Privacy Policy

Your stories, your data,
your shelf.

How FavRead collects, uses, and protects the personal information you share with us — written in plain language, in the same spirit we curate our books.

Read the full policy → Ask a question
Last updated March 14, 2025
Effective date April 1, 2025
Document version v2.1 — Revised
Jurisdiction GDPR · CCPA · CPRA
Scroll to read
About this document

A privacy policy should read like a good foreword — clear, honest, and worth your time.

FavRead is a curated library of contemporary fiction, family drama, and the quieter stories in between. This policy explains what we collect when you read with us, why we collect it, and the choices you have. The preview below mirrors the app you already know.

FavRead · Today's shelf
Home / Discover
All Family Drama Contemporary Fiction Literary
The Scenic Route
The Scenic Route
Helen Carroway
Susan cleans out the old Volvo — and a life tumbles out.
★★★★☆
The Amber Light
The Amber Light
Mon D. Ong
In a hospital corridor, Lena finally sees her mother.
★★★★★
The Ferryman's Bargain
The Ferryman's Bargain
V. M. Ashford
Becca strikes a quiet deal with the man at the crossing.
★★★★☆
The Charity Teddy
The Charity Teddy
L. K. Voss
Isla's coat catches in the truck door — and time stops.
★★★★☆
01

Introduction

FavRead ("we", "us", or "our") operates a mobile application and web service that offers a curated collection of contemporary fiction, family drama, and related literary works for discovery and reading. We built FavRead on a simple belief: the relationship between a reader and their library is private.

This Privacy Policy describes what personal information we collect when you use FavRead, how we use it, the choices available to you, and the safeguards we have put in place. It applies to the FavRead iOS app, Android app, and any web-based experience we operate under the FavRead name.

This policy is written in plain language. Where legal terms are necessary, we explain them. If anything here is unclear, please contact us — we would rather answer a question than leave you guessing.

In short

We collect what we need to run FavRead: your account details, your reading activity, and basic device information. We do not sell your personal data. We do not share your reading history with advertisers. We do not track you across other apps or websites.

02

Information We Collect

We collect information in three ways: information you give us directly, information collected automatically when you use FavRead, and information from third parties (only when strictly necessary, such as a sign-in provider).

2.1 — Information you provide directly

  • Account information — your name, email address, and a password (stored as a one-way hash) when you create a FavRead account.
  • Profile preferences — the genres and themes you tell us you enjoy, such as "Family Drama" or "Contemporary Fiction", so we can curate your home shelf.
  • Reading lists and notes — books you save, ratings you give, and any annotations you write in the margins of stories that support them.
  • Support requests — anything you tell us when you write to support, including the content of your message and any attachments.
  • Optional profile fields — a display name, bio, and avatar, if you choose to add them.

2.2 — Information collected automatically

When you open FavRead, certain information is collected by your device and our servers in the normal course of operation:

  • Reading activity — which stories you open, how far you read, ratings you assign, and titles you add to your shelf. This powers your recommendations and your "continue reading" queue.
  • Device and technical information — device type, operating system version, app version, screen size, language setting, and a randomized device identifier that resets on uninstall.
  • Connection information — IP address (truncated for storage), approximate region derived from IP, and timestamps of your sessions.
  • Crash and performance data — anonymous diagnostics when the app crashes or performs slowly, so we can fix what is broken.

2.3 — Information from third parties

If you sign in with Apple, Google, or another provider, we receive the email address and name you authorize them to share — nothing more. We do not request, and they do not provide, access to your contacts, posts, or friends list.

What we do not collect

We do not access your phone's contacts, photo library, microphone, or precise location. We do not read your text messages. We do not scan other apps on your device. If FavRead ever needs a new permission, we will ask — and explain why — before it is granted.

03

How We Use Your Information

We use your information to do five things — and only these five things:

Purpose What we use Why
Provide the service Account info, reading activity To display your shelf, sync across devices, and remember where you stopped reading.
Curate recommendations Genre preferences, ratings To suggest stories you may enjoy — never to sell you anything.
Communicate with you Email address For account security, support replies, and the newsletter if you opt in.
Improve FavRead Aggregated usage data, crash logs To fix bugs, understand which features are loved, and plan what to build next.
Protect the service IP address, device ID, session logs To detect abuse, prevent fraud, and block accounts that harm the community.

We do not use your information to build a profile for advertisers. We do not use your reading history to train external AI models. We do not share, sell, or rent your data to third parties for their own marketing purposes.

A library keeps its borrowers' records private. FavRead keeps yours.
04

Information Sharing & Disclosure

We share your information only in the limited circumstances described below. We never sell your personal data — this is a position we have written into our company bylaws, and it cannot be changed without a formal, public revision of this policy.

4.1 — Service providers

We work with a small number of trusted vendors who help us operate FavRead. Each is bound by contract to handle your data only on our behalf, for the specific purpose we have defined, and to delete it when their work is complete.

  • Cloud hosting — where your account and shelf data are stored.
  • Email delivery — for transactional messages and the optional newsletter.
  • Crash reporting — for diagnosing app stability issues.
  • Payment processing — if you subscribe to FavRead Premium, your card details never touch our servers.

4.2 — Legal requirements

If we receive a valid legal request — a court order, a regulator's demand, or a lawful government request — we may be required to disclose specific information. We will narrow the disclosure to what is legally required and, where we are permitted, we will tell you it happened.

4.3 — Safety and harm prevention

If we believe someone is in serious danger — a credible threat of self-harm, for instance — we may share limited information with the appropriate authorities. This is rare, and we document every instance internally.

4.4 — Business transfers

If FavRead is ever acquired, merged, or restructured, your information may transfer to the new entity. We will notify you by email before any such transfer, and the new entity must honor this policy or give you the opportunity to delete your account first.

Our promise

No advertiser, no data broker, no AI training partner has ever received a copy of your reading history. They never will.

05

Data Security

We treat your reading life the way we would treat our own: with care, with reasonable caution, and with the understanding that no system is ever perfectly secure. Here is what we do:

  • Encryption in transit — every connection between the FavRead app and our servers uses TLS 1.3. Your data does not travel in plain text.
  • Encryption at rest — your account information, reading history, and annotations are encrypted on disk using AES-256.
  • Hashed passwords — we never see your password. It is hashed with bcrypt before it ever reaches our database.
  • Strict access controls — only a small number of engineers can access production data, and only through individual, audited credentials. No shared logins.
  • Regular reviews — we conduct internal access reviews quarterly and engage an external security firm annually.
  • Breach response — if a breach occurs, we will notify affected users within 72 hours of confirming it, in line with GDPR Article 34.

Security is a discipline, not a destination. If you believe you have found a vulnerability in FavRead, please write to security@favread.app. We respond to credible reports within 48 hours and credit researchers who help us improve.

06

Cookies & Tracking Technologies

FavRead's mobile app does not use third-party advertising cookies. The web experience uses a small number of first-party cookies and local storage entries that exist for one of two purposes: keeping you signed in, and remembering your reading preferences.

Cookie Purpose Duration
fr_session Keeps you signed in 30 days
fr_prefs Remembers theme, font size, reading width 1 year
fr_csrf Protects forms from cross-site request forgery Session
fr_anon Aggregated, anonymized analytics (no personal identifiers) 24 hours

You can clear cookies at any time through your browser settings. Doing so will sign you out of FavRead on the web, but will not affect your mobile app session.

No advertising trackers

We do not use the Facebook Pixel, Google Ads, or any third-party advertising SDK. FavRead's analytics are first-party and aggregate. We cannot tell what else you do on the internet.

07

Your Privacy Rights

Depending on where you live, you may have specific legal rights regarding your personal information. FavRead honors these rights for all users, regardless of jurisdiction — privacy should not be a regional perk.

Rights you always have

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix inaccurate information.
  • Deletion — request that we erase your account and associated data.
  • Portability — receive your data in a structured, machine-readable format (JSON or CSV).
  • Objection — ask us to stop using your data for a specific purpose.
  • Restriction — request that we limit processing while a dispute is resolved.
  • Withdrawal of consent — withdraw any consent you previously gave, at any time, without giving a reason.

How to exercise these rights

Open FavRead, go to Settings → Privacy → Data controls, and choose "Download my data" or "Delete my account". You can also write to us at privacy@favread.app. We respond to all requests within 30 days.

If you live in California

Under the CCPA and CPRA, California residents have the right to know what personal information is collected, request deletion, opt out of any "sale" or "sharing" of personal information, and not be discriminated against for exercising these rights. FavRead does not sell or share personal information as defined by California law.

If you live in the EU, UK, or EEA

Under GDPR, you have additional rights including the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first — most concerns can be resolved directly and faster — but you are free to approach the regulator at any time.

08

Children's Privacy

FavRead is designed for general audiences. We do not knowingly collect personal information from children under 13 (under 16 in EU member states that have set a higher age). The stories we curate span a range of themes — some family drama, some contemporary fiction — and may include content intended for mature readers.

If you believe a child has provided us with personal information without parental consent, please write to privacy@favread.app. We will delete the information promptly and close the account.

Parents who wish to share FavRead with younger readers may set up a shared family account and use the platform together — that is a choice many of our readers have made, and one we support. We do not, however, currently offer a dedicated kids' mode.

09

International Data Transfers

FavRead is used by readers around the world. Your information may be processed in countries other than your own — including the United States, Ireland, and Singapore — depending on where our servers and service providers are located at a given time.

When we transfer your data across borders, we use one of the following safeguards:

  • Standard Contractual Clauses approved by the European Commission.
  • The UK International Data Transfer Addendum for transfers from the United Kingdom.
  • Adequacy decisions — for transfers to countries recognized by your jurisdiction as providing adequate protection.

If you would like a copy of the relevant transfer mechanism, we will provide one on request.

10

Changes to This Policy

We will update this policy from time to time. When we do, we will:

  • Revise the "Last updated" date at the top of this document.
  • Notify you by email if the changes are material and affect how your data is used.
  • Maintain a public changelog of every revision, with prior versions available for review.

Material changes — for instance, a new purpose for which we use your data, or a new category of information we collect — will take effect 30 days after we send the notification. Continued use of FavRead after that period constitutes acceptance of the revised policy.

If you do not agree with a change, you may close your account at any time. We will export your reading history to you first, so nothing is lost.

Changelog

v2.1 — March 14, 2025 — Clarified analytics practices; added AI training commitment.
v2.0 — January 8, 2025 — Comprehensive rewrite aligned with CPRA.
v1.4 — August 22, 2024 — Added international transfer safeguards.
v1.0 — March 3, 2024 — Initial publication.

11

Contact Us

If you have questions about this Privacy Policy, your personal information, or anything else related to how FavRead handles your data, we would genuinely like to hear from you. Privacy is not a department here — it is everyone's job, and a real person reads every message.

Reach us directly

We answer within two business days.

Privacy enquiries
Data Protection Officer
Security reports
Postal address
FavRead, Ltd.
42 Marginal Way, Suite 300
Portland, ME 04101
United States
EU representative
FavRead EU Representative
14 Pearse Street
Dublin 2, D02 YX60
Ireland
Response time
2 business days — all enquiries
48 hours — security reports
30 days — data subject requests