Skip to content
Legal

Privacy Policy

Last updated:

Short version: Your books, metadata, and reading data live only on your device. Anonymous usage stats (app version, OS — never your books or personal data) are enabled by default and can be turned off anytime in Settings → About & Updates → Privacy. Payment data is handled entirely by Paddle — we never see your card number. If you joined the waitlist, we hold your email for two messages — your sign-up confirmation and the launch announcement — and nothing else.

1. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), the UK GDPR, and the Spanish LOPDGDD, the Data Controller is Liber. You can contact us regarding your privacy and data at support@tryliber.com.

2. Data We Collect, Purpose, and Legal Basis

We only collect personal data when strictly necessary. Below is exactly what we collect, why, and our legal basis for doing so:

Note on Premium: Liber Premium is not on sale yet, so the entries below that depend on it — license data, AI features, cloud backup and payment records — describe processing that does not happen today. They are published in advance so you know what will apply when Premium launches. The only personal data we hold right now is your waitlist email, if you gave us one.

  • License Data: When you purchase Premium, we receive your email address, license key, subscription status, and a random device UUID from our payment processor. There is no user account: the key identifies the license, and the device UUID is what ties it to one machine at a time.
    Purpose: To verify your license, provide customer support, and protect your license from unauthorized use.
    Legal Basis: Performance of a Contract.
  • AI Features (Premium): If you use Liber AI, text excerpts are sent to our AI proxy and forwarded to our AI provider.
    Purpose: To generate AI summaries and insights.
    Legal Basis: Performance of a Contract. (Note: We configure our AI providers not to use submitted content for model training where such controls are available).
  • Cloud Backup (Premium): Your library data is encrypted on your device before transmission. We store the encrypted blob on Cloudflare R2.
    Purpose: To provide sync and backup services.
    Legal Basis: Performance of a Contract.
  • App Telemetry (Opt-Out): Anonymous usage data. This is the complete list of what is sent, and nothing else ever is: the name of the event (e.g. app_start), the app version, the operating system, and whether the license in use is free or premium. No identifier, no device ID, and nothing about your books.
    Purpose: To analyze performance, improve the app, and fix bugs.
    Legal Basis: Legitimate Interest. You can opt-out and disable this at any time via Settings → About & Updates → Privacy.
  • Regulatory Records: Transaction data provided by Paddle.
    Purpose: Tax, accounting, and compliance.
    Legal Basis: Legal Obligation.
  • Waitlist Email: If you sign up to the pre-launch waitlist on this website, we store your email address, the language of the page you signed up on (English or Spanish), the date, and which call to action you used (the general one or the Premium one), in a Cloudflare D1 database.
    Purpose: To send you exactly two emails, in your language: an immediate confirmation that you joined, and one notification when Liber becomes available to download. We do not send newsletters or marketing campaigns to this list.
    Legal Basis: Consent, given when you submit the form.
    Retention: Deleted within 90 days of the public launch, or immediately on request.
    Withdrawal: Email us at any time to be removed — see section 7.

3. Data Stored Locally (Never Sent to Us)

The following data never leaves your device (unless you explicitly enable Cloud Backup, in which case it is encrypted on your device before upload):

  • Your eBook files (EPUB, MOBI, PDF, etc.)
  • Book metadata, tags, reading progress, and book cover thumbnails
  • Library database and local app settings

Requests the app makes to other services. "We never receive it" is not the same as "it never leaves your computer". A few features work by asking someone else's server, and that server sees the request and your IP address, exactly as if you had opened it in your browser. This is the complete list:

  • Metadata and covers — automatic: when you import a book, its ISBN, title and author are sent to OpenLibrary, and to Google Books if OpenLibrary finds nothing, to fill in the description, publisher, year and cover art. This is the only request Liber makes without you asking for it.
  • Book sources — when you use them: what you search for goes to the source you are searching, whether it is one of the public ones we ship with (such as Project Gutenberg or Standard Ebooks) or one you added yourself.
  • Updates and the conversion engine: the app looks for new versions at GitHub, and downloads the Calibre conversion engine from calibre-ebook.com if you accept the prompt that offers it.

None of that traffic reaches us: we do not see what you searched for and we do not receive a copy. Each of those services is an independent controller with its own privacy policy.

4. Cookies, Local Storage and Web Analytics

Our website uses only what is strictly necessary for it to work. We do not use intrusive tracking cookies or third-party marketing analytics that profile your behavior, and we never use cookies or browser storage for advertising.

What we store in your browser. All of the following is functional — it remembers a choice you made or keeps the page working — and none of it identifies you or leaves your device:

  • Language preference (cookie, up to 1 year): remembers whether you chose English or Spanish, so the homepage does not send you to the other one.
  • Theme and custom cursor preferences (local storage, until you clear it): remembers light/dark and whether you switched the custom cursor off.
  • Session cache (session storage, cleared when you close the tab): holds the waitlist counter and the currency symbol so we do not re-request them on every page.
  • Cloudflare Turnstile may set its own cookies when it needs to check that you are not a bot, on the waitlist form only. Turnstile is a privacy-preserving alternative to a CAPTCHA: it does not track you across sites.

Because these are strictly necessary or purely functional, they do not require consent under the ePrivacy rules. You can clear them at any time from your browser settings.

To understand how our website is used, we rely on Cloudflare Web Analytics, a privacy-first, cookieless analytics service that measures aggregate data (page views, visitor countries, etc.) without cookies, fingerprinting, cross-site tracking, or profiling of individual visitors.

We also keep a small set of first-party counters on our own infrastructure, so we can tell how many people reach the sign-up form and how many complete it. These are aggregate totals per day only — for example, “page views: 412” or “sign-ups: 9”. We do not store your IP address, any visitor identifier, cookie, referrer, or the page you came from, so these counters cannot be linked back to you or to any individual visit. Because they are aggregate from the moment they are written, they are not personal data and there is nothing in them to access or delete.

5. Data Sharing and International Transfers

We never sell your personal data. We only share data with trusted processors under strict agreements:

  • Paddle.com: Merchant of Record for payments (UK/USA).
  • Cloudflare (Processor): Infrastructure, waitlist database and encrypted backup storage (USA/Global). This includes Turnstile, the anti-bot check on the waitlist form, which receives your IP address in order to verify the submission. The IP is used for that check and is not stored by us.
  • Resend (Processor): Transactional emails (USA).
  • Google (Gemini) (Sub-processor): Processing text excerpts for AI features (USA/Global).

Like any web server, our infrastructure at Cloudflare receives the IP address of the requests it answers — this website, license validation, anonymous telemetry. We do not store it and we do not link it to anything else.

Where data is transferred outside the European Economic Area (EEA) or the UK, we ensure it is protected by appropriate safeguards, such as the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).

6. Data Retention

We retain your License data for as long as your subscription is active, plus any additional period required by tax and accounting laws (typically up to 6 years). Encrypted cloud backups are deleted when you ask the app to delete your data, or 30 days after your subscription ends. Telemetry data is aggregated and retained for 12 months.

Waitlist emails are deleted within 90 days of the public launch, or immediately on request — see section 2. The first-party counters described in section 4 are aggregate totals and contain no personal data, so no retention period applies to them.

7. Your Privacy Rights

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erasure (Right to be forgotten): Request deletion of your data. The app does most of it for you: when you deactivate your license it can delete everything you keep in our cloud at the same time. The license record itself — your email, key and subscription status — has to stay while the subscription is running, so write to us and we will delete it. Certain records may be retained where required by law, including tax and accounting obligations.
  • Restrict or Object to our processing of your data. This is the right that applies to app telemetry, which we process under Legitimate Interest: you can object at any time, and the switch in Settings → About & Updates → Privacy gives effect to that objection immediately, without having to write to us.
  • Data Portability: Receive a copy of your data in a machine-readable format.
  • Withdraw Consent at any time for processing based on consent. The only processing we base on consent is the waitlist email: reply to any of our emails, or write to the address below, and we remove you.

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

To exercise these rights, email us at support@tryliber.com. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with your local supervisory authority (e.g., the AEPD in Spain or the ICO in the UK).

8. Children

Liber is not directed at children. In line with our Terms of Service, you must be at least 16 years old — or the minimum age of digital consent in your country, if it is lower — to use Liber or to join the waitlist. We do not knowingly collect personal data from anyone below that age. If you believe a child has given us their data, write to us and we will delete it.

9. Contact Us

If you have any questions about this Privacy Policy, please contact: support@tryliber.com.