Privacy Policy
OpenReader · Effective date: May 17, 2026
OpenReader (“the App”) is an iOS application developed and operated by HBKL Labs LLC. This policy explains what data the App collects, why, and what you can do about it.
The short version
- You can use OpenReader as a guest. In guest mode, nothing leaves your device.
- We collect as little as possible. No third-party analytics, no ads, no tracking across other apps or websites.
- You can delete your account and all associated data from inside the app at any time.
What we collect
If you use OpenReader as a guest (no sign-in)
Nothing leaves your device. Your library, reading progress, highlights, notes, and notification schedules are stored locally using Apple’s SwiftData. We cannot see them.
If you sign in
OpenReader supports three sign-in methods: Sign in with Apple, Google Sign-In, and email magic-code (sent through Resend). Authentication is handled by Firebase Authentication. We never see or store your password.
From the sign-in flow we receive:
- Your email address. Used as your account identifier. If you choose Apple’s “Hide My Email,” we only ever see the relay address.
- A user ID. A Firebase Authentication identifier that links your library to your account.
Once signed in, the following lives in Google’s Firestore and Firebase Storage, tied to your user ID:
- Books you’ve added (metadata and reading position)
- EPUB files you’ve imported
- Book cover images
- Highlights and notes
- Reading sessions and pace data
- Highlight notification schedules
- Generated audiobooks (if you purchased AI audiobook generation)
- Subscription state
If you enable push notifications
We store the Firebase Cloud Messaging token Apple issues for your device, so we can deliver highlight notifications at the times you’ve scheduled. The token is tied to your user ID. If you disable notifications in iOS Settings, we stop using it.
What we do NOT collect
- Location data
- Contacts
- Photos, microphone, or camera access
- Browsing history outside the app
- Analytics, crash reports, or telemetry from third-party SDKs
How we use it
- App functionality only. Your library, reading progress, highlights, and schedules exist so the app works across your devices.
- AI audiobook generation (optional, paid). If you purchase audiobook generation for a book, the book’s text is sent to Fish Audio for text-to-speech, and the resulting audio is stored in your library.
- Push notifications. Only if you opt in, and only to surface highlights on the schedule you set.
- No advertising. We do not share or sell data to advertisers, data brokers, or anyone else.
Who else sees your data (processors)
OpenReader relies on a few third-party services to operate. They process data on our behalf and are bound by their own privacy terms:
- Firebase (Google). Privacy . Provides authentication, Firestore (where your library lives), Firebase Storage (where your EPUB files live), and Cloud Messaging (push notification delivery).
- Apple Push Notification service. Privacy . Delivers push notifications. Apple sees the device token and notification payload.
- Resend. Privacy . Sends the email sign-in code. Resend sees your email address and the one-time code, nothing more.
- Google Sign-In. Privacy . Only if you chose Google to sign in. Google sees the sign-in event, not your in-app activity.
- Fish Audio. Privacy . Generates AI audiobooks from book text. Only invoked when you explicitly purchase audiobook generation for a specific book. Fish Audio receives the book text and voice selection; it does not receive your account information.
- Apple StoreKit and RevenueCat ( RevenueCat privacy ). Manage in-app subscription purchase verification.
We do not share your data with anyone else.
Your rights
- Delete your account. Open the app, go to Settings, and tap Delete Account. Your account, library metadata, EPUB files, highlights, schedules, audiobooks, and subscription state are removed immediately on the server side and within 30 days everywhere else.
- Sign out. Settings, Sign Out. Your local library on this device is wiped; your cloud library stays in your account.
- Export your highlights. Settings offers a JSON export of all your highlights. For a full data export, email us and we’ll send you everything within 30 days.
- Opt out of notifications. Toggle off in Settings, or disable in iOS Settings, Notifications, OpenReader.
Data retention
- Account data is kept while your account is active.
- When you delete your account, the server wipes your data immediately. A daily cleanup job removes any tombstoned files left over within 30 days.
- Stale push tokens are cleaned up automatically.
Data security
All network traffic uses encrypted HTTPS. Data lives in Google Cloud infrastructure with row-level access scoped to your user ID. Server-side functions that handle your data require authenticated requests. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
Children’s privacy
OpenReader is rated 4+ on the App Store. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can take appropriate action.
Changes to this policy
We may update this privacy policy from time to time. Material changes will be noted in the app or by email before they take effect. Minor edits (typos, clarifications) may happen silently.
Contact us
If you have questions or concerns about this privacy policy or your data, please contact us at: