Summary
Dyslexly locally changes how compatible text is presented on webpages and, after separate consent, in top-level PDF documents. Website text, PDF bytes, page images and OCR text are not sent to Dyslexly, Supabase, an OCR service, a font CDN, advertising or analytics.
Data processed on your device
Webpages
Dyslexly processes compatible visible webpage text to create the visual configuration you selected. The current address and hostname are used locally for site access rules and current-page status. Dyslexly does not upload page text, automatically collect visited URLs or mirror your Chrome browsing history.
PDF documents and OCR
Top-level PDF support requires an in-product opt-in. Source PDF bytes, page images, extracted text and manual OCR results are processed locally. OCR is started by the user and uses packaged models; it does not call an OCR API. Source PDF bytes are kept in viewer-tab memory and discarded when that tab closes.
If you enable local PDF history, extension IndexedDB may store up to 30 PDF links, titles, fingerprints, reading position and view preferences, plus a bounded OCR layout/text cache. Bookmarks can be stored separately. Source PDF bytes are not stored in history.
Configuration and fonts
Extension storage contains reading configuration, language and theme choices, site policy, PDF preferences, onboarding, local survey eligibility, account session and cached entitlement. User-selected custom font files remain in extension-local IndexedDB and are not uploaded or included in configuration export.
Optional account and Early Access Claim
If you request Early Access Pro, Supabase Auth receives your email address and sends an email one-time password. After verification, the account uses a stable Supabase UUID, authentication session and explicit Early Access entitlement. Authentication tokens remain in chrome.storage.local and are never provided to webpage content scripts or sync storage.
Any verified Dyslexly account can explicitly Claim the current Open Early Access. Claiming is not a purchase or subscription and is stored as paid:false. Purchases, trials, ExtensionPay and card processing are not present in this build.
Voluntary feedback
Eligibility for an in-extension feedback invitation is calculated locally from account age and days when Dyslexly actually transformed compatible text. Those local counters are not uploaded. For signed-in product feedback, the server receives only answers you submit, the survey version and optional contact consent. A website address is sent only if you type it into a problem report yourself.
After uninstalling, Chrome may open Dyslexly's public uninstall page. If you choose to submit the anonymous exit survey there, Dyslexly stores only the reasons you select, any optional detail choices for those reasons, optional comments you enter for individual reasons, an optional overall comment, the survey version and submission time. The uninstall survey does not require an account and does not send your email, Extension ID, browsing history, page text, PDF/OCR content or visited page URL.
Dyslexly does not send passive usage events, module analytics, page content, browsing history or automatically collected URLs.
Retention and your control
Local data remains until you clear it or uninstall Dyslexly, subject to Chrome's normal storage behaviour. Account, entitlement and submitted signed-in feedback remain while the account is active and may remain in limited provider backups or security logs under provider retention practices.
Anonymous uninstall feedback is retained for product-improvement analysis and contains no account identifier supplied by Dyslexly. If a comment contains personal information that you typed yourself, contact Dyslexly to request deletion where it can reasonably be identified.
You can disable Web or PDF processing, clear local PDF history/OCR/bookmarks, remove custom fonts, export or replace reading configuration, sign out or uninstall the extension. During Early Access, request a copy or deletion of server account data by email. Deleting server account data does not delete the independent local reading configuration.
Service providers and security
Dyslexly uses the reviewed Supabase project for optional authentication, entitlement, voluntary signed-in feedback and the anonymous uninstall survey, plus a configured email provider for OTP delivery. Those providers may process ordinary IP address, browser/device, delivery, abuse-prevention and operational log data under their own policies.
This public policy/support site is hosted by GitHub Pages. It uses no cookies, advertising or external fonts. The uninstall page contains a small first-party script solely to display and submit the optional exit survey to Dyslexly's Supabase endpoint; other public policy/support pages do not use client-side analytics. GitHub may process ordinary network and security logs when serving the site.
Network transmissions use HTTPS. Personal data obtained through the extension or voluntarily submitted feedback is used only to provide or improve user-facing Dyslexly functionality, security and legal compliance; it is not sold or used for personalised advertising.
Changes and contact
Any new endpoint, telemetry, permission, remotely transmitted website/PDF data category or billing provider requires a new privacy review. Material changes will update the effective date and be communicated through an appropriate product or release channel.
Privacy, account copy or deletion request: dyslexly.app@gmail.com
Dyslexly is currently operated as an Early Access project. Formal publisher identity and jurisdiction will be added before any commercial launch.