Privacy policy
How Paperlight (“PDF Dark Mode & Read Aloud”) handles your data. Effective 22 July 2026, for version 2.7.0 and later.
Paperlight has no backend. There is no account, no analytics, no telemetry, and no server operated by the developer. The extension never transmits the contents of your PDFs, your selected text, your browsing history, or any identifier anywhere.
The only data that leaves your machine is the one-time download of the speech-model files from Hugging Face, and only if you choose the Fluent voice.
None of the following is readable by the developer.
chrome.storage.sync is synchronised by Chrome itself across devices where you are signed into the same Google account — a Chrome feature governed by Google's Privacy Policy. The extension only writes the preference values above into it. If you are not signed into Chrome, this data stays on the one device. Model weights are never synced — they are per-device.
Hugging Face is the model host and is a third party; their handling of request logs is covered by the Hugging Face Privacy Policy. Once the files are cached, the extension works with the network off and makes no further requests.
- Fluent runs the Kokoro-82M model entirely inside your browser, on your CPU. Your text is turned into audio locally and is never transmitted.
- Robot hands your text to
chrome.tts, Chrome's own speech API. Depending on your operating system and the selected system voice, Chrome may synthesize that speech locally orthrough a network speech service. That behaviour belongs to Chrome and your OS, not to this extension, and is outside the developer's control. If you want a guarantee that no text ever leaves your device, use the Fluent voice.
The broad host permission is the part worth understanding: it is required because Chrome cannot filter content scripts by document type, only by URL, and a PDF may live at any URL. Selected text is read only at the moment you explicitly choose Read aloud, and it travels only to the extension's own offscreen page for synthesis.
- No analytics, telemetry, crash reporting, or usage statistics
- No advertising, tracking pixels, fingerprinting, or cookies
- No collection of browsing history, page content, form data, or credentials
- No sale, sharing, or transfer of any data to anyone
- No remote code execution — all executable code ships inside the extension, as Manifest V3 requires
For the store listing, Paperlight declares that it collects none of the disclosure categories — personally identifiable information, health information, financial information, authentication information, personal communications, location, web history, or user activity — and that it does not sell or transfer user data, use it for anything unrelated to its single purpose, or use it to determine creditworthiness.
- Preferences: remove the extension, or clear its data from
chrome://extensions→ Paperlight → Details. - Downloaded voice files:removing the extension deletes its caches. You can also clear cached site data for the extension from Chrome's settings.
Paperlight is a document-reading utility, is not directed at children, and collects no personal information from anyone.
If this policy changes materially, the effective date is updated and the change appears in the repository's commit history, which serves as the public revision record.
Open an issue at github.com/kabir0st/paperlight/issues, or reach the developer via kabirtamari.com.
Last updated 22 July 2026