Privacy
Last updated 1 October 2026
Do not put student data into Reading Leveler. No names, no grades, no assessment records, no IEP content, nothing that identifies a child. The tool is not built for it today and sends what you give it to an outside language-model provider.
Two other things worth knowing up front: the passages you paste are sent to a language-model provider to generate the leveled versions, and a share link is public to anyone who has the URL. Both are explained below.
Who runs this
Reading Leveler is operated by Bulrush Labs LLC. You can reach us at privacy@bulrushlabs.com with any question about this policy or about data we hold.
What we collect
Your account. When you sign in with Google we receive your name, email address, and profile picture through our authentication provider, Clerk. We never see your Google password, and we do not request access to Gmail, Drive, Calendar, or any other Google service.
What you put into the tool. The reading passages you paste, and any photo, PDF, or Word document you upload. Also the titles you give them and the vocabulary you mark as protected.
What the tool produces. The three leveled versions, the summary of changes, and the readability score for each.
How you use it. Which levels you generated and when, and whether a share link was opened, copied, or liked.
We do not use advertising trackers, we do not sell personal information, and we do not build advertising profiles.
Where your passages go
Leveling a passage means sending it to a language model run by someone else. The same is true of reading text out of a photo, a PDF, or a Word document you upload.
Right now that provider is Google, through the Gemini API, with Anthropic used to pull the text out of Word documents. We change providers as models improve, and the ones we use or may use are Google, Anthropic, Lunaroute, OpenAI, or another provider we adopt later. We will keep this paragraph current rather than list every change separately.
Whoever it is, they process the content to return a result to you, and we rely on their published API terms — which at the time of writing do not permit using submitted content to train their models. Those are their terms, not ours. If it matters to you, read them: Google and Anthropic.
Where it is stored
Saved readings live in a Postgres database hosted by Supabase. The site runs on Vercel, which also provides the bot-detection check that protects the generate button from automated abuse.
Diagnostic logs are written to temporary storage on the server and are not retained — they disappear when the server instance recycles, typically within the hour.
Share links are public
When you create a share link, anyone holding that URL can read the passage and its leveled versions without signing in. The link is not listed or indexed by us, but it is not protected by a password either. You can revoke a share link at any time, which immediately stops it working.
Using it without an account
You can level a passage without signing in. When you do, your browser generates a random session identifier so we can apply a usage limit. It is not linked to your identity, and we do not profile anonymous visitors by IP address. Work done without an account is not saved to your account unless you sign in afterwards and choose to keep it.
No student data
Do not put student data into Reading Leveler today. That means no student names, initials, or ID numbers; no grades, scores, or assessment results; no IEP, 504, or special-education content; no disciplinary or attendance records; no family or contact details; and no student work that identifies its author.
This is not a formality. Anything you paste or upload is sent to an outside language-model provider and stored in our database. Reading Leveler has not been built or reviewed for student records, we have no agreement with your school or district covering them, and nothing here should be read as making the service suitable under FERPA, COPPA, or your local equivalent.
Level the reading material — the article, the passage, the textbook excerpt. That is what the tool is for, and it needs nothing about any particular child to do it.
The service is not directed to children under 13 and we do not knowingly collect their personal information. If you believe a child’s information has reached us, write to privacy@bulrushlabs.com and we will delete it.
Keeping and deleting your data
Saved readings stay until you delete them. Deleting a reading also deletes its leveled versions, its event history, and any share links pointing at it. To remove your account and everything attached to it, email us at privacy@bulrushlabs.com and we will do it.
Depending on where you live you may have the right to see a copy of your data, correct it, or have it erased. Ask and we will help — we do not require a particular form of words.
Changes
If this policy changes in a way that affects what we do with your content, we will update the date at the top and say what changed.