1. Scope
This Privacy Policy applies to the Bookora Android application, Bookora account and online features, and the public website at bookora-reader.com. In this Policy, “Bookora,” “we,” “us,” and “our” refer to the controller identified below.
Feature availability may differ by app version, country, device, or account status. A cloud feature processes data only when it is available to you and you choose to use it.
2. Privacy at a Glance
- Imported EPUB and FB2 files and ordinary reading data stay on your device by default. Bookora does not automatically upload an entire book to its servers or to an AI provider.
- The Bookora Android app requires a Bookora account and successful sign-in. Google sign-in or email-and-password sign-in creates and maintains your account and session in the service database.
- Bookora Voice generates speech on the Android device. The relevant book text and generated audio are not sent to Bookora's servers for speech generation.
- When you intentionally use an AI tool, Bookora sends only the question, selected text, and relevant reading context needed for that request to OpenAI through a protected connection.
- Bookora does not sell personal data and does not use advertising, third-party product analytics, or third-party crash-reporting SDKs in the current Android release.
Who is responsible
3. Controller and Contact Details
Data controller: Bookora.
Privacy and support contact: bookora.assistance@hotmail.com
Privacy Policy: https://bookora-reader.com/privacy-policy
Terms of Use: https://bookora-reader.com/terms-of-use
Account deletion: https://bookora-reader.com/delete_account
4. Data We Process
4.1 Books and reading data stored locally
Bookora may store the EPUB or FB2 file you select, parsed text and structure, title, author, cover, file reference, search or pagination cache, reading and narration position, bookmarks, quotes, highlights, language, reader appearance, voice settings, and related state needed to open, display, search, and narrate the book. Because you choose the content, it may contain personal or sensitive information.
This data is stored in Bookora's app storage and is not saved in the Bookora database. Android backup or device transfer may copy eligible app data according to your Android and device-provider settings; that is not Bookora cloud synchronization.
4.2 Account and authentication data
The Bookora Android app has no guest mode. A Bookora account and successful sign-in are required to use the app. Bookora and its authentication service process your email address, internal account ID, sign-in method, profile, session information, sign-in dates, and security logs.
With Google sign-in, Bookora may receive your Google account identifier, email address, display name, and profile-image URL. Bookora does not receive your Google password. With email-and-password sign-in, the authentication service handles password verification, email confirmation, and password reset. Bookora does not store your password in readable form.
4.3 Narration
Bookora Voice: speech generation runs on your Android device. The relevant book text and generated audio are not sent to Bookora's servers for speech generation.
4.4 AI reading tools
When an AI feature is available and you intentionally use it, Bookora may send OpenAI your question, selected text, and the relevant part of the book needed to answer. Bookora does not automatically send the entire book. Avoid including sensitive information that is not needed.
Bookora also keeps the AI response, sources, time, request status, and credit use so the feature can work, duplicate charges can be prevented, and errors can be investigated. Bookora does not allow OpenAI to use this information to train its models.
4.5 Google Play subscriptions, purchases, and AI credits
Google Play processes your payment method and displays the localized price and tax before confirmation. Bookora does not receive or store your full payment-card details. To verify purchases and grant access, Bookora may process purchase and order references, purchase dates, subscription status, renewals, cancellations, refunds, country and currency, access status, and AI-credit history.
Prices, trial terms, credit allowances, and the cost of each AI action are shown in Bookora and Google Play before the relevant purchase or use. Google Play's checkout price controls the amount charged. Purchase verification information is treated as confidential and is not included in support messages or public logs.
4.6 Device access, notifications, and network access
Bookora uses Android's file picker to access only a book you select. It may request notification permission and show narration controls while a book is being read aloud. Internet access is used for sign-in, purchase verification, AI requests, and public pages when those features are used. Bookora does not request microphone permission in the current release.
4.7 Technical error reports
Bookora may collect limited technical information to find and fix problems with sign-in, adding books, narration, storage, and the app. Reports are accepted only from a signed-in Bookora account.
A report may include the type of problem, the app version, basic device information, and the time of the error. It does not include book content, filenames, AI requests, passwords, payment details, or advertising and hardware identifiers. Ordinary internet connection problems are not collected.
Errors that happen before sign-in stay on the device and may be sent only after a successful sign-in. Reports are not moved between accounts.
4.8 Support and deletion requests
The website support form sends your email address, description, time, and delivery metadata through FormSubmit to Bookora's Microsoft-hosted support mailbox. A deletion request is instead prepared for the email service you choose, and you review and send it from your own mailbox so account ownership can be verified. Bookora does not automatically attach books, reading history, or hidden diagnostics. Do not send passwords, full card details, payment confirmations, book files, or identity documents unless we explain why they are necessary and provide a secure method.
4.9 Website and security data
Website hosting and security providers may process IP address, browser and device type, requested URL, time, response status, and error or security logs. Cloudflare may set the strictly necessary __cf_bm cookie to distinguish automated traffic and protect the site. Bookora does not use advertising or analytics cookies.
5. Purposes, Necessity, and Legal Bases
- Contract: to provide reading, narration, account, AI, purchase, credit, and support functions you request.
- Legitimate interests: to secure the service, prevent fraud and duplicate credit grants, troubleshoot failures, protect legal rights, and maintain reliable operations, after balancing those interests against your rights.
- Legal obligation: to keep or disclose records required by tax, accounting, consumer, court, or other applicable law.
- Consent: only for optional processing where consent is legally required. You may withdraw it without affecting processing already carried out lawfully.
A Bookora account is necessary to use the Android application. Billing data is necessary to verify a purchase; the selected text and context are necessary only when you request the relevant AI or narration feature.
6. Service Providers and Recipients
- Supabase provides authentication, database, account, entitlement, and security services. See its privacy notice and Data Processing Addendum.
- Google provides Google sign-in, Google Play billing and verification, and may provide Android backup. See the Google Privacy Policy.
- OpenAI processes the text and context needed for an AI request through a protected connection. See OpenAI data controls and the OpenAI Privacy Policy.
- FormSubmit delivers public support-form messages. See the FormSubmit Privacy Policy.
- Microsoft hosts Bookora's support mailbox. See the Microsoft Privacy Statement.
- Cloudflare and website hosting providers deliver and protect the public site. See the Cloudflare Privacy Policy and Cloudflare cookie information.
Authorities, courts, professional advisers, or transaction counterparties may receive limited data when legally required or necessary to establish, exercise, or defend legal claims. Bookora does not sell personal data or disclose it to data brokers.
7. Advertising, Analytics, and Crash Reporting
As of the effective date, Bookora's Android app has no advertising SDK, third-party product-analytics SDK, or third-party crash-reporting SDK. Imported book content, filenames, questions, and reading history are not used for advertising or marketing profiles. Bookora may operate the limited technical error reports described in Section 4.7 to troubleshoot the Service; those records are not used for advertising, behavioural marketing, or reading-interest profiles. Any future third-party analytics or crash-reporting addition will be disclosed before or when it becomes active, with consent where required.
8. International Transfers
Bookora is operated from Cyprus. Providers may process data in the EEA and other countries. Where GDPR applies to a transfer outside the EEA, Bookora relies on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard as applicable. Contact us for information about safeguards relevant to your data.
9. Retention
Bookora uses the following retention periods or criteria:
| Data category | Retention approach |
|---|---|
| Books and reading data stored on your device | Until you delete the book or related item, clear Bookora app data, or uninstall the app. Android backup or device-transfer copies follow the lifecycle selected in your Android or backup-provider settings. |
| Account, profile, sessions, access, and AI-credit balance | While your account is active and until a verified deletion request is completed. Any remaining backup copies are replaced on the service provider's normal schedule and are not used to recreate a deleted account. |
| Authentication and security logs | Normally no more than 90 days, unless a specific security incident, abuse investigation, or legal obligation requires a documented longer hold. |
| Technical error reports | When collected in a compatible Android release, no more than 90 days. These records are also deleted when the linked Bookora account is deleted. |
| AI requests and usage | Bookora keeps only the information needed to provide the AI feature, show credit use, avoid duplicate charges, and fix errors. This information is deleted with your account unless it is part of a billing record that must be kept. OpenAI may keep information sent to it for up to 30 days by default unless the law requires longer. |
| Google Play purchase verification | Encrypted purchase proof is kept while a subscription is active or a payment must be checked, and for no more than 180 days after the subscription ends or the payment is reversed. A separate billing reference may remain in the payment history. |
| Billing and refund history | Kept for six years after the end of the calendar year in which the payment or refund happened. For example, a record from 2026 is kept until January 1, 2033. Direct account details are removed when the account is deleted. A record may be kept longer only while a legal dispute or investigation is open. |
| Support correspondence | Messages delivered to Bookora's support mailbox are normally kept for 12 months after the last substantive response. A message may be kept longer only for an unresolved request, security incident, dispute, or legal obligation. FormSubmit handles website-form delivery under its own privacy notice. |
| Website request and security logs | Normally up to 30 days, unless a specific security incident requires a documented longer hold. Cloudflare's strictly necessary bot-management cookie normally expires after about 30 minutes of inactivity. |
If a legal dispute or investigation is open, only the necessary record may be kept longer. It is deleted or permanently anonymized within 30 days after the matter ends if its normal retention period has expired.
10. Security
Bookora encrypts data in transit, limits access to account information, protects payment-verification records, and keeps local book content separate from account data. No security measure can guarantee absolute security.
11. Your Rights and Choices
Depending on applicable law, you may request access, correction, deletion, restriction, or portability; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. Lawful exceptions may apply.
Send a request to bookora.assistance@hotmail.com. We may request information reasonably necessary to verify the account. We normally respond to a GDPR request within one month, subject to the extensions permitted by law.
12. Account Deletion
You can request deletion from Profile > Delete accountin Bookora or from the public account-deletion page. After verification, Bookora deletes your account, active sessions, profile, access to features, AI-credit balance, and ordinary linked AI information and technical error reports.
Bookora keeps a limited billing history for six years as described in Section 9. Your direct account details are removed from it when the account is deleted. This record cannot restore your account and is not used for marketing or reading profiles.
Encrypted Google Play purchase proof is kept while a subscription is active or a payment must be checked, and for no more than 180 days after it ends. A separate reference may remain in the payment history. If a tax audit or payment dispute is open, only the necessary record is kept until the matter is resolved.
Account deletion does not delete books or reading data stored locally. Delete individual books, clear Bookora's Android app storage, or uninstall the app to remove local data. It also does not cancel a Google Play subscription; cancel separately in Google Play. It does not delete your Google account or information Google processes independently.
See how to delete your account13. Age Requirement
Bookora is for users aged 16 or older. A person under 16 must not create an account, use Bookora's online services, make a purchase, submit content to AI, or send a support request. Bookora does not currently request a date of birth, so a parent or guardian who believes a person under 16 provided personal data should contact us. We will investigate and delete the data where required.
14. Automated Decision-Making
Bookora does not use personal data for solely automated decisions that produce legal or similarly significant effects. AI responses assist reading; they do not determine eligibility, pricing, employment, credit, health, legal rights, or access to essential services.
15. Third-Party Services and Links
Google Play, Google sign-in, and external links may also process data independently under their own notices. Bookora's Terms of Use govern the Service, purchases, user-provided books, AI features, and credits.
16. Changes to this Policy
We may update this Policy when features, providers, retention practices, or legal duties change. The current version and effective date will be posted at the canonical URL. We will provide an appropriate notice before a material change takes effect where required.
Questions, requests or complaints
17. Contact and Complaints
Contact Bookora at bookora.assistance@hotmail.com.
Cyprus supervisory authority: Office of the Commissioner for Personal Data Protection. See its contact page. You may also contact the competent authority where you live or work.
Do not send passwords, full payment-card details, book files, payment confirmations, or identity documents unless we explain why they are necessary and provide a secure process.