Privacy Policy
This Privacy Policy explains what personal information ZephRead processes, why it is processed, when it is disclosed, how long it is kept, and the choices available to you.
1. Who we are and how to contact us
ZephRead is an independently operated software project and is responsible for the personal information described in this policy. This policy covers Zeph Read for Windows, zephread.com, ZephRead account and cloud services, and support or privacy correspondence.
Questions, privacy requests, and complaints may be sent to contact@zephread.com. Please do not send passwords, access tokens, payment-card details, books, or confidential documents with a request. We may need to verify your identity before acting on a request.
2. Privacy at a glance
The following points summarize the most important boundaries. The rest of this policy provides the details.
- Local reading does not require an account or an upload.
- Cloud sync is off until you enable it, and only content you select for sync is uploaded.
- ZephRead does not sell personal information, share it for cross-context behavioral advertising, or use private reading content to train generative AI models.
- Cloud content is private to your account, but it is not end-to-end encrypted.
- You can control sync, remove cloud content, export applicable account data, or request account deletion.
3. Scope and definitions
“Personal information” means information that identifies, relates to, or can reasonably be linked with a person or account. “Content” means files, library metadata, reading positions, highlights, notes, covers, and similar material you choose to store or sync. “Services” means the ZephRead software, website, account system, cloud API, private storage, and related communications.
This policy does not govern third-party websites, identity providers, or Microsoft Store services that you choose to use. Those services process information under their own privacy terms.
4. Information that stays on your device
Files imported for local reading, the local library database, reading positions, highlights, notes, covers, and settings are processed on your device. They do not leave the device merely because you open or read a file.
Language and appearance preferences on zephread.com are stored in browser local storage. Windows account sessions and one-time sign-in state are stored using operating-system protected credential storage rather than ordinary browser storage or the reading database.
5. Account and identity information
If you create or use a ZephRead account, Supabase Auth processes your email address, password verifier, optional Google sign-in identifier, authentication method, session and security metadata, and account-confirmation or recovery events. ZephRead receives the verified identity needed to create an internal ZephRead user ID and does not receive your plaintext password.
We also process the account’s policy-acceptance version and timestamp, account status, device registrations, plan and quota state, and security events needed to prevent unauthorized access. Account and cloud services require an 18-or-older self-attestation; we do not collect a birth date or identity document solely for this age check.
6. Optional cloud-sync information
If you explicitly enable cloud sync and select content, ZephRead processes the selected files, content hashes, sizes, file format, library metadata, custom titles or covers, reading positions, highlights, notes, deletion records, sync revisions, device identifiers, and transfer status needed to synchronize that content.
Files are stored in private Cloudflare R2 storage. Account, quota, device, entitlement, and sync metadata are stored in Cloudflare D1. Cloud resources require authenticated authorization and are not exposed through public links. ZephRead currently provides no public sharing feature.
7. Website, device, diagnostic, and security information
When you use the website or network services, ZephRead and Cloudflare may process IP address, approximate region derived from IP, requested URL, timestamp, browser or app version, operating system, device category, network outcome, and security signals. The app may also send safe error codes, performance or crash signals, quota and rate-limit counters, file-format category, size bucket, and sync success or failure.
Operational logging is designed to exclude book body text, highlight or note text, filenames used merely for analytics, passwords, access or refresh tokens, payment-card details, and private document content. ZephRead does not currently load third-party advertising pixels or behavioral analytics on the website. Cloudflare may use strictly necessary security cookies or similar signals during abuse detection or a challenge; the Cookie Policy explains the current website storage.
8. Purchase and membership information
Microsoft Store processes payment credentials, billing address, taxes, and the purchase transaction under Microsoft’s terms. ZephRead receives only the product, Store source, purchase or transaction reference, entitlement state, start and expiry dates, grace status, verification status, and refund or revocation events needed to provide account-level membership.
ZephRead does not receive or store full payment-card numbers. Provider transaction facts are separated from the ZephRead-account binding. Provider references are stored as one-way hashes and, only where a Store server API requires later lookup, as an application-encrypted server-side reference.
9. Support and communications
If you contact us, we process your email address, message, attachments, and standard message metadata to respond, provide support, handle privacy or legal requests, and prevent abuse. If we send account confirmation, recovery, security, service, or policy notices, we process the delivery information required for that communication.
10. Where information comes from
We obtain information from you, from the ZephRead app or website when you use them, from Supabase or Google when you authenticate, from Microsoft when a Store transaction is verified, and from Cloudflare when it provides hosting, security, email, database, or storage services.
11. Why we process information and our legal bases
We process personal information only for defined purposes and, where applicable law requires a legal basis, rely on the bases described below.
- Contract or requested steps: create and secure your account, synchronize selected content, provide membership benefits, deliver support, and process deletion requests.
- Legitimate interests: protect users and the Services, prevent fraud and abuse, diagnose failures, enforce quotas and terms, and improve reliability using minimized information.
- Legal obligation: comply with valid legal process, accounting or consumer obligations, and establish or defend legal claims.
- Consent: enable optional sync or another optional activity where consent is required. You may withdraw consent, but prior lawful processing and processing needed on another basis are unaffected.
12. When we disclose information
We disclose only what is reasonably necessary to service providers acting for us: Cloudflare for website delivery, API, D1 database, private R2 storage, email, and security; Supabase for authentication; Microsoft for Store distribution, billing, and entitlement verification; and Google for optional sign-in. These providers process information under their own agreements and security obligations.
We may also disclose limited information when you direct us to, to professional advisers bound by confidentiality, to comply with valid legal process, to protect rights or safety, or as part of a merger, financing, reorganization, or transfer of the project or its assets. Where required, we will give notice and require the recipient to respect applicable privacy obligations.
13. Private content, no sale, and no advertising use
ZephRead does not sell personal information or private content, does not share personal information for cross-context behavioral advertising, and does not serve targeted advertising. We do not use private books, document text, highlights, or notes to train generative AI models.
Cloud content is private to the account and is not routinely inspected. Because v1 is not end-to-end encrypted, authorized service infrastructure can technically process cloud content to provide sync, recover from failures, investigate security incidents, respond to a support request you make, or comply with law. Access is limited to what is necessary for those purposes.
14. International processing
ZephRead’s providers operate infrastructure in multiple countries. Personal information may therefore be processed outside the country where you live, where privacy laws may differ. When applicable law requires it, we use provider commitments, contractual protections, adequacy decisions, or another lawful transfer mechanism.
15. Retention and deletion
Retention depends on the type of information and why it is needed.
- Local data remains on your device until you remove it through the app or operating system.
- Active cloud content and account metadata remain while needed to provide the account and sync service. Deleted cloud files normally remain in a recycle state for 7 days.
- After paid access expires, cloud data exceeding Free limits is retained for 30 days before Free limits are enforced. Local copies are not remotely deleted.
- An accepted account-deletion request has an exact 7-day recovery period. Finalization then removes account-owned cloud content and business data, the Store-account binding, and the Supabase Auth identity.
- A minimized keyed identity blocker remains for 90 days after account deletion so disaster recovery cannot restore the deleted account. It contains no email, book content, or profile.
- Unbound Store transaction facts may remain while lifecycle events can still arrive and, after terminal status, for up to 24 months by default for fraud prevention, accounting, and Store dispute handling.
- Support correspondence is normally retained no longer than 24 months unless a longer period is required for an active issue or legal obligation. Website preferences remain until you change them or clear browser data.
16. Security
ZephRead uses HTTPS, private storage, per-resource authorization, rate and size limits, content-minimized logs, and platform-backed credential storage. Access credentials and server secrets are not embedded in public client code. We review service boundaries and use recovery controls intended to prevent deleted accounts from reappearing after a database restoration.
No method of storage or transmission is completely secure, and ZephRead cannot guarantee absolute security. Cloud sync is not end-to-end encrypted. Keep independent copies of important files and annotations, protect your device and Microsoft or ZephRead credentials, and contact us if you suspect unauthorized access.
17. Your choices and privacy rights
You may read locally without an account, leave sync disabled, choose which files are synchronized, remove devices, delete cloud files, manage the Microsoft Store subscription, export applicable account data, or request account deletion. Deleting a ZephRead account does not cancel a Microsoft Store subscription.
Depending on where you live, you may have rights to know, access, correct, delete, obtain a portable copy of, restrict, or object to processing; withdraw consent; use an authorized agent; and appeal or complain to a privacy or data-protection authority. We will not discriminate against you for exercising a privacy right. Rights can be limited where necessary to protect another person, provide a service you requested, prevent fraud, or comply with law.
18. Age limitation
Local reading does not require an account. ZephRead accounts, cloud services, and paid membership are intended only for people age 18 or older. If we learn that an ineligible person created an account, we may suspend cloud access and delete the account subject to appropriate safeguards and applicable law.
19. Changes to this policy
We may update this policy when the product, providers, law, or data practices change. We will post the current version and updated date on this page. If a change materially affects your rights or how existing account data is used, we will provide additional notice through the app, website, or account email where reasonably practicable before the change takes effect.
20. Contact and complaints
Email contact@zephread.com with “Privacy request” in the subject line. Describe the right or issue without attaching private reading files or credentials. We aim to review genuine requests within 30 days and will respond within any shorter or longer period required by applicable law. You may also complain to the privacy regulator or consumer authority available in your jurisdiction.