Privacy Policy

Bell Book Daily

Effective date: 2026-09-22

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Bell Book Daily stores the books you enter, titles, authors, page or chapter totals, reading status, latest pause reasons, dates, reading session amounts and units, quotations, thoughts, mood tags, page references and selected cover images in a SQLite database on your device. The same reading library is sent to our server for synchronization. A random installation secret is stored in your device Keychain; the server stores its cryptographic hash and an installation creation timestamp. There are no user accounts, login credentials or requested email addresses. Your optional display name stays in device preferences and is not sent to the server. The local reading database is excluded from device backups by the app. Requests to the app service and this website necessarily expose network and request metadata, such as IP addresses, request timing and browser or client information, to the hosting infrastructure. The application server does not log library contents, authorization headers or client IP addresses. It logs startup and error types and keeps temporary rate-limit counters. We use no advertising or analytics SDKs and this website sets no cookies.

How we use information

We process your reading library to save and display your books, calculate progress and reading patterns, preserve meaningful passages, support a gentle return to paused books, and synchronize changes when connectivity returns. The installation secret authorizes access to this installation's private data. Dates and session units support the Book Pulse timeline and Library Flow statistics. Network metadata, operational logs and temporary request counters support hosting, reliability and abuse prevention. Photos are processed only when you select a cover or explicitly export a quote image.

Service providers and sharing

The backend and public website are hosted on Railway, which processes stored library data and infrastructure metadata to operate the service. Authorized service operators with infrastructure access can access server data; this is not end-to-end encrypted storage. No external book search, advertising, analytics or email delivery provider is integrated. When you use the system share sheet, export a JSON file or save an image, the destination you choose receives that copy and its own practices apply. Apple provides the system photo picker, Photos library, Keychain and operating system services; Photos and device preferences may be affected by your own Apple synchronization settings. We do not sell reading data.

Data retention

Local records remain until you delete them or remove the app's data. Server records and the installation credential hash remain until deletion is requested and completed; the service does not apply an automatic expiry schedule. Temporary rate-limit counters live in server memory and reset when the process restarts. No application-level backup job or backup retention schedule is configured. Railway may retain infrastructure logs or platform copies under its own practices; we have not established a specific retention duration and do not promise immediate physical erasure from provider backups or snapshots. Device Keychain storage can persist independently of the app, and exported or shared copies remain at their chosen destinations.

Deleting your information

Use Delete all data in Settings to clear the local library and optional local name and request deletion of the installation's server records and authorization credential. If offline, the app keeps a deletion request and the credential needed to perform it, displays that server deletion is pending, and pauses new entries until deletion completes. It retries when opened with connectivity or when you choose Retry sync. After server confirmation, the Keychain secret is removed; future use creates a new installation. Deleting an individual book also removes its sessions and quotations locally and on the next successful synchronization. Server deletion removes active database rows and invalidates the secret; historical hosting backups or snapshots are not guaranteed to be erased immediately. Removing the app alone does not request server deletion. Photos, JSON exports and copies shared elsewhere must be removed separately. Without the installation secret there is no identity-based recovery mechanism, and we may be unable to identify server records from an email address alone.

Permissions and your choices

The system photo picker lets you select a cover without granting access to your entire photo library. The app requests permission to add photos only when you choose Save to Photos for a quote image. You can deny or withdraw this permission in iOS Settings; the reading library remains usable and the system share sheet remains available. A cover already selected and synchronized remains in the library until you remove it or delete its book. Bell Book Daily does not request camera, location, contacts, microphone or notification access.

Your privacy rights

You can view and edit your records in the app, export the library as JSON, remove individual books or quotations, and delete all data through Settings. Depending on where you live, you may have rights to access, correct, erase, restrict or object to processing, receive a portable copy, or complain to your local data protection authority. Contact leti.dallo1way@icloud.com with privacy questions or rights requests. Do not send your installation secret or unnecessary private reading content by email. We may need information sufficient to verify a request, and the lack of an account limits our ability to locate records if the installation secret is lost.

Security

The deployed client uses HTTPS. Each installation receives an independent cryptographically random secret held in the iOS Keychain with device-only accessibility; the server retains only its SHA-256 hash and checks authorization before private data access. Database relationships isolate installations, writes are transactional, inputs and request sizes are validated, and request limits reduce misuse. Device storage uses the operating system sandbox, and server data resides on a persistent Railway volume. The app does not embed a shared server password. These controls do not eliminate every risk; someone who obtains an installation secret can access that installation's data. There is no end-to-end encryption or promised recovery after loss of the secret.

Children’s privacy

Bell Book Daily is designed for adult readers and is not directed to children. We do not request age or knowingly solicit personal information from children. If you believe a child has provided personal information through the service, contact leti.dallo1way@icloud.com so that we can consider the concern and available deletion options.

Changes to this policy

We may update this policy when the app's processing, infrastructure or features change. The current policy is available through the Privacy Policy link in app Settings and at this public page. The effective date at the top identifies the latest version. Material changes will be reflected in the policy and, where appropriate, in the app or its release information.