✦ Privacy
What we know about you,
and what we will never do
Last updated 19 September 2026 · hello@apicbooks.com
ApicBooks is built and run by one reader, not a data company. This page says, in plain words, what we keep about you, why, who else touches it, and what we will never do with it. It was written from the code rather than from a template, and it is long only because it is complete.
1. The short version
- We keep your account and your reading life so that they are there when you come back. We use them for nothing else.
- No advertising, no trackers, no analytics cookies. Nothing about you is sold, rented or shared.
- Your conversations with Anika are never stored. There is no table in our database that could hold one.
- Books you upload are private, forever, by design: never shown, shared, described or looked up.
- Your data sits in India, with one encrypted backup copy in the European Union. Some processing passes through the United States, and this page names every case.
2. What we keep, and why
Your account. Your email address and a password — or your Google sign-in, in which case Google gives us your name, your email address and your profile picture, and the picture becomes your avatar until you change it. A display name; an avatar (avatars are served from a public address, so anyone holding the link can see the picture); your favourite genres; your language; your region and currency, used to order the store links; and your theme. Three optional fields you may fill in or leave empty — a short bio, a website, and a place — appear on your profile, so other signed-in readers can see them unless you make your profile private. Why: so that you can sign in, and so that the shelves know they are yours.
Your reading life. The books on your shelves and where you are with each; reading sessions — when you started and stopped, minutes, pages, and a note if you leave one; streaks and goals; notes, quotes and journal entries; ratings and reviews; collections; the series suggestions you send us; and the bug reports and feature requests you file, with the page you were on and which browser you sent them from. Why: this is the product. It is your reading life, kept for you. A review you mark public is visible to other readers on that book’s page; everything else is visible only to you.
Your own books. The EPUB files you upload and their covers. They have their own section below, because the promise about them is stronger.
Social. Who you follow, and — only when you post a public review — an activity item (“reviewed Middlemarch”) that your followers see and that appears on your profile page. Your profile is visible to other signed-in readers unless you switch it off in Settings → Privacy & Visibility. We say it plainly: the switch starts on.
Usage counts — how many, never what. We record that a sign-in happened, that a book was opened, that a search returned twelve results, that a message went to Anika and cost so many tokens. We do not record the words you searched for, the mood you typed, or anything you said to Anika. Those are your words, and there is deliberately nowhere in our database to put them.
Errors. When something breaks, we keep which route failed, the error message and your account id, so that it can be fixed. Error reports also go to Sentry, named below, with identifiers stripped before they leave.
3. What we never do
- No advertising, no ad networks, no analytics trackers. There is no ad-tech or analytics code in the page at all.
- No selling, renting or sharing of your personal data with anyone, for any reason.
- No device location, no contacts, no payment details — there is nothing to pay for. (You can type a place into your profile if you want to; that is yours to fill in or leave blank, and it is not the same as us taking it.)
- Anika conversations are never stored: not by us, not in a log, not “for quality”. They live in your browser while you chat and are gone when you close it.
- Your uploads are never shown to anyone, never looked up anywhere, and never sent to any AI provider.
4. Your own books
My Uploads is a personal locker, not a library we publish, and that difference is the whole basis on which it exists. No sharing feature exists and none will be added. The rules below are enforced in the database and in storage, not only on the screen, so that a future change cannot forget them.
- Only you. The database refuses a request for an upload from any account but yours. Our own admin tools can delete a file on a valid legal complaint; they cannot open one, and we do not read them.
- Private storage. Files sit in private storage that only your account can reach, through links that expire.
- Never described to anyone. An upload is never sent to Google Books, Open Library, Wikipedia or any other book service. Anika is told only that you are in “a private book” and which page of how many — no title, no author. The button for attaching a photo is not offered while you are inside one, and if a picture reaches us from there anyway it is thrown away before the message leaves — so no image of a private book reaches the AI provider either.
- Never public by accident. A review of an upload cannot be made public — the database forces the setting back. An upload never appears in the activity feed, in recommendations, or in a series.
- Backed up with the same care. The nightly backup copies your files, encrypted, to private storage with Backblaze in the European Union. Delete an upload and it is gone from the backup within thirty days.
- Limits. Three books, ten megabytes each, thirty megabytes in all. ApicBooks is not a backup service — keep your own copies.
5. Anika, and what reaches the AI
Anika is an AI. When you talk to her, your message has to leave ApicBooks to be answered. Here is exactly what goes, to OpenRouter in the United States, which routes it to the model — Google’s Gemini 2.5 Flash at the time of writing:
- The most recent sixteen messages of the current chat, yours and hers.
- Your first name and up to eight of your favourite genres, so that she can address you and knows your taste.
- Your language.
- If you are in the reading room with a catalogue book: its title, its author and your page. For one of your own uploads: only “a private book” and the page numbers.
- Any picture you attach, up to two in a message. Pictures are for asking about a page or a cover, and they reach the provider exactly as a message does — so attach one as you would show it to a stranger who is helpful and forgets nothing you can check.
We send no account identifier and no email address with a request. Of the exchange itself we keep nothing — not a word of it. What we do keep is a billing line: which model answered, how many tokens it took, what that cost, and the reference number OpenRouter gives the call. OpenRouter and the model provider handle the message under their own policies; we cannot read a conversation back from them, and neither can anyone else at ApicBooks.
Mood search sends the mood you type to Google Books as a search and to the model as a prompt; we store neither. Recommendations send the titles and authors of books you rated highly, and your genres, to ask for read-alikes; your uploads are left out.
6. Who helps run ApicBooks
A few services run parts of ApicBooks that one person cannot, and each sees only what its job requires. This is the complete list. A name that is not here receives nothing — and a test in our code fails if the code ever contacts a service this page does not name.
Supabase
IndiaDatabase, sign-in and file storage
Everything in “What we keep”: your account, your shelves and notes, your uploaded books. This is where your data lives.
Vercel
United StatesHosts and serves the website
Every request passes through it — your IP address, browser and the page you asked for — and it keeps short-lived request logs. It also resizes catalogue cover images; covers of your own uploads never go through it.
Backblaze B2
European UnionNightly backup
An encrypted copy of the database and of every stored file, your private uploads included, made every night into private storage. Anything you delete is gone from the backup within thirty days.
Sentry
United StatesError reports
When something breaks in your browser or on our server, a report of the error. Before it leaves: no cookies, no headers, no account details, no query strings; ids and email addresses are blanked out; addresses that would name a private file are dropped whole. No session recording and no performance tracing — errors only.
OpenRouter, and through it Google
United StatesAnika, mood search and recommendations
The messages described under “Anika, and what reaches the AI”. OpenRouter routes them to the model — Google’s Gemini 2.5 Flash at the time of writing. We send no account identifier and no email address with a request, and we keep none of the conversation afterwards — only a billing line: the model, the token counts, the cost, and OpenRouter’s reference for the call.
Resend
United StatesSends our email
Your email address, to deliver your welcome note. When you file a bug report or a feature request, the alert it sends to our own inbox carries your address as the reply-to, so that answering you is one tap.
Zoho Mail
IndiaOur inbox
Anything you email us, and the alerts above.
Cloudflare Turnstile
United StatesBot check
At sign-up, sign-in, password reset, and when you save a book while signed out, a small challenge from Cloudflare confirms you are a person. Cloudflare sees your IP address and browser for that check.
Google (sign-in)
United StatesThe “Continue with Google” button
If you choose it, your browser goes to Google to sign in, so Google sees that visit and knows you have an ApicBooks account. Google then hands us your name, email address and profile picture. The picture is not copied here: it stays on Google’s servers and is fetched from there whenever your avatar is shown. Sign in with an email address and password instead and Google receives nothing.
Google Fonts
United StatesTypefaces in the reading room
The reading room loads two typefaces, Merriweather and Lora, from Google — inside every book you open, your own uploads included. Google sees a request for a font from your IP address. It sees nothing about the book: not its name, not its text, not that it is yours.
Google Books
United StatesSearch and catalogue covers
The words you type into search and mood search, and the ids of catalogue books, so that results and covers can be found. Never anything about an upload. If you press “Preview” on a book page, an embedded Google Books page opens inside ours, and Google’s own cookies and policy apply while it is open.
Open Library
United StatesCovers and editions
The ISBN or the title of a catalogue book when a cover is missing. The request identifies itself as coming from ApicBooks. Never anything about an upload.
Wikipedia
United StatesAuthor biographies
On a catalogue book’s page, your browser asks Wikipedia for the author’s summary directly, so Wikipedia sees your IP address and the author’s name. It is never asked about an upload.
Project Gutenberg and LibriVox
United StatesFree texts and audiobooks for old books
The title and author of a catalogue book that looks old enough to be public domain, to find a free text (Gutenberg, via Gutendex) or a free audiobook (LibriVox). Nothing about you, never an upload.
The New York Times Books API
United StatesBestseller lists
Nothing about you. We fetch the lists; you are not in the request.
IT Bookstore
United StatesPrice lookup for technical books
The ISBN of a catalogue book, to ask for a price. Nothing about you, never an upload.
Bookshops
Their own sitesStore links
Amazon, Flipkart, eBay, AbeBooks, Alibris, Barnes & Noble, Better World Books, BookFinder, Powell’s and ThriftBooks. A store link is a plain search on that shop’s own site: clicking it takes you there, under their policy, and nothing about you is sent by us. There are no affiliate tags today. If that changes, this page changes first.
7. Where your data lives
At rest, your data is in India, with Supabase. One encrypted backup copy is held in the European Union, with Backblaze. Some processing passes through the United States for as long as it takes and no longer: a message to Anika, an email we send, an error report, and the request logs of the company that serves the site. The Digital Personal Data Protection Act, 2023 permits transfers to countries the Central Government has not restricted; if that list ever changes in a way that touches us, this page changes with it.
8. Cookies and your browser
One cookie. It keeps you signed in, and it is set by Supabase on our behalf. There are no advertising cookies and no analytics cookies, which is why there is no cookie banner: there is nothing to choose.
Local storage. Your browser keeps a few conveniences that never leave your device: your theme, your region, where you are in each book and your bookmarks, the page map that numbers a book, the reading timer, and whether you have seen the welcome tour.
Two of the services above set their own: Cloudflare during the bot check, and Google if you open a Google Books preview.
9. How long we keep things
For as long as your account exists. To delete it, email hello@apicbooks.com from your account’s address; we confirm it is you and remove the account, your shelves, sessions, notes, reviews, uploads and avatar. Backup copies expire on their own within about thirty days, and error reports at Sentry on its schedule (about ninety days). A self-serve delete button is on the roadmap; email is the honest current answer.
10. Your rights
Under the Digital Personal Data Protection Act, 2023 — and in plain decency — you can:
- See and correct what we hold: your profile and settings are editable in the app, and you can ask us for anything the app does not show.
- Erase it, as described just above.
- Withdraw consent at any time, which is the same as deleting your account.
- Raise a grievance. Write to hello@apicbooks.com. The person reading that inbox is the person who can fix it, and we acknowledge within a few days. If we do not resolve it, you may take it to the Data Protection Board of India.
- Nominate someone to exercise these rights for you if you cannot — email us and we will note it.
11. Age
ApicBooks is for readers aged eighteen and over. If you are younger, please do not create an account. We do not knowingly keep an account, or any data, for anyone under eighteen; if we learn that we have one, we delete it. A parent or guardian who believes a child has an account here can write to hello@apicbooks.com and we will remove it. We show no advertising and do no behavioural tracking of anyone, of any age.
12. If something goes wrong
If a data breach ever affects you, we will tell you plainly and quickly, and we will notify the Data Protection Board of India as the law requires.
13. Changes to this page
The date at the top moves whenever this page does. If a change matters — a new service receiving your data, a new kind of data kept — we say so in the app and, for anything significant, by email. We will not quietly rewrite the deal.
14. Contact
hello@apicbooks.com, or the contact page. This policy is governed by the laws of India.
— a fellow reader