Skip to content

Privacy Policy

Flateight (the operator) handles information in BookReader as described below. Local book storage and cloud reading information are separate. The information handled depends on the features you use.

1. Operator and contact

The operator is Flateight. Contact the email address below about information handling or requests to access, correct, stop using or delete your information. We verify identity to the extent needed and respond under applicable law. Do not attach passwords, authentication tokens or book files to your request.

2. Information stored on your device

Book files, titles, authors, matching identifiers, reading positions, bookmarks, history, settings and catalog records are stored in your browser using IndexedDB, OPFS and LocalStorage. Service Worker and Cache Storage store app files for offline PWA use.

Local EPUB and image archive files are not uploaded to the operator’s sync server for reading or reading sync. Normal reading does not change the original book on your device or in Google Drive.

3. Google sign-in

Google/Firebase Authentication provides sign-in. The app handles your account identifier, display name, email address and authentication state for account display and authentication. The operator does not obtain your Google password.

When syncing, a Firebase authentication token is sent to the sync server and verified to associate records with your account identifier. Google’s policies also apply to information handled by its authentication services.

4. Reading from Google Drive

When you choose Open from Google Drive, the app uses Google authorization and Google Picker. It checks the selected file’s ID, name, size, format and download permissions, and retrieves the book directly from Google into your browser. The book is saved in your device’s library.

The requested scope is drive.file. Google’s permission includes editing selected files, but the current app only reads metadata and content. It does not collect your entire Drive. Drive access tokens remain in memory for the operation and are not saved in settings or on the sync server.

Google API information is used only to provide visible features such as reading, book management and sync that you enable. BookReader follows the Google API Services User Data Policy, including Limited Use requirements. This information is not used for advertising, data sales, credit assessment or training AI models. Human access is limited to purposes allowed by that policy, such as support you specifically authorize, necessary security measures or legal requirements.

5. Reading information sync

If you enable sync, the app sends book IDs, titles, authors, matching fingerprints, progress, text positions or image indices, reading preferences such as font size, and bookmark positions, labels, timestamps, device identifiers, colors and deletion records. This supports resuming reading, matching books and merging bookmarks across devices.

The default service uses Cloudflare Workers and a database. Reading sync excludes book text, image content and excerpts. Titles and bookmark labels can reveal reading interests or personal information. Web-novel positions may contain identifiers such as the work URL.

6. Catalog and optional destinations

Catalog records are stored locally. If you explicitly enable catalog sync, series, titles, authors, volumes, editions, providers, formats, service IDs, permitted work URLs, purchase or loan status, access periods, progress, completion history and update/deletion records are sent to your account’s sync destination. This does not include book files.

If you configure another cloud service or custom sync destination, sync information may be sent there. Review that provider’s terms and privacy settings. Catalog JSON/CSV exports and reading-log copying or sharing pass information to the destination you choose.

7. Diagnostics, web novels and network requests

Some archive parsing or image loading errors automatically send filenames, archive names or formats, error messages and stack traces. The diagnostics server stores filenames, error messages, stack traces, browser information and timestamps for investigation and fixes. Archive entry names or errors may reveal titles or paths. These reports are separate from transferring book files.

Web-novel search and retrieval send search terms or work URLs to the source site or retrieval proxy. Text may be retrieved directly or through that proxy.

App delivery, library loading, sign-in and API requests contact Google/Firebase, Cloudflare, hosting providers and CDNs. These services may process IP addresses, request URLs, timestamps and browser information. The current app does not include advertising or Google Analytics tracking code.

8. Purposes and service providers

Information is used for sign-in, reading, storage, sync, catalog management, sharing, troubleshooting, preventing abuse and responding to requests. We do not sell personal information or Google API information or provide it for advertising.

Google/Firebase, Cloudflare and other providers support these features. Information can also be sent to destinations you choose or provided where legally required. Processing may occur outside Japan depending on provider locations and agreements. Refer to each provider’s policies for its own processing.

9. Retention, deletion and disconnecting

You can remove local information through library deletion or browser site-data controls. Clearing site data also removes books, records, settings and offline caches, so export what you need first. Signing out or disabling sync does not delete local or cloud records.

Cloud reading and catalog records are retained while needed to provide the features. The current service does not automatically delete records after inactivity. Deletions shown in the app may retain sync deletion records. Email the contact below to request deletion or cessation of use of your account’s cloud information. After verifying identity, we delete or stop using it except where retention is required by law or justified security needs.

Diagnostics are kept while needed for investigation or security. There is currently no automatic diagnostics expiry. Backup and provider-log deletion timing depends on their storage and agreements and may differ from primary storage.

You can revoke the app’s access in your Google Account’s third-party connections. Revocation does not delete downloaded books or sync records. The app does not delete your Google Account.

10. Security

The public site uses HTTPS for authentication, sync and Drive retrieval. The sync server verifies tokens and separates account records. Browser storage manages local information. Protect your device, manage shared devices and keep your own backups.

Cloud sync is not end-to-end encrypted with a key held only by you. It is not technically inaccessible to the operator. Access is limited to what is needed for service delivery, security and support.

11. Information in support requests

Names, email addresses, messages and support history received through email are used to respond, verify identity, investigate issues and handle rights requests. Send only needed information. Before sending a book file or text for investigation, ensure you have the right to share it and discuss it with support first.

12. Policy changes

We update this page and its date when this policy changes. Material changes to purposes or Google information handling are notified before the new use, and consent is obtained where required by law or Google policy.