Legal

Privacy

Short, specific, and true. Your reading is correspondence and drafts of things you have not decided to care about yet; it is not material for anything.

Last updated 20 August 2026.

What we store

Data stored and why
What Why How long
Your email address Signing in, and the address your documents are sent from. Until you delete the account
Your password Signing in. Stored only as a salted hash — never the password itself — so a database leak does not reveal it. Until you delete the account
Your sending and inbound addresses Delivering documents, and receiving refusal notices back. Until you delete the account
Kindle addresses and labels Knowing where to send. Until you remove the device
Sources and schedules Polling the feeds you asked for at the times you chose. Until you remove them
Article text and images Building the file, letting you re-send or download it later, and searching it on Pro. Your plan's retention window
Forwarded newsletter emails Turning the issue into an article. The raw message is deleted as soon as it is processed, and in any case within 24 hours
Delivery records Telling you what happened, and diagnosing failures. Your plan's retention window
Uploaded documents Converting them. Deleted within 7 days of the conversion

Retention, by plan

Retention is both a feature and our storage bill, so it is enforced by storage lifecycle rules and a nightly sweep rather than by a promise:

  • Standard — 90 days, then the article body, its images and its built files are deleted
  • Pro — kept until you delete it, either individually or with the whole account
  • Lapsed account — 7 days. A trial that ended or a subscription that stopped leaves the account open and readable, and everything in it downloadable, for that long.

When retention expires, the index row goes with the content. What survives is a delivery record with no body attached, so your history still adds up.

One user, one copy

Every extracted article belongs to the account that extracted it. We do not deduplicate content across accounts, do not build a shared archive, and do not serve anyone else's copy to anyone. If two people send the same article, there are two copies with two expiry dates.

This is deliberate. The legitimacy of this whole category rests on a person making a personal-use copy of something they can already read. A shared library would be a different product with a different legal posture, and we are not building it.

Who else touches it

  • Cloudflare — hosting, storage, the database and inbound mail routing.
  • Amazon SES — outbound mail delivery. Every document we send passes through it, addressed to the Kindle address you gave us.
  • Stripe — payments and invoices. They receive your billing details; we never see a card number.
  • Amazon — a document sent to a Kindle is handled by Amazon's Send to Kindle service under Amazon's terms.

That is the complete list. There is no analytics vendor, no session recorder, no ad network and no data broker.

Cookies

One: a session cookie, set when you sign in, so the dashboard knows who you are. It is HttpOnly, Secure and SameSite=Lax, and it does nothing else. No cookie banner, because there is nothing to consent to.

Email we send you

Your documents, and account mail you cannot switch off (sign-in links, a delivery that needs you to do something, and notice of a change to this policy). Product announcements are opt-in and one click to leave.

Deleting things

  • One article — delete it from the library; the body and images go immediately.
  • One source or device — remove it in the dashboard.
  • EverythingSettings → Delete account. The account, its content, its images, its built files and its delivery history are removed within 30 days, and the sending address is retired rather than reissued.

You can also export first: every article you have kept, as EPUB files plus a JSON index, in one download.

Your rights

If you are in the UK, EU or a state with comparable law, you can ask for a copy of your data, have it corrected, have it deleted, or object to processing. The dashboard already does the first three without asking anyone. For anything else, help@routineink.com reaches a person, and we answer within 30 days.

Who is responsible for it

The data controller is RoutineInk, which operates routineink.com. help@routineink.com is the address for any request under this policy, and it reaches a person rather than a queue.

Security

Everything is encrypted in transit and at rest by the platform. Passwords are stored only as a salted hash, never in the clear, so a database leak cannot reveal them. Sending domains are configured with SPF, DKIM and DMARC, because a service that mails your documents to Amazon has an obligation not to be spoofable.

Changes

If this policy changes in a way that affects what we keep or who touches it, we email you before it takes effect. Typo fixes just get a new date at the top.

Amazon, Kindle, Kindle Scribe and Send to Kindle are trademarks of Amazon.com, Inc. or its affiliates. RoutineInk is not affiliated with Amazon.