Boox Reader · Privacy

Privacy Policy

How Boox Reader handles your data across authentication, sync, storage, and AI features.

Last updated: 2025-12-12 Scope: Android app & cloud sync

What we collect

Only what is needed to sync your library and AI notes.

All cloud data is isolated to your account. We do not show ads or run third-party analytics.

Account & identity

Supabase Authentication manages sign-in. We store your Supabase user ID and the sign-in email you provide.

App data you create

Book files (EPUB) uploaded for backup, reading progress, bookmarks, AI notes, and AI profiles/settings you configure.

AI requests

Prompts, selected text, and system instructions you send to AI providers (Gemini or OpenAI-compatible endpoints). If enabled, Gemini requests may use Google Search.

Diagnostics

Limited device details (Android version, device model) and crash logs as needed to debug issues; no advertising identifiers.

How we use data

To sync your reading state and power AI responses.

  • Sync library files, progress, bookmarks, and notes across your devices via Supabase Postgres and Cloudflare R2.
  • Generate AI explanations or summaries by sending your provided text to the AI provider you choose.
  • Maintain your AI profiles and preferences so you can reuse them on all signed-in devices.
  • Troubleshoot reliability issues using minimal diagnostic logs.

Where data lives

  • Authentication: Supabase Authentication.
  • Cloud database: Supabase Postgres (per-user rows).
  • File storage: Cloudflare R2 for EPUB backups.
  • AI providers: Gemini (Google Generative Language API) or OpenAI-compatible endpoints you configure; optional Google Search when enabled.
  • On-device: Local caches for offline reading; removed when you uninstall the app.

Sharing

Your data is not sold.

We share data only with services required to run the app (Supabase and the AI provider you select). No ads, no third-party tracking SDKs.

Retention & control

You stay in control.

  • Delete books, bookmarks, or notes from within the app to remove them from sync.
  • Sign out to stop new sync. To remove your cloud data, delete your account data in-app if available or contact support.
  • Local caches are removed when you uninstall the app; cloud copies remain until you delete them.

Security

Transport encryption and per-user access rules.

  1. All network traffic uses HTTPS/TLS.
  2. Row-level security policies scope records to your authenticated user.
  3. We minimize stored data to what is necessary for sync and AI features.

Contact

Questions or deletion requests

Use your usual support channel. If you prefer GitHub, open a private issue with “privacy” in the title.

Need changes?

Tell us if you want a data export, correction, or deletion. We will respond using the contact method you provide.