Legal
Privacy Policy
Last updated: 4 August 2026
This Privacy Policy explains what personal data Readence collects, why we collect it, and the rights you have over it. It applies to the Readence mobile app and the readence.hu website.
1. Who we are
Readence (“Readence”, “we”, “us”) is operated by Gere Lajos e.v., a sole proprietor established in Hungary, European Union. For the purposes of the EU General Data Protection Regulation (GDPR), Gere Lajos e.v. is the data controller for your personal data.
If you have any questions about this policy or your data, contact us at hello@gerelajos.hu.
2. Data we collect
We collect only the data we need to provide and improve Readence:
- Guest account & device identifier: the first time you open Readence, we create a guest account on our servers so that your reading, goals, and streaks are saved from the very first session — before you sign up for anything. A guest account is a pseudonymous record: a random account identifier, your reading activity, and a random identifier stored on your device so we recognise the same installation. It holds no name and no email address, but it is still personal data under the GDPR, which is why we disclose it here. The legal basis is performance of a contract — it is what makes the app work before you have an account. If you later sign up, that same record becomes your account. Guest accounts that go unused for 180 days are deleted automatically (see section 9).
- Account data: your email address and your display name / handle.
- Authentication identifiers: when you sign in with Apple or Google, we receive an account identifier from that provider so we can recognise you. We do not receive your provider password.
- Authentication credentials: if you sign up with an email address and password, we store a hash of your password, never the password itself. We also store short-lived email-verification codes and password-reset tokens, and one API token per signed-in device so that you stay signed in.
- Reading activity: reading progress, streaks, and statistics. We use this to provide the core service and to sync your progress across your devices.
- Device & advertising identifiers: collected via Google AdMob, and only with your consent. On iOS this is gated by App Tracking Transparency (ATT), and in the EU by Google’s User Messaging Platform (UMP) consent flow.
- Subscription status: whether you have an active subscription and which entitlements it grants. Purchases themselves are processed by Apple; subscription state is managed on our behalf by RevenueCat.
- IP address & server logs: our servers record the IP address, timestamp, requested address, and app or browser identification of requests made to the Readence API and website. We need these to run the service safely — to rate-limit sign-in attempts, detect abuse, and diagnose failures. They are kept for 30 days (see section 9).
3. Books you upload stay on your device
This is important: book files you add from your device stay on your device. Readence stores only the book’s title, metadata, cover image, and a content hash on its servers so we can show your library and sync your progress. The book file itself is never uploaded to us.
You are responsible for ensuring you have the rights to any file you add to Readence.
4. How we use your data
- To create and maintain your account and authenticate you.
- To provide the core reading experience and sync your library, progress, and streaks across devices.
- To manage your subscription and unlock the features it includes.
- To show advertising (only with your consent), and to measure and improve it.
- To prevent abuse, diagnose failures, and keep the service secure.
5. Legal bases (GDPR)
- Performance of a contract: providing the app, your account — including the guest account created when you first open Readence — sync, and subscriptions.
- Consent: advertising and advertising/device identifiers, obtained through ATT and Google’s UMP consent flow. You may withdraw consent at any time.
- Legitimate interests: keeping the service secure, preventing abuse (including rate limiting and server logs), and diagnosing failures from those logs.
6. Advertising
Readence uses Google AdMob to show ads. Personalized (interest-based) ads are shown only where you have given consent; without consent, ads are limited to non-personalized ads. Google may process device and advertising identifiers as an independent controller for its own purposes. See Google’s partner privacy policy for details.
7. Payments & subscriptions
Subscriptions are sold and billed by Apple through the App Store. Readence never receives or stores your card or payment details. We use RevenueCat to process and verify your subscription entitlements so we know which features to unlock.
8. Sub-processors
We share data with the following service providers as needed to run Readence:
- Apple: Sign in with Apple and App Store billing.
- Google: AdMob advertising and Google Sign-In.
- RevenueCat: subscription entitlement processing.
- Our hosting provider: application, database, and backup hosting on a virtual private server located in the European Union.
- Resend: transactional email — verification codes, password resets, and account notices.
9. Data retention
We keep personal data only for as long as we need it, and we delete it on the schedule below. Each period runs from the moment the data is created or last used.
- Guest accounts: if you never sign in, the guest account is deleted automatically after 180 dayswithout use, together with everything attached to it — the device identifier and your reading activity included.
- Account data and reading activity: kept for as long as your account exists.
- Deleted accounts: deleted, not deactivated. We remove the account and the personal data attached to it, and keep only an anonymised placeholder containing no personal data, so that other people’s follows, counts, and feeds do not break.
- Server logs (IP address and request metadata): 30 days.
- Database backups: 14 days, then overwritten. Data you deleted may still exist in a backup until that backup expires.
- Authentication credentials: verification codes and password-reset tokens expire within minutes or hours; a device’s API token lasts until you sign out, revoke it, or delete your account.
- Records we are required to keep (for example accounting records relating to a subscription): for as long as the applicable law requires, even after your account is deleted.
Deleting your account. You can delete your account from inside the app, on the Settings → Account → Delete account row. It takes effect straight away, it is there for guest accounts as well as signed-in ones, and it removes the account together with the personal data attached to it, as described above. If you would rather we did it for you, email hello@gerelajos.hu and we will action the request within 30 days. Deleting your account does not cancel an active App Store subscription — cancel that in your App Store account settings, or it will continue to bill.
10. Your rights
If you are in the EU/EEA, the GDPR gives you the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- receive your data in a portable format (data export);
- restrict or object to certain processing;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these rights, email hello@gerelajos.hu. You also have the right to lodge a complaint with your local data protection authority (in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH).
Data export. You can export your data from inside the app, on the Settings → Account → Export my data row. It returns a machine-readable copy of everything your account holds: your profile, the sign-in methods linked to it, your devices and open sessions; the books you added, your reading progress and every reading session; your subscription entitlements; your streak, your daily totals and every individual XP entry behind them; the reports you have filed and whether your account is suspended; the activity your friends were shown about you; and your social graph — friends, friend requests in both directions, and the people you have blocked or muted. Two things are deliberately left out, because handing them over would expose somebody else: reports filed about you, and who has blocked or muted you. Purchase and billing history is not ours to give — Apple bills you, and it is exportable from your App Store account. Like deletion, it is there for guest accounts too, and there is nothing to wait for. If you would rather we sent it to you, email hello@gerelajos.hu and we will do so within 30 days.
11. Children
Readence is not for anyone under 16. We are established in Hungary, where the age of digital consent under Article 8 of the GDPR is 16 — and because parts of Readence (in particular advertising) rely on consent, someone aged 13 to 15 in Hungary cannot give that consent validly. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
12. International transfers
Some of our sub-processors (such as Apple, Google, RevenueCat, and Resend) may process data outside the EU/EEA. Where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you in the app.
14. Contact
Gere Lajos e.v. (Hungary, EU) , hello@gerelajos.hu.
