Privacy Policy
Effective August 28, 2026
The short version
GemReader collects nothing. No accounts. No cloud. No analytics. No automatic crash reports. No telemetry. Your books, highlights, notes, and reading habits stay on your device, encrypted, and are never transmitted anywhere. The app reaches the network only when you ask it to — to browse the built-in book catalog, to fetch a file you asked it to download, to download an optional read-aloud voice, or to open a page in the in-app browser — never to report on you. The one report the app can produce, a diagnostics file, is created only when you ask for it and goes only where you send it; it is described below.
Data collection
We collect no personal data. GemReader does not require account registration, and there is no GemReader server for it to send data to. The app contains no analytics SDKs, no crash reporting libraries, and no telemetry of any kind.
Diagnostics reports
Settings → Advanced → Security Diagnostics can export a zip describing your device's hardware and encryption health, the app and Android versions, and a rolling buffer of the last few hundred internal warnings and errors. It exists so a problem can be diagnosed without anyone needing to see your library. It is produced only when you tap the button, it is never generated or transmitted in the background, and it leaves your device only through the Android share sheet, to whatever destination you choose. Before anything is written to the buffer it is scrubbed: book and file names, hashes, encryption keys, PINs, email addresses, IP addresses, filesystem paths, and the hostnames of any custom catalogs you added are removed. Book titles, notes, highlights, bookmarks, and folder names are never written to it in the first place. If you send us a report at support@gemreader.com, we read it to fix the bug and keep nothing from it.
The website
This policy covers both the GemReader app and gemreader.com. The app collects nothing. The website is hosted on Vercel and uses Vercel Web Analytics, which counts page views without cookies and without building a cross-site profile of you. We also keep one aggregate counter of how many times the APK download link has been used — a single number, with nothing attached to it. Neither touches the app, your library, or anything inside it.
Downloading the app
The Download APK button redirects to a release asset on the public GitHub repository cnohall/gem-reader-releases. GitHub serves the file, and like any web server it sees your IP address and browser user agent for that request — that is GitHub's log under GitHub's privacy statement, not ours. Installing from Google Play instead puts that transaction under Google's terms.
Book storage and encryption
Every book you import — EPUB, PDF or otherwise — is encrypted at rest using AES-256 GCM before being written to your device's storage. Decryption happens in memory only — plaintext never touches your file system. Encryption keys are derived locally and never transmitted.
PIN-locked folders
PIN-protected folder keys are derived from your PIN using Argon2id (folders created by older versions use PBKDF2). The derived key is not stored in recoverable form. After 3 failed PIN attempts, the folder's encrypted files are permanently deleted and the keys are destroyed. There is no recovery mechanism — this is by design.
Screenshot and clipboard protection
When a locked folder is open, GemReader programmatically blocks the OS screenshot API and suppresses your content from appearing in the recent apps switcher. If you background the app while in a secure folder, the clipboard is wiped automatically.
The in-app book catalog
GemReader can browse and search catalogs of freely available books — Project Gutenberg, Standard Ebooks and Wolne Lektury are included, and you can add any HTTPS catalog you trust. When you open the catalog, search it, or download a book, your device talks directly to that site. Like any web server it sees your IP address and user agent for those requests, and that is logged under its privacy policy, not ours. Nothing about you or your library is attached: no account, no device identifier, no list of what you already have. There is no GemReader server in between — we never see that you opened the catalog, what you searched for, or what you downloaded. Books you download are encrypted on arrival exactly like the ones you import yourself. Ignore the catalog entirely and the app never contacts these sites.
Third-party services
No advertising network, analytics provider, crash reporter, or data broker is compiled into the app, and no code in it reports to us. The Google Play build does link a small number of Google's own libraries, and we would rather name them than hide behind a blanket claim: Play Asset Delivery, which fetches the optional font packs; the Play In-App Review library, which is how the occasional “rate GemReader” sheet is shown — that sheet is drawn and submitted by the Play Store app itself, so GemReader never learns whether it appeared or what you rated; Play Billing, which is present but dormant, because there is nothing to buy yet; and Google's on-device ML Kit library, currently unused by any feature you can reach. None of them are given anything about you or your library, and the build distributed from this website contains fewer of them still. Apart from Google Play's own services, the only outside servers the app ever contacts are the ones you point it at yourself: a book catalog, a Gem List download, a read-aloud voice hosted on GitHub, or a page you open in the in-app browser. The website is a different matter and is covered above: Vercel hosts it, GitHub hosts the APK, and Google Play distributes the store build.
Children's privacy
GemReader does not collect data from anyone, including children under 13. No personal information is gathered at any point.
Changes to this policy
If this policy changes materially, the updated version will be posted here with a new effective date. Since we collect no data, changes are unlikely to affect you in any practical way.
Permissions
File storage: used solely to read and write the books you import — no file content is transmitted outside your device. Network access: used only when you explicitly reach for it — browsing or downloading from the in-app book catalog, downloading a book listed in a Gem List, downloading an optional read-aloud voice or font pack, or opening the in-app browser; the app never contacts a GemReader server, because there isn't one. Camera (optional): used only when you choose to scan a QR code — the feed is processed locally in real time and is never recorded, saved, or transmitted. Biometrics (optional): used only for app lock, and verified by Android on-device. Notifications (optional): used only to display playback controls while a book is being read aloud, and to show progress while a font pack is being unpacked. The Android permission list also shows entries GemReader holds without using them today. RECORD_AUDIO is declared by the audio-playback and QR-scanning libraries it depends on; the app contains no recording code and will never prompt you for microphone access. The nearby-devices and Wi-Fi permissions belong to Gem Beam, an unreleased feature for copying a book straight from one phone to another over a direct Wi-Fi link with no server in between; no shipped build can start a transfer, and the permissions are flagged to Android as never used to derive your location.
Data deletion
All data stored by GemReader — encrypted books, annotations, reading progress, and encryption keys — resides exclusively on your device. Uninstalling the app permanently removes all of this data. There is no server-side data to delete.
Contact
Questions about this policy? Reach us at support@gemreader.com.