Privacy policy
Updated: October 3, 2026.
This policy describes how the FluentRead browser extension handles translation content, local records, service credentials, and optional Google Drive configuration backups. FluentRead is a bilingual translation and reading-assistance tool maintained by its open-source project contributors. The website and this policy are publicly accessible without signing in. Translation does not require connecting a Google account.
The feature and service you choose determine which content leaves the browser. FluentRead does not run its own translation server; cloud translation is handled by the selected provider.
What gets sent?
| Feature | Content and destination |
|---|---|
| Page, hover, selection, and input translation | Text and language details to the selected service |
| Free translation | Text sent to enabled providers chosen by background balancing based on success rate, response time, and recent errors; failures may send the text to another candidate |
| Extra AI context | Page title, description, and parts of the article to the AI service; off by default |
| Reading card and learning explanations | Submitted expressions, permitted source context, necessary conversation, and enabled memories used for the response, to the selected AI service |
| Glossaries | Only matched terms and preferred translations, attached to supported AI requests |
| Images and local OCR area capture | Recognition happens locally; recognized text goes to the selected translation service |
| Area capture with model recognition | When enabled and supported by the model, the cropped selection is sent to the selected provider for recognition, followed by text translation; the full screen is not uploaded |
| Documents | Files are parsed locally; text to translate goes to the selected service |
| Video subtitles | Subtitle text goes to the subtitle service. X local AI audio recognition happens on the device |
| Dictionary and read-aloud | Requested words or text go to the corresponding dictionary or voice service |
| Google Drive configuration sync (Chrome testing feature) | After explicit confirmation, an encrypted complete configuration backup is saved to your own Google Drive; the scope is described below |
Initial recognition-pack and local-model preparation requires network downloads. Input translation is disabled by default and handles text you deliberately submit from ordinary fields, not password fields.
English word cards include a common-word dictionary. Looking up a word outside it may download and cache a fixed full-dictionary data file of about 3.9 MB from JSDMirror, GitHub Raw, or jsDelivr. That static asset request does not include the word being looked up. Online dictionary providers may still receive the word as described above.
Sites configured for automatic translation can start requests automatically. Choosing a local translation model does not also make dictionaries, read-aloud, downloads, or other tools offline.
What stays in the browser?
Settings, rules, glossaries, collections, and review records are stored in this browser’s extension storage. Free-translation health, error, and performance statistics are also stored locally for background balancing and cooldown recovery. Service credentials are stored locally by default. When you deliberately use Drive sync, they are also included in the configuration backup described below. Someone with access to the browser profile or backups may still access them.
Regular-window reading-card conversations are retained for 30 days and can be viewed or deleted. Private windows do not read or save this history and do not provide persistent learning collections.
Translation cache defaults to at most 5 MiB or 2,000 entries, with a maximum entry lifetime of 24 hours. You can adjust or clear it. X transcript caching keeps text and timing for up to 32 videos and 7 days, not recognition audio. Clear it in video settings.
The optional full English dictionary is held in the browser's CacheStorage. Clearing browser data or uninstalling the extension removes it.
Document translation and edits stay in the current page. Download files before leaving.
Google Drive configuration sync
Drive configuration sync is currently being tested in the Chrome extension. Availability depends on the settings page of your installed version. Its purpose is to back up and restore FluentRead settings across your own devices. It does not provide translation or require a persistent connected state.
When is data accessed, and what is accessed?
Only choosing the Google Drive sync action starts authorization for that operation and reads the backup to prepare a preview. Uploading or applying downloaded settings requires your confirmation of the direction and changes. Opening settings does not automatically access Google Drive.
- Configuration: includes API keys, OAuth tokens, authentication headers, custom request bodies, and authentication parameters in URLs. Wordbooks, conversations, and usage statistics are excluded. These OAuth tokens are your configured service credentials; the access token for Google sync is excluded from the backup.
- Google permissions: only
drive.appdata, which manages FluentRead's own hidden application data. The extension does not request access to your other Drive files, Gmail messages, or contacts. See Google's application-data documentation. - Account information: the selected account's Drive identifier prevents mixing configurations from different accounts. Email, when returned by Google, is used only in the preview. No separate email identity permission is requested, and sync works without an email response.
- Authorization tokens: Chrome's identity API manages them for Google API requests. Completion, failure, cancellation, or leaving settings clears the extension's identity cache. Clearing that cache does not revoke the permission in your Google account or delete a backup.
The operation handles the following data. Backup access is limited to FluentRead's own hidden application data folder.
| Data category | Specific content | Purpose |
|---|---|---|
| Configuration backup content | Translation providers and models, languages and appearance, shortcuts, website rules, glossaries, custom prompts, and the service credentials and request parameters listed above | Upload to back up settings; download to preview differences, then restore or merge settings in the direction you confirm |
| Google account information | Drive account identifier and email address when Google returns it | The identifier prevents mixing backups from different accounts; email is only displayed in the current preview |
| FluentRead backup file information | File ID, name, version, modification time, and available version-check information | Locate the configuration file and check for changes during sync to avoid overwriting newer settings from another device |
| Google access token for this operation | A short-lived authorization token obtained through Chrome's identity API | Authenticate authorized requests to Google; it is not uploaded as configuration or provided to translation services |
Content you enter into prompts, custom request bodies, or URLs is also part of the configuration backup. Sync does not scan webpages or read downloaded documents, learning records, conversations, or usage records as backup content.
Storage and protection
The backup is sent over HTTPS directly to your own Google Drive hidden application data folder as fluentread-config.encrypted.json. It does not pass through a FluentRead developer configuration server or appear as a regular My Drive file. The account identifier, last-sync time, and an encrypted copy used to compare changes remain in this browser.
The configuration is encrypted on the device before upload using a fixed, publicly available application passphrase. You do not enter a password. Anyone who obtains the encrypted backup can decrypt it using the public passphrase. Access protection primarily depends on your Google account, application permissions, and device security. Protect your account, browser profile, and exported backups. Do not attach a backup or complete configuration to a public report.
| Storage location | Content and retention |
|---|---|
| Your Google Drive | The encrypted configuration file remains until you delete hidden application data; successful uploads update that file |
| This browser's extension storage | Account identifier, last-sync time, and an encrypted configuration copy for comparing changes remain until the relevant browser data is cleared or the extension is uninstalled; changing accounts rebuilds the comparison baseline |
| Temporary operation state | Account and file information, the confirmation preview, and its encrypted snapshot; previews are valid for 10 minutes, and completion, failure, cancellation, or leaving settings clears pending state and the authorization cache |
Stop access and delete data
Each sync requires a deliberate action. Stop initiating sync to stop further operations. To revoke permission, select FluentRead in your Google account's third-party connections and remove access. Sync then requires authorization again.
The cloud backup remains until you delete it. In Google Drive on the web, use Settings → Manage apps → FluentRead → Options → Delete hidden app data. Revoking access, uninstalling the browser extension, or clearing local records does not by itself delete the Drive backup. Deleting the cloud backup does not erase settings already downloaded on other devices.
Use of Google data
Google account identifiers and configuration backups are used only to check the selected account and synchronize or restore settings. During sync, the account identifier and complete backup are not sent to third parties other than Google. FluentRead does not sell this data or use it for advertising, profiling, or generating content unrelated to sync. Google Workspace API data is not used to develop, improve, or train non-personalized AI or machine-learning models. Developers do not inspect your backup through the sync service. You may voluntarily submit a report after removing credentials and private content. Restored service credentials continue to be used with your selected translation services; the first section explains what those requests send.
FluentRead's use of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements. Google APIs support configuration backup and restoration, not the generation of non-consensual intimate imagery. Google's own handling of cloud storage and account data is also governed by Google's Privacy Policy.
Control and remove other data
Turn off automatic translation, extra AI context, memories, or saving if you do not need them. Restrict the reading card to the current selection to send less context.
Clearing translation cache does not delete learning collections. Manage collections, reading history, and memories in their own pages. Uninstalling or clearing browser data may remove local records.
Backups can include credentials, source sentences, and source information. Check export scope and file contents before sharing. Refer to each cloud provider’s policy for its retention and use of submitted content.
Website and external links
GitHub Pages hosts the website, which requires no registration or login. Chinese and English content have separate URLs; switching languages is a deliberate choice, and the homepage does not automatically redirect to a different language URL. Website preferences such as appearance are stored in your browser and can be removed by clearing the site's browser data. The website does not read configuration backups or service credentials from the extension. The hosting service's processing of access requests is also governed by GitHub's Privacy Statement. When you visit an extension store, Google, or a translation provider's website, that service's own privacy policy also applies.
Policy updates and contact
The policy is updated as features and data handling change, with the date shown at the top. Changes to the purposes or scope of Google data use will be disclosed, and consent requested before new access or use.
For privacy questions or data-deletion help, contact the project maintainers through GitHub Issues or email. Remove credentials, account information, and private text from public reports.
