identifiers.
- Performance and reliability data. Core Web Vitals, normalized route, request timing, service dependencies, deployment context and error details measured through Vercel Speed Insights and privacy-filtered OpenTelemetry traces. Submitted addresses, query strings, request bodies and database statements are removed before trace export.
- Reports and support messages you choose to send. A contextual problem or policy report may contain source URL, product context, optional note, page count, timestamp and user agent. The general Contact form instead contains only the selected category, optional reply email, subject, message, optional public page URL and timestamp; it does not attach page text, PDF bytes, an account ID or user agent.
One view, separate storage boundaries
All Materials is an owner-only index, not a new public copy of your work. Its database projection omits private storage paths, signed file links, complete note bodies, PDF annotation workspaces and source bytes. Opening a result returns to the object's existing Library, Images, PDF or Research surface. Autocomplete responses are capped at eight and rebuild each destination from a closed material type plus owner object ID; they omit source keys, tag and collection IDs, storage paths, full bodies and user identifiers.
Local PDF metadata is added only after the page opens in this browser. If the same SHA-256 file also has an explicit private account copy, Ratdolt presents one identity and prefers the exact on-device reopen path. A device-only PDF remains absent on another browser unless you separately choose to save a private cloud copy. Importing portable PDF research reads at most 2 MB locally, accepts only normalized annotations whose document identity equals that exact SHA-256 digest, and preserves an existing local annotation when the imported file repeats its ID. The JSON file is not uploaded by the import action. Downloading an on-device PDF creates a temporary browser Blob from the already retained bytes after signature, size and—when chosen from the shelf—digest verification. Ratdolt gives it a path-free filename and does not upload, modify, rasterize or attach the separate annotation workspace to that exact copy. A distinct Annotated PDF action uses the local pdf-lib runtime to rewrite another temporary Blob with only the visible page-relative highlight rectangles embedded. It does not upload the source, alter the retained original or place editable labels and notes inside the generated PDF; those remain in Markdown/JSON. The action is unavailable for encrypted source PDFs, whose original bytes and portable research remain separate. The local integrity panel can remove metadata only after the same transaction confirms that no file bytes exist, and can remove unindexed bytes only when no shelf metadata exists. Either action preserves research-only workspaces. Research-only deletion is separate, confirmed and offered beside a portable JSON export.
Account tags are owner-scoped IDs and names joined to each matching material; the index never exposes another account's tag taxonomy. A PDF that exists only on this device stores its selected tag IDs beside local metadata in IndexedDB. Those local assignments do not enter Postgres, and reopening the PDF preserves rather than replaces them. Selecting several tags requires an object to contain all of them; repeated URL values are de-duplicated and bounded before either the account or local filter runs.
Private reading progress, not a scroll history
Reader waits for a short dwell on an observed page before reporting progress. Spread and Focus use the active page; Continuous uses the page crossing the reading line. Grid and Browser Print do not count as reading. Closing or hiding the page may flush the latest bounded fraction, but no event-by-event trail is retained.
The owner-authenticated database operation accepts one active publication UUID and a finite number from zero to one, rounds it to five decimals and keeps only the greater of the stored and observed values plus last_opened_at. It refuses Trash and cannot update another account's object. Anonymous pages, public shares, demos and private one-off captures have no eligible Library identity and send no progress update.
A bounded private-file allowance
Free accounts include 100 MB and Pro accounts include 5 GB for account-backed file objects. Before a new indexed object can exceed that allowance, the database serializes concurrent writes for the owner and rejects the increase. Ratdolt removes a just-uploaded image, PDF or newly created permanent artifact when that commit is rejected. Deleting an indexed object releases its recorded bytes; a provider object left behind after a rare deletion outage may require operational cleanup but is no longer reachable or counted by the account index.
Save for later without a source request
A manual bookmark stores bounded Library metadata only. Creating it does not contact the source website, create a permanent copy, inspect another browser tab or consume a publication credit. Credential-bearing addresses are refused so a username or password cannot become shelf metadata. Fragments are removed because they identify a position inside one source, not another Library object.
Collections, tags and cover images are validated against the signed-in owner in the same database transaction. If the address already exists, Ratdolt leaves the existing object unchanged; if it is in Trash, the Library asks you to restore it instead of creating a hidden duplicate. The first successful Reader or Composer open follows the ordinary publication-credit and private permanent-copy rules.
Private and public bookmark covers
A custom cover remains owner-private on the Library shelf and receives a short-lived signed preview. If—and only if—both the account profile and that publication are public, Ratdolt may show the same bitmap on the public profile, public collection, Reading Commons and collection embed through an opaque first-party cover token. Anonymous projections contain neither the image's private storage path nor its database ID or owner account ID.
The public cover route rechecks both visibility choices and image ownership, verifies the bitmap signature, byte count and content digest, refuses SVG or other executable formats, and sends no source-site request. Removing the cover, deleting its image, archiving or trashing the publication, or withdrawing either public setting blocks new origin reads. A browser or intermediary may retain a previously public response for at most five minutes.
Unsplash covers use a different boundary. Search begins only after two characters in the explicit cover search field. The selected photo remains hotlinked from images.unsplash.com with its provider tracking parameter, and Ratdolt reports the required selection event before saving it. Private shelf, preview and public surfaces show visible photographer and Unsplash links. Loading that cover therefore sends the viewer's network request to Unsplash; replacing or resetting it stops future loads from Ratdolt surfaces. Ratdolt never proxies the photo into its private image bucket.
On-demand media and map previews
Opening a Library card or its stored Preview does not automatically request an image, audio track, video, map or original website from a third party. A separate load control creates that browser request only after you choose it. Embedded views receive no Referer header and run inside a constrained frame; Ratdolt does not proxy the request, ask for browser geolocation or turn a map preview into a server-side location lookup.
Map previews accept only credential-free HTTPS addresses on the exact supported Google Maps or OpenStreetMap hosts. Coordinates are range checked, OpenStreetMap receives a bounded map box and marker, and Google receives at most a bounded place or coordinate query. Unsupported, shortened or malformed map links remain ordinary source links and can still use the separately gated Web view. Once loaded, the provider receives the ordinary network information disclosed by a direct browser request, including the viewer's IP address and its own cookies subject to browser policy.
Browser-native Share intake
Ratdolt is a website and does not require extension access to another tab. If you optionally install the web app and choose Ratdolt from a supported operating-system Share menu, the browser sends the title, text and public address you deliberately shared. Ratdolt keeps only the validated address in the next navigation step and discards the shared title and prose before asking whether to open Reader or Composer.
Receiving a share does not fetch or save the page and does not spend a publication credit. The ordinary content-policy and network-safety checks still run after you make an explicit choice. Installation grants no permission to inspect tabs, cookies, passwords, hidden elements, form values or browsing history.
Optional Save from X commands
Linking X for sign-in does not activate Save from X. If you separately opt in, Ratdolt stores the numeric X identity needed to map a deliberate @Ratdolt savereply or direct message to your private Library. Disabling the setting or unlinking X deletes that mapping immediately.
X sends activity directed at the dedicated Ratdolt account to a signed webhook. Ratdolt verifies that signature, extracts only the replied-to post or one eligible public URL, and discards the post or message body. It does not store the raw sender ID or event ID; a one-way event digest is kept for 30 days to prevent duplicate saves and ordinary duplicate confirmations. If bot writes are enabled, the post ID or sender ID exists only in webhook memory while Ratdolt sends a short source-URL-free reply or DM; that target is not added to the receipt table. The new object is private and unfetched, and uses no publication credit until you choose to open it. X processes both the command and confirmation under its own terms and developer-platform rules.
A save thread bookmark also retains the public source-post ID already visible in its URL. When you open it, and only after account, allowance and private- storage checks pass, Ratdolt may ask X for one configured maximum of posts in that conversation, keep only posts by the source author, and mark any longer result partial. That attributed synthetic page then follows the same private permanent-copy and deletion rules as another Library source. X charges Ratdolt for provider reads.
Why it is processed
Ratdolt uses this data to fetch and compose the page you request, generate previews and PDFs, understand aggregate product usage, enforce the Content Policy, prevent abuse and network attacks, diagnose failures, respond to reports, comply with law and improve the reliability of the service. Ratdolt does not use submitted page content to build an advertising profile.
Legal bases
Where data-protection law requires a legal basis, Ratdolt relies on performing the service you request, legitimate interests in operating and securing the service, compliance with legal obligations, and your consent when you voluntarily submit a report or request. You may withdraw consent for future processing at any time without affecting processing that was already lawful.
How long data is kept
- Composed pages, selected-text/private captures and print comparisons are cached in memory for no more than 15 minutes.
- Capture links use a random bearer token and expire with the in-memory capture.
- Account, Library, permanent-copy and private research data remain until you delete the object or account, subject to bounded operational backups.
- A manual bookmark and its curated metadata remain until you move it through Trash and permanently delete it or delete the account. Remembered saving preferences remain until you replace or disable them.
- Reading, URL-routing, Composer, narration and preferred translation-pair defaults remain in browser/account preferences until you replace them, restore the Ratdolt set, clear browser storage or delete the account. Changing them does not rewrite an existing source workspace, record unrelated tab history, retain translated text or upload a local PDF.
- A saved bitmap remains until you delete that image or account. Removing it as a bookmark cover removes the reference only; deleting the image restores the generated cover automatically.
- Shared-page invitations and contributions remain until the owner removes the invitation, revokes/deletes the share or deletes the account; removing a collaborator removes that contribution.
- An immutable highlight-folder snapshot remains available to anyone holding its unlisted bearer link until the owner revokes it or deletes the account. Later folder edits do not rewrite it. The stored account row retains only the token digest, frozen excerpts and bounded source identities—not the reusable URL, source-page snapshots or PDF bytes.
- Pending private-collection invitations expire after 30 days. Accepted collection access remains until the owner revokes it or deletes the collection/account; revocation does not delete a private bookmark you deliberately copied into your own Library.
- An Editor may deliberately contribute one of their active Library sources to a shared collection. Ratdolt gives the owner a private, unfetched bookmark containing source metadata only; the Editor's permanent copy, highlights, notes and research do not transfer.
- An opted-in X identity mapping remains until Save from X is disabled, X is unlinked or the account is deleted. One-way webhook retry digests expire after 30 days; raw commands are not stored. A captured X thread remains as its attributed private Library snapshot until that version, publication or account is deleted.
- IP-based contextual-report rate-limit state is held in memory for 10 minutes. General Contact keeps only a process-salted one-way network digest for its 15-minute abuse window.
- Downloaded PDFs remain wherever you save them; Ratdolt does not retain that local copy.
- Vercel Web Analytics discards its short-lived visitor-session identifier after 24 hours. Aggregate analytics, Speed Insights measurements and application traces follow the configured retention period of Ratdolt's Vercel or observability-provider plan.
- Reports sent to Ratdolt's official inbox or a configured delivery provider may remain until the operator or provider deletes them. Hosting and security logs follow the hosting provider's configured retention period and are kept only as long as reasonably necessary.
- Transactional email delivery records, including shared-reading and collection invitations, follow Resend's configured retention and suppression requirements.
International processing
The internet, hosting providers, GitHub and source websites may process data in countries other than yours. Where applicable law requires it, Ratdolt will use an approved transfer mechanism or another lawful safeguard. Mandatory rights in your home jurisdiction remain available to you.
Your privacy rights
Depending on where you live, you may request access, confirmation, correction, deletion, portability or restriction of personal data; object to processing; withdraw or revoke consent; request proof of authorization where applicable; ask how data has been used or disclosed; and complain to your data-protection authority. You will not be discriminated against for exercising a privacy right. Ratdolt may need enough information to verify that a request concerns you and may retain data where law permits or requires it.
Send a request to get@ratdolt.com. Ratdolt will acknowledge and respond within the period required by the law that applies to you.
Automated content checks
Ratdolt uses deterministic checks to refuse obvious paywalls, adult material and harmful commerce. A refusal controls only whether Ratdolt composes that page; it does not create a legal or similarly significant decision about a person. You may request a policy review from the Content Policy page.
Security
Ratdolt isolates browser fetches, blocks private-network destinations, strips executable capture content, limits request size, uses short retention, protects captures with random access tokens and sends no referrer on outbound navigation. No internet service can guarantee absolute security; please report a suspected exposure promptly.
Children
Ratdolt is not directed to children under 13 and does not knowingly collect their personal information. Do not submit private information about a child. If you believe a child has provided personal data, contact us so it can be investigated and deleted where required.
Changes to this policy
Material changes will be posted here with a new effective date. If a change requires notice or consent under applicable law, Ratdolt will provide it before that change applies.