Privacy Policy

Effective date: July 15, 2026

Leer en español

This Privacy Policy explains how Inkspell ("we", "our", or "us") collects, uses, and protects your information when you use the Inkspell mobile application (the "App"). By using the App you consent to the practices described here.

Sections 1 to 13 describe the App. Our public website at theinkspell.com collects far less and is described separately in Section 14, which covers the cookie banner shown there and the launch waitlist.

1. Information we collect

We collect only the information necessary to deliver the App's features:

  • Account information — Email address, display name, and a unique user identifier. Provided through Firebase Authentication when you sign in with Google, Apple, or email/password.
  • Anonymous identifier (before sign-in) — When you start the onboarding quiz, we issue you a temporary anonymous identifier via Firebase Authentication. This identifier lets us save your quiz answers, your generated companion portrait, and any subscription you purchase, so that they are transferred to your real account once you complete sign-up. If you abandon the onboarding flow, the anonymous identifier and any data attached to it are automatically deleted after 30 days (see Section 5).
  • Onboarding quiz answers — Your responses to the optional pre-account quiz (genre preferences, reading frequency, struggles you face when reading, a self-chosen adventurer name, and the text prompt you type to generate a companion portrait). We use these to personalize the recommendation we show you on the paywall and, after sign-up, to keep your library tailored to your preferences. Quiz answers are tied to your anonymous identifier until you sign up; if you never sign up, they are deleted with the anonymous account.
  • Uploaded book files — Book files (EPUB or PDF) you upload to use the App's reading-aid features. These files are stored on our infrastructure (Google Cloud Storage). See Section 5 (Data retention) for how long we keep them and when they are deleted, Section 10 (Your responsibilities for uploaded content) and Section 11 (Intellectual property) for additional terms.
  • Reading activity — Your current chapter and reading progress, used to keep your library in sync across devices and to filter spoilers.
  • App activity signals — When usage analytics is enabled (see Section 1 analytics above and Section 7), the App periodically records that your account was recently active and which book you are currently reading. We use this to understand how many readers are active and to target relevant service notifications. This is governed by the same consent as product analytics: it is off until you opt in within the EU, EEA, United Kingdom, and Switzerland, and you can turn it off anywhere in Settings → Privacy. Turning it off also deletes the recorded activity signals.
  • User-generated content — Optional customizations you make to your library (renamed entities, hidden items, selected portrait variants).
  • Subscription information — Your subscription tier, status, and renewal dates as reported to us by RevenueCat after a purchase. We do not see your payment card details — those are handled exclusively by Google Play or the Apple App Store.
  • Push notification token — A device-specific token from Firebase Cloud Messaging used to deliver notifications. We do not collect general device identifiers (advertising ID, IMEI, or hardware identifiers) outside this token.
  • Product-analytics data — To understand how the App is used and to improve it, we use PostHog, a first-party product-analytics provider. PostHog stores a pseudonymous analytics identifier and basic usage events (for example, which onboarding steps you complete and which features you use), together with device context (model, operating system, app version, language) and your IP address, which is used only to infer a coarse region on our servers. We do not enable automatic screen or tap capture, session recording, or any advertising or cross-app tracking, and we do not send PostHog your name, email address, book titles, or portrait prompts. In the EU, EEA, United Kingdom, and Switzerland this analytics is disabled until you opt in; everywhere else you can turn it off at any time in Settings → Privacy. See Section 4.
  • Crash and error diagnostics — To detect and fix bugs and crashes, we collect diagnostic reports when the App encounters an error or crashes. These reports include the error type and message, a stack trace, and device/app context (device model, operating system, app version), and may be associated with your account identifier so we can reproduce the problem. Errors on the JavaScript layer are captured by PostHog; native crashes, application-not-responding events, and out-of-memory terminations are captured by Google Firebase Crashlytics. Diagnostics are treated as part of the same analytics choice: in the EU, EEA, United Kingdom, and Switzerland they are disabled until you opt in, and everywhere else you can turn them off at any time in Settings → Privacy. We do not use crash or error data for advertising or cross-app tracking, and we never include your book content or portrait prompts in a report.

We do not collect: location data, contacts, calendar, photos outside what you upload, microphone audio, biometric data, web browsing history, or advertising identifiers. The App contains no advertisements, no advertising identifiers, and no cross-app tracking. The only analytics we use is the first-party product analytics described above and in Section 4.

2. How we use your information

  • To authenticate you and maintain your account.
  • To process your uploaded books through our AI pipeline, generate entity glossaries, character relationships, and chapter summaries, and deliver them to your device.
  • To synchronize your reading progress and library across your devices.
  • To filter content so you do not see spoilers.
  • To verify your subscription status and grant you access to features your subscription includes.
  • To send push notifications about content you have requested (e.g., when book processing finishes).
  • To maintain the security and integrity of our services and to comply with legal obligations.

3. Our reading aids and service catalog

When you use Inkspell with a book, the App generates reading aids — entity glossaries, character information, relationship maps, and chapter summaries — through automated AI processing of the book's text. These reading aids are part of Inkspell's service catalog and are produced and maintained by us.

Your personal use of the App — your reading progress, your customizations (renamed entities, hidden items, selected portrait variants, personal notes), and your library entries — is private to your account and is deleted when you delete your account (see Section 7).

The reading aids themselves, as part of our service catalog and as our intellectual property (see Section 11), are retained independently of any individual user account so that Inkspell can continue to offer them as a service.

4. Service providers

We use the following third-party service providers to operate the App. Each processes your data only as needed to deliver their service to us, under their respective privacy commitments.

  • Google Firebase — Authentication, database, storage, push notifications, and hosting. Privacy: firebase.google.com/support/privacy
  • Google Cloud Platform — Backend processing infrastructure (Cloud Run, Cloud Tasks). Privacy: cloud.google.com/terms/cloud-privacy-notice
  • Google Gemini API — AI processing of your uploaded book text to generate glossaries and summaries. Book text is sent to Google's API for processing and is governed by Google's Gemini API terms.
  • fal.ai — Image generation for character portraits. Receives only generated text descriptions, not your personal information.
  • RevenueCat — Subscription management and entitlement verification. Privacy: revenuecat.com/privacy
  • PostHog — First-party product analytics that help us understand how the App is used and improve it. PostHog processes a pseudonymous analytics identifier, usage events, device context, and your IP address (used for coarse server-side region detection only) on our behalf and under our instructions — not for its own purposes. We have disabled automatic screen/tap capture and session recording, and we never send PostHog your name, email, book titles, or portrait prompts. PostHog also records diagnostic reports of JavaScript errors (error message, stack trace, and device/app context) under the same analytics choice. This data is hosted in the United States. In the EU, EEA, United Kingdom, and Switzerland, product analytics and diagnostics are off until you opt in; elsewhere you can opt out at any time in Settings → Privacy. Privacy: posthog.com/privacy
  • Google Firebase Crashlytics — Native crash and stability reporting. When the App crashes or becomes unresponsive, Crashlytics processes a crash stack trace, device state, a Crashlytics installation identifier, and (where you are signed in) your account identifier, on our behalf, so we can diagnose and fix the problem. It is governed by the same analytics choice — off until you opt in in the EU, EEA, United Kingdom, and Switzerland, and toggleable everywhere else in Settings → Privacy. Crash reports are retained by Crashlytics for up to 90 days. Privacy: firebase.google.com/support/privacy
  • Google Play Billing / Apple App Store — Payment processing. We never receive your payment card details.
  • Upstash — Rate limiting infrastructure (no personal data stored beyond ephemeral request counts).
  • Google Play Integrity / Apple App Attest — Used by Firebase App Check to verify that requests to our backend originate from the genuine Inkspell app on a genuine device. These services receive a short-lived device-attestation token only; they do not receive your personal information or your account identifier.

We do not sell your personal information. We do not share your personal information with advertising networks, data brokers, or analytics providers for their own purposes.

5. Data retention

  • Account data — Retained while your account is active. Deleted in line with Section 7 when you delete your account.
  • Deletion record — After you delete your account, we retain a minimal record (the deletion timestamp and your account email) for 18 months. This lets us continue to honor your deletion request against any subscription still active through the App Store or Play Store during that window; the record then expires automatically.
  • Anonymous identifiers and onboarding data — If you start the onboarding quiz but do not complete sign-up, your anonymous Firebase Authentication record, your quiz answers, and any companion portrait you generated are automatically deleted after 30 days of inactivity. Anonymous identifiers do not count toward our user usage records once this cleanup runs.
  • Uploaded book files — the book file you upload is stored privately and used only to build and maintain your reading companion data. It is never shared with, displayed to, or downloadable by anyone. We permanently delete your uploaded file when you delete the book from your library or delete your account.
  • Inkspell-generated reading aids — Retained as part of our service catalog (see Section 3 and Section 11).
  • Subscription transaction records — Retained as long as required by tax and consumer-protection laws (typically 5–7 years), and may be kept in anonymized form after the legal retention period.
  • Backups — Containing your data are retained for up to 30 days after a deletion request before being purged.
  • Upload statistics — We keep an aggregate ledger of upload outcomes for service statistics. When you delete your account, these entries are permanently disassociated from your identity — the statistics survive, the link to you does not. (Withdrawing analytics consent deletes your analytics data, as described in Section 7, but does not affect this operational ledger until account deletion.)

6. Security

We protect your data using industry-standard practices: encryption in transit (HTTPS/TLS), encryption at rest in Firebase and Google Cloud Storage, access controls based on Firebase Authentication, server-side authorization on every API request, and minimum-privilege service accounts. No security system is perfect, and we cannot guarantee absolute security.

7. Your rights

Depending on your jurisdiction (including the EU/EEA under GDPR and California under CCPA), you may have the following rights:

  • Access — Request a copy of your personal data.
  • Correction — Request that we correct inaccurate data.
  • Deletion — Request that we delete your account and personal data. See our account deletion page.
  • Portability — Request your data in a portable format.
  • Withdraw consent — Where processing is based on consent, you may withdraw it. You can turn product analytics and crash diagnostics on or off at any time in Settings → Privacy in the App. Withdrawing is not just prospective: when you turn analytics off, we also delete the analytics data already collected about you (your analytics profile and events, onboarding analytics, and recorded activity signals). Crash reports already uploaded to Crashlytics cannot be individually deleted but expire automatically within 90 days. Deleting your account erases the rest of your personal data (see Section 5).
  • Object / restrict — Object to certain processing or request restriction.
  • Lodge a complaint — With your local data protection authority.

To exercise these rights, email us at support@theinkspell.com. We will respond within 30 days.

8. Children

The App is not directed to children under 13 (or under the age of digital consent in your country). We do not knowingly collect information from children under 13. If you believe a child has provided us their information, contact us at support@theinkspell.com and we will delete it.

9. International data transfers

Several of our service providers — including Google (Firebase, Google Cloud Platform, and the Gemini API), RevenueCat, PostHog, and fal.ai — operate from the United States. As a result, your personal data is transferred to and processed in the United States, and may be processed in other countries where our providers operate. Where we transfer personal data out of the EU/EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, a provider's certification under the EU–U.S. Data Privacy Framework. You may contact us at the address in Section 13 for more information about these safeguards.

10. Your responsibilities for uploaded content

You are solely responsible for the book files and any other content you upload to the App. By uploading, you represent and warrant that:

  • You own the content or have obtained all rights, licenses, and permissions necessary to upload it and to allow us to process it as described in this Policy.
  • The content does not infringe the copyright, trademark, trade secret, privacy, publicity, or other rights of any third party.
  • The content complies with all applicable laws and regulations in your jurisdiction and in the jurisdictions where Inkspell operates.

We do not verify the legality or originality of uploaded content. Inkspell is not liable for content you upload, and you agree to indemnify Inkspell against any claims arising from your uploaded content.

We do not distribute, share, or otherwise make uploaded book files available to other users.

11. Intellectual property

All reading aids generated by the App — including but not limited to entity glossaries, character profiles, relationship maps, chapter summaries, biographies, and any other AI-generated or editorial content produced by Inkspell — are the exclusive intellectual property of Inkspell. They are part of our service catalog.

Your subscription grants you a personal, non-exclusive, non-transferable license to access and use these reading aids within the App for your personal, non-commercial use. The license terminates when your subscription ends or your account is deleted. You acquire no ownership interest in the reading aids or in any other Inkspell intellectual property.

You retain whatever rights you held in the original content you uploaded, subject to Section 10.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice or email. The "Effective date" at the top reflects the most recent revision.

13. Contact us

For privacy questions, requests, or complaints: support@theinkspell.com

14. Our website (theinkspell.com)

This section covers our public website at theinkspell.com only. The website has no accounts and stores none of your files. It collects far less than the App.

  • Analytics that runs for every visitor — We measure how far people get through the page, using PostHog. This is built so that nothing is stored on your device: no cookies, nothing written to local or session storage, no profile created for you, and no recording of your screen or of what you type. Every visit is a fresh, unlinked session, so we cannot tell that two visits are the same person. We record that the page was opened, whether you began scrolling, how far you reached, which sections you saw, whether you reached the download screen, and whether you opened or completed the waitlist form, together with ordinary technical details your browser sends to any website: browser, operating system, device type, screen and window size, language, timezone, the page address, and the site you arrived from.
  • Approximate location — Your IP address is used, at the moment your visit is received, to derive an approximate location: country, region, city, and a position accurate to roughly 20 kilometres. The IP address itself is not stored. We keep the approximate location; we do not keep the address it came from. We use this to understand which countries our visitors come from.
  • Analytics that only runs if you agree — If you accept the cookie banner, we additionally use Google Analytics, which does set cookies on your device that can recognise a returning visitor. It runs only after you click Accept. If you decline, or ignore the banner, Google Analytics is never downloaded at all.
  • Changing your mind — The Cookie settings control is on screen throughout your visit. Withdrawing takes effect immediately: collection stops and the cookies already set are deleted, rather than waiting until your next visit. We store your choice itself on your device so that we do not ask again on every page load. That one item is necessary to honour your decision and is kept whichever way you answer.
  • The launch waitlist — If you submit your email address to be told when the App is released, we store the address, which button you used, your browser language, and the date. The record is filed under a one-way cryptographic hash of your address rather than the address itself, so it does not appear in system paths or logs. We use it for that one announcement and nothing else: not a newsletter, not marketing, and never sold or shared.Your address is never sent to either analytics system — our analytics records only that someone joined, never who. Write to us and we will delete it.
  • Providers — PostHog (product analytics, processed in the United States), Google (hosting, the waitlist database, and the consent-based analytics), and Cloudflare (which serves the images and video). Serving a website necessarily involves these providers receiving your IP address, as any website does, in order to send the page to you. See Section 9 on international transfers.
  • What we do not do on the website — No advertising or tracking cookies and no ad-network pixels, no cross-site tracking, no selling or sharing of data with data brokers, no session recording, and no fingerprinting or attempt to identify you across visits.

See also: Terms of Service · How to delete your account