ReadEden

Privacy Policy

Version 1.3 · effective 19 July 2026

ReadEden works without an Account. In that case, your reading journal stays on your phone and is not stored on our servers. Selected catalogue and recommendation requests may still contain the information described below. If you voluntarily create an Account and enable sync, selected data is sent to the cloud. This Policy explains what we use, why we use it and how you can control it.

1. Controller and contact details

The controller is Easy Life Sp. z o.o., registered at Hoża 51, 00-681 Warsaw, Poland, KRS 0000716356, NIP 1182164729 and REGON 369376133 ("ReadEden", "we", "us").

For privacy matters, email kontakt@readeden.com or write to the address above, marked "ReadEden - privacy".

2. Scope

This Policy covers the ReadEden mobile Application, optional Accounts, sync, Premium and the public pages at readeden.com.

3. Data we use

Journal without an Account

Books, sessions, progress, notes, goals, achievements and settings are stored locally on your phone. Without an Account, we do not upload the complete journal to the cloud for storage. The exception is information needed for a search or recommendation request that you initiate, as described below. You can remove local data in Settings, by uninstalling the Application or by clearing its data.

Account and sync

We process your email address, Account identifier, technical Account data and the reading data covered by sync. This can include books, sessions, progress, notes, goals, achievements and settings. We use it to maintain your Account, restore data and sync supported devices. In the EEA, the legal basis is performance of a contract under Article 6(1)(b) GDPR.

Search and recommendations

When you search for a book, the selected catalogue receives your search phrase and technical connection data such as your IP address. For recommendations, we may send author names or genre names selected from a small number of books in your library. We do not add your email address or Account identifier. The data is used to perform the feature you request.

Premium and payments

Google Play processes payments. We do not receive your card or bank account details.

The Application asks Google Play whether you have an active subscription. The purchase identifier and subscription status received for this purpose remain on your device. We do not send them to ReadEden servers or keep our own register of user purchases.

Separately, as the seller, we may receive billing information and sales reports from Google when needed for tax, accounting and complaint handling. This information comes to us from Google, not from the Application on your device. Our legal bases are performance of a contract and legal obligations, including tax and accounting obligations.

The public website at readeden.com

We do not use cookies, behavioural advertising analytics or tools that track you across unrelated services. We use local browser storage only for your chosen site language and session storage for the scroll position needed when switching languages. Cloudflare may process your IP address, request time, requested URL, browser type and other technical data needed to deliver and protect the site.

Messages and complaints

When you contact us or submit a publisher brief, we process the information in your message or form to respond, prepare a collaboration proposal, handle a complaint, fulfil a data request or establish and defend legal claims. The content of a publisher brief is sent to a ReadEden email address and stays there. We do not store it in any database on our side. Depending on the matter, the basis is taking steps before entering into a contract, a contract, a legal obligation or our legitimate interest.

4. Service providers and recipients

We do not sell personal data or reading history, and we do not share it for behavioural advertising. We use providers required for selected features:

  • Supabase provides Accounts, database, sync, file storage and Account deletion. The main project database is configured in the Ireland region (European Union).
  • Cloudflare delivers and protects readeden.com and sends the email messages generated by the publisher brief form. Its network operates globally.
  • Google distributes the application, processes Google Play payments and provides the Google Books catalogue.
  • Open Library and the National Library of Poland provide bibliographic data. Open Library may also receive a request used to prepare recommendations.

Public authorities may receive data where applicable law requires it.

5. International data transfers

Some providers operate outside Poland and the European Economic Area. Where GDPR applies, we use a transfer mechanism permitted by law, such as an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses. You can contact us for information about current safeguards.

6. Affiliate links and external sites

When you click a bookshop link, you leave ReadEden. The external site applies its own privacy rules and may set its own cookies. We do not send it your journal or Account data. The link may contain an affiliate identifier that lets a purchase be attributed to ReadEden.

7. Retention

  • We keep Account data and the synced journal while you use the Account.
  • After a verified deletion request, we remove data from active systems without undue delay, normally within 30 days.
  • Backups remain until overwritten under the provider's rolling schedule. If a backup containing deleted data is restored after a failure, we repeat the deletion.
  • We retain accounting data for the period required by tax and accounting law.
  • We retain correspondence, complaints and security records until the matter ends and then until the relevant limitation period expires, unless law requires longer retention.

8. Your rights

Depending on where you live and the legal basis, you may have rights to access, obtain a copy, correct, delete, restrict, port or object to the use of personal data. Where processing relies on consent, you may withdraw it without affecting earlier processing.

If GDPR applies, you may complain to a supervisory authority in the country of your habitual residence, place of work or the alleged infringement. In Poland, this is the President of the Personal Data Protection Office.

Laws in some US states and other countries may provide additional rights. If they apply to ReadEden and your situation, we will honour them after receiving a verifiable request. We do not discriminate against people who exercise privacy rights.

9. Automated decisions

Recommendations do not make decisions that produce legal or similarly significant effects. They are suggestions based on authors and genres. You can switch them off or choose not to use them.

10. Age

ReadEden is intended for people aged 16 or over. We do not ask for your full date of birth, but we require confirmation that you are at least 16. If local law requires parental or guardian permission for an Account or the processing of a minor's data, do not create an Account without that permission.

If we learn that an Account belongs to someone under 16, we may delete it and the related data.

11. Security

We use technical and organisational measures appropriate to the data, including access controls, encrypted connections and data minimisation. No system can guarantee complete security. If an incident occurs, we will provide notices required by law.

12. Changes to this Policy

If a change materially affects how we use data, we will notify you in the Application or by email before it takes effect. Minor corrections may be published on this page. The current version and date appear at the top.

← Back to the home page