Privacy Policy
ReadEden works without an Account. In that case, your reading journal stays on your phone and is not stored on our servers. Selected catalogue and recommendation requests may still contain the information described below. If you voluntarily create an Account, selected data is sent to the cloud. A copy of your reading journal is sent there only while Premium is active. This Policy explains what we use, why we use it and how you can control it.
1. Controller and contact details
The controller is Easy Life Sp. z o.o., registered at Hoża 51, 00-681 Warsaw, Poland, KRS 0000716356, NIP 1182164729 and REGON 369376133 ("ReadEden", "we", "us").
For privacy matters, email [email protected] or write to the address above, marked "ReadEden - privacy".
2. Scope
This Policy covers the ReadEden mobile Application, optional Accounts, sync, Premium and the public pages at readeden.com.
3. Data we use
Journal without an Account
Books, sessions, progress, notes, goals, achievements and settings are stored locally on your phone. Without an Account, we do not upload the complete journal to the cloud for storage. The exception is information needed for a search or recommendation request that you initiate, as described below. You can remove local data in Settings, by uninstalling the Application or by clearing its data.
Account and sync
We process your email address, Account identifier, technical Account data and the reading data covered by sync. This can include books, sessions, progress, notes, goals, achievements and settings. We use it to maintain your Account, restore data and sync supported devices. In the EEA, the legal basis is performance of a contract under Article 6(1)(b) GDPR.
Shared catalogue and cover photos
Book information entered manually may help complete the shared ReadEden catalogue. If you select a cover photo, it remains private and does not enter the shared catalogue unless you give separate permission. You may voluntarily submit your own photograph of a book for review. The permission is separate and off by default.
Until a moderator makes a decision, the photo is kept in private storage and is available only to people authorised to moderate it. After approval, we process a reduced version of the photo, the related book information, the version of the licence you accepted and the date of acceptance. An approved photo may be visible to other users when a catalogue cover is missing. We do not display the contributor's email address or Account identifier with it.
While a photo is awaiting a decision, the moderator can see a shortened identifier of the contributor's Account together with the number of their previously accepted and rejected photos. This serves only to recognise repeated abuse. A single mistake looks different from repeatedly sending unsuitable content. The moderator does not see an email address at this point; contact details are available only to people administering the service, and only where this is necessary to deal with a case. Our basis is our legitimate interest in protecting the shared catalogue and the rights of others.
Content can be reported in the Application. When a report is made, we may process the entry identifier, the reporter's identifier, the reason for the report and information about the moderator's decision. We use this information to protect the shared catalogue, handle reports, prevent abuse and consider appeals. Our bases are performance of the agreement and our legitimate interests in keeping the service safe and protecting the rights of others.
Search and recommendations
When you search for a book, the selected catalogue receives your search phrase and technical connection data such as your IP address. For recommendations, we may send author names or genre names selected from a small number of books in your library. We do not add your email address or Account identifier. The data is used to perform the feature you request.
Premium and payments
Depending on your device and where you obtained the Application, payments are processed by Google Play or the Apple App Store. We do not receive your card or bank account details.
The Application asks the store from which it was obtained whether you have an active subscription. The purchase identifier and subscription status received for this purpose remain on your device. We do not send them to ReadEden servers or keep our own register of user purchases.
Separately, as the seller, we may receive billing information and sales reports from Google or Apple when needed for tax, accounting and complaint handling. This information comes to us from the store operator, not from the Application on your device. Our legal bases are performance of a contract and legal obligations, including tax and accounting obligations.
The public website at readeden.com
We do not use cookies, behavioural advertising analytics or tools that track you across unrelated services. We use local browser storage only for your chosen site language and session storage for the scroll position needed when switching languages. Cloudflare may process your IP address, request time, requested URL, browser type and other technical data needed to deliver and protect the site.
We measure visits with Cloudflare Web Analytics. It sets no cookies, creates no visitor identifier and does not track anyone across pages or visits. It collects data about the visit itself: the requested URL, the referring URL, an approximate country, the device and browser type, and page load timings. Your IP address is used only to derive the country at that moment and is not stored. We see the statistics in aggregate and they cannot be traced back to what a particular person did. The basis is our legitimate interest in learning which content is read and whether the site is fast enough.
Launch notification signup
If you leave your email address in the form on the home page, we store it for one purpose only: to write to you once when the Application launches. We send nothing else to that address. Resend receives the address in a message delivered to ReadEden so that we can be notified of the new signup. The basis is your consent (Article 6(1)(a) GDPR), which you may withdraw at any time by writing to [email protected] - we then remove the address from the list. Addresses are kept until the launch message is sent, and no longer than one year from signup.
Messages and complaints
When you contact us or submit a publisher brief, we process the information in your message or form to respond, prepare a collaboration proposal, handle a complaint, fulfil a data request or establish and defend legal claims. The content of a publisher brief is sent by email to a ReadEden address and stays there. We do not store it in any database on our side. Depending on the matter, the basis is taking steps before entering into a contract, a contract, a legal obligation or our legitimate interest.
4. Service providers and recipients
We do not sell personal data or reading history, and we do not share it for behavioural advertising. We use providers required for selected features:
- Supabase provides Accounts, database, sync, private and approved cover photo storage, and Account deletion. The main project database is configured in the Ireland region (European Union).
- Cloudflare delivers and protects readeden.com, receives the publisher brief form and measures site visits (Cloudflare Web Analytics). Its network operates globally.
- Resend sends publisher brief messages and notifications about new launch signups to our address. It receives the information contained in the relevant message solely in order to deliver it. The provider operates in the United States.
- Google may distribute the Application and processes Google Play payments.
- Apple may distribute the Application and process payments in the Apple App Store.
- Open Library and the National Library of Poland provide bibliographic data. Open Library also provides URLs for available cover thumbnails and may receive a request used to prepare recommendations.
Public authorities may receive data where applicable law requires it.
5. International data transfers
Some providers operate outside Poland and the European Economic Area. Where GDPR applies, we use a transfer mechanism permitted by law, such as an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses. You can contact us for information about current safeguards.
6. Affiliate links and external sites
When you click a bookshop link, you leave ReadEden. The external site applies its own privacy rules and may set its own cookies. We do not send it your journal or Account data. The link may contain an affiliate identifier that lets a purchase be attributed to ReadEden. We use the BUY.BOX affiliate network.
The “Where to buy” screen in the Application fetches bookshop offers from the BUY.BOX network. The Application sends it the ISBN of the book you are viewing, or its title and author when no ISBN is known. This happens when you open that screen, before you click any offer.
The request contains no name, e-mail address, Account identifier or journal content. We also keep no record of which books were queried. BUY.BOX does receive the query and your IP address, on the same basis as any website you visit.
7. Retention
- We keep Account data while you use the Account. We keep the cloud copy of your reading journal for as long as it is being updated. If a copy has not been updated for 12 months, we delete it, and we send a notice to the address linked to your Account one month beforehand. The journal on your device is left untouched, and you can export it to a file at any time in the app settings.
- We keep a photo awaiting review until a decision is made, you withdraw it or the Account is deleted. A rejected photo is deleted.
- We keep an approved cover photo until it is removed by the user or ReadEden, or following a justified request from a rights holder. When you delete your Account, approved photos are deleted by default. You may expressly choose to leave approved photos in the catalogue. In that case, we detach them from the Account and keep only the reduced image, the version of the licence you accepted and the date of acceptance.
- After a verified deletion request, we remove data from active systems without undue delay, normally within 30 days.
- Backups remain until overwritten under the provider's rolling schedule. If a backup containing deleted data is restored after a failure, we repeat the deletion.
- We retain accounting data for the period required by tax and accounting law.
- We retain correspondence, complaints and security records until the matter ends and then until the relevant limitation period expires, unless law requires longer retention.
8. Your rights
Depending on where you live and the legal basis, you may have rights to access, obtain a copy, correct, delete, restrict, port or object to the use of personal data. Where processing relies on consent, you may withdraw it without affecting earlier processing.
- Export: Settings → Export data.
- Delete Account: Settings → Delete Account or Delete your account and data. During deletion, you can decide whether approved cover photos should also be removed. They are selected for deletion by default.
- Other requests: email [email protected] or use the postal address in section 1. We may reasonably verify your identity.
If GDPR applies, you may complain to a supervisory authority in the country of your habitual residence, place of work or the alleged infringement. In Poland, this is the President of the Personal Data Protection Office.
Laws in some US states and other countries may provide additional rights. If they apply to ReadEden and your situation, we will honour them after receiving a verifiable request. We do not discriminate against people who exercise privacy rights.
9. Automated decisions
Recommendations do not make decisions that produce legal or similarly significant effects. They are suggestions based on authors and genres. You can switch them off or choose not to use them.
10. Age
ReadEden is intended for people aged 16 or over. We do not ask for your full date of birth, but we require confirmation that you are at least 16. If local law requires parental or guardian permission for an Account or the processing of a minor's data, do not create an Account without that permission.
If we learn that an Account belongs to someone under 16, we may delete it and the related data.
11. Security
We use technical and organisational measures appropriate to the data, including access controls, encrypted connections and data minimisation. No system can guarantee complete security. If an incident occurs, we will provide notices required by law.
12. Changes to this Policy
If a change materially affects how we use data, we will notify you in the Application or by email before it takes effect. Minor corrections may be published on this page. The current version and date appear at the top.
ReadEden