← SumSpot

Privacy Policy

SumSpot LLC · Last updated 23 August 2026

The short version. Nothing about the pages you read leaves your device until you switch SumSpot’s extension on in Safari and allow it to run on a site. Installing the app is not enough on its own. The app does send us a small count when you open it — that it was opened, and whether the extension has ever run here — which carries nothing about you or any page; the counts are described below.

Once it is on, it summarizes pages automatically as you open them — it does not wait for you to tap anything. To summarize a page, SumSpot has to send that page somewhere: its address and its visible text go to our server, and the text is passed to OpenAI, which writes the summary.

We keep a copy of the page address, the page text and the summary. We do not ask you to create an account, and we do not collect your name or email address.

If you would rather a page never be sent, turn SumSpot off for that site in Safari’s extension settings, or turn the extension off entirely. Nothing is sent from a page SumSpot is not running on.

Who we are

SumSpot is published by SumSpot LLC. This policy covers the SumSpot app for iPhone, iPad and Mac, the SumSpot Safari extension, and this website. Questions, requests and complaints: [email protected].

When SumSpot sends a page

Once you enable the extension in Safari and grant it permission for a site, SumSpot runs on the pages you open on that site over HTTPS. On a page it has not summarized before, it sends the page for summarizing on its own, as the page loads. There is no button to press first.

Two things limit this:

Because it works this way, please assume that any page you open with SumSpot enabled will be sent — including pages you are signed in to, and pages that are not public. If a site holds anything you would not want copied to our server and to OpenAI, turn SumSpot off for that site.

What is sent, and to whom

To our server

For each page summarized, the extension sends the full page address (including anything after ? or #) and the visible text of the page body. Our server runs on Amazon Web Services in the US West (Oregon) region.

There is one more case where an address reaches us without any page text. If summarizing fails and you tap “Try again”, SumSpot first asks our server whether it already has a summary for that address, so that a summary already generated is not paid for and generated twice. That request sends the page address and nothing else.

To OpenAI

Our server passes the page text to OpenAI’s API, which generates the summary and returns it. OpenAI receives the page text. It does not receive the page address.

As OpenAI’s policy stands in July 2026, text sent to it through the API is not used to train or improve its models unless the sender opts in to share it, which we have not. OpenAI does keep API inputs and outputs for up to 30 days to check for misuse of its service.

Both of those are OpenAI’s policies rather than promises we are in a position to make for them, and OpenAI can change them without changing anything about SumSpot. Its current terms are published in OpenAI’s own documentation.

Recorded with every request

Our server keeps a short diagnostic record of the requests it receives, so that when something breaks we can tell what broke. That record holds the kind of request, how much text it carried, and — for a summary — the domain of the page, such as example.com. It does not hold the rest of the address, the page text, your IP address or your browser’s user-agent. These records are deleted after 14 days.

Small requests that carry no page content

SumSpot sends a handful of requests that are not about any particular page. None of them contains an identifier, an account, or a page address, and none of them summarizes anything or generates any content. What they are for is counting: how many people get SumSpot working, and where people get stuck. Because they carry no identifier, they cannot be joined together or traced back to a person — a count is all they can ever be.

The settings check is not counted at all — it leaves only the 14-day diagnostic record described above. The five counts below it are kept for 12 months. All of them are sent whether or not you have a subscription. Clearing your browser data or reinstalling can make the “first time” ones happen again, because the only record that they already happened is the one kept on your device.

What we store, and for how long

WhatWhereKept for
Page address, page text, generated summary, timestampOur database (AWS DynamoDB, US West)12 months
Older records, stored before 30 July 2026: page address, generated summary, timestamp. The page text has been deleted from all of themOur database (AWS DynamoDB, US West)No fixed limit
Diagnostic records: kind of request, amount of text, page domain. No IP address, no user-agent, no page address, no page textOur server logs (AWS CloudWatch, US West)14 days
The counts described above: limit reached, extension is working, extension ran for the first time, app was opened, app was opened for the first time. No identifier, no page addressOur server logs (AWS CloudWatch, US West)12 months
Cached summaries, your remaining free-summary count, cached settingsYour device onlyUntil you clear it or remove the extension

Summaries stored from 30 July 2026 onwards are deleted automatically after twelve months, which is how far back we look when counting how SumSpot is used. Records stored before that date were made before we set that limit and do not expire on their own — but on 30 July 2026 we deleted the stored page text from every one of them. What is left is the page address, the summary we generated, and the date.

Subscriptions and payment

Subscriptions are sold through Apple. Apple handles the payment; we never see your card details, and Apple tells the app only whether a subscription is currently active.

We use RevenueCat, a subscription-management service, to keep track of subscription status. RevenueCat receives purchase and receipt information from Apple and assigns your installation a random identifier of its own. That identifier is not linked to the summaries described above, and it is not your name, email or Apple Account.

This website

sumspot.app uses Google Analytics to count visits and see which pages people read. Google sets cookies and receives your IP address and page views in the process. This is separate from the app and the extension, and blocking it in your browser has no effect on how SumSpot works.

What we do not do

Your choices

Children

SumSpot is not directed at children under 13, and we do not knowingly collect information from them.

Where your information goes

Our servers are in the United States, and OpenAI processes page text in the United States. If you use SumSpot from elsewhere, the information described here is transferred to and stored in the United States.

Security

Traffic between the extension, our server and OpenAI is encrypted in transit. Stored data sits in Amazon Web Services with access restricted to us. No system is perfectly secure, and we would rather say so than imply otherwise.

Changes to this policy

If we change how SumSpot handles your information, we will update this page and change the date at the top. Significant changes will also be described in the app’s release notes.