Skip to content

Privacy Policy

Effective September 14, 2026.

BookOrbit is a client for a self-hosted reading server. The iOS app is designed to keep your library, reading activity, and account data under the control of you and your BookOrbit server administrator. BookOrbit does not sell personal information, show advertising, or track you across apps or websites.

The app may handle the following data to provide its features:

  • The address of the BookOrbit server you connect to
  • Account information returned by that server, such as your username, display name, email address, and avatar
  • Authentication tokens needed to keep you signed in
  • Library metadata, reading progress, annotations, bookmarks, activity, downloads, uploads, and playback state
  • Purchase status for BookOrbit Premium
  • Local performance and diagnostic information generated by Apple frameworks

Authentication tokens are stored in the Apple Keychain. Offline library data, downloaded media, preferences, and diagnostics are stored on your device. Removing an account from the app removes that account’s private offline data from the app.

Most account and library data is exchanged directly between the app and the BookOrbit server you choose. That server is operated by you or by an administrator you trust, not by the BookOrbit app developer. Its administrator controls its accounts, storage, backups, logs, connected services, and retention practices.

To access, correct, export, or delete data held by a BookOrbit server, contact that server’s administrator. Deleting the iOS app does not delete data stored on the server.

Apple processes App Store payments. BookOrbit does not receive your payment-card details.

BookOrbit uses RevenueCat to retrieve products and determine whether BookOrbit Premium is active. RevenueCat receives an app-generated anonymous identifier and purchase information such as product identifiers, transaction status, and entitlement status. The app does not send your BookOrbit username, email address, library, or reading activity to RevenueCat.

See Apple’s privacy policy and RevenueCat’s privacy policy for their practices.

Some features contact other services only when you use or enable them:

  • Network text-to-speech sends the text selected for narration to the speech provider so audio can be generated. BookOrbit credentials are never sent with that text.
  • Streaming or downloading a podcast connects to the podcast publisher or hosting provider. That provider may receive ordinary network information such as your IP address and request details.
  • Sign-in through an OpenID Connect provider opens the provider’s authentication page and follows the settings of your BookOrbit server administrator.

The app uses Apple’s MetricKit to retain bounded performance and diagnostic reports locally on the device. These reports are not automatically uploaded by BookOrbit. If you choose to share a diagnostic archive for support, review its contents before sending it.

BookOrbit is a general-purpose reading app and is not directed to children under 13. A BookOrbit server administrator decides who may have an account on their server.

This policy may be updated as BookOrbit changes. The effective date at the top of this page identifies the current version.

For privacy questions about the iOS app, open a private security report through GitHub Security Advisories. For data held by a self-hosted server, contact that server’s administrator.