Privacy Policy
Last Updated: 2026-07-14
“RSSFlow Reader ("RSSFlow" or "this extension") values your privacy and data security. This policy explains: what data we process when you install and use this extension, how it's stored, under what circumstances it's transmitted, and how you can manage your own data.”
1. Introduction
The core design principle of RSSFlow is: keep data on user's local device as much as possible. However, when you actively enable certain networked features, relevant data may be sent to your selected third-party services or our functional infrastructure to complete the requested functionality.
2. Data We Process
2.1 Local Reading & Subscription Data
Stored in your browser locally to implement RSS reading and management:
- RSS Feed URLs added by you
- Article titles, links, summaries, content cache or parsed text
- Read/unread status, favorites, tags, and filtering preferences
- Local cache from Discovery, Summary, and Flow views
2.2 Settings & Personalization
To provide a personalized experience, the extension may save locally:
- Themes, language, display modes, and reading preferences
- Shortcuts, custom commands, and custom Prompts
- AI feature toggles, model selection, and parameters
- TTS voice settings, automation task, and notification configurations
- MCP Bridge and other extended feature settings
2.3 AI & Chat Related Data
If you enable AI summaries, AI chat, HTML preview generation, or other AI capabilities:
- Article content, summary context, and question content
- Your Prompts, instructions, and chat messages
- AI-generated summaries, answers, and analysis results
- Configured API Hosts, model names, parameters, and API Keys
2.4 Activation, Trial & Permission Verification
- Locally generated device or user identifiers
- Activation status, trial status, and permission info
- Activation time, expiration, signature verification info, and your activation code
2.5 Notification & Push Related Data
If you enable Telegram, Feishu, or other notification/automation push capabilities:
- Telegram Bot Token, Chat ID
- Feishu Webhook address and related configurations
- Pushed article titles, links, summaries, and automated analysis results
- Automation task names, report links, and execution results
2.6 Voice Broadcast & TTS Data
If you enable voice broadcast or cloud TTS features:
- Text content to be read aloud
- TTS voice configurations
- Generated audio cache data
3. Browser Permissions Requested
To ensure proper functioning and local storage stability, the extension requests the following browser permissions:
- offscreen: Under Manifest V3, the background Service Worker lacks DOM APIs. We use an offscreen document to safely parse HTML/XML formatted RSS feeds and run the local SQLite WebAssembly database engine.
- unlimitedStorage: Used to store offline articles, AI chat logs, vector embeddings, and SQLite databases. This prevents data loss or corruption when storage exceeds the default 5MB quota.
4. How Data is Stored
4.1 Local Storage
Most RSSFlow data is saved on your device locally (e.g., browser local storage or databases), including subscriptions, reading history, settings, chat sessions, and automation logs.
4.2 No Default Server Sync
RSSFlow does NOT automatically upload all your local reading data, settings, or chat data to our servers. Data is only sent when you actively enable features that require network connectivity.
5. When Data is Transmitted
5.1 Fetching RSS Content Updates
The extension requests the corresponding RSS source sites to pull subscribed content.
5.2 Using AI Capabilities
When AI features are enabled, article content, questions, and parameters may be sent to your selected providers (OpenAI, Google Gemini, SiliconFlow, DeepSeek, or other compatible services).
5.3 Using Activation, Trial or Verification
Data like device identifiers and activation codes may be sent to our validation service to complete authorization.
5.4 Using Message Push Features
Summaries and links may be sent to Telegram, Feishu, or other configured receivers.
5.5 Using MCP Bridge & Automation
Input instructions, article context, and task results may be transmitted for workflow execution.
5.6 Using Cloud TTS Capabilities
Text may be sent to speech services to generate audio content.
6. How We Share Data
We do not sell your personal data. Data is shared with providers only to implement features you request:
- RSS content sources for fetching updates
- AI Service providers you choose or configure
- Messaging and collaboration platforms (Telegram, Feishu)
- Our functional infrastructure (Activation, MCP Bridge, Automation reports, Cloud TTS relay)
6.5 Third-Party Rules
Third-party services process data according to their own privacy policies. We recommend reviewing them before enabling related features.
7. Data Retention Period
7.1 Local Data
Remains on your device until you delete it, reset the extension, uninstall it, or the browser clears local storage.
7.2 Remote Data
Retention depends on the time needed for processing and the third-party provider's own storage policies/legal requirements.
8. Data Security
We protect data via local storage, HTTPS encryption, and signature verification. However, no transmission method is absolutely secure; please protect your sensitive credentials (API Keys, Bot Tokens, etc.).
9. Your Rights & Control
You retain full control over your data:
- View and modify local settings
- Delete local subscriptions, cache, chat records, or configurations
- Disable AI, Push, Bridge, TTS, or automation features
- Clear all data via the 'Reset' feature or by uninstalling
10. Children's Privacy
RSSFlow is designed for general users and not specifically for minors. If you are a minor, please use it under the guidance of a guardian.
11. Policy Updates
We may update this policy due to product iterations or legal changes. The latest version will be posted on this page with the 'Last Updated' date.