Privacy Policy
Effective PLACEHOLDER — not yet published
The short version
- Your books and your reading are yours. We do not sell any of it.
- Your book files sit on our own servers — not in a third-party cloud drive.
- We do not run advertising trackers or third-party analytics. Usage measurement is our own, and it is about features, not about you.
- Deleting your account deletes your library with it.
Your account
To have an account we store your email address, a display name if you give one, and either a hashed password or a link to the Google or Apple account you signed in with. We never see your password in readable form, and when you use a social login we receive only the identifiers that provider sends us — never your password there.
We also keep active session records so you stay signed in, and a log of security-relevant actions on your account, such as password changes.
Your books
Book files you upload or import are stored on the server’s own disks, along with the cover images and the reading-ready version we build from each file. Alongside them we keep the details needed to show a library: title, authors, publisher, language, genres, identifiers, file size and format.
We do not read your books. Their contents are processed automatically so they can be displayed and searched, and are not reviewed by a person except where you explicitly ask us to look at a specific book because something is wrong with it.
Your reading
So that a book opens where you left it and stays in step across your devices, we store your reading position and progress per book, together with the highlights, notes and bookmarks you create and the text they refer to. We also store your reading preferences — typography, layout, colours, tap zones.
This information syncs between your own devices only: the web reader and any reading app you have connected to your personal feed, such as KOReader. To make that work we record a name and last-seen time for each connected device, and a history of sync conflicts so you can resolve them. None of it is shared with other users.
How we measure usage
We record product events — an import finished, a book was opened, a reading session ended — with your account identifier and a small set of properties about the action. We use them to understand which parts of the product work, and for nothing else. There is no advertising network, no third-party analytics service and no cross-site tracking.
Individual events are deleted after about six months. Daily totals derived from them — how much was read on a given day — are kept so long-term reading statistics survive, and they contain no book content.
We send email you need: address verification, password resets, security notices, and notifications you have switched on. Delivery goes through an email provider acting on our behalf, which necessarily sees your address and the message. We do not send marketing email, and notification emails can be turned off in settings.
The beta waitlist
If you ask for an invite from the front page, we store the email address you gave us, the date, the network address the request came from, the browser and device string your browser sent, and the language it asked for. The address is there so we can write to you; the date and network address are the record that you asked, which is what allows us to write to you at all; the language tells us which one to write in.
We use it for one thing: telling you when there is a seat in the beta. No marketing, no newsletter, and it is not shared with anyone. Asking for an invite does not create an account.
We keep it until the beta ends or you ask us to remove it, whichever comes first. To be removed, write to contact@aldusapp.com and we will delete the entry.
Feedback you send us
When you report a problem from inside the app, your message is stored with technical context attached automatically — the screen you were on, your browser and device type, and identifiers of the book, annotation or sync event you were looking at. It is there so a bug can be reproduced. Do not put anything in the message box you would not want us to read, because we will read it.
Who else sees your data
We use a small number of outside services, each for one job, each receiving only what that job needs:
- Google Books and Open Library — when we look up cover art and book details, we send the title, author or identifier of the book. We do not tell them who asked.
- A dictionary service — when you look up a word while reading, that single word is sent to it. Nothing identifies you or the book.
- A translation service — when you translate a selection, the selected passage is sent to it. Nothing identifies you or the book.
- An email provider — as described above.
- Google and Apple — only if you choose to sign in with them, and only to confirm who you are.
- Catalogs you connect yourself — when you import from your own OPDS server, we contact that server using the credentials you gave us. They are stored encrypted and are sent nowhere else.
We do not sell personal data, and we do not share it for advertising. We may disclose data where the law requires it.
Google Drive
If you choose to import a book from Google Drive, Aldus uses the drive.file scope, which is the narrowest access Google offers. In practice that means:
- You pick the files, in Google’s own picker. We only ever receive the ones you select.
- We cannot browse, search or list your Drive. Files you do not pick are invisible to us — the permission does not extend to them.
- A selected file is downloaded once, added to your library, and treated from then on exactly like a file you uploaded yourself.
- We never write to, modify or delete anything in your Drive, and we never share Drive content with anyone.
- You can disconnect the integration at any time from your Google account settings or ours.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How long we keep things
- Books and annotations — until you remove them or close your account.
- Removed books — recoverable for 30 days after you remove them, then permanently deleted along with their files.
- Usage events — about six months. Daily reading totals are kept indefinitely.
- Security and account logs — a year, or up to three years for records we are required to retain.
Deleting your account
You can delete your account yourself, from the danger zone in settings. It is immediate and it is not reversible. Deleting removes your account record, your books and their files, your covers, your highlights, notes and bookmarks, your reading positions and preferences, your connected devices and sources, and your usage history.
What survives: records we are legally required to keep, and aggregate figures that no longer identify you.
Your rights
You can see and correct most of your data directly in the app, and delete all of it by closing your account. Depending on where you live you may also have the right to a copy of your data, to object to particular processing, or to complain to a data protection authority. Write to us and we will help.
Changes and contact
If this policy changes materially, we will say so here and, where it affects you meaningfully, by email. Questions about your data go to contact@aldusapp.com.