Privacy Policy
Effective date: June 21, 2026
RookReader ("we", "our", or "us") is a reader-first ebook, audiobook, and web-novel app developed by cosmiklore. RookReader is built to be local-first: your library, your books, your reading position, highlights, notes, and vocabulary live on your device by default. We collect as little as possible, we never sell your data, and we never use your reading content to train AI models. This Privacy Policy explains what is stored, what is optional, and where data goes when you choose to enable a connected feature. By using RookReader, you agree to the practices described here.
1. Data Stored Only On Your Device
The following is stored locally in RookReader's on-device database and never leaves your phone unless you explicitly enable cloud sync, backup, or an export feature described below:
- Your library & book files: The ebooks, audiobooks, PDFs, comics, and documents you import are copied into the app's private storage on your device. Their metadata (title, author, series, tags, cover, format) is stored locally.
- Reading position & mechanics: Your current chapter, scroll position, page, reading themes, and typography settings.
- Highlights, notes & bookmarks: Any annotations you create while reading.
- Vocabulary & learning data: Words you look up, your vocabulary deck, review schedules, and reading streaks.
- Reading DNA & statistics: Reading sessions, time read, finish rates, and goals — computed and stored on device.
- Web-novel follows & cached chapters: The RSS feeds you follow and chapter text cached for offline reading.
2. Account & Cloud Sync (Optional)
If you create an account and sign in, RookReader can sync your reading data across your devices. This is optional — the app is fully usable without an account. When signed in, we store:
- Account data: Your email address and authentication provider (email/password or Google Sign-In), managed by our backend provider Supabase.
- Reading position sync: Your current position in a book, keyed by a book "fingerprint" (a hash of the file name and size) rather than the file itself — so the same book syncs across devices without us ever receiving the book's contents.
- Highlights & bookmarks sync (Pro): For Pro users, your highlights, notes, and bookmarks sync across devices, also keyed by book fingerprint.
- Settings sync: Your reader and app preferences.
We do not upload your actual book files, audiobook files, or their full text to our servers. Sync covers your position and annotations, not your library's contents.
3. AI Reading Companion (Bring-Your-Own-Key)
RookReader's optional AI Reading Companion uses a bring-your-own-key model. When you connect a provider (such as Anthropic or OpenAI), you supply your own API key, which is stored in your device's secure storage. When you use an AI feature, the relevant book text and your question are sent directly from your device to the AI provider you chose, using your own key — it never passes through a RookReader server. Your use of that provider is governed by their privacy policy and terms. We do not log, store, or train on your AI conversations or the book content sent to the provider. If you do not connect a key, no reading content is sent anywhere.
4. Connected Sources & Lookups
Several features connect to third-party services only when you use them. Where a feature requires sign-in (e.g. cloud storage or a self-hosted server), your access tokens and credentials are kept in your device's encrypted secure storage, not in our database:
- Dictionary & Translation: Word definitions and translations are fetched from public, key-less services (dictionaryapi.dev, Wiktionary, and a Google translation endpoint). The selected word or passage is sent to those services to return a result.
- Importing books: When you import from a public catalog (e.g. Project Gutenberg, Standard Ebooks, OPDS), a direct URL, a self-hosted server (OPDS/WebDAV), or a cloud drive (Google Drive, Dropbox, OneDrive), RookReader connects to that source to download the file you selected. Cloud-drive connections use OAuth; we request only the access needed to list and download files you choose.
- Audiobooks: Streaming or downloading from LibriVox or a self-hosted Audiobookshelf server connects to those services. Audiobookshelf credentials are stored in secure storage on your device.
- Web novels: RookReader reads serials through their public RSS/Atom feeds. It does not scrape or bypass any site's access controls.
- Highlight export (optional): You can export your highlights to a file or, if you connect a Readwise account, to Readwise using a token you provide (stored in secure storage).
- Kindle import (optional): Importing a "My Clippings.txt" file is processed entirely on your device.
5. Purchases (RookReader Pro)
RookReader Pro is a one-time purchase unlocked through Google Play Billing. We do not collect or store your payment card or financial account details — those are handled by Google Play. To confirm your purchase, our server verifies the purchase token with the Google Play Developer API and records an entitlement flag (whether Pro is active) bound to your account. We also process refund/void notifications from Google Play so that Pro access reflects your current purchase status.
6. Notifications
Web-novel "new chapter" alerts are delivered as local notifications scheduled on your device. We do not use a push-notification server or Firebase for this, and no device push token is collected. You can disable notifications at any time from the app or your device settings.
7. Error & Diagnostic Data
If crash reporting is enabled in a given build, RookReader uses Sentry to collect anonymised crash reports and performance data to help us fix problems. These reports may include your device model, OS version, and app state at the time of an error. They do not include your book files, book text, highlights, AI conversations, or API keys.
8. Third-Party Services
Depending on the features you use, RookReader may interact with the following services, each governed by its own privacy policy:
- Supabase — account authentication and cloud sync. Supabase Privacy Policy
- Google Play Billing — purchase processing for RookReader Pro. Google Privacy Policy
- Google Sign-In — optional authentication. We receive your name, email, and profile photo only.
- AI providers (Anthropic, OpenAI, or your choice) — only if you connect your own key; governed by that provider's policy.
- Sentry — crash reporting, where enabled. Sentry Privacy Policy
- Content sources you choose (Google Drive, Dropbox, OneDrive, Readwise, Audiobookshelf, LibriVox, dictionary/translation services) — each used only when you enable the corresponding feature.
9. What We Don't Do
- We do not sell or rent your personal data.
- We do not show third-party advertising or share data with advertisers.
- We do not use your books, highlights, notes, or AI conversations to train AI models.
- We do not upload your book or audiobook files to our servers.
10. Data Retention & Deletion
- Local data is removed when you delete the item in the app, clear the app's data, or uninstall RookReader.
- Cloud-synced data (if you use an account) is retained while your account is active.
- To delete your account and all associated synced data, contact us at epoch.feedback@gmail.com. Upon confirmed deletion, your account and synced reading data will be permanently removed within 30 days.
11. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate account data.
- Request deletion of your account and all synced data.
- Disconnect any connected service (AI key, cloud drive, Readwise, Audiobookshelf) from within the app at any time.
- Use the app fully offline, without an account.
12. Children's Privacy
RookReader is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date above and, where appropriate, via an in-app notice. Continued use of RookReader after changes constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy, please contact us at epoch.feedback@gmail.com.