Manamo Reader — Privacy Policy
How Manamo Reader handles your data.
Last updated: 21 September 2026
Manamo Reader is an e-reader with AI-assisted study features. This policy explains what data the app collects, why, who else processes it, how long it is kept, and how you can delete it. It applies to the Manamo Reader iOS app and the Manamo Reader web app.
The short version. Your account is stored on our servers, and with Manamo Pro your library and study data are stored so they sync across your devices. AI features send the relevant text (and any image you attach) to model providers to generate a response. Your chats stay on your device. We collect pseudonymous product analytics and crash reports to see how features perform. There is no advertising, no cross-app tracking, no data broker, and nothing is sold. You can delete your account and its data from inside the app at any time.
Who is responsible
Manamo Reader is an independent app. The developer is the data controller for the information described here and can be reached at support@manamo.net.
What we collect and why
| Data | Why | Linked to you |
|---|---|---|
| Email address and display name | To create and authenticate your account | Yes |
| Account identifier (user ID) | Keys everything stored for you; used to enforce usage limits and, in aggregate, to understand how features are used | Yes |
| Your library: book files, titles and authors, reading position and progress | To sync your library and place across your devices. Cloud sync is a Manamo Pro feature; without it your library stays on the device you added it to | Yes |
| Highlights, notes, flashcards and study history | To sync your study data and schedule reviews, under the same Pro sync gate | Yes |
| Chat messages, text you select in a book, and the study profile the assistant keeps | To produce AI answers, definitions, summaries and recaps. These are stored on your device, not on our servers; they are transmitted to model providers only when you invoke a feature | On your device |
| Images you attach to a chat | To let the AI answer questions about the image | Yes, in transit |
| Feature usage records (which AI feature ran, which model, token counts, estimated cost, timestamps) | To enforce fair-use limits and prevent abuse, and to understand feature usage in aggregate | Yes |
| Product analytics events (screens opened, reading and study sessions, feature outcomes, performance timings, app version and device model) | To understand how features are used and where they fail, and to measure changes we test. Sent under a pseudonymous identifier derived from your account, never your raw account ID, and never carrying book titles, notes, prompts, selections or search text | Pseudonymously |
| Crash and error reports (exception type, screen, app version, stack trace) | To find and fix crashes. Reported under an installation identifier, with error messages stripped because they can contain text you selected | Pseudonymously |
| Subscription status and purchase history | To unlock paid features and restore purchases | Yes |
What we do not collect
- No location data of any kind.
- No contacts, calendar, or address book.
- No microphone or camera recordings. Read-aloud, where available, synthesises speech; it does not record you.
- No health, fitness, financial or other sensitive-category data.
- No advertising identifier (IDFA), no advertising SDKs, and no attribution or ad-network SDKs.
- No book titles, highlights, notes, prompts, selections, search text or file paths in analytics or crash reports — the event schema forbids those fields outright.
- No payment card details. Purchases are handled by Apple; we never see your card.
Advertising and tracking
Manamo Reader contains no advertising. We measure how our own app is used, as described under “Product analytics and crash reports” below, but we do not track you across other companies' apps or websites, do not combine your data with data from them for advertising, and do not share it with data brokers. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Because of this, the app does not ask for App Tracking Transparency permission.
AI features
AI features are opt-in per action — they run when you tap or ask for them, never in the background while you read. When one runs, the app sends the material it needs through our own server to a model provider: the relevant passage or chapter, your question, and any image you attached. The provider returns a response, which the app shows you.
- Requests reach providers through our server. We do not store or log the contents of your chats or the passages you send. Your conversation history is kept on your device.
- Chapter illustrations are generated from a description our server derives from the chapter text, which is sent to an image model for that purpose.
- We do keep a record that a request happened — feature, model, token counts, estimated cost and time — to enforce usage limits and prevent abuse.
- Some derived results (chapter summaries, chapter guides, article overviews) are cached on our server so that a later request for the same public content is fast and cheap. These caches are keyed by a hash of the source text, not by you, and they contain the generated summary rather than anything personal to you.
- Model providers may retain request content briefly for abuse monitoring under their own terms, and their handling of it is governed by those terms.
- Some AI features are not available on every platform or at every moment. Chapter narration and read-aloud are currently switched off in the shipping app; the definition card's pronounce button uses your device's own speech engine and sends nothing to us.
Product analytics and crash reports
We collect our own product analytics to understand how the app is used and where it fails. This is first-party telemetry sent to our own infrastructure — there is no third-party analytics, advertising or attribution SDK in the app, and nothing is shared with other companies for their own purposes.
- What is sent: a fixed, versioned list of events — app sessions, screens opened, reading and study sessions, feature outcomes (for example whether a recap or definition succeeded), purchase and paywall events, sampled performance timings, and client errors — along with app version, build, platform and device model.
- What is never sent: the schema forbids book and card text, titles, authors, prompts, selections, notes, search text, URLs, file paths, email addresses, names, tokens, provider responses and raw error messages. Checks in our build pipeline reject any change that would add them.
- How you are identified: events carry a pseudonymous identifier derived from your account with a keyed one-way hash, plus an installation identifier. Our analytics store never receives your raw account ID or email.
- Experiments: we may run A/B tests of app changes and record which variant you saw so we can compare outcomes.
- Crash reporting uses Firebase Crashlytics, keyed to the installation identifier rather than your account. Exception messages are replaced before sending because they can contain text from the book you were reading; the stack trace is kept.
- There is no in-app toggle for product analytics. It is limited to the bounded, content-free event list above, and it is deleted with your account.
Who else processes your data
We use the following providers. Each processes data only to deliver the function listed.
| Provider | What it handles |
|---|---|
| Google Firebase & Google Cloud | Sign-in, database, file storage, the server that fronts AI requests, and the analytics pipeline and warehouse that stores the events described above |
| Firebase Crashlytics | Crash and non-fatal error reports |
| Apple | Sign in with Apple, and App Store purchases |
| RevenueCat | Subscription and entitlement management |
| OpenRouter | Routes AI requests to model providers for text and image generation, and — for narration features, when they are enabled — speech synthesis and transcription for read-aloud alignment |
| Anthropic | Some AI chat and assistant responses |
| Exa | Web search, when the assistant needs current information to answer your question |
The app also fetches book and article content from public sources you choose in Discover — for example Project Gutenberg, arXiv, PubMed, and publisher feeds. These requests deliver content to you; they do not carry your account information.
How long we keep data
- Your library and study data are kept while your account exists, so they remain available on your devices. Deleting a book in the app removes it from your account across devices.
- Individual usage records expire automatically about 13 months after they are written.
- Aggregate usage totals (per-account capacity windows and daily counts) are kept while your account exists and are removed when you delete it.
- Analytics events expire about 25 months after they are recorded. Operational server logs, which contain no message bodies, are kept for 90 days. Crash and session exports are kept for 90 days.
- Aggregate figures that identify no one — such as totals per day or per feature — may be kept indefinitely.
- Shared result caches are keyed by a hash of the source content, not by account, and persist independently of any user.
Deleting your account and data
Open Profile → Delete Account in the app. It is permanent, there is no waiting period, and there is no need to email us. Your database records, your uploaded book files, your usage and subscription records, and your sign-in account itself are erased straight away.
Your analytics and crash data are deleted on a short schedule rather than in the same instant: the deletion is recorded at once and your events are excluded from every report immediately, the underlying analytics rows are removed within a day, and crash-report rows within seven days. Two things are deliberately kept: shared result caches, which are keyed by book or article content and contain nothing personal to you, and financial totals that are not linked to any account.
An active subscription is billed by Apple, not by us — cancel it in Settings → Apple Account → Subscriptions on your device. Deleting your Manamo account does not cancel an App Store subscription.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. Deletion is available directly in the app as described above. For any other request, email support@manamo.net and we will respond within 30 days.
We process your data to provide the service you asked for (performance of a contract), to keep it secure and prevent abuse (legitimate interests), and where required, with your consent. Data is stored on Google Cloud infrastructure and may be processed in the United States and other countries where our providers operate.
Security
Data in transit is encrypted with TLS. Stored data is encrypted at rest by our infrastructure providers. Access rules restrict each account's data to that account, and requests to our server are authenticated. No system is perfectly secure, but we design for least access and store only what the features need.
Children
Manamo Reader is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, email us and we will delete it.
Changes to this policy
If this policy changes materially, we will update the date at the top of this page and, where appropriate, notify you in the app. Continued use after a change means you accept the updated policy.
Contact
Questions about privacy, or a request about your data: support@manamo.net