Privacy Policy — Read My Document (Google Docs add-on)
Effective date: 31 July 2026 · Last updated: 31 July 2026 · Data controller: Birdie Ltda., Santiago, Chile · Contact: support@birdie.cl
This policy explains how the Read My Document add-on for Google Docs handles your information: what it accesses, what leaves your device, what we store, what we deliberately do not store, and the concrete measures that protect all of it.
1. What the add-on does
Read My Document reads the document you have open out loud. When you press play, the text is sent to our servers, converted to speech, and streamed back to the side panel as audio. Everything else the add-on offers — highlighting, MP3 export, reading text inside images, the pronunciation dictionary and the AI summaries — is built on that same flow.
2. Permissions we request, and why
documents.currentonly— read the text of the document you currently have open, highlight the paragraph being read, and insert text you explicitly ask us to insert. This permission cannot reach any other document, and it gives us no access to your Google Drive.script.external_request— let the add-on call our servers, which is where speech synthesis happens.script.container.ui— draw the side panel inside Google Docs.openid,userinfo.email,userinfo.profile— identify you when you buy or use a paid plan, so your subscription and monthly allowance follow your account. If you only use the free tier, this identity is not used to build any profile.
We request no Google Drive, Gmail, Calendar or Contacts permissions of any kind.
3. Limited Use disclosure
Read My Document’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use the data only to provide the features described above, we do not transfer it to third parties except as strictly necessary to provide those features (see §5), we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
4. What we do not store
- The content of your documents. Text you send to be read is held in volatile memory only for as long as it takes to produce the audio, and is discarded. It is never written to a database or to disk, never indexed, never reviewed by a person, and never used to train any AI model — ours or anyone else’s.
- The audio we generate, except for MP3 exports that you explicitly request (see §6).
- Images from your document. When you use “read text inside images”, the image is processed by our own optical character recognition service running on our own server. It is not sent to any third party and is not retained after the text is extracted.
- Your document text in telemetry. Our operational telemetry records how many characters were synthesised, which voice, how long it took and whether it failed — never the text itself.
5. What leaves our servers, and to whom
Which providers see your text depends entirely on the voice or feature you choose. Each receives only what it needs to do its job, and each processes it for synthesis only.
- Standard voices — synthesised on Birdie’s own server. Your text is not sent to any third party.
- Premium (neural) voices — text is sent to Microsoft Azure AI Speech (West US region) and discarded by Azure after synthesis.
- Studio-tier voices — depending on the specific voice you pick, text is sent to ElevenLabs, OpenAI or Google Cloud Text-to-Speech for synthesis only.
- AI features (summary, key points, quiz) — the selected text is sent to Azure OpenAI Service on a Microsoft Azure resource operated by Birdie. Under Microsoft’s terms, data sent to Azure OpenAI is not used to train Microsoft’s or OpenAI’s models.
- Hosting and infrastructure — Microsoft Azure (application hosting, Azure SQL Database, Azure Storage, Application Insights telemetry).
- Payments — Polar, acting as merchant of record. Polar receives your email address and the plan you bought. Birdie never sees or stores your card details.
We do not sell or rent personal data, and we share nothing beyond what is technically necessary to run the service.
6. What we do store
- Account record (only if you sign in) — your Google account identifier, email address, display name, and the dates you were created and last seen.
- Subscription record — the plan, its status and billing period, and the subscription identifier issued by the payment processor.
- Usage counters — the number of characters you have synthesised in the current month, so plan limits can be enforced. A count, not content.
- Your pronunciation dictionary — the words and replacements you choose to save, because they must persist between sessions. These are entries you author yourself, not extracts of your documents. You can delete them from the panel at any time.
- MP3 exports — when you export a document to audio, the resulting file is written to a private storage container under a random, non-guessable name, is reachable only through that one link, and is automatically deleted 24 hours later.
- Voice previews — the short sample you hear when auditioning a voice is cached to avoid re-synthesising it. It is a fixed demonstration phrase chosen by us, never your document text.
7. How we protect it
These are the concrete technical and organisational measures protecting the data described in this policy.
- Encryption in transit. All traffic between the add-on and our servers travels over HTTPS. Unencrypted connections are refused and redirected to HTTPS, and TLS 1.2 or higher is required.
- Encryption at rest. Our database is Azure SQL Database with Transparent Data Encryption enabled, so data files, logs and automatic backups are encrypted on disk with AES-256. Files in Azure Storage, including MP3 exports, are encrypted at rest by the platform.
- Data minimisation. The single most effective protection for your documents is that we never keep them. Document text exists only in memory, for seconds. What is not collected cannot leak.
- Private storage with unguessable links. The container holding MP3 exports allows no public or anonymous listing. Each export is addressed by a 128-bit cryptographically random token, so one user cannot reach another’s file by guessing or by incrementing an identifier, and the file expires after 24 hours regardless.
- Authenticated access to paid features. Premium requests are authorised against a token issued by Google and validated on every call against Google’s public signing keys. We never see or handle your Google password.
- Access control. Access to production systems is restricted to Birdie Ltda. personnel who need it to operate the service, through individually named accounts. The internal administration dashboard requires a corporate birdie.cl account with an explicitly assigned administrator role; it is not reachable by add-on users or by third parties.
- Secrets management. Production credentials for the database, the payment processor and the speech providers are held in protected platform configuration — Azure App Service application settings and machine-level environment variables on the server — and are never sent by email or messaging.
- Managed, patched platform. Hosting, database and storage are managed Microsoft Azure services that receive operating system and engine security updates continuously.
- Incident response. If a security incident affecting user data occurred, we would investigate it, close the cause, and notify affected users by email at the address on their account, together with any authority the applicable law requires, without undue delay.
8. Retention
- Document text — not retained; in memory only.
- MP3 exports — 24 hours, then deleted automatically.
- Operational telemetry — 90 days, then deleted automatically.
- Account, subscription and pronunciation records — kept while your account is active, plus 18 months after cancellation for billing and audit purposes, then deleted.
9. Where your data is processed
Our servers and database run in Microsoft Azure in the West US region, in the United States. Speech and AI providers may process requests in their own regions. If you are in the European Economic Area or the United Kingdom, this means your data may be transferred outside your region; we rely on the standard contractual clauses offered by these providers for such transfers.
10. Your rights
You can ask us to access, correct, export or delete your personal data at any time by writing to support@birdie.cl. We respond within 30 days. If you are in the European Economic Area, the United Kingdom or California, you have additional rights under the GDPR, UK GDPR or CCPA respectively; the same address is how you exercise them.
You can also revoke the add-on’s access at any time from your Google account permissions page, or uninstall it from Google Workspace Marketplace.
11. Cookies and local storage
The side panel uses your browser’s local storage to remember your chosen voice, speed and preferences between sessions. We use no advertising or cross-site tracking cookies.
12. Children
The service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us with personal data, write to us and we will remove it.
13. Changes
We may update this policy. When we do, we update the “Last updated” date above. Material changes to how we process your data will be announced inside the add-on and, for subscribers, by email.
14. Contact
Birdie Ltda. — Santiago, Chile — support@birdie.cl
This policy is provided for transparency and is not legal advice.


