Knowledge Base

Privacy Policy

What Crossleaf collects, why, who it is shared with, how long it is kept, and the choices you have.

Effective 21 September 2026.

Crossleaf is operated by its founder as a sole proprietor in California, United States ("Crossleaf", "we", "us"). This policy explains what we collect when you use crossleaf.app and the Crossleaf Capture browser extension, why we collect it, who we share it with, and the choices you have. Questions: hello@crossleaf.app.

What we collect

Account details. Your email address, the name you enter, an optional profile photo, and, if you answer it, a note about what you like to read. Your password is stored only as a one-way hash; we cannot read it.

Your content. The books you import or capture, the translations Crossleaf produces for you, versions and edits, glossary terms, and any custom prompts you write. This is your material; we process it only to provide the service to you.

Payments. When you start a membership or buy a pack of leaves, Stripe handles the payment and, for a membership, the monthly renewal. We receive the amount, what was bought, the status of your membership and a payment reference. We never receive or store your card number.

Usage and security records. Each sign-up and sign-in attempt is logged with your email address and IP address, kept for 90 days, so we can spot abuse of your account. Server errors are logged with the request path and a short error code, and kept for 30 days. We do not run third-party analytics or advertising trackers of any kind.

Messages you send us. A message sent through the support form is kept with the address to reply to, and the page and browser you sent it from (the browser's name, version and operating system), so we can reproduce what you saw. If you are signed in, it also carries your leaf balance and plan, so we don't have to ask.

How you found us, and how far you got. When you first arrive, we set a cookie of our own holding a randomly generated visitor id, and we record where that visit came from: the site that linked you, the page you landed on, any campaign tags in the address, and the country your visit came from (worked out from your IP address at the time, which we do not keep). We also count which steps a browser or account reaches (for example "sign-up started" or "first chapter translated"), against that same id or your account. Neither record holds your IP address, your browser details, or anything you wrote. We use them only to understand how people find Crossleaf and where they get stuck. Nothing is shared, no advertising network or analytics company is involved, and the cookie and the record of where you came from are kept for a year.

Local storage in your browser. A session token that keeps you signed in, and display preferences such as theme and reading position. No third-party or advertising cookies.

How we use it

  • To run the service: import your books, translate them with the model you choose, keep your library, and export your files.
  • To bill you correctly, renew or end your membership as you have asked, and show you receipts.
  • To keep accounts safe: sign-in logs, rate limits, fraud prevention.
  • To send you the emails the service needs: confirming your address, resetting your password, confirming a new address when you change it, and telling you when your address or your password has been changed. We do not send marketing email.
  • To respond when you contact us.

We do not sell your personal information, and we do not use your books, translations or prompts to advertise to you.

Who we share it with

We share data only with the providers we need to run Crossleaf:

  • Model providers via OpenRouter. To translate or polish, the relevant text is sent to OpenRouter and on to the model you selected (for example Anthropic, OpenAI, Google, DeepSeek, Moonshot, Zhipu or Aion Labs). Every request we send asks OpenRouter to use only providers that do not train on inputs, and our account is set the same way, so your text is not used to train models. Providers may retain requests briefly for abuse monitoring under their own policies.
  • Railway, which hosts our servers and database in the United States.
  • Stripe, which processes payments. We send it your email address, the name on your account and our internal account id, so that each payment is tied to the right account.
  • Resend, which delivers our emails and therefore sees your email address and those messages: the sign-up confirmation, the password reset, the confirmation of a new address, the notices that your address or your password was changed, and every message you send through the support form, which reaches us with your reply address, the page you wrote from and, if you are signed in, your account's email, leaf balance, plan and internal account id. It also carries the notices about an account's payments that we send to ourselves (a refund, a dispute, a payment we could not match to an account, a suspended account's billing), which can name your email address.
  • Google Fonts, which serves the typefaces on the site and therefore sees your IP address when a page loads.

We may also disclose information if the law requires it, or to protect the rights and safety of readers or ourselves.

How long we keep it

  • Your account and content: until you delete your account. Deletion is scheduled with a 30-day grace period during which signing in again restores everything; after that, your books, translations, ledger and sessions are permanently removed, and your security records and sign-up step counts are anonymized.
  • Sign-up and sign-in records: 90 days.
  • Server error records: 30 days.
  • Messages you send us through the support form: until your account is deleted, when they are anonymized. If you wrote without an account, one year.
  • The visitor cookie and the record of where a visit came from: one year.
  • Payment records: as long as tax and accounting rules require.
  • Backups held by our hosting provider are kept for a limited period and then overwritten.

Your choices and rights

  • See and change your name, email, photo and preferences in Settings.
  • Export your translations at any time in EPUB, PDF, DOCX or text.
  • Delete your account in Settings; the 30-day grace period is described above.
  • Sessions: revoke any device from Settings; changing your password signs out every other device.
  • Ask us at hello@crossleaf.app for a copy of the personal information we hold about you, to correct it, or to delete it.

California residents. You have the right to know what personal information we collect, use and disclose, to request its deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not follow you across other websites, and we treat every browser as if it had sent a Do Not Track signal.

Children

Crossleaf is for adults. You must be 18 or older to create an account, and we do not knowingly collect information from anyone under 18. If you believe a minor has an account, tell us at hello@crossleaf.app and we will remove it.

Security

Passwords are hashed, session tokens are stored hashed, all traffic uses HTTPS, and administrative actions are logged. No system is perfectly secure; if we learn of a breach affecting your information we will tell you as the law requires.

Changes

We will post changes here with a new effective date. Material changes will be announced in the product before they take effect.

Contact

Crossleaf · San Francisco, CA 94105, United States · hello@crossleaf.app