Privacy Policy
Effective date: October 1, 2026
The short version
- Questions? Reach us at team@toaudio.app or @toaudioapp on X.
- There are no toaudio accounts, so we hold no passwords. If you subscribe to Pro, Stripe handles the payment and we never see your full card number.
- No ads, no third-party analytics or tracking scripts. We don't sell your information or share it for advertising.
- If you join the waitlist, we'll email you only launch updates, and every email lets you unsubscribe.
- If you request audio with our web form, we use your email only to send you that listening link. The request isn't posted anywhere.
- If you request a reading on X, we may reply once to ask how it went. We publish what you tell us only if you agree.
- Wrote a post or article we read aloud? We keep its text and audio and publish a listening page for it. You can ask us to remove it. See what we keep and Removal requests.
- To make the audio, we send the text to an AI speech service.
- On listening pages we count opens and plays with one first-party cookie and a keyed hash of the IP address and browser. These records never contain the raw IP address.
- You can ask to see, correct or delete what we hold about you. Your choices and rights explains how.
This summary helps you find your way. The full policy below has the details.
The information described here is the responsibility of Zheyuan Ou, doing business as toaudio ("we", "us"; in EU and UK terms, the controller). This policy explains what information we collect when you use toaudio.app, the listening pages at app.toaudio.app and the @toaudioapp account on X. It also explains how we use that information and what choices you have.
1. What we collect
If you join the waitlist
- your email address;
- the language of the page and which page you signed up on;
- which version of the consent text you agreed to, and when.
To limit abuse, we also keep a keyed hash of your IP address (never the IP itself) with a submission counter. We keep these counters for about a day, then delete them.
If you request audio on X
- your X username;
- links to, and IDs of, your mention, the post or web article you asked us to read and our reply;
- when the request was made and what happened to it: accepted, declined and why, sent or failed.
All of this comes from public activity on X.
After we deliver a reading, we may reply once, publicly on X, to ask how it went and invite you to message us. Whether you answer is up to you. We don't look up in our listening records whether you personally played it.
If you request audio with our web form
- your email address;
- the link you submitted, and the article address we work out from it;
- which of our pages you used, and any campaign tags (such as utm_source) in that page's address;
- which version of the consent text you agreed to, and when;
- what happened to your request: accepted, declined and why, sent or failed.
We use your email address only to send you the listening link for that article and to handle that request. We don't add it to the waitlist or send you anything else. Web form requests aren't posted anywhere, but the listening link we send you works for anyone who has it (see What is public).
To limit abuse, we also keep a keyed hash of your IP address (never the IP itself) with a submission counter. We keep these counters for about a day, then delete them.
If you subscribe to Pro
You pay on a checkout page run by Stripe, our payment processor. Stripe collects your card details, name, email address, billing country and postal code, and your X username if you choose to give it. Stripe keeps your card on file to charge each renewal.
From Stripe, we receive:
- your name, email address, billing country and postal code, and your X username if you gave it;
- your subscription's plan, status and payment history, including invoices and refunds;
- limited card details: the brand, the last four digits and the expiry date. We never receive your full card number.
We use your email address and X username to recognize your requests as Pro. We use the rest to give you Pro, to answer you, to issue refunds and to keep the records tax law requires. You can update your card or cancel on the subscription page that Stripe hosts.
If you wrote a post or article we read aloud
Someone asked us to read your public post on X, or your public web article, aloud. Here is what we hold about it:
- What we keep: the link to your post or article (for X posts, the link usually includes your X username) and an ID we derive from it, its title and text, the version we prepared for reading aloud, and the generated audio.
- Where it comes from: for an X post, your public post, which another X user asked us to read. We retrieve it through a third-party X data service, or copy it from X by hand. For a web article, someone gave us its link, and we copy the text from your public page by hand.
- Why: to make the reading that person asked for.
- What's public: the listening page shows the title, the audio and a link to your post or article.
- Sensitive details: if your post reveals things like your health, beliefs or politics, we rely on the fact that you made it public. People named or pictured in a post can also ask us to remove a reading; we review those requests case by case.
- Removing it or objecting: see Removal requests.
- How long: see How long we keep it.
Public accounts we check for new Articles
We check a small number of public X accounts for new X Articles, so we know when there's one we might offer a reading of. To do this, we regularly retrieve those accounts' recent public posts (their links, times and text) through a third-party X data service.
We don't store those posts. For each account, we keep only the ID of the newest post we've checked, so we know where to pick up next time. When a post is a new Article, we send ourselves an alert with its links, when it was posted and a short preview of its text (see Who we share it with).
When someone opens a listening page
For each time the page is opened, we record:
- the time;
- a random visitor ID stored in a cookie (see Cookies);
- a keyed hash of the IP address combined with the browser's user agent, never the raw IP;
- the browser's user agent string, and the device type worked out from it, including whether it's X's in-app browser;
- the approximate country and time zone, which our hosting provider derives from the IP address;
- the browser's language preference and the referring page;
- whether the visit looks like a bot;
- whether playback started.
We use this to count how many people open and play readings. We don't use it to identify you. These records don't contain a name or the raw IP address, but they can tell the same browser apart across visits, so we treat them as personal information.
When you contact us
We keep the messages you send us on X or by email, and our replies. Email sent to our address is forwarded to our mailbox, and we keep copies there of the emails we send you, such as your listening link.
If you tell us what you think of toaudio, we may ask whether we can quote you. We publish a quote, and your name or X username with it, only if you agree.
Hosting and security
Our hosting provider, Cloudflare, processes technical data such as IP addresses to deliver pages and to protect the Service against attacks.
There are no toaudio accounts, so we hold no passwords, and we never see or store full card numbers. You don't have to give us anything. We need an email only for the waitlist, to request audio with our web form or to subscribe to Pro, and an X mention only to request a reading on X. Listening works with cookies blocked.
2. How we use it
- To run the Service: receive requests, make audio, and deliver it by replying on X or by email.
- To apply allowances and prevent abuse.
- To sell and provide Pro: take payment, recognize subscribers' requests, and handle cancellations and refunds.
- To understand, in aggregate, whether readings get opened and played.
- To notice new Articles from the public accounts we check.
- To send launch updates to people on the waitlist, and to let us know when someone joins it.
- To handle takedown and privacy requests, and to answer messages.
- To ask people who requested a reading, once, how it went.
- To publish what people tell us about toaudio, only with their permission.
- To meet legal obligations.
We don't use your information for advertising or profiling.
A person enters or accepts every request, but some checks then run automatically and can decline it: the requesting X username or email address has already used up its allowance, the same requester has already asked for the same post or article, or it has been taken down. None of these checks has legal or similarly significant effects on you. If you think one got it wrong, contact us and a person will look at it.
If you're in the European Economic Area (EEA) or the United Kingdom, these are our legal bases:
| Purpose | Information | Legal basis |
|---|---|---|
| Sending launch emails | Your email address, the page language and the page you signed up on | Your consent. You can withdraw it at any time. |
| Alerting us to new waitlist signups | Your email address, the page language, the page you signed up on and when | Legitimate interests: knowing promptly who has joined |
| Handling requests and applying allowances | Your X username or email address, links to the posts or articles involved, and request records | Legitimate interests: giving the requester the reading they asked for, and keeping use fair |
| Emailing you the listening link you asked for with our web form | Your email address, the link you submitted and the request record | Legitimate interests: sending the reading you asked for to the address you gave us |
| Selling and providing Pro | Your name, email address, billing country and postal code, your X username if you gave it, your subscription and payment records, and limited card details | Performing our contract with you. Legal obligation, for the records tax law requires. |
| Reading a post or article aloud | Its link, title and text, and the audio | Legitimate interests: making public posts and articles listenable when someone asks. For sensitive details in an author's own post or article: the author made them public. |
| Checking public accounts for new Articles | Those accounts' usernames and recent public posts | Legitimate interests: knowing when there's a new Article we might offer a reading of |
| Preventing abuse | Counters stored against a keyed hash of the IP address | Legitimate interests: stopping spam |
| Listening statistics | Listening-page records and the cookie | Legitimate interests: knowing whether readings get played |
| Answering messages and handling removal and privacy requests | Your messages and our replies | Legitimate interests: answering you and handling removals. Legal obligation, where privacy law requires us to respond. |
| Asking a requester how the reading went | Your X username and the request record | Legitimate interests: learning whether readings are useful. One message; you can ignore it. |
| Publishing a quote from you | Your words, and your name or X username if you agree to show it | Your consent. You can withdraw it at any time. |
| Hosting and security | Technical data such as IP addresses | Legitimate interests: keeping the Service available and secure |
| Answering legal requests | Whatever the request requires | Legal obligation |
You can ask us for the balancing test behind our legitimate interests, and you can object at any time (see Your choices and rights).
3. Who we share it with
We don't sell your personal information. We share it only with the service providers that help us run toaudio, and only what each one needs:
| Provider | What it does for us | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, file storage, security, access control for our admin tools, and forwarding email sent to our address | Everything described in What we collect, stored on its infrastructure |
| Google (Gmail) | Our mailbox: email sent to our address arrives there, and we write the emails we send you there | Your email address, the messages you send us, and the emails we send you, such as your listening link |
| Brevo | Delivers the emails we send you, such as the listening link you asked for with our web form | Your email address and the email itself: the article's title, your listening link and the article's link |
| Stripe | Processes Pro subscription payments, renewals and refunds, sends receipts and invoices, and hosts the page where you manage your subscription. Stripe also uses payment data for its own purposes, such as preventing fraud, under its privacy policy. | Your card details, name, email address, billing country and postal code, your X username if you give it at checkout, and technical data such as your IP address |
| A third-party X data service | Retrieves public posts from X | The ID of each post to read, and the usernames of the public accounts we check for new Articles |
| OpenRouter, and the speech model provider it routes to | Converts text to speech | The text of the post or article being read; nothing about who asked for it |
| Inworld | Converts text to speech for Pro readings | The text of the post or article being read; nothing about who asked for it |
| Telegram | Sends us alerts about new waitlist signups and new Articles from the public accounts we check | For signups: each new signup's email address, page language, signup page and time. For new Articles: the account's username, links to the post and the Article, when it was posted and a short preview of its text. |
| X | Where requests and replies happen. X is an independent service with its own privacy policy. | Our public reply, which mentions your username |
We don't sell or share personal information as California law defines those terms, and we haven't in the past 12 months.
We haven't sent any launch emails yet. If we use a different service to send them, we'll add it to this list before the first one goes out.
We may also disclose information when the law requires it, to protect someone's rights or safety, or as part of a transfer of the Service. If the Service is transferred, this policy continues to apply to the information transferred with it.
4. What is public
- If you request on X, your mention and our reply are public on X. Our reply shows that you asked for this reading.
- If you request with our web form, we don't post your request or your email address anywhere.
- Anyone with the link can open a listening page. The page shows the title, the audio and a link to the original post or article. It doesn't show who requested the reading. Listening pages ask search engines not to index them.
- Listening links are hard to guess, but anyone who has one can open or share it. Asking search engines not to index a page doesn't guarantee they won't.
5. Cookies
The main site at toaudio.app sets no cookies. Listening pages use one cookie:
| Name | Why | How long |
|---|---|---|
toaudio_visitor_id | Set on listening pages at app.toaudio.app. Tells repeat visits from the same browser apart when we count listens. First-party, used only for our own statistics. | 1 year |
It isn't used for advertising and isn't shared with anyone. If you block or clear cookies, the listening page still works.
Our pages don't currently respond to Do Not Track or Global Privacy Control signals.
Our pages load no third-party analytics or tracking scripts, and no other company collects information about your activity across websites through them.
6. How long we keep it
| Information | How long we keep it |
|---|---|
| Waitlist email | Until 12 months after our last launch update, or until you leave the list, whichever comes first. When you leave, we also delete your email from our Telegram alerts. |
| Abuse-prevention counters | About a day |
| Request records | Until the Service stops operating |
| Web form requests and the email address you gave | Until the Service stops operating, or until you ask us to delete them, whichever comes first |
| Pro subscription and payment records | As long as tax law requires us to keep them, which in Canada is generally six years. If you ask, we remove your X username from your subscription record sooner. |
| Listening-page records | Until the Service stops operating, then only totals that can't be linked to a browser |
| Post and article text, and audio | Until the post or article is taken down or we stop the Service. After a takedown, we delete the text and audio but keep its ID, so that we don't read it again. Request records that link to it are kept as listed above. |
| Messages, and copies of the emails we send you | As long as we need them to deal with your request |
| Published quotes | Until you withdraw your consent or ask us to remove the quote |
Deleted information can stay in our hosting provider's backups for a limited time before it's overwritten.
7. Your choices and rights
- Leave the waitlist: email team@toaudio.app, message @toaudioapp on X, or use the unsubscribe link in any email we send. To check that a waitlist request is yours, we'll ask you to write from the email address on the list.
- See, correct or delete your information, or object to how we use it: contact us. For records tied to an X username, we may ask you to show that you control the account. For web form requests, we'll ask you to write from the email address you used, and we'll delete it from both our request records and our list of submissions.
- Pro subscribers: to cancel or change your card, use the "Manage subscription" link in your receipt emails. For anything else about your subscription record, write to us from the email address you used at checkout. We keep payment records for as long as tax law requires.
- Authors: to remove a reading of your post or article, see Removal requests.
- Withdraw a quote: contact us and we'll remove it from our pages within 24 hours.
We offer these choices to everyone, wherever you live.
If you're in the EEA or the UK, you have the right to access, correct and delete your personal information, to restrict how we use it, to receive it in a portable format, to object to how we use it, and to withdraw your consent at any time. You also have the right to complain to a data protection authority: in the EEA, the authority in your country; in the UK, the Information Commissioner's Office.
You can object at any time to processing based on our legitimate interests. If you wrote a post or article we read aloud, that includes objecting to the reading (see Removal requests).
We'll reply within 30 days.
We can delete what we hold. We can't delete things on X that you posted yourself, such as your mention; you can delete those on X.
8. Security
Our admin tools sit behind access control. Traffic is encrypted with HTTPS. Where we only need to tell visitors apart, we store keyed hashes instead of IP addresses. No system is perfectly secure, but we work to protect what we hold.
To report a security issue, email team@toaudio.app.
9. International transfers
Our providers may process information outside your country, including in the United States. Cloudflare serves pages from data centers around the world.
10. Children
toaudio is not directed to children under 13, or under the minimum age in your country. If you believe a child has given us personal information, contact us and we'll delete it.
11. Changes to this policy
We'll post any update on this page with a new effective date. For material changes, we'll also give notice on this page and on @toaudioapp before they take effect.
Version history:
- September 24, 2026: first version.
- September 26, 2026: added asking requesters once how a reading went, and publishing quotes with consent.
- September 27, 2026: added requesting audio of web articles, including by email through our web form, and the providers we use for email (Google and Brevo).
- October 1, 2026: added Pro subscriptions: payments through Stripe, and Inworld as a speech provider for Pro readings.
12. Contact
- Email: team@toaudio.app
- On X: @toaudioapp
Privacy questions, requests and security reports all go to this email address.