Privacy
Readom has no user accounts, doesn’t sell data, and includes no advertising trackers. Here’s exactly what happens with your information, at two levels of detail.
In one sentence
Your reading progress, favorites, and settings live only on your device; we never see them. For catalog and book operations, your browser or app contacts only readom.org, which we serve through Cloudflare to protect it from attacks — we explain what that means below.
What we store on your device
Reading progress, bookmarks, favorites, and app preferences. Everything is stored locally and deleted if you uninstall the app. None of it is ever sent to a server.
What leaves your device
- When you search for or download a book, your device makes an HTTPS request to readom.org. As with any web connection, the server temporarily receives the IP address needed to reply, but Readom does not include it in application logs. That request first passes through Cloudflare, which does see your IP and the address requested and applies its own security logging — the next section explains this in full.
- Catalog searches are processed to return results, but they are not stored, linked to an identifier, or used to build reading profiles. We do keep an aggregate count of how many times each book is downloaded, in which language and on which day, so we know which works are of interest and in which languages. That counter stores no IP, no identifier and no exact time: it is an anonymous per-book tally that cannot be tied to a person.
- If you choose translation, the app first asks permission to download language models from Google over Wi-Fi. For diagnostics and usage analytics, ML Kit collects device and app information, per-installation identifiers not intended to identify you, technical metrics, events/errors, and configured languages. Google states that this data is encrypted in transit and not shared with third parties. Text and results remain on the phone. Speech is delegated to your configured Android TTS engine. If you choose Nearby sharing, Google Play Services Nearby uses local Bluetooth/Wi-Fi and collects performance, reliability, and technical device metrics; EPUBs are transferred encrypted directly to the phone you approve, without passing through Readom’s VPS.
Cloudflare, our protection against attacks
The readom.org server is not exposed directly to the internet: all traffic enters through Cloudflare’s network, which filters denial-of-service attacks and intrusion attempts before they reach our machine. Without that layer, a free project with no revenue like this one goes down — or gets compromised — at the first serious attack, and the people left without books are the ones who need them most. The honest price of that protection is that Cloudflare processes every request as a technical intermediary: it sees your IP address and which page or book you request, and applies its own security rules and logs. It does so as a data processor on our behalf; it does not receive your reading progress or your library, which never leave your device, and we hand it no additional data about you. Its network also asks your browser to report connection errors to it (NEL headers), a standard technical diagnostic that does not follow your browsing. We spell this out because claiming “you only talk to readom.org” while omitting the intermediary would be incomplete.
What we don’t do
We don’t use advertising SDKs or analyze reading behavior. We don’t ask you to register or sign in, and Readom does not sell data. The only SDK analytics are the ML Kit telemetry used for translation and Nearby telemetry used for sharing, described above and activated only by an explicit action.
