CalibReader Privacy Policy
Plain-language summary
CalibReader is built privacy-first. We have no servers and no backend. We do not collect, store, transmit, sell, or share any personal data. We run no analytics, advertising, tracking, or crash-reporting. Everything happens on your device and, if you choose, directly between your device and your own cloud-storage account. We never see your books, your reading activity, or your account.
If you connect a cloud account (Dropbox, Google Drive, or OneDrive), the app needs read and write access to the one library folder you choose. The write access exists for a single purpose: saving two small sync files (your reading positions and your read / unread status) back into that folder, so your progress follows you across devices. The app never modifies, deletes, renames, moves, or uploads your book files, and never touches anything outside the folder you select. Full detail is in Section 4.
This policy explains exactly what the app does with data so you (and the App Store / Google Play review teams) can verify the above.
1. Who we are (Data Controller)
CalibReader is provided by Gram 1 LLC ("we", "us"). Because the app collects no personal data on any server, we act as a data controller only in the narrow sense described below. For data held in your cloud account (Dropbox, Google Drive, OneDrive), that provider is the controller and their privacy policy governs it.
- Contact: privacy@calibreader.com
- Website: https://calibreader.com
2. What we do NOT collect
We do not collect or have access to any of the following:
- Names, emails, phone numbers, or account identifiers (beyond what your chosen cloud provider shows to your own device during sign-in).
- Your books, their contents, titles, or what, when, or how long you read.
- Device identifiers, advertising IDs, location, contacts, or usage analytics.
- Crash logs or telemetry.
There is no account to create with us, no login to us, and no data sent to us. The app contains no analytics, advertising, tracking, or crash-reporting SDKs.
3. Data stored on your device (only)
To function, the app stores the following locally on your device, never transmitted to us:
- Your library cache: book files and metadata you sync, kept in a folder you choose.
- App settings: theme, fonts, margins, sort and filter preferences, reading positions and read-status.
- Cloud access tokens: if you connect a cloud provider, the OAuth tokens are kept in the operating system's secure storage (iOS Keychain / Android Keystore-backed encrypted storage). They never leave your device except to talk to that provider directly.
- Trial and purchase state: see Section 7.
You can erase all of this at any time by clearing the app's data or uninstalling it.
4. Cloud storage access (Dropbox / Google Drive / OneDrive)
Connecting a cloud account is optional (you can use a purely local folder instead). When you connect one, the connection is directly between your device and your provider; it does not pass through us.
What we read: the contents of the library folder you select, so the app can download and display your books and covers on your device.
What we write, and why the app asks for "edit" permission: the app's only write activity is saving two small JSON files into your library folder:
CalibReader_positions.json: your reading positions, so they follow you across devices.CalibReader_sync.json: your read / unread status, for the same reason.
That is the entire purpose of the edit/write permission: two-way sync of your reading progress and read-status. The app never modifies, deletes, renames, moves, or uploads your book files, and never touches any folder outside the library folder you selected. (Some providers, like Dropbox, phrase this on their consent screen as "edit content of your files and folders" because that is the closest scope they offer; in CalibReader it is used solely for the two sync files above.)
Revoking access: you can disconnect at any time inside the app, and revoke the app entirely from your provider's connected-apps settings (Dropbox: Connected apps; Google Account: Security, Third-party access; Microsoft account: Apps and services). Revoking immediately invalidates the on-device tokens.
5. Third-party services we touch (only when you act)
| Service | When | What is sent | What we receive |
|---|---|---|---|
| Your cloud provider (Dropbox / Google Drive / OneDrive) | Only after you connect it | OAuth sign-in and requests to your selected folder | Your books, plus the right to write the two sync files above |
| Open Library and Google Books (cover lookup) | When generating a share card or fetching a missing cover | A book's title and author, or ISBN | A public cover image. No personal identifiers are sent. |
| Apple App Store / Google Play (purchases) | When you start a trial or buy the one-time upgrade | Handled entirely by Apple and Google | Only a yes or no entitlement; we never see your payment details |
| Your OS share sheet | When you share a book card | You choose the recipient or app | Only the rendered card image is shared, never the book file |
Each third party's own privacy policy governs data you provide to them.
6. Permissions we request (and why)
- Storage / All-files access (Android) / file access (iOS): to read your local Calibre library folder and save your downloaded books plus the two sync files. We do not scan or access unrelated files.
- Network: to talk to your chosen cloud provider and to fetch public book covers. The app makes no other network calls.
7. Purchases, trial, and entitlement
CalibReader offers a free trial and a one-time paid upgrade. Billing, receipts, and refunds are handled entirely by Apple and Google. We receive only an anonymous entitlement (purchased or not purchased). The trial-start marker is stored on-device (and, on iOS, in the Keychain; on Android, via the platform's encrypted backup) purely to enforce the trial; it contains no personal data and is not sent to us.
8. Children's privacy
CalibReader is not directed at children and does not knowingly collect any data from anyone, including children under 13 (or 16 in the EU). Because we collect no personal data at all, there is nothing for us to delete on request; on-device data is controlled by the device owner.
9. Data retention
We retain no personal data, because we hold none. On-device data persists only on your device and only until you clear the app's data or uninstall it. Data in your cloud account is retained per your provider's policy and your own control.
10. Your rights (GDPR, UK GDPR, CCPA/CPRA, and similar)
You have rights to access, correct, delete, port, and restrict processing of your personal data, and to object to processing. Because we do not hold any of your personal data on any server, there is nothing for us to retrieve, correct, or erase on your behalf. You exercise these rights directly:
- On-device data: clear the app's data or uninstall the app.
- Cloud data: manage it in your provider's account and revoke the app's access (Section 4). For that data, your provider is the controller.
We do not "sell" or "share" personal information as defined by the CCPA/CPRA (we have none to sell or share). If you believe we hold personal data about you and wish to make a request or complaint, contact us at the address in Section 1; EU and UK users may also complain to their local data protection authority.
11. International users and data transfers
The app stores data on your device and communicates only with your chosen cloud provider and the public cover services. Any cross-border transfer of your cloud data is governed by your provider, not by us.
12. Security
Cloud tokens are stored in the operating system's secure keystore. Network communication with cloud providers and cover services uses HTTPS/TLS. Because no data is sent to or held by us, there is no central store of your data to breach.
13. Changes to this policy
If we change this policy, we will update the "Effective date" above and post the new version at https://calibreader.com/privacy. Material changes will be surfaced in-app or in the store listing.
14. Contact
Questions about this policy or your privacy: privacy@calibreader.com.