Privacy Policy
Effective date: September 12, 2026
RookReader ("we", "our", or "us") is a reader-first ebook, audiobook, and web-novel app developed by cosmiklore, available on Android and iOS. RookReader is built to be local-first: your books, your reading position, highlights, notes, and vocabulary live on your device by default. We collect as little as possible, we never sell your data, and we never use your reading content to train AI models. This Privacy Policy explains what is stored, what is optional, and where data goes when you choose to enable a connected feature. By using RookReader, you agree to the practices described here.
1. Data Stored Only On Your Device
The following is stored locally in RookReader's on-device database. If you use the app without an account, none of it leaves your device. If you sign in, some of it syncs to your account — see Section 2 for exactly which:
- Your book files: The ebooks, audiobooks, PDFs, comics, and documents you import are copied into the app's private storage on your device. The files themselves are never uploaded to our servers, whether or not you have an account.
- Reading position & mechanics: Your current chapter, scroll position, page, reading themes, and typography settings.
- Highlights, notes & bookmarks: Any annotations you create while reading.
- Vocabulary & learning data: Words you look up, your vocabulary deck, review schedules, and reading streaks.
- Reading DNA & statistics: Reading sessions, time read, finish rates, and goals.
- Web-novel follows & cached chapters: The RSS feeds you follow and chapter text cached for offline reading.
- Credentials for services you connect: API keys and access tokens for any cloud drive, self-hosted server, or AI provider you connect are held in your device's encrypted secure storage, never in our database.
2. Account & Cloud Sync (Optional)
If you create an account and sign in, RookReader syncs your reading data across your devices. This is optional — the app is fully usable without an account. When signed in, we store the following on our backend, bound to your account:
- Account data: Your email address and authentication provider (email/password, Google Sign-In, or Sign in with Apple), managed by our backend provider Supabase.
- Reading position: Your current position in a book, keyed by a book "fingerprint" (a hash derived from the file) rather than the file itself — so the same book syncs across devices without us ever receiving the book's contents.
- Library catalog: Metadata about the books on your shelf — title, author, series, tags, collections, and format — but not the files.
- Highlights, notes & bookmarks (Pro): For Pro users, your annotations sync across devices. This includes the text you highlighted and any note you wrote, keyed by book fingerprint.
- Reading statistics & vocabulary: Your reading sessions, stats, vocabulary deck, and followed web-novel serials sync so they carry across your devices.
- Settings sync: Your reader and app preferences.
- Cover thumbnails: To show the right cover on every device, a small cover image extracted from a book on your device may be uploaded to our storage. These images are stored at an unguessable, per-account path that is readable by anyone holding the exact link; they are deleted when you remove the book from your library. Only the cover image is uploaded — never the book.
We do not upload your book files, audiobook files, or their full text to our servers. Sync covers your position, annotations, catalog metadata, and learning data — not your library's contents.
3. AI Reading Companion
RookReader's optional AI Reading Companion is off until you use it, and it runs in one of two modes. In both, the text sent is limited to the portion of the book you have already read, so the companion cannot reveal later plot points.
- Managed mode (our key): If you use the built-in companion, the relevant book text and your question are sent from your device to our own relay server, which forwards the request to OpenRouter, which routes it to the model we use (currently Google Gemini 2.5 Flash) and returns the answer. The relay exists so that our provider key never ships inside the app. Managed use is metered against AI credits on your account: we record token counts and credit balances, not your prompts. We do not log, store, or train on the book text or your questions. Handling by OpenRouter and the model provider is governed by their own policies, linked in Section 10.
- Bring-your-own-key mode: If you connect your own provider key (such as Anthropic or OpenAI), it is stored in your device's secure storage and requests go directly from your device to that provider — they do not pass through our servers at all. Your use of that provider is governed by their privacy policy and terms.
If you never use the AI companion, no book text is sent anywhere.
4. Analytics
RookReader uses PostHog to understand which features are used and where the app is failing people, so we can decide what to build and fix. This is limited by design:
- We send a fixed, curated list of events — such as opening a book, completing onboarding, importing a file, viewing the Pro screen, or a sync error — along with technical properties like file format, outcome, app version, platform, and device model.
- We do not send book titles, authors, book text, highlight or note content, search queries, or the URLs of feeds and servers you connect to.
- Session replay and automatic screen/tap capture are disabled. We do not record your screen.
- Events are tagged with your account identifier (a random ID), not your email address, so we can tell one person's sessions apart without analytics holding your contact details.
- You can turn analytics off at any time in Settings → Data & storage. No analytics are collected while that setting is off.
5. Error & Diagnostic Data
RookReader uses Sentry to collect crash reports and performance data (such as slow screen loads) so we can fix problems. These reports include your device model, OS version, app version, and app state at the time of an error, and — when you are signed in — your account identifier, so we can tell whether a crash is hitting one person repeatedly or many people once. They do not include your email address or IP address by configuration, and we run an automatic filter that strips access tokens, API keys, and authorization headers and truncates free text before a report is sent. Crash reports do not include your book files, highlights, AI conversations, or API keys.
6. Feedback & Support
If you send feedback or a bug report from inside the app, we store the message you wrote, the reply-to email address you choose to include (prefilled from your account, and editable), your account identifier, and basic technical context — app version, platform, and device model — so we can reproduce the problem and reply to you. We use this only to handle your report.
7. Connected Sources & Lookups
Several features connect to third-party services only when you use them. Where a feature requires sign-in (e.g. cloud storage or a self-hosted server), your access tokens and credentials are kept in your device's encrypted secure storage, not in our database:
- Dictionary & Translation: Word definitions and translations are fetched from public, key-less services (dictionaryapi.dev, Wiktionary, and a Google translation endpoint). The selected word or passage is sent to those services to return a result.
- Importing books: When you import from a public catalog (e.g. Project Gutenberg, Standard Ebooks, OPDS), a direct URL, a self-hosted server (OPDS/WebDAV), or a cloud drive (Google Drive, Dropbox, OneDrive), RookReader connects to that source to download the file you selected. Cloud-drive connections use OAuth; we request only the access needed to list and download files you choose.
- Audiobooks: Streaming or downloading from LibriVox or a self-hosted Audiobookshelf server connects to those services. Audiobookshelf credentials are stored in secure storage on your device.
- Web novels: RookReader reads serials through their public RSS/Atom feeds. It does not scrape or bypass any site's access controls.
- Highlight export (optional): You can export your highlights to a file or, if you connect a Readwise account, to Readwise using a token you provide (stored in secure storage).
- Kindle import (optional): Importing a "My Clippings.txt" file is processed entirely on your device.
8. Purchases (RookReader Pro & AI Credits)
RookReader Pro is a one-time purchase, and AI credit packs are optional consumable purchases. Both are processed by the app store you installed from — Google Play Billing on Android or the Apple App Store on iOS. We do not collect or store your payment card or financial account details; those are handled entirely by Google or Apple and are never visible to us.
To confirm a purchase, our server verifies the purchase token or receipt with Google or Apple and records an entitlement bound to your account (whether Pro is active, and your AI credit balance). We also process refund, void, and subscription-status notifications from Google and Apple so that access reflects your current purchase status.
9. Notifications
Web-novel "new chapter" alerts are delivered as local notifications scheduled on your device. We do not use a push-notification server or Firebase for this, and no device push token is collected. You can disable notifications at any time from the app or your device settings.
10. Third-Party Services
Depending on the features you use, RookReader may interact with the following services, each governed by its own privacy policy:
- Supabase — account authentication, cloud sync, and our server functions. Supabase Privacy Policy
- PostHog — product analytics, unless you turn analytics off. PostHog Privacy Policy
- Sentry — crash and performance reporting. Sentry Privacy Policy
- Google Play Billing (Android) and the Apple App Store (iOS) — purchase processing. Google Privacy Policy · Apple Privacy Policy
- Google Sign-In and Sign in with Apple — optional authentication. We use only your email address to identify your account; we do not store your name or profile photo.
- OpenRouter and the model provider it routes to (currently Google Gemini) — only when you use the built-in AI companion. OpenRouter Privacy Policy
- AI providers you connect yourself (Anthropic, OpenAI, or your choice) — only if you supply your own key; governed by that provider's policy.
- Content sources you choose (Google Drive, Dropbox, OneDrive, Readwise, Audiobookshelf, LibriVox, dictionary/translation services) — each used only when you enable the corresponding feature.
11. What We Don't Do
- We do not sell or rent your personal data.
- We do not show advertising, work with advertising networks, or share your data with data brokers.
- We do not track you across other companies' apps or websites.
- We do not use your books, highlights, notes, or AI conversations to train AI models.
- We do not upload your book or audiobook files to our servers.
- We do not record your screen or capture your keystrokes.
12. Data Retention & Deletion
- Local data is removed when you delete the item in the app, clear the app's data, or uninstall RookReader.
- Cloud-synced data (if you use an account) is retained while your account is active.
- You can delete your account and all associated synced data from inside the app: open Settings and scroll to the bottom, where Delete account sits below Sign out. This removes your server-side record — synced position, annotations, catalog, stats, settings, and uploaded covers. Your book files stay on your device, since they were never ours to delete.
- If you cannot reach the in-app option, contact us at epoch.feedback@gmail.com and we will delete your account and synced reading data within 30 days of confirming your request.
13. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate account data.
- Delete your account and all synced data, from within the app.
- Turn off analytics collection at any time in Settings.
- Disconnect any connected service (AI key, cloud drive, Readwise, Audiobookshelf) from within the app at any time.
- Use the app fully offline, without an account.
14. Children's Privacy
RookReader is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date above and, where appropriate, via an in-app notice. Continued use of RookReader after changes constitutes your acceptance of the updated policy.
16. Contact Us
If you have any questions about this Privacy Policy, please contact us at epoch.feedback@gmail.com.