1. Scope
This policy applies to the ReaderVox iOS app, its share extension, widget and system shortcuts. It describes data processing for reading, listening, importing, voice cloning and optional usage analytics. Available features vary by release; listing a feature here does not activate it or its data processing.
Current local reading and listening features do not require registration. The app does not provide an app account system or merge identities across devices. This page describes the app; any cookies, logs or website analytics independently used by the website hosting it should be disclosed separately by that website.
2. Local reading, listening and voice data
- Books and reading records: Imported TXT, EPUB, PDF and text, including titles, authors, covers, book contents, library information, progress, bookmarks, notes, highlights, search actions, reading history and preferences, support local reading, search, resuming and reading statistics. This information is stored on your device by default.
- Local listening: System speech and the local Kokoro and ZipVoice engines process text to generate or play speech. Locally generated audio may be cached on your device. ReaderVox does not upload book contents or locally synthesized audio to analytics services. Apple supplies system voices and associated system services under your system settings and its privacy rules.
- Voice cloning: When you choose to record, the app uses the microphone to capture reference audio and stores your voice name, reference text and necessary voice configuration. Reference recordings and cloned speech synthesis are processed on-device, are not uploaded to Firebase or Umeng, and are not used for identity authentication or by the app operator to train cloud models. Voices may contain identifiable personal information; record only your own voice or a voice you have permission to use. Deleting a cloned voice removes its corresponding app record and reference audio; exported copies must be deleted separately.
- Local resources: Imported fonts, installed speech models, voice favorites and preferences are stored locally to personalize reading and listening.
3. Imports, networking and system entry points
- Files and share imports: The app reads files or text you select through the system file picker or share menu. The share extension places selected content in the app’s shared container for import by the main app; it does not scan files you have not selected.
- Clipboard: The app reads importable text when you open clipboard import or run its corresponding shortcut. Copying selected text or a transfer address writes to the clipboard. The app does not continuously monitor the clipboard or send its raw contents as analytics parameters.
- Wi-Fi transfer: When enabled by you, the app runs a temporary local-network web service. Devices holding its access address can view the book list and upload, download or delete books. Transfers may include files, titles, authors and book identifiers, and connections involve local-network addresses. The service uses an HTTP address with an access token and is not an end-to-end encrypted service. Use a trusted network, protect the address and stop the service when finished.
- Model downloads: Downloading speech packages sends network requests to the model hosting service. Current resource addresses use Hugging Face and may be delivered through its storage or CDN providers. Providers may receive your IP address, requested model file path, request time and technical request information. Download requests do not include your book contents, notes or reference recordings. Subsequent local synthesis does not require sending this content to the hosting service.
- Widget, Siri, Spotlight and deep links: The app provides necessary book titles, authors, progress summaries and local book identifiers to its shared container or Apple’s system index for widgets, system search, opening books and resuming listening. Information may appear in widgets or system search. Apple processes Siri requests under your system settings. The share extension and widget do not independently initialize analytics SDKs.
4. System permissions
| Permission / capability | Purpose and choice |
|---|---|
| Microphone | Requested when you initiate a voice-cloning recording. Denying access prevents reference recording, but other reading and listening with existing voices remain available. |
| Local network | Used for Wi-Fi transfer. Denying access prevents normal use of that transfer service; file imports and local reading remain available. |
| File access and system fonts | System pickers grant access to files you select. System capabilities provide available fonts when you choose system fonts. |
| Background audio | Supports listening while the screen is locked or another app is active, through iOS audio and background execution mechanisms. |
You can manage revocable app permissions in iOS Settings. The app does not request contacts, precise location or access to your entire photo library.
5. Optional usage analytics
Analytics depends on your choice. Firebase Analytics and Umeng are initialized and enabled only when analytics is available and configured in your app release and you explicitly consent. While your choice is undecided or denied, app business analytics events are not sent. Declining does not prevent reading or listening. Behavior before consent is not backfilled.
Analytics helps assess successful imports, effective reading or listening, download and playback obstacles, feature usage, activity and retention. The same behavior may be sent separately to both services.
- Feature events: Screen views; importing and opening books; reading and listening sessions; settings changes; voice selection and previews; model downloads; and voice-cloning flows. Releases that offer membership may also report membership screen views, purchase and restore results.
- Limited parameters: Import source and format, speech engine and language, predefined result and error categories, operation latency, actual reading and playback duration, aggregated page turns and pauses, buffering duration, reference-recording duration ranges, entry source, product category, usage date and distribution information.
- SDK technical data: SDKs may process app-instance or device identifiers, app and SDK versions, device model, operating system, language, time zone, session information, network status and IP addresses involved in requests for deduplication, sessions and analytics. Data may be associated with the same app installation and should not be regarded as fully anonymous.
App business event parameters exclude book titles, authors, contents, search terms, file paths, recordings, clone names, note contents and raw error messages. The app does not set a user ID shared across the two providers.
You can turn off “Usage analytics” in app settings. The app then stops generating new business events and instructs the SDKs to stop collection; the disabled choice persists after restart. Turning analytics off does not delete previously uploaded data or mean that every SDK cache is immediately erased. Uploaded data is retained and deleted through the relevant provider’s mechanisms. Re-enabling does not backfill business activity from the disabled period. Local reading statistics are independent of online analytics.
6. Third-party SDKs and services
| SDK / service and provider | Purpose, data and processing |
|---|---|
| Firebase Analytics Google LLC FirebaseAnalyticsCore 12.19.2 | Consented behavior and retention analysis using feature events, app-instance identifiers and device/app technical information. The integrated product does not collect IDFA; advertising storage, advertising user data and ad personalization are disabled. Google Privacy Policy; Firebase privacy and security information. |
| Umeng U-App 友盟同欣(北京)科技有限公司 UMCommon 7.6.7 / UMDevice 3.6.0 | Consented screen, event, activity and retention analysis using feature events, device or app identifiers and device, app and network technical information. Identifier types depend on iOS and SDK configuration. The app does not use its advertising attribution features. Umeng Privacy Policy. |
| Local speech components sherpa-onnx / ONNX Runtime Kokoro / ZipVoice / espeak-ng | Process text, models and reference audio on-device for speech synthesis, language processing and voice cloning. Local inference does not upload content to the maintainers of these open-source projects. |
| ZIPFoundation | Processes archives such as EPUB files and, where available, backup archives locally. Unpacking or archiving does not upload content to project maintainers. |
| Apple system services | Provide file selection, system speech, Siri/Shortcuts, Spotlight, widgets and, where available, StoreKit purchases. Apple manages the processing for these system services. Apple Privacy Policy. |
| Hugging Face and resource delivery services | Deliver requested speech models and resources and may process connection and download request information. App books and clone recordings are not provided as download parameters. Hugging Face Privacy Policy. |
The current local-speech release does not enable Alibaba Cloud NUI/Qwen online speech services. If a future release offers speech that sends text to a cloud service, the new recipient, data types and processing will be disclosed first and appropriate authorization obtained where required.
8. Retention, security and deletion
Local books, reading records, voice configurations and reference recordings are retained while providing the associated features. Use available app actions to delete books or voices; items moved to a recycle bin may remain until permanently deleted. Speech caches and downloaded models can be cleared through their storage or resource management features. Uninstalling usually removes local app data, but does not automatically delete original files, exports or system backups saved separately.
If your release offers backup export, archives may contain books, reading records, notes and reference audio. Protect exported archives; integrity checks are not file encryption. The app does not actively establish a cloud library sync service, but iCloud Drive, other cloud storage, sharing services or iOS device backups may retain copies according to your choices. Analytics consent is not restored from library backups.
SDKs may cache analytics records on-device while awaiting upload. Retention for server-side events, instance data and aggregate reports depends on each service’s data type, actual retention settings and applicable rules; one uniform retention period for all data is not guaranteed. Disabling analytics or uninstalling does not automatically delete historical server reports.
The app uses iOS sandboxing, system permissions and local data separation to limit access; model downloads use HTTPS. Device unlock status, shared transfer addresses and exported files can still affect privacy. Protect your device and any copies you create.
9. Your choices and rights
- You can leave analytics disabled and turn off “Usage analytics” at any time in app settings.
- You can revoke microphone, local-network and other applicable permissions in system settings; features relying on them will be affected.
- You can view and manage app books, reading records and voices using available editing, deletion, permanent deletion and cache-clearing actions. Export features, where available, let you keep a copy.
- You can manage system-search and widget visibility, stop Wi-Fi transfer, and delete copies saved to external services or other devices.
Depending on applicable law, you may also have rights to access, copy, correct or delete personal data, restrict processing and withdraw consent. Withdrawal does not change processing already performed before withdrawal. The app does not require registration and therefore has no app-account closure flow. Local device data, SDK instance data, Apple transactions and external copies require separate handling.
10. Minors
Minors should use the app with guidance from a parent or guardian, especially for recording voices, sharing files, online analytics and purchases. A guardian should decide whether to authorize analytics or recording for users under fourteen. The app is not designed to identify children or collect children’s personal information. Guardians can limit relevant features through device permissions and app settings.
11. Policy updates
This policy will be updated when features, SDKs or data processing change, with the updated date shown. Material changes to analytics purposes, recipients or other important processing will be communicated through in-app explanations or other appropriate notices, with renewed consent where required. Viewing this page alone does not authorize optional analytics or additional processing.