Privacy Policy
Summary. ReadAura has no user accounts, no advertising, and no behavioral tracking. Your books, reading logs, and statistics are stored locally on your device and are never uploaded automatically. They leave ReadAura only when you deliberately export and share them. The other data that leaves your device is the minimum needed to provide and manage Aura Plus (RevenueCat), report errors and measure limited release health (Sentry), and respond when you contact support. When you visit our website, Cloudflare processes the technical request data needed to deliver and protect it.
Who we are
ReadAura is developed and operated by Oleh Vasylyshyn, a sole proprietor (individual entrepreneur) established in Poland, NIP 9592087441, REGON 543109200 (the "developer", "we"), and the data controller for the processing described in this policy. Contact: support@olekraft.com.
Data stored on your device
Books, reading logs, progress, statistics, reminder settings, and app preferences are stored in a local database on your device. Book cover images are stored as separate local files on your device. We do not have access to this data, do not receive a copy of it, and cannot see, recover, or delete it for you.
Your device's operating system may include some local data in device backups and device-to-device transfers (Apple iCloud/device backup, Android Auto Backup). Coverage depends on platform settings and operating-system backup rules; book cover images are never included, and no backup or successful restore is guaranteed. Those backups are managed by Apple or Google under your device settings and their own privacy policies, not by us.
Library exports and startup recovery
From About & Support → Data, you can create a portable archive containing your books, reading logs, and available cover images. If ReadAura cannot start and a retry fails, it may instead offer a recovery database containing readable books and reading history. ReadAura creates these files locally and never uploads them automatically. You decide whether and where to share them through your device's system share sheet. ReadAura cannot import either file in this version.
Export files are stored temporarily in the app's cache. ReadAura removes files older than approximately 24 hours when it next creates an export or recovery archive, and your operating system may clear cached files sooner. A recovery database may contain private reading data. If you deliberately send one to support, we and our email service provider receive the attachment and use it only to investigate the startup problem or help you recover readable data. The attachment is retained and deleted with the related support correspondence as described below.
Website data
When you visit the ReadAura website, Cloudflare, our hosting, content-delivery, and security provider, processes technical request data such as your IP address, requested URL, timestamp, browser or user-agent information, and network and security metadata. This is necessary to deliver, cache, and protect the website. We do not use website analytics, advertising trackers, or non-essential cookies.
The website stores your selected theme and language locally in your browser so it can remember those choices. These functional preferences are not used for tracking and remain until you clear the site's stored data in your browser.
Purpose: delivering and securing the website and remembering settings you select. Legal basis (GDPR): legitimate interest, Art. 6(1)(f). Retention: browser preferences remain until you clear them; technical request data is retained only as needed for delivery and security under the applicable Cloudflare service settings.
Purchases
Payments for the optional Aura Plus subscription are processed entirely by Apple (App Store) or Google (Google Play). We never receive your name, billing address, or payment card details.
To retrieve the Aura Plus offering and subscription status, validate purchases, and keep paid access working (including after reinstalling the app), we use RevenueCat as our service provider. The RevenueCat SDK initializes when the app starts, including for users who have not made a purchase. It processes a randomly generated pseudonymous App User ID, first- and last-seen timestamps, and basic technical information such as platform, OS version, app version, and locale. If you purchase or restore Aura Plus, it also processes the applicable purchase receipt or token, transaction history, and subscription status. During ordinary app use, the identifier is not linked to your name, email address, or Diagnostic ID, because ReadAura has no accounts. It is shown as the Purchase ID in the app under About & Support → Support Information. When available, ReadAura also prefills it in an in-app support email draft. You can review, edit, or remove it before sending. It becomes linked to your email address and support correspondence only if you choose to send the message.
RevenueCat also produces limited subscription metrics from these purchase and entitlement records, such as active subscriptions, renewals, refunds, plan period, and aggregate revenue trends. ReadAura does not send books, reading logs, screen activity, or general usage events to RevenueCat. We do not use these metrics for advertising, profiling, or automated decisions.
Purpose: determining whether free or paid access applies, presenting and managing Aura Plus, validating purchases, restoring paid features, and understanding the operation and sustainability of the subscription. Legal basis (GDPR): performing the free/paid service contract and taking steps you request before a subscription purchase, Art. 6(1)(b). The pseudonymous status check is necessary to determine the access level that applies to your installation. For the limited subscription metrics only, our legal basis is our legitimate interest in understanding subscription operation and sustainability, Art. 6(1)(f). Retention: purchase and entitlement records are kept as long as needed to maintain your access and to comply with legal obligations.
Crash reports, diagnostics, and release health
When the app starts, our service provider Sentry, hosted in the European Union (Germany), automatically begins a limited technical session and ends it when the app closes. A session may include a random session identifier; the installation identifier described below; its start, update, and end times and duration; the app release and environment; the number of errors; and its outcome or status. We use this only to calculate crash-free sessions and installations, compare release reliability, understand how broadly a problem affects the installed base, and prioritise fixes. Automatic sessions do not record screens viewed, taps, features used, reading activity, or engagement.
When the app produces an error or crash, it also sends a diagnostic report. A report may include technical error details and a stack trace; app, runtime, operating-system, and device technical context; app language; timestamp; event and trace identifiers; loaded module versions; and recent technical breadcrumbs such as app lifecycle, navigation, touch, or network events preceding the error.
Each report also carries a randomly generated installation identifier, shown as the Diagnostic ID in the app under About & Support → Support Information. It is created on first run and stored inside the app's sandbox. It lets us distinguish repeated errors on one installation from a defect affecting many installations, and lets you identify your diagnostic records if you request access to or deletion of them. The value is not linked to your name, email address, purchase, or RevenueCat identifier during ordinary app use. When available, ReadAura prefills it in an in-app support email draft. You can review, edit, or remove it before sending. It becomes linked to your email address, Purchase ID, and support correspondence only if you choose to send the message, so we can locate the relevant records. Reinstalling the app normally replaces it with a new value, although an operating-system device backup may carry it forward.
Reports do not include your books, reading logs, cover images, other content you create, screenshots, screen contents, text entered or displayed in controls, or page titles. As with any network request, your IP address is processed transiently for delivery; Sentry may use network information to derive approximate location context.
You can turn diagnostics off in the app under About & Support → Support Information. Diagnostics are on by default. When they are off, the app stops sending new diagnostic reports and stops the automatic technical sessions described above; the change applies in full the next time you open the app. Turning diagnostics off does not delete reports we have already received — to request their deletion, email us and include your Diagnostic ID. It also does not remove the Diagnostic ID stored locally or prevent ReadAura from showing it or prefilling it in a support email draft. When diagnostics are off, we will not receive new crash reports or technical session information from your app. This can make it harder for us to identify and fix a problem you experience.
Purpose: maintaining stability and security, measuring limited release health, understanding the overall severity of defects, and prioritising fixes. We do not use Sentry for feature-popularity analytics, reading analytics, advertising, profiling, or automated decisions. Legal basis (GDPR): legitimate interest, Art. 6(1)(f). Retention: session and diagnostic data are retained for a limited period (approximately 30 days) and then deleted.
Support email
If you contact us, we receive your email address and the message you choose to send. If you use the in-app support option, ReadAura prefills a diagnostic block containing the Diagnostic ID and Purchase ID when available, app version and build, platform, OS version, device model, device type and idiom, app language, and an error reference when one is available. Your email app shows this information before sending, so you can review, edit, or remove it. Opening the draft does not send anything; the information reaches us and our email service provider only if you choose to send the message. If ReadAura cannot open a mail app, it shows the support email address and available IDs locally so you can copy them. Showing or copying those values does not send them. A library export or recovery database is never attached automatically; you must select and address the file yourself through the system share sheet.
Support correspondence sent to support@olekraft.com is handled through our email service provider acting on our instructions under a data processing agreement. We use it only to respond to your request. Legal basis (GDPR): legitimate interest, Art. 6(1)(f). Retention: support correspondence and any export or recovery attachment are deleted no later than 24 months after the last message, unless a legal claim requires longer retention.
App permissions
- Camera and photo library (optional): used only to add book cover images. Images are stored locally on your device and are never uploaded.
- Notifications (optional): reading reminders are scheduled locally on your device; no data is sent anywhere.
- Network access: used only for purchase validation and crash reporting as described above. All core reading features work offline.
What information is required
None of the information described in this policy is required by law. RevenueCat's pseudonymous identifier and basic technical information are processed automatically when the app starts and are necessary to retrieve and manage Aura Plus; if that processing is unavailable, subscription offers, status, purchases, and restoration may not work. Purchase information is processed only if you purchase or restore Aura Plus.
An error report is sent automatically when the app produces an error or crash, unless you turn diagnostics off in the app. Core reading features do not depend on a report being delivered, but without diagnostics we may be unable to identify and fix the defect. Contacting support and sending the optional diagnostic block are voluntary. ReadAura may prefill available IDs and technical details, but you can review, edit, or remove them before sending. Creating and sharing a library export or recovery database is also voluntary. If you do not provide a return address or enough information about the problem, we may be unable to respond or investigate it. Technical request data is necessary to load and protect the website. Saving the theme or language you select is optional, and you can remove those preferences using your browser controls.
Data sharing
We do not sell personal data, do not share it for advertising, and do not use general-purpose behavioral analytics, reading-activity analytics, or advertising SDKs. Personal data is disclosed only to the service providers named above and to people working on our behalf under confidentiality obligations. RevenueCat, Sentry, and Cloudflare act on our instructions under data processing agreements; our support email service provider handles correspondence and any attachment you deliberately submit on our instructions. Data may also be disclosed to Apple or Google as independent controllers of your purchase, or where disclosure is required by law. We do not "sell" or "share" personal information as those terms are defined in the California Consumer Privacy Act. We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
International transfers
Sentry event data is stored in the European Union (Germany). Sentry may process or allow access to personal data from the United States or other non-EEA locations; applicable transfers are protected by the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses under its data processing agreement. RevenueCat is based in the United States; transfers to it are protected by appropriate safeguards, including the European Commission's Standard Contractual Clauses incorporated in its data processing agreement. Cloudflare may process website request data in the United States and other locations; its Data Processing Addendum provides the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses as transfer mechanisms. Support correspondence may be processed outside the European Economic Area under the email provider's data processing agreement and, where required, Standard Contractual Clauses. You may contact us to request information about the safeguards applicable to a transfer.
Sources of personal data
We receive app and website technical data directly from your device, app, or browser. Apple or Google supplies purchase and entitlement information through RevenueCat when applicable. Sentry may derive approximate location context from network information. Support information comes from the email, available IDs and diagnostic details prefilled in a draft, and any export or recovery attachment you deliberately choose to send. Drafted or locally displayed information reaches us only if you send it.
Data retention and deletion
Local data remains on your device until you delete it in the app or uninstall the app (copies may persist in your Apple or Google device backups under their retention rules). Export files in the app's cache are eligible for deletion after approximately 24 hours. Session and diagnostic data are deleted after approximately 30 days. Purchase records are kept as long as needed to maintain your entitlement and to comply with legal obligations. Support correspondence and deliberately submitted export or recovery attachments are deleted no later than 24 months after the last message, unless a legal claim requires longer retention. To request deletion of remotely processed data, email us; note that we cannot delete data held independently by Apple or Google.
Your rights
Where the GDPR or similar laws apply, you have the right to access, rectify, erase, restrict, object to the processing of, and receive a copy of your personal data, as well as the right to data portability where applicable. You also have the right to lodge a complaint with a data protection supervisory authority — the developer's lead authority is Poland's UODO (Urząd Ochrony Danych Osobowych), and you may also complain to the authority in the EU member state of your residence. To exercise these rights, contact us at the email above. You can object to future diagnostic processing yourself, without contacting us, by turning diagnostics off in the app under About & Support → Support Information. To identify diagnostic records associated with your installation, include the Diagnostic ID available in the app under About & Support → Support Information. Because your reading data is stored only on your device, you can access, correct, or delete it directly in the app at any time.
If you are in the United Kingdom or Switzerland, you have equivalent rights under the UK GDPR or the Swiss Federal Act on Data Protection, and may lodge a complaint with the UK Information Commissioner's Office (ICO) or the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Children
ReadAura is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the app or legal requirements change. The current version is always available at readaura.olekraft.com/privacy; material changes will be indicated by the date above and, where appropriate, notice in the app. We keep every earlier version of this policy on file and will provide the version in force on a given date on request.
Contact
Oleh VasylyshynNIP: 9592087441
REGON: 543109200
Marcina Kasprzaka 31 lok. 119
01-234 Warszawa, Poland
Telephone: +48 459 569 595
Email: support@olekraft.com