Privacy Policy
Last updated: April 6, 2026
This Privacy Policy describes how Leaf - Book & Reading Tracker ("the App", "we", "us", or "our") collects, uses, and discloses information when you use our mobile application, including optional account creation, cloud sync, and subscription features.
By using the App, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Information We Collect
1.1 Account Information
When you create an account using Apple Sign-In or Google Sign-In, we collect:
- Authentication identifiers: A unique user ID provided by your sign-in provider (Apple or Google)
- Email address: As provided by your sign-in provider, used for account identification and communication
- Display name: If provided by your sign-in provider
Account creation is optional. You can use the App without creating an account, in which case your data is stored locally on your device only.
1.2 Reading Data (Cloud Sync)
If you subscribe to Leaf Pro and enable cloud sync, we store the following data on our servers:
- Your book library (titles, authors, page counts, cover images)
- Reading progress and session history
- Reading streaks and milestones
- App preferences and settings
If you enable the AI integration feature (see section 3.6), a subset of this reading data may also be shared with third-party AI assistants during active sessions.
1.3 Location Information
We may request access to your device's location to determine your country for currency and pricing purposes (e.g., displaying the correct subscription price). We do not use location data for tracking, advertising, or any other purpose.
1.4 Automatically Collected Information
We use third-party analytics tools that may automatically collect certain information, including but not limited to:
- Device type, operating system, and app version
- Usage data such as screens viewed, interactions, and session duration
- Approximate location derived from IP address
2. How We Use Your Information
We use the collected information for the following purposes:
- To provide and operate the App's features, including cloud sync
- To authenticate your identity and manage your account
- To sync your reading data across your devices
- To process and manage your subscription
- To improve user experience and app performance
- To understand how users interact with the App
- To display advertisements (free tier only)
- To comply with legal obligations
3. Third-Party Services
3.1 Authentication & Cloud Storage – Supabase
We use Supabase for user authentication and cloud data storage. Supabase processes your account information and synced reading data on secure servers.
You can learn more about how Supabase processes data by reviewing their Privacy Policy: https://supabase.com/privacy (opens in new tab)
3.2 Subscription Management – RevenueCat
We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes purchase receipts and subscription status information.
You can learn more about how RevenueCat processes data by reviewing their Privacy Policy: https://www.revenuecat.com/privacy (opens in new tab)
3.3 Analytics – Mixpanel
We use Mixpanel for product analytics. Mixpanel helps us understand how users interact with the App.
You can learn more about how Mixpanel processes data by reviewing their Privacy Policy: https://mixpanel.com/legal/privacy-policy/ (opens in new tab)
3.4 Error Tracking – Bugsnag
We use Bugsnag for error tracking and crash reporting. Bugsnag helps us identify and fix technical issues in the App.
You can learn more about how Bugsnag processes data by reviewing their Privacy Policy: https://www.bugsnag.com/privacy-policy/ (opens in new tab)
3.5 Advertising – Google AdMob
The App uses Google AdMob to display advertisements to free-tier users. AdMob may collect and use data to provide personalized or non-personalized ads, depending on your consent and applicable laws. Leaf Pro subscribers do not see ads.
You can learn more about Google's data practices here: https://policies.google.com/privacy (opens in new tab)
3.6 AI Integration – Third-Party AI Assistants
Leaf Pro subscribers may connect their reading library to supported third-party AI assistants (including ChatGPT, Claude, and Notion) via the Model Context Protocol (MCP). When this integration is active, your reading data — including your book library and reading progress — is transmitted to the connected AI service during the session.
We do not control how third-party AI providers store, process, or use data received during a session. You should review the privacy policy of any AI service you connect before enabling the integration.
The integration is opt-in and requires explicit setup. You can disconnect it at any time by removing Leaf from your AI assistant's connected services.
3.7 Affiliate Programs – Amazon and Partners
The App includes a "Buy book" feature that links to Amazon and other booksellers. When you tap a seller link, the URL may include an affiliate tag that identifies Leaf as the referrer. If you complete a purchase through one of these links, Leaf may earn a small commission at no additional cost to you.
These links open external websites. We do not share any personal data about you with these sellers beyond what is contained in the URL (book identifiers and the affiliate tag). Data collected once you leave the App is governed by the respective seller's privacy policy.
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Consent: When you grant permission, such as for accessing location data or creating an account
- Contract: To provide cloud sync and subscription services you have purchased
- Legitimate Interests: To improve and maintain the App
- Legal Obligations: To comply with applicable laws and regulations
5. Your Privacy Rights
5.1 GDPR Rights (EEA Users)
Under the GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Request deletion of your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
5.2 CCPA & CPRA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the right to:
- Know what personal information is collected, used, shared, or sold
- Request access to their personal information
- Request deletion of their personal information
- Correct inaccurate personal information
- Limit the use and disclosure of sensitive personal information
- Opt out of the sale or sharing of personal information
- Not be discriminated against for exercising privacy rights
We do not knowingly sell personal information. Some data sharing with advertising partners may be considered "sharing" under CPRA.
5.3 CalOPPA (California Online Privacy Protection Act)
In compliance with CalOPPA:
- Users can visit the App anonymously where possible
- This Privacy Policy is accessible within the App
- Users will be notified of any Privacy Policy changes on this page
- We currently do not respond to Do Not Track (DNT) signals, as there is no industry standard for compliance
6. Account Deletion
You may delete your account at any time from the App's Settings screen. When you delete your account:
- Your authentication credentials and account profile are permanently deleted
- All cloud-synced reading data is permanently deleted from our servers
- Your local data on your device is not affected and remains available
- Any active subscription must be cancelled separately through Apple or Google
7. Children's Information
The App is not intended for children under the age of 13. We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us and we will delete such information.
8. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
If your Leaf Pro subscription expires or is cancelled, your cloud data is retained for 90 days. After 90 days without an active subscription, your cloud data is permanently deleted. Local data on your device is not affected.
9. Data Security
We take reasonable measures to protect your information from unauthorized access, alteration, disclosure, or destruction. Authentication tokens are stored securely on your device. Cloud data is transmitted over encrypted connections and stored in secure databases with row-level security policies. However, no method of transmission over the internet or electronic storage is 100% secure.
10. International Data Transfers
Your information may be transferred to and processed in countries outside of your country of residence, including countries that may have different data protection laws.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.
12. App Store & Google Play Compliance
Apple App Store Requirements
In accordance with Apple App Store Review Guidelines:
- This Privacy Policy is accessible within the App and on the App Store listing
- Users are informed about data collection, usage, and third-party sharing
- Location data is collected only with explicit user consent
- Account creation is optional; users can use the App without signing in
- Users can delete their account and associated data from within the App
- Data is not used for purposes other than those disclosed in this Privacy Policy
- Users may withdraw consent at any time through device settings
Google Play Store Requirements
In accordance with Google Play User Data policies:
- We disclose the collection and use of personal and sensitive data, including location
- Data collection is limited to what is necessary for app functionality and analytics
- Data is transmitted securely
- Users can request deletion of their data and account
- Advertising identifiers are used in compliance with Google policies
This Privacy Policy is available on the Google Play Store listing and within the App.
13. Contact Us
If you have any questions about this Privacy Policy or your privacy rights, please visit our Support page .
This Privacy Policy is provided for general informational purposes and does not constitute legal advice.