Privacy Policy
Effective September 11, 2026
PhonoLeaf ("the app", "we", "our") turns epub books stored in your Google Drive into read-aloud audio, on your own device. This policy explains what data the app touches, why, and — just as importantly — what it never does.
The short version
Your books never leave your device. They go straight from your Google Drive to your phone, and the voice that reads them is generated on the phone itself, so we never receive, see or store a single one of your books — and there is no arrangement under which we could. PhonoLeaf also offers an optional backup of a small record of your reading, so that replacing your phone does not lose your place in every book. That backup holds titles, authors, reading positions and listening time. It never holds a book. You can turn it off in Settings, which also deletes what has been stored. If you turn it on, Friends shows the people you invite what you are listening to. Everything the app sends anywhere is listed below.
"Does PhonoLeaf store my data or not?"
Both things are true at once, and the distinction is simply
where:
the app does save things — your reading position, listening
stats, settings and cached book covers — and all of it is written to
your own device, the same way a browser saves a bookmark.
Your books are never sent to us. PhonoLeaf also offers an
optional backup, which keeps titles, authors, reading positions and
listening time so that replacing your phone does not lose your place in
every book. It never keeps a book, and you can turn it off in Settings, which also deletes what has been stored. Friends, if you turn it on, and everything else the app sends are described below. That is also why you can export or erase everything yourself from
Settings, without asking us and without waiting — see
Your rights over your data below.
What the app accesses, and why
| Data | Why | Where it goes |
| Google Drive access (read-only) | To list and download the epub files in the folder you choose | Directly between your device and Google — never through us |
| Your Google display name | For the greeting on the Home screen, and, if you use Friends, so the people you chose can see who you are | Stored on your device. Also stored on our server once you use Friends |
| What you are listening to, if you share it | So the people you chose can see where you are in your books | Shown only to people connected to you through an invite code, only while sharing is on, never for a book you hid |
| Book titles/authors | To look up genre and page-count metadata | Sent to Open Library (openlibrary.org), a public, third-party book database — no personal or account data is included |
| Reading progress, stats, settings, voice choice | So the app remembers your place and preferences | Stored on your device. Also copied to your backup, if you have backup turned on |
| Your books themselves | They are yours; the app only reads them aloud | Never sent anywhere. They travel from your Drive to your device and stop there |
| Your phone's model and speed score | To learn which voices work well on which phones | Sent once per install, with no account or identifier of any kind attached |
| Your subscription | So the app knows whether you have paid access | Kept on our server under an identifier derived from your sign-in. The payment itself is handled by Google Play or the App Store |
| Book covers | Cached so they don't re-download every time | Stored on your device only |
Google Drive access, specifically
PhonoLeaf requests read-only access to Google Drive (the drive.readonly scope). This is a broad, Google-classified "restricted" scope — broader than the app strictly needs for the one folder you connect — chosen because it's the only way to support "connect a folder once, new books appear automatically" without you re-selecting files every time. Because of that scope, PhonoLeaf is required to go through Google's own app verification process; see Google's own explanation of what that review covers at support.google.com/cloud/answer/13463737.
The app never modifies, deletes, or uploads anything to your Drive. It only lists and downloads the epub files inside the one folder you pick.
Limited Use commitment
PhonoLeaf's use and transfer of information received from Google APIs to any other app will adhere to the
Google API Services User Data Policy, including the
Limited Use requirements. Specifically: Google user data is used only to provide the user-facing reading features described on this page. It is never transferred to anyone except as the features you have turned on require: your own backup, held under an identifier derived from your sign-in and readable by nobody else; and, only if you use Friends, the title, author and your progress for books you have not hidden, and the details of any book you recommend, shown only to people connected to you through an invite code. It is never sold, and never used for advertising, ad targeting or credit assessment. No one at PhonoLeaf reads it. It is never used to train any AI or machine-learning model.
Friends, and what you share
Friends is optional and off until you turn it on. Nothing in this section happens unless you do. Friends works through your backup, so it needs backup to be on.
- Who can see you. Only people you give your invite code to can follow you. There is no directory, no search and no list of suggested people, so nobody can find you any other way. You can remove any follower, and get a new code so the old one stops working.
- What they see, while sharing is on. Your name as it appears on your Google account, the book you are listening to, its author, how far along you are, how long you have listened to it, and when you last listened. Nothing else from your library, your account or your device.
- What they never see. The contents of any book. Any book you have hidden: each book's page has a "Hide from friends" switch. Your email address or any other account detail.
- Likes and replies. You can like a friend's progress and answer it with a reply chosen from a short fixed list. You cannot type a message, and neither can they. The person you reacted to sees your name and your reply. Their other friends see only how many likes there are, never who gave them.
- Recommendations. If you recommend a book to a friend, they receive its title, author and ISBN, with your name.
- If you follow someone, they see your name in their list of followers, even if you have not turned sharing on yourself.
- Your name on our server. It is stored only once you use Friends, by turning sharing on or following someone, and it is kept up to date from your Google account while you use the feature. It is never stored for anyone who does not use Friends.
- Turning it off. Turning sharing off stops the people who follow you from seeing your reading. Turning backup off, or using Delete my data, erases everything Friends holds on our server and removes you from other people's lists.
Measuring what your phone can do
We measure what your phone can do, never what you read. Once per install, the app sends your phone's make, model, Android version and the score from a short speed test it already runs to choose your voice. Nothing else goes with it: no account, no identifier, nothing about your books or your reading. We use these reports to decide which voice to offer on which phones, and to publish combined results for each phone model. A single report cannot be linked back to you, because we store nothing that could link it.
Subscriptions
Subscriptions are bought through Google Play or the App Store, and paid to them. We never see your card or payment details. The store tells us whether your subscription is active, and we keep your plan, its status and its trial and renewal dates under the same identifier derived from your sign-in. When you follow someone using their code, we record that they invited you, so any referral reward goes to the right person. Gift codes are recorded the same way: who created each code, and who used it.
Where your data is kept, and for how long
- Where. Our server runs on Cloudflare. Its database is located in eastern North America, which may be outside Québec and outside Canada.
- How long. Your backup, and everything Friends holds, is kept until you turn backup off or use Delete my data, which erase it immediately. If you simply stop using PhonoLeaf, it stays, so you can pick up where you left off; you can erase it at any time.
- Payment records. The record of your subscription or Lifetime purchase is kept even after Delete my data, because it is the proof of what you paid for. It holds no book and nothing about your reading. A gift code that someone has already used is kept for the same reason.
- Phone reports carry no identifier, so they cannot be traced to you or deleted one by one. They are kept, combined by phone model.
- Your IP address. When the app contacts our server, the server uses your IP address for a moment to block abuse, such as too many requests from one place, and does not store it. Cloudflare, which runs the server, may keep ordinary request logs under its own privacy policy.
How we protect your data
- Encrypted in transit. Every connection the app makes — to Google, to our own server, to Open Library for book metadata, to download a natural-voice model — goes over HTTPS/TLS. Nothing the app sends or receives travels in plain text.
- Your Google sign-in is encrypted at rest on the Android app. The native app stores the long-lived authorization that keeps you signed in in the device's Android Keystore-backed encrypted storage (
EncryptedSharedPreferences), not in plain app storage. The web version uses a short-lived (~1 hour) access token instead of a long-lived one; it lives only in your own browser profile and is never transmitted anywhere except directly to Google.
- There is no store of your books to breach. Your books and the audio made from them exist only on your own device, so no server breach could ever expose them. If you use backup, what we hold is limited to titles, authors, reading positions and listening time, kept under an identifier derived from your Google sign-in rather than your email address. Your name is added only if you use Friends.
- A locked-down app. The app enforces a Content Security Policy that limits which sites it can ever load code from or send data to, to a short, explicit list (Google, Open Library, our own server, and the specific CDNs the natural-voice model needs). The core epub-reading code is bundled directly into the app rather than pulled from a third-party CDN at runtime, so a compromised CDN there has nothing to inject into.
- You control deletion, on your schedule. See Your rights over your data below for how to erase everything stored on your device, including revoking the app's access to your Google account, at any time.
What we never do
- We never send your books or their contents anywhere. Nothing you read is uploaded, and the audio is generated on your own device.
- We do not read, sell or rent what backup holds, we share it only as you choose through Friends, and we do not use it to build a profile of you. It exists so you can get your reading life back on a new phone.
- Nothing you share with Friends is shown to anyone outside the people connected to you through an invite code.
- We do not sell, rent, or share your data with advertisers or data brokers. There is no advertising in the app.
- We do not use your data to train any AI/ML model.
- The text-to-speech voice runs entirely on your device (or, as a fallback, through your device's own built-in voice engine). Book text is never sent to a cloud speech service.
Third parties the app talks to
Your device talks directly to a short, fixed list of external services:
- PhonoLeaf’s own server (hosted by Cloudflare): holds your backup and, if you use them, Friends and your subscription status, under an identifier derived from your sign-in rather than your email address. It never receives a book. It also receives the anonymous phone report described above.
- Google Play and the Apple App Store: if you subscribe, you buy and pay there, under their own terms and privacy policies. We never see your card or payment details.
- Google (accounts.google.com, googleapis.com) — sign-in and Drive access. Governed by Google's Privacy Policy.
- Open Library (openlibrary.org) — a free, public book-metadata API operated by the Internet Archive, used only to look up genre/page count from a title and author.
- jsDelivr / Hugging Face (cdn.jsdelivr.net, huggingface.co) — only if your device falls back to the in-browser neural voice model, this downloads the (non-personal) voice model files.
- PhonoLeaf’s own voice mirror (packs.phonoleaf.com) — when you download a voice, the app fetches the model files from our own storage, hosted by Cloudflare. Nothing about you or your books is sent with the request, and each file is checked against a recorded fingerprint, so a substituted or corrupted file is refused rather than used.
- GitHub (github.com) — the fallback source for those same voice files if our mirror is unavailable. Same files, same fingerprint check.
- Cloudflare Web Analytics (static.cloudflareinsights.com) — on our public website pages only, never inside the app. It counts page views without cookies and without building a profile of you.
Data stored on your device
Everything else — your reading progress, listening stats, theme choice, voice preference, and which folder you've connected — is stored locally in your browser's or app's own storage. Apart from the optional backup, which you can turn off in Settings, and Friends, if you turn it on, both described in this policy, it never leaves your device. Uninstalling the app, clearing site data, or using "Reset listening data" in Settings removes it.
Signing out
Signing out revokes the app's access to your Google account. On the native app, this also revokes the underlying Google authorization grant, not just the local session.
Your rights over your data
Almost everything is on your own device, so you can act on it directly, without asking us and without waiting:
- Access / portability. Settings → Export my data downloads everything the app has saved on this device as a readable JSON file: reading progress, listening stats, book metadata and settings. Sign-in tokens are deliberately excluded from the file, since a copy of one would give anyone holding it access to your Drive.
- Erasure. Settings → Delete my data erases all of it from this device — local storage, cached cover images, and any downloaded natural-voice models — and disconnects your Google account, revoking PhonoLeaf's access at Google. Your ebooks in Google Drive are not touched.
- Partial erasure. Stats → Reset listening data clears just your listening history and progress, leaving settings alone.
- Erasing the backup. Turning backup off in Settings deletes everything it holds, immediately, and Settings → Delete my data does the same before it erases the copy on your device. Neither touches your books in Google Drive.
- What our server holds. Your backup is a copy of what the app already shows you, so exporting from the app gives you its contents. To ask for a copy of anything our server holds about you, or to have it corrected, write to support@phonoleaf.com. We answer within 30 days.
If you have a question we can't answer through the app itself, contact us using the address below.
Children's privacy
PhonoLeaf is not intended for anyone under 14. We do not knowingly collect personal information from anyone under 14, and if we learn that we have, we delete it. We do not build profiles, serve advertising, or collect anything beyond what the backup and Friends described above hold.
Changes to this policy
If this policy changes in a way that affects what we collect or how we use it, we will tell you in the app before the change takes effect. The current version is always at this address, with its effective date.
Contact
Questions about this policy, or requests about your personal information: support@phonoleaf.com. The person responsible for the protection of personal information at PhonoLeaf is the person who runs it, reachable at the same address.