Your documents, and the trust of the people who read them, are yours. Here is exactly how we protect both.
Last updated: 1st July 2026
BackRead is a document intelligence service that lets you share documents and understand how they are read. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and the rights you have over it.
For the purposes of the Nigeria Data Protection Regulation (NDPR), the Nigeria Data Protection Act 2023, and, where it applies, the EU and UK General Data Protection Regulation (GDPR), BackRead is the data controller for the account and marketing data we hold about our users, and a data processor for the document and reader data our users choose to process through the service.
We designed BackRead so that understanding your readers never comes at the cost of their privacy or yours. Reading this policy should leave you reassured, not uneasy.
We collect only what we need to run the service well. We group it into four categories:
We do not collect special categories of personal data (such as health, religion, or biometric data) and we ask that you do not upload documents whose primary purpose is to process such data through BackRead.
Under the NDPR and GDPR we must have a lawful basis for every use of personal data. Ours are:
Readers whose activity is captured are informed that the document is a BackRead document. As the person sharing a document, you are responsible for having a lawful basis to share it and to observe how it is read.
We use personal data to operate the document companion, produce reading signals and verdicts, show you reader activity, secure your account, provide support, and, where you have opted in, send you product updates. We never sell your personal data, and we never use the contents of your documents to train external models or for any purpose other than delivering the service to you.
Security is not a feature we bolt on; it is how the service is built. We apply layered technical and organizational measures designed to prevent data leaks:
No system can promise perfection, but we hold ourselves to a high standard and treat any incident with the seriousness it deserves. If a breach ever affected your personal data, we would notify the National Data Protection Commission and affected individuals in line with the timelines set by Nigerian law and the GDPR.
We keep personal data only as long as we need it. Documents and reader data remain until you delete them or close your account. Account data is retained for the life of your account and for a short, defined period afterward to meet legal and accounting obligations, then securely erased. You can delete individual documents at any time, which removes their associated reader data.
Under the NDPR, the Nigeria Data Protection Act, and the GDPR where it applies, you have the right to:
To exercise any of these rights, contact us using the details below. We will respond within the timeframe required by law, and we will never charge you for making a request in ordinary circumstances.
Where personal data is transferred outside Nigeria, we ensure an adequate level of protection through appropriate safeguards, such as contractual clauses that bind the recipient to standards equivalent to the NDPR and GDPR. We transfer data internationally only where it is necessary to provide the service and lawful to do so.
BackRead is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us data, contact us and we will remove it.
We may update this policy as the service or the law evolves. When we make a material change, we will update the date at the top and, where appropriate, notify you directly. Continued use of BackRead after a change means you accept the updated policy.
If you have any question about this policy, or wish to exercise a right, the fastest way to reach our data protection team is the live chat on our website. We treat every message from a user or a reader with care and respond promptly.