1. Scope and controller
This policy applies to the ReadTally Android application, the readtally.app website, ReadTally Cloud, direct .rtbook file sharing, and support and account-deletion flows operated by EasyProjects.
You can use the core reader and direct .rtbook file sharing without signing in. Google Sign-In, ReadTally Cloud, server-verified Premium access, and web account-data deletion are optional features.
2. Data we process
2.1 Local library and reading data
On your device, ReadTally may store imported EPUB, PDF, FB2, TXT and archive content; covers and book metadata; shelves; reading position, history, sessions, goals and statistics; bookmarks, highlights, notes and saved translations; reader preferences; notification schedules; widget state; a cached account profile; Premium status; and bounded diagnostic events. Android automatic app backup is disabled. Files you export or share are stored wherever you choose.
2.2 Google identity and ReadTally sessions
If you sign in, the app receives your Google subject identifier, email address, display name and profile-photo URL. The ReadTally authentication service verifies a Google ID token and processes the subject identifier and verified email. It derives a one-way account hash and issues a short-lived signed ReadTally session. Profile data is cached on your device; the verified email may also be used for an explicitly granted beta entitlement or a support report.
2.3 ReadTally Cloud storage and sync
When you enable or run cloud features, ReadTally may upload books, covers, library snapshots, shelves, notes, bookmarks, translations, reading progress, history and statistics to a private Cloudflare R2 bucket. Cloudflare D1 stores the account hash and object, upload, quota and ownership metadata such as object names, sizes, content types, timestamps and checksums. It also stores the last authenticated account activity time solely to apply the cloud-data retention period. Short-lived signed URLs let the app transfer files without receiving permanent R2 credentials.
2.4 Direct book-file sharing
When you choose Share, ReadTally creates a .rtbook archive locally and passes it to the Android system share sheet. It does not upload the archive, create a public link, or send the book file, title, authors, annotation, cover or other archive metadata to ReadTally or Cloudflare for this feature. The Android app, service and recipient you select may process or retain the file under their own practices. Share only files you have the right to distribute.
2.5 Premium purchases and entitlements
Google Play processes billing and payment details. ReadTally receives and stores purchase tokens and hashes, product identifiers, subscription state, trial status, entitlement dates, verification timestamps and the pseudonymous account hash. Google Play real-time notifications may be processed to keep Premium access current. ReadTally does not receive your full payment-card number.
2.6 Diagnostics, exports and support reports
ReadTally stores redacted and size-limited diagnostic events locally for up to 14 days or 5,000 events. Exports are created only when you request them. If you submit an in-app report, you choose a description and up to five screenshots or videos; the app also attaches a diagnostic ZIP. It includes technical events; the app version and build; Android release and SDK; device manufacturer, model and supported architectures; screen, memory, processor and app-storage indicators; active locale, theme and time zone; feature and Premium status snapshots; and information about the last opened book and related reading statistics, including title, author, format, file-name details, a hash of the original path, reading sessions, progress and page-navigation data. The ZIP also includes a bounded, de-identified history of recent completed reading sessions for investigating reading-time and speed calculations. That history contains session-relative timing, aggregate and interval reading durations and word estimates, interaction, lifecycle and visibility signals, book format, and reader layout settings such as font size, margins, line height, reading mode and viewport. Separately, it may include de-identified aggregate metric-quality totals across all stored completed sessions, such as counts of sessions and intervals, summed durations, calculation coverage, book-format and page-span source distributions, and recovery counts. These aggregates do not contain book or session identifiers, titles, text, locators, page identifiers or positions, file paths, custom font names, hashes, or absolute event timestamps. The detailed history also does not include book text, book IDs or titles, locators, page identifiers or positions, full file paths, custom font names, hashes, or absolute event timestamps. Full file paths are redacted. The report may include your signed-in email. Cloudflare validates the report in memory and sends it to ReadTally support by email; the body and attachments are not written to R2, D1 or KV. A random support-report identifier stored on the device is sent with the report; Cloudflare retains only its SHA-256 hash together with a network rate-limit signal, action, timestamp and counter to prevent abuse.
2.7 Product analytics
Product analytics is enabled by default and can be disabled in Settings → Data. Google Analytics for Firebase may process an app instance or device/advertising identifier, event time, app version, operating system, device model, language, IP-derived approximate location, referrer and campaign data. ReadTally sends coarse events about first use, imports, reader opens and active reading, Premium views, and purchase-flow results. It does not send book content, titles, authors, file paths, shelves, email, Google or book IDs, reading-session IDs, raw errors, or purchase tokens and hashes.
2.8 Website analytics
This website uses Cloudflare Web Analytics to understand aggregate visits, popular pages, referrers, countries, browsers, operating systems and page performance. Cloudflare states that Web Analytics does not use cookies, local storage or fingerprinting to track visitors across sites. ReadTally does not use this website analytics data to identify individual visitors.
2.9 Release email notifications
If you ask to be notified about the ReadTally release, we store your normalized email address, language, consent time, subscription status and a random unsubscribe token in Cloudflare D1. We use this data only to send one release message through Resend. You can unsubscribe using the link in that message. Subscription records may remain for a reasonable period after delivery or unsubscribe to document consent, prevent duplicate sending and honor suppression requests.
2.10 Device permissions and technical data
Depending on Android version and your choices, ReadTally may use file access to import or scan supported books, notification permission for local reminders, boot events to restore schedules, and a foreground data-sync service for cloud transfers. ReadTally and its infrastructure providers may also process IP address, request time, user agent, request identifiers and security logs when you use online features or this website. Google ML Kit may download language models; translation processing is designed to occur on the device.
3. How we use data
We use the data described above to:
- provide reading, library, annotation, translation, statistics, reminder and widget features;
- authenticate users and provide optional backup, sync and restore;
- verify purchases, restore Premium access and prevent entitlement abuse;
- measure acquisition, feature use, reading activation, retention and Premium conversion, and improve the product;
- create requested exports, deliver support reports and troubleshoot faults;
- operate, secure, rate-limit and improve the reliability of ReadTally services;
- comply with law and enforce applicable terms and rights.
4. When we share data and service providers
We disclose data only as needed for a feature you use, service operation, security, or legal compliance:
- Cloudflare provides CDN and website security, Workers, R2 object storage, D1 database services, rate limiting and support-email delivery.
- Google provides Sign-In and Identity Services, Google Play billing and purchase verification, Analytics for Firebase, optional Google Ads attribution and cost reporting, ML Kit model delivery, and the Gmail mailbox used for support.
- ReadTally does not host .rtbook files or operate public book-share pages for direct file sharing.
- Android and apps you select process files when you import, open, export or share them.
- Authorities or other parties may receive data when required by law or necessary to protect users, rights and service security.
ReadTally does not sell or rent personal data, use it for cross-context behavioral advertising, or disclose book content for advertising.
5. Legal bases where applicable
Where data-protection law requires a legal basis, we process data to perform the service you request or our agreement with you; with your consent for optional permissions and actions; for legitimate interests such as security, fraud prevention, support and reliability where those interests are not overridden by your rights; and to meet legal obligations. You may withdraw consent through Android settings, app settings or by contacting us, without affecting earlier processing.
6. Data retention
- Local data remains until you delete it in ReadTally, clear app storage, remove exported files, or uninstall the app.
- Private cloud content is deleted after 90 consecutive days without authenticated ReadTally account activity, or earlier when you delete it. Replaced generations and failed cleanups may remain temporarily until automated cleanup or account-data deletion succeeds. After automatic deletion, ReadTally keeps only a pseudonymous deletion marker until it can notify you at your next sign-in, then removes that marker.
- ReadTally does not retain .rtbook sharing archives on its servers. A locally prepared archive may remain in the app cache until Android or ReadTally clears it; a recipient or selected sharing service may retain its own copy.
- Local diagnostics are limited to 14 days and 5,000 events unless exported or removed sooner.
- Google Analytics retains product-analytics events according to the configured GA4 property and provider retention settings. Disabling analytics stops future collection and resets the app's local analytics identity, but does not retroactively erase already processed aggregate reports.
- Support-report content is not persisted in ReadTally storage, but delivered email and attachments may remain in the support mailbox as long as reasonably necessary to resolve the request and protect against abuse.
- Purchase, subscription, trial and entitlement-verification records may be retained after cloud-data deletion as needed to restore purchases, prevent fraud, resolve disputes and meet tax, accounting or legal obligations.
- Pseudonymous session-revocation, request and rate-limit records may be retained for security and abuse prevention. After cloud-data deletion, scrubbed upload reservations may remain for up to their short signed-URL lifetime before scheduled cleanup.
Infrastructure providers may retain limited backup, security or access logs under their own retention policies. We delete or anonymize data when it is no longer needed for the purposes described above.
7. Security
ReadTally uses HTTPS, a private R2 bucket, account-scoped authorization, short-lived signed transfer URLs, signed ReadTally sessions, secure on-device credential storage, bounded uploads, rate limits, and redaction and size limits for diagnostics. Cloudflare states that R2 objects and metadata are encrypted at rest and transfers are protected in transit.
No system is completely secure. A direct .rtbook transfer can be copied by its recipient or the service you choose. Share only content you have the right to distribute, and only with people and services you trust.
8. Your choices, export, deletion and rights
- Use ReadTally without signing in; manage permissions in Android; delete books and reading data in the app; or clear app storage/uninstall to remove local data.
- Disable product analytics at any time in Settings → Data. This stops future product-event collection and resets the local analytics identifier; earlier provider-side records follow Google Analytics retention and deletion controls.
- Enable cloud sync only when wanted, and delete cloud-only or local-and-cloud content from Settings → Cloud → Account options. Delete locally prepared sharing files by clearing app storage or removing copies from the selected sharing service.
- Disconnect the current device or every ReadTally session. Revoking Google access does not by itself delete ReadTally Cloud data.
- Manage or cancel subscriptions in Google Play. Deleting ReadTally data does not cancel billing.
- Use the in-app data export where available, or contact us to request access, correction, portability or deletion.
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, and complain to a data-protection authority. We may need to verify your identity before fulfilling a request. Legal exceptions may apply.
9. Children’s privacy
ReadTally is not directed to children who cannot legally consent to data processing in their jurisdiction, and we do not knowingly collect their personal data through account features. If you believe a child provided data improperly, contact us so we can investigate and delete it where required.
10. International data transfers
ReadTally and its providers may process data in countries other than yours. Where required, transfers rely on recognized safeguards or other lawful mechanisms. Provider locations and subprocessors can change as their infrastructure evolves.
11. Changes to this policy
We may update this policy when ReadTally features, providers or legal requirements change. The current version will remain at this URL with a revised effective date. Material changes may also be communicated in the app or store listing when appropriate.
12. Contact
For privacy questions or requests, contact the ReadTally developer and data controller, EasyProjects:
EasyProjects
readtally.app@gmail.com
Describe the request and the Google Account used with ReadTally if it concerns cloud data. Do not email passwords, payment-card details, or book files unless support specifically asks for a relevant attachment.