- We keep what the app needs to work: your account, your place in each book, your saves and highlights, and a record of how you use the app.
- Our analytics are our own. The app does not use a third-party analytics service, does not read your advertising identifier, and does not track you across other companies' apps or websites.
- We do not sell your personal data.
- You can delete your account inside the app. That deletes everything we hold about that account.
- This policy describes the app as it is today. If we add something that changes what we collect or who receives it, such as ads or purchases, we will update this policy before that change reaches you.
Who we are
Read Bro is made by Ameya Sahasrabudhe, an individual based in Bengaluru, Karnataka, India. In this policy, "we" and "us" mean Ameya Sahasrabudhe, who is responsible for the personal data described here (the data controller, or data fiduciary under India's Digital Personal Data Protection Act).
Questions, requests and complaints go to readbro@foxnutstudios.com. Ameya Sahasrabudhe is also the grievance contact for India, at the same address.
What we collect
Your account
You can read without signing in. When you finish the first-run questions, the app makes a guest account on our server. What we store then depends on how you use the app.
- Guest account. Keyed by an identifier that Apple gives our apps on your device. If Apple does not give one, the app makes a random one instead. It is not your device's advertising identifier and it is not shared with anyone. A guest account has no name and no email address.
- Sign in with Apple. Apple gives us a stable account identifier and, if you choose to share them, your email address (or an Apple private relay address) and your name. We also keep a token from Apple so that we can ask Apple to revoke Read Bro's access when you delete your account.
- Sign in with Google. Google gives us a stable account identifier, your email address and your name.
- Email. Your email address and your password. We store only a one-way hash of the password, never the password itself. Email verification codes and password-reset codes are stored only as hashes, can be used once, and expire.
For every account we also keep an optional display name, your time zone and language setting, which sign-in method you use, whether you finished the first-run questions, when the account was created, and which version of a feature you were shown when we test two versions of something.
What you do in the app
- Your reading. Which books you open, where you are in each one, the chapters and books you finish, your daily goal and your streak, including any grace day or pause.
- What you keep. Books you save, passages you highlight, and your answers to the first-run questions about what you like to read.
- Usage events. A fixed list of in-app actions, such as opening the app, viewing and finishing a screen of a book, seeing and tapping a recommendation, searching, saving, highlighting and using a streak pause. Each event carries the time, your time zone, the app version, a session identifier, the book, chapter or screen it is about, and the version of any feature test you were shown. Our server rejects any event that is not on the list.
- Searches. A search event records how many characters you typed and how many books were found, never the words. The words go to our server only to find the books. Our server does not store or log them.
- Define. When you look up a word, we record that a definition was opened, whether your dictionary had the word, and how long the word was, never the word itself. The definition comes from the dictionary on your iPhone.
- Share cards. When you share a passage, we record that a card was made and which style you chose, never the passage.
- Reminders. Reminders are scheduled on your phone. We record whether you allowed them, which reminders are scheduled and at what hour, and when you open one, never the text of your notifications.
- Recommendations. Which books we showed you, and any "more like this" or "not for me" feedback, so we can pick better books.
What we do not collect today
- Location, contacts, camera, microphone, health or financial data.
- Your advertising identifier, or any data used to track you across other companies' apps or websites.
- Payment details. The app has no purchases or subscriptions at present.
- Crash reports sent to a third party.
- Your photos. If you save a share card, iOS asks your permission to add that one image to your photo library. The app never reads your photo library.
- Your IP address. Our server uses it briefly, in scrambled form and only in memory, to limit repeated sign-in attempts, and then discards it. Our hosting provider may keep it in its network logs for a short time for security.
If a future version needs any of these, we will update this policy first and, where the law or Apple requires it, ask for your permission in the app before we collect it.
How we use it
- To run the app: sign you in, keep your place in every book, and keep your saves, highlights and streak.
- To choose books for you. Recommendations use your first-run answers, your reading and your saves. Tap the reason shown on a recommended book to see why it was picked.
- To count your streak by your own midnight, using your time zone.
- To understand and improve the app, from our own analytics, including testing two versions of a feature.
- To send email verification codes and password-reset emails, if you use email sign-in. We do not send marketing email today. If we ever do, you will be able to say no, and we will send it only where the law allows.
We do not make decisions about you that have legal or similarly significant effects. We use your data because you asked us to provide the app (to run your account and your reading) and, for analytics, because improving the app is a legitimate interest that does not override your rights.
Who else handles it
We do not sell or rent your personal data. These service providers process it for us, only to run the app:
| Provider | What they do |
|---|---|
| Railway | Hosts our servers and database, where everything above is stored. |
| Resend | Delivers email verification codes and password-reset emails. They receive your email address and the message. |
| Apple, Google | Confirm who you are when you choose to sign in with them. |
| Google Search | Only if you tap Search the web in Define: the word opens as a Google search in your browser, under Google's own privacy policy. |
These providers may store data outside the country you live in, including outside India. We may also disclose data when the law requires it.
If we add a provider, for example to show ads, take payments or report crashes, we will add it to this list and update this policy before it receives any of your data. We will not let any provider use your data to track you across other companies' apps or websites unless you give permission in the app first, as Apple requires.
How long we keep it
- Your account and everything linked to it, including usage events, is kept until you delete your account. Deleting it removes all of it at once.
- A guest account that you can no longer open, because you signed out as a guest or deleted the app, stays on our server. It holds no name or email address.
- If our hosting provider keeps backups of the database, data you delete can remain in those backups until they expire, and is then gone. Backups are used only to restore the service.
- Server logs contain a request identifier, never your name, email, password or sign-in tokens.
Deleting your account
In the app, open the You tab, tap the settings gear, then Account, Delete account, and confirm with Delete. Guests can do this too. You do not need to contact us.
Deletion is immediate and complete. We sign you out on every device, then permanently delete your account and everything linked to it: your sign-in details, preferences and first-run answers, reading progress, saves, highlights, streak, usage events and recommendation history. We keep nothing personal. Our logs record that an account was deleted, with a scrambled identifier that cannot be traced back to you. Emails we already sent may stay in our email provider's delivery logs for a limited time.
If you signed in with Apple, we also ask Apple to revoke Read Bro's access to your Apple ID.
Your rights
Depending on where you live, including under India's Digital Personal Data Protection Act and the GDPR, you may have the right to access, correct, delete or get a copy of your data, to withdraw consent, to nominate someone to act for you, and to complain to a data protection authority. Delete your account in the app at any time, or write to readbro@foxnutstudios.com for anything else. We answer every request.
Age
Read Bro is for people aged 16 and over. It is not directed at children, and some of the classics in it deal frankly with adult themes. If you believe someone under 16 has given us personal data, write to us and we will delete it.
Security
All traffic between the app and our servers is encrypted with HTTPS. Your sign-in tokens are kept in your iPhone's Keychain. On our server, session tokens, passwords and email codes are stored only as one-way hashes. The one exception is the token Apple gives us when you sign in with Apple: we keep it only so that we can ask Apple to revoke it when you delete your account, and we never log it or send it anywhere else.
Changes to this policy
We will update this policy when the app changes what it collects, how it uses data, or who receives it. We will change the date at the top of this page each time. If a change affects data you already gave us, or adds a new kind of data or a new provider, we will tell you in the app before it applies and, where the law requires it, ask for your consent.
Contact
Ameya Sahasrabudhe, Bengaluru, Karnataka, India. Email readbro@foxnutstudios.com.