This policy explains what the BookReader app collects, why, who it is shared with, and the choices you have. It applies to the BookReader Android application and this website.
The short version: your books and documents stay on your device. You can use the app without an account. If you choose to sign in, we sync only reading data — book titles, progress, highlights, notes, stats and settings — not the files themselves, unless you explicitly turn on cloud backup.
1. Who we are
BookReader (“we”, “us”) is the developer and publisher of the BookReader Android app. For any privacy question, request or complaint, contact us at hello@bookreader24.com.
2. Your files stay on your device
BookReader is an offline-first reader. The PDF, Word, EPUB, text and HTML files you open are read directly from your device’s storage. They are not uploaded, scanned or copied to our servers as part of normal use. The app requests storage access solely so it can open the documents you select.
Two exceptions, both under your control, are described in sections 3.6 (cloud backup of files) and 3.7 (AI features).
3. What we collect
3.1 Using the app without an account
You can install and use BookReader without signing in. In that mode we do not create a user record for you. The app still uses analytics, crash reporting and advertising, described below, which do not identify you by name or email.
3.2 Account information (only if you sign in)
Signing in is optional and is offered from the Profile tab. It uses Google Sign-In through Firebase Authentication. When you sign in, we receive and store:
- your email address;
- your display name;
- your profile photo URL, if your Google account has one;
- an identifier from the authentication provider, linked to an internal account ID we generate.
We never receive or store your Google password.
3.3 Reading data we sync
If you are signed in, the following syncs across your devices:
| Category | Examples |
|---|---|
| Library metadata | Book title, author, file name, format, page or word count, a content fingerprint of the file, date added |
| Reading progress | Current page or position, percentage complete, last-read time |
| Annotations | Highlights, bookmarks and notes you create, including the text you highlighted or typed |
| Reading activity | Minutes read per day, documents read, current and best streaks, daily goal |
| Preferences | Theme, font size and style, line and letter spacing, text alignment, read-aloud voice and speed |
| Reminder settings | Display name for stats, whether reminders are on, reminder time and days |
| Devices | A device identifier the app generates, platform, and when that device last synced |
Note that highlights and notes contain excerpts of your documents that you chose to save. If a document is sensitive, do not highlight or annotate it while signed in.
3.4 Analytics and crash reports
We use Google Analytics for Firebase and Firebase Crashlytics to understand which features are used and to diagnose crashes. These collect app usage events, a randomly generated app instance identifier, device model, operating system version, language, approximate region derived from IP address, and — when the app crashes — a stack trace and device state at the time. They do not collect the contents of your documents.
3.5 Advertising
The app shows banner ads supplied by Google AdMob. To serve and measure ads, Google may collect your device’s advertising identifier, IP address, ad interactions and general device information. See section 6 for your choices and section 5 for Google’s own policies.
If you are in the European Economic Area, the United Kingdom or Switzerland, the app shows a consent form (Google’s User Messaging Platform) before personalised ads are used, and records your choice.
3.6 Optional cloud backup of book files
Book files are kept on your device by default. If you explicitly enable cloud backup for a book, that file is uploaded to our object storage (Amazon S3) so you can restore it on another device. Uploads happen only for books you choose to back up, transfers use encrypted connections, and you can delete backed-up files from within the app.
3.7 AI features
If you use the app’s AI assistant, the text you type and the excerpt or document context needed to answer your request are sent to Amazon Bedrock (Amazon Nova) to generate a response. We also keep a usage record for each request — the model used, token counts, response time and outcome — to enforce fair-use limits and for accounting. That record does not store the content of your prompt. If you never use the AI features, no document text is sent for AI processing.
3.8 Read-aloud and dictionary
Read-aloud uses the text-to-speech engine installed on your device; the text spoken is processed by that engine according to its own settings, and playback continues in the background through a notification you can dismiss. Language detection for dictionary lookups runs on-device using Google ML Kit and does not send text to us.
4. Device permissions and why we ask
| Permission | Why the app needs it |
|---|---|
| Internet, network state | Sync, ads, analytics, AI features and update checks |
| Storage / all files access | To find and open the documents you want to read. The app reads documents only — it does not request access to your photos, videos or audio |
| Notifications | Reading reminders you configure and the read-aloud playback notification |
| Foreground service (media playback) | To keep read-aloud playing when the app is in the background |
5. Who we share information with
We do not sell your personal information. We share data only with the service providers that make the app work:
- Google — Firebase Authentication, Analytics, Crashlytics, AdMob, Google Play services (in-app review and updates). See the Google Privacy Policy and how Google uses data from apps that use its services.
- Amazon Web Services — Amazon Bedrock for AI responses and Amazon S3 for optional file backup. See the AWS Privacy Notice.
- MongoDB Atlas — the database that stores your synced reading data. See the MongoDB Privacy Policy.
We may also disclose information where required by law, or to protect the rights, safety and property of our users or ourselves.
6. Your choices
- Do not sign in. The reader works fully offline without an account, and nothing is synced.
- Ads. You can reset or delete your advertising ID in Android Settings → Privacy → Ads, which limits ad personalisation across all apps. Where a consent form was shown, you can change your choice from the app’s settings.
- Notifications. Turn reminders off in the app, or revoke the notification permission in Android settings.
- Cloud backup. Leave it off to keep every file on your device only.
- AI features. Simply do not use them if you prefer no document text to leave your device.
7. Deleting your data
You can delete your account and its synced data from the Profile section of the app. Deletion removes your account record, library metadata, progress, annotations, activity history, settings and any files you backed up. You can also delete only the synced data and keep your account. Step-by-step instructions, and a table of exactly what each option removes, are on our account and data deletion page. You can also email hello@bookreader24.com and we will action the request within 30 days.
Deleting the app from your device removes the local library and reading data stored on it. Backups made by Android’s own backup service are governed by your Google account settings.
8. How long we keep data
Synced reading data is kept while your account is active and is removed when you delete your account. Analytics and crash data are retained for the periods set by Firebase (typically up to 14 months for analytics events and 90 days for crash reports). AI usage records are kept as an accounting ledger. Backup copies may persist for a short period after deletion before being overwritten.
9. Security
Data in transit is protected with TLS. Access to our backend requires a verified sign-in token, and each request is checked so that you can only read and write your own data. File backups are transferred using short-lived, single-purpose links. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.
10. Children
BookReader is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
11. International transfers
Our service providers operate globally, so your information may be processed in countries other than your own, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
12. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of California may request details of the categories of information collected and disclosed, and may opt out of the sharing of personal information for cross-context behavioural advertising through the ad controls described in section 6. To exercise any right, email hello@bookreader24.com. You also have the right to complain to your local data protection authority.
13. Changes to this policy
We may update this policy as the app changes. The revised version will be posted at this address with a new “last updated” date, and material changes will be highlighted in the app.
14. Contact
BookReader
Email: hello@bookreader24.com