Privacy & Security
At ExportReader, your privacy comes first. Your data remains yours — always. We never share or sell your content.
📋 Quick Navigation
- 🔒 How we protect your data
- 🛡️ Advanced Security Features
- 🧠 What we store
- 🗑️ Data Deletion
- 🔧 Technical Security Measures
- 🌍 Data Location & Compliance
- 🔐 Your Responsibilities
- 🇪🇺 Your GDPR Rights
- ⚖️ Legal Basis for Processing
- ⏳ Data Retention
- 🚨 Data Safety & Breach Notifications
- 🤝 Third-Party Service Providers
- 🔞 Age Requirement
- 📝 Your Uploaded Content
- 🔄 Updates to This Policy
- 📬 Contact
🔒 How we protect your data
- Secure upload: all transfers use HTTPS encryption with TLS 1.2+.
- Private storage: your files stay private on our server and are never shared or sold.
- ZIP cleanup: uploaded ZIP files are automatically deleted after successful extraction to save space. Only the extracted files remain so we can build your personal archive and enable search, tagging and organisational features.
- Purpose‑limited: uploads are used only to build your personal archive (no selling, sharing, or AI training).
- Your control: you can delete chats and snippets anytime; you can also request deletion of uploads or full data removal.
- No tracking: we don't run ad pixels or third‑party analytics on your data.
- Malicious file protection: all uploads are automatically scanned for malicious content including executable code, shell scripts, and ZIP bombs.
🛡️ Advanced Security Features
- File scanning: every upload is scanned for 20+ dangerous file types, double extensions, null byte injection, and malicious code patterns.
- Auto-ban system: malicious uploads trigger automatic account locks and IP bans to protect our community.
- ZIP bomb protection: we detect and block suspicious compression ratios and files that expand beyond safe limits.
- MIME validation: file content is verified to match declared types (ZIP only).
- Rate limiting: automated protections prevent abuse and brute-force attacks.
- Security headers: strict CSP, X-Frame-Options, HSTS, and other modern security headers are enforced.
🧠 What we store
User data:
- Email address (for authentication and account recovery)
- Encrypted password (using bcrypt hashing)
- Uploaded chat archives (stored privately per user)
- Conversation text, tags, and snippets you create
- Minimal metadata (timestamps, file sizes) for functionality
Security logs:
- Login attempts and session data (for security)
- Security incidents (malicious uploads, failed authentication)
- IP addresses (only for security and abuse prevention)
We store only what's necessary to provide the service and keep it secure.
🗑️ Data Deletion
You have full control over your data:
- Individual chats: delete specific conversations anytime from your archive.
- Snippets: remove saved snippets whenever you want.
- Complete removal: visit your Settings page to permanently delete all your data, including uploads, chats, and account information.
- Automatic cleanup: ZIP files are auto-deleted after extraction; extracted files remain until you delete them.
When you delete data, it's permanently removed from our servers (not just hidden).
🔧 Technical Security Measures
- HTTPS everywhere: all connections use TLS encryption.
- Secure cookies: HttpOnly, Secure, SameSite=Strict flags prevent cookie theft.
- CSRF protection: all forms use tokens to prevent cross-site request forgery.
- Content Security Policy: strict CSP with nonces prevents XSS attacks.
- Input sanitization: all user input is sanitized before display or storage.
- SQL injection prevention: prepared statements protect against database attacks.
- Password security: bcrypt hashing with per-user salts.
- Session security: strict session management with automatic timeouts.
🌍 Data Location & Compliance
Your data is stored on secure servers located in the EU/UK. We comply with data protection best practices:
- Data is stored in isolated, per-user directories
- No sharing of your data with advertisers, marketers, or unrelated third parties (our infrastructure providers act only as contracted processors)
- No selling of user data or content
- No use of your data for AI training
- Transparent data handling practices
🔐 Your Responsibilities
To keep your account secure:
- Use a strong, unique password
- Don't share your login credentials
- Log out when using shared devices
- Report suspicious activity to us immediately
- Only upload files you have the right to upload
🇪🇺 Your GDPR Rights
If you are in the EU/UK, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Request a copy of your data in a portable format
- Restrict or object to certain types of processing
- Withdraw consent at any time (when consent is the legal basis)
To exercise any of these rights, contact us at support@exportreader.com.
⚖️ Legal Basis for Processing
We process personal data under the following GDPR legal bases:
- Contract: We need your data to provide ExportReader (upload, process and display your chat exports).
- Legitimate Interest: Maintaining security, stability and service improvements.
- Consent: Optional features where you explicitly opt in.
We never sell or share your data for advertising, profiling, or marketing.
⏳ Data Retention
- Chat export files and indexed data are stored until you delete them or delete your account.
- ZIP uploads are automatically removed after extraction.
- If an account becomes completely inactive for a long period, we may delete stored files after sending you notice.
- Deleted files may remain briefly in automated backups until those backups rotate.
🚨 Data Safety & Breach Notifications
We use appropriate technical and organisational measures to keep your data secure.
If a data breach occurs that risks your rights or privacy, we will contact you without undue delay and notify the relevant supervisory authority as required by GDPR.
🤝 Use of Third-Party Service Providers
We use trusted providers for hosting, backups and essential infrastructure.
These providers only access data when necessary to perform their service and must keep it confidential under contract.
We do not use third-party analytics on your uploaded content.
🔞 Age Requirement
ExportReader is not intended for children. You must be at least 16 years old to use the service.
If we become aware of an account belonging to someone under 16, we will delete the account and all related data.
📝 Your Uploaded Content
You retain full ownership of all files you upload. We only use your content to:
- store it,
- display it to you,
- index it for search,
- generate tags or organisational metadata,
We do not use your chat exports to train AI models or for any purpose outside ExportReader's functionality.
🔄 Updates to This Privacy Policy
We may update this policy from time to time. If changes are significant, we will notify you by email or via a notice on the website.
📬 Contact
For privacy questions or data requests, email support@exportreader.com.
Data Controller:
ExportReader is operated by Lee Nolan, who acts as the Data Controller for all user data.
For all data protection matters, you may contact the Data Controller via the email address above.