Read-flow

Privacy Policy of Read-flow

Last updated: 26 August 2026

This policy explains what personal data Read-flow collects, why it is collected, where it goes, how long it is kept, and what rights you have in relation to it.

Previous versions of this policy, and a record of the changes made to it, are available on request using the contact details at the end of this document.

1. WHO WE ARE

Owner and Data Controller

Read-flow
5215 Omar Ibn Ahmad Al Aqili
Jeddah 23814
Kingdom of Saudi Arabia

Email: support@read-flow.app
Phone: +966 58 223 6355
Website: https://read-flow.app

For the purposes of the Personal Data Protection Law of the Kingdom of Saudi Arabia, Read-flow is the Data Controller for the personal data described in this policy. In this policy, "we", "us" and "our" mean Read-flow.

We have not appointed a dedicated personal data protection officer. Our processing activities do not fall within the cases in which such an appointment is required under the Personal Data Protection Law. All matters concerning personal data may be addressed to us at support@read-flow.app.

2. WHAT READ-FLOW DOES

Read-flow is a writing and reading application.

It allows you to build a personal library of books, to write and organise your own notes, manuscripts and long-form documents, and to develop original creative material including characters, places, timelines, and the relationships between them. It synchronises that material across your devices.

It also offers assistive features that use artificial intelligence to analyse, summarise, explain and generate content based on the material you have written or collected. These features are described in detail in section 6.

Read-flow is offered to individual consumers. It provides a free initial period, after which continued writing requires a paid subscription.

3. WHAT DATA WE COLLECT

3.1 Account data

Your email address, and a unique account identifier that we generate.

Your email address is collected directly from you when you register, or is received from Google or Apple if you choose to sign in through one of those providers. If you sign in with Apple, this may be an Apple private relay address rather than your real address.

We also store a display name. You are not asked for one and there is no screen on which you can set one. It is worked out automatically when your account is created: from the name your sign-in provider supplies, or, if there is none, from the part of your email address before the @ sign, or, failing both, from the word "Reader". It appears at the top of your account screen.

3.2 Content you create

The notes, manuscripts, documents, characters, places, concepts, timelines, relationships and library entries that you create or store in Read-flow, together with any material you submit to the artificial intelligence features.

This category is broad, and deliberately so. It includes the full text of everything you write; the titles and descriptions you give to notes and folders; every field of every character, place, concept, timeline event and relationship, including free-text fields such as a character's fears, beliefs, secrets and contradictions; and the free text you attach to any of them.

This is your own work. We store and synchronise it so the application can function, and we process it through the artificial intelligence features when you ask us to. We do not read it, publish it, or make it available to other users, except in the two situations described in 3.3 and 6.6.

3.3 Content created for you by the artificial intelligence features

The outlines, analyses, syntheses, connections essays, character dossiers, theme pages, wiki answers you have pinned, and the searchable index built from them. These are generated at your request from your own material and are stored on our servers and on your device.

One category of this output is shared. Where the outline generated for a widely-read published book contains nothing specific to you, it is cached and may be reused to set up the same book for another user. This cache holds the generated outline only. It is not linked to your account and does not identify you.

3.4 Preferences

The reading and writing preferences you provide during onboarding — genres, topics, authors, languages and reading goals — and any application settings you change afterwards, including your reading and writing goals and your content-language preference.

3.5 Messages you send us

If you contact support or report a problem from inside Read-flow, we store the subject and body of your message, together with your email address and account identifier. If you delete your account and give a reason, that reason is stored the same way.

Please note that these records are retained after account deletion. This is explained in section 11.

3.6 Reports about generated content

If you report content produced by an artificial intelligence feature, we store the reported content itself, the reason you selected, any explanation you write, which feature produced it, and the version of the application you were using.

3.7 Device and purchase data

Information about the device, operating system and application version you are using, and records of the purchases and subscriptions associated with your account.

3.8 Usage and diagnostic data

Records generated automatically by the operation of the service, including:

3.9 Camera

Read-flow asks for permission to use your camera so that you can add a book by scanning its barcode. The image is decoded on your device by a component that runs locally. No image and no scan result is transmitted to us or to anyone else. If you do not use the barcode scanner, no permission prompt appears.

3.10 Unique identifiers

Identifiers assigned to your installation of Read-flow by the services described in section 7, used to associate analytics events, diagnostic reports and device attestation with a single installation.

On Android, Google Play also supplies to Google Analytics the referrer string recording how the application was installed.

Read-flow does not use cookies and has no browser-based interface of its own. The Terms, this policy, and the links for managing your subscription open in your device's own browser, which is outside Read-flow and governed by its own settings.

4. WHAT WE DO NOT COLLECT

We think it is as useful to tell you what we do not hold as what we do.

4.1 Passwords

We never collect, transmit or store your password. If you register with an email address and password, that password is held by Google as part of the Firebase Authentication service and is never sent to us. Our systems contain no field capable of storing a password, and an automated check prevents one from being introduced.

4.2 Real names, usernames, dates of birth, biographies

Read-flow does not ask for or store a username, a real name, a date of birth or a biography. There is no profile editor and no screen on which any of these can be entered. The display name described in 3.1 is generated automatically and is the only name-like value we hold.

If you sign in with Google or Apple, the profile photograph held by that provider may be shown at the top of your account screen. It is fetched directly from the provider by your device when that screen is drawn. We neither store it nor copy it, and if your provider has no photograph, a coloured circle with your initial is shown instead.

4.3 Payment details

We never see your card or bank details. All payments are handled by the app store you obtained Read-flow from, which acts as the seller. We receive only confirmation of whether a purchase or subscription is active.

4.4 Location

Read-flow does not collect location data. You may notice that the Android version declares location permissions. These are contributed by a third-party security library that we use to detect whether a device has been modified or compromised. No location interface is ever called, no permission prompt is ever shown, and no location information is collected, stored or transmitted.

4.5 Advertising identifiers

Read-flow contains no advertising, contains no advertising software, and does not collect your device advertising identifier. On Android we have explicitly removed the permission that would allow that identifier to be read.

You may nonetheless see three permissions with advertising-related names declared by the Android version: two relating to Google's advertising services, and one allowing the install referrer to be read. These are contributed automatically by Google Analytics, which is described in section 7. They are not there because Read-flow shows advertisements, and no advertising identifier is read through them.

4.6 Uploaded files

Read-flow does not accept file uploads. There is no route by which a document, image or other file is uploaded from your device to our servers as a file, and there is no file storage associated with your account.

One thing this does not cover, and we would rather say so plainly. You can import a plain-text or Markdown file from your device to create notes. When you do, the file's contents are read on your device and turned into notes, and the file's name becomes the title of the note. Those notes then synchronise to our servers in the ordinary way, exactly as if you had typed them. The file itself is not uploaded and is not stored, but what was written inside it reaches our servers as note content.

4.7 Sensitive data

We do not collect or process sensitive data, meaning personal data revealing racial or ethnic origin, religious, intellectual or political belief, data relating to security criminal convictions and offences, biometric or genetic data used to identify a person, health data, or data indicating that one or both of a person's parents are unknown.

Please do not submit sensitive data to Read-flow, and in particular do not submit it to the artificial intelligence features. If we become aware that sensitive data has been submitted, we will destroy it without undue delay.

5. WHY WE PROCESS YOUR DATA, AND ON WHAT LEGAL BASIS

Under the Personal Data Protection Law we must have a lawful basis for processing your personal data. The basis differs by purpose, so we set them out individually rather than as a list.

5.1 To provide the service you subscribed to

Basis: performance of the agreement between you and us.

This covers creating and securing your account, storing and synchronising everything you write, running the artificial intelligence features when you request them, and managing your subscription and entitlements.

This is the service you asked for. It is not based on your consent, and we do not ask for consent to it. If you no longer wish us to carry it out, the remedy is to stop using Read-flow and delete your account, which destroys the data as described in section 11.

5.2 To keep the service working, secure and free of abuse

Basis: our legitimate interests.

This covers diagnostic reports, application analytics, security event records, and verifying that requests come from a genuine, unmodified installation of Read-flow. Our interest is in operating a service that works and is not abused. We have considered your interests and have limited what we collect: analytics event values are restricted to numbers, true or false values and short labels, and cannot contain your content; diagnostic reports have request and response contents removed before transmission.

5.3 To meet our legal obligations

Basis: compliance with a legal obligation.

This covers records we are required to keep, and responding to lawful requests from a competent authority.

5.4 Where we ask you

Basis: your consent.

If we ever process your personal data for a purpose that none of the above covers, we will ask you first, we will ask separately for each purpose, and we will explain the purpose before asking. Consent given this way can be withdrawn at any time, and withdrawing it is as simple as giving it was. Consent is never a condition of providing Read-flow or any part of it, except where the part in question is directly about the data concerned.

At present we do not rely on consent for any processing described in this policy.

6. THE ARTIFICIAL INTELLIGENCE FEATURES

Read-flow's assistive features are provided using Claude, an artificial intelligence service operated by Anthropic PBC in the United States.

6.1 These features run only when you ask

Content that you merely write, open or store in Read-flow is never transmitted to Anthropic. Saving a note does not transmit it. Opening a book does not transmit it. Synchronising your devices does not transmit anything to Anthropic. Transmission happens only at the moment you request one of the features listed in 6.2, and only the material listed there.

6.2 What is transmitted, feature by feature

There are ten features that transmit material to Anthropic. We set out each one separately, because they send different things and you are entitled to know which.

Setting up a book you are reading

Sent: the book's title, authors and genre; the description and subject labels held for that book in the public book catalogues; and the names of the folders in your own workspace. Also sent, in some cases, is a short block of anonymised context — up to 200 words of entity and theme labels drawn from other users' material for the same genre, containing nothing that identifies anyone. Notes you have imported are not sent.

Returned: the outline and the starter notes that are created for you.

Setting up a book you are writing

Sent: the book's genre, title and author, and your own free-text description of the book — in full, exactly as you wrote it, including material that is unpublished.

Returned: the outline and the starter notes that are created for you.

Analysing a folder

Sent: the folder's name, the book's genre, the title of each note in the folder, and the full text of each note — or, on a later run, the full text of the blocks that have changed. Also sent: any earlier analysis of that folder, and the book's setup output.

Returned: an analysis in markdown, stored as a note.

Synthesising a book

Sent: the book's title and genre, the name and description of each folder, and the full analysis text of each folder that has changed since the last run.

Returned: a synthesis in markdown, stored as a note.

Connections between books

Sent: for each book you select — its title, authors and genre, plus the setup content for books you are reading, and the setup content together with the complete book analysis for books you are writing. Also sent: any earlier connections essay.

Returned: an essay in markdown, stored as a note.

Building a character dossier

Sent: the character's name, role, profile text, notes, aliases and traits; every line of dialogue you have written for that character; every passage of your writing that mentions them; all of their relationships and your free-text notes on those relationships; the timeline events they appear in; and the places associated with them. Each is labelled with the title of the note and the name of the folder it came from.

Returned: a written dossier, stored and used to support character chat.

Character chat

Sent: the character's name and role, the dossier described above, any scene context you have written, and your message.

Returned: a reply written in the character's voice. Nothing is stored on our servers.

Asking a question about a note, folder, book or connection

Sent: the book's title and genre; and, depending on what you are asking about, the full text of the note, or the analysis of the folder, or the synthesis of the book, or the connections essay. Also sent: your question, and up to six preceding turns of that conversation.

Returned: an answer. Nothing is stored on our servers.

Asking a question of your whole library

Sent, in the first stage: a list of every book in your library, with its title, author, page count, topics and a short content snippet. Sent in later stages: summaries of the candidate pages, and then the full text of the pages selected to answer you. Your question is sent at every stage.

Returned: an answer with source attribution.

Generating a theme page

Sent: the theme title, and for each relevant book its title, author and a short summary of each of its pages.

Returned: a theme page in markdown.

One further signal accompanies every one of these requests: whether to reply in English or in Arabic. This is worked out from your language preferences before the request is made; only the resulting choice is sent.

6.3 What is never transmitted to Anthropic

We do not include your email address, your name, your account identifier, your IP address, or any device identifier in anything sent to Anthropic. We have verified this at every one of the ten features above.

Identifiers do appear in what is sent, but they identify pieces of content — a note, a block of text, a folder — and not you. They are included so that the result can be matched back to the right place in your workspace.

Anthropic is not told who you are. It receives text and returns text.

6.4 What Anthropic does with it

Anthropic automatically deletes the material we send and the results it returns within 30 days of receipt or generation, except where a longer period is required to investigate a violation of its usage policy or by law.

Anthropic does not use the material we send to train its models. This is Anthropic's stated default position for commercial and API customers.

6.5 Accuracy

Content generated by these features may be inaccurate, incomplete or misleading. Please verify it against your source material and other reliable sources before relying on it. It is not professional advice of any kind.

6.6 Reporting

If a feature generates content you consider offensive or inappropriate, you can report it using the report control shown alongside that content in the application. We review reports and act on them.

6.7 No automated decisions about you

We do not take any decision producing legal effects concerning you, or otherwise significantly affecting you, on the basis of automated processing alone. The output of these features is content provided to you inside Read-flow. It is not used to decide anything about you.

6.8 Features that stay on your device or our servers

Several features that look like artificial intelligence are not, and transmit nothing to Anthropic. These include detecting entities and duplicates in your writing, suggesting folders, matching names and places, and building the index used to search your material.

7. WHO WE SHARE DATA WITH

We do not sell your personal data and we do not share it for anyone else's purposes. The organisations below process it on our behalf, or as a necessary part of delivering Read-flow to you.

7.1 Storage and infrastructure

Supabase, Inc. — Germany The database in which your account and your content are stored. Receives all categories of data described in section 3, continuously.

Supabase Storage — Germany Stores book cover images that we retrieve from public catalogues and re-host. Contains no personal data and no files from you.

Railway Corp. — Netherlands The platform on which our application server runs. As the operator of that environment it has access to the running server, its configuration and its logs.

7.2 Sign-in

Google Ireland Limited (Firebase Authentication) — European Union and United States Holds your email address, your password if you use one, your sign-in timestamps and a unique identifier. Involved every time you register, sign in or your session is renewed.

Google LLC (Google Sign-In) — United States If you sign in with Google, provides us with your email address and any profile information Google supplies.

Apple Inc. (Sign in with Apple) — United States If you sign in with Apple, provides us with your email address, which may be a private relay address.

Google LLC (reCAPTCHA) — United States Included as part of the Firebase Authentication component. It may be invoked during sign-in to establish that a request comes from a person rather than an automated system.

7.3 Security and integrity

Google Ireland Limited (Firebase App Check) — European Union and United States Confirms that requests come from a genuine, unmodified installation of Read-flow. Device attestation tokens are generated by Google Play Integrity or Apple App Attest and sent to Google and to us.

Google Ireland Limited (Firebase Installations) — European Union and United States Assigns a unique identifier to each installation of Read-flow, required by the analytics and diagnostic services below.

7.4 Analytics and diagnostics

Google Ireland Limited (Firebase Analytics) — European Union and United States Records events describing how Read-flow is used, associated with your account identifier. Event values are restricted to numbers, true or false values and short labels; your content is never included. Google also collects standard information including session data, application version, device model, language, and approximate location derived from your IP address.

Google Ireland Limited (Firebase Crashlytics) — European Union and United States Records diagnostic information when the application encounters a fault: what failed, the sequence of code that produced it, your device model and operating system version, and your account identifier. Network faults are reduced to the request method, address and status code; request and response contents are never included.

Functional Software, Inc., trading as Sentry — United States Records diagnostic information when our server encounters a fault. Only your internal account identifier is attached. Request contents, cookies and authorisation headers are removed before transmission. Sentry runs on our servers only and is not present in the mobile application.

7.5 Notifications

Google Ireland Limited (Firebase Cloud Messaging) — European Union and United States Read-flow includes this component but does not use it. We do not request notification permission, do not read a messaging token, and do not send push notifications. Because the component is present, Google may nonetheless generate and hold a registration token for your installation. We neither receive nor use it.

7.6 Payments and subscriptions

Google LLC (Google Play Billing) — United States Processes purchases and subscriptions made through Google Play. Google is the seller of record and handles payment, tax and refunds.

RevenueCat, Inc. — United States Validates purchases and maintains your subscription status. We send it your authentication identifier. We do not send your email address, your name or any of your content.

7.7 Artificial intelligence

Anthropic PBC — United States Described in full in section 6.

7.8 Book information

Google LLC (Google Books) — United States
Internet Archive (Open Library) — United States

Used to look up information about books and to retrieve cover images. The words you type when searching for a book are sent to these services. Your account identifier is not.

7.9 Images loaded by your device

Book cover images, and the profile photograph described in 4.2, are requested by your device directly from the service that holds them — a public book catalogue, our own image store, or your sign-in provider. Those services therefore see your device's IP address and the address of the image at the moment it is displayed. They are not told who you are and receive nothing else from us.

7.10 Components that run on your device and send nothing

Two components deserve a mention because they appear in the application's technical declarations and might otherwise look like recipients of data.

The barcode reader decodes an image entirely on your device. The check that determines whether your device has been modified or compromised also runs entirely on your device. Neither transmits anything to us or to anyone else.

7.11 Legal disclosure

We may disclose personal data to a judicial or administrative authority where the disclosure is required by law, is necessary to comply with a judicial requirement, or is made in response to a request from a competent public authority. Any such disclosure is limited to the minimum data necessary, the request is documented, and the disclosure is recorded.

8. WHERE YOUR DATA IS STORED AND PROCESSED

We do not operate our own servers. Your personal data is stored with the providers named in section 7, in the countries stated for each of them, and on your own device.

Read-flow is local-first. What you write is saved to your device first and synchronised to our servers afterwards. If you are offline, your work may exist only on your device for an unlimited period before it reaches us.

The database on your device is encrypted. The key is held in your device's own secure storage — the Android Keystore or the iOS Keychain — and the database file is excluded from device backup.

Three other things are kept on your device outside that encrypted database, and are not encrypted by us:

Documents you export are written to your device's temporary folder so that they can be passed to whichever application you choose to send them to. Files left there from a previous session are removed the next time Read-flow starts.

9. TRANSFERS OUTSIDE THE KINGDOM OF SAUDI ARABIA

Your personal data is transferred to and processed in the following places outside the Kingdom:

Germany Supabase and Supabase Storage Netherlands Railway European Union Firebase Authentication, App Check, Installations, and United Analytics, Crashlytics and Cloud Messaging. Google contracts States through Google Ireland Limited and processes data in the European Union and in the United States. United States Anthropic, RevenueCat, Sentry, Google Books, Google Play Billing, Google Sign-In, reCAPTCHA, Sign in with Apple, and Open Library

Where you use the artificial intelligence features, the material you submit is transferred to the United States. This happens only at the moment you request one of those features.

These transfers are made in order to perform our agreement with you — that is, to provide the service you asked for — and to provide a service or benefit directly to you.

The Competent Authority has not published a list of countries recognised as providing an adequate level of protection. Until it does, we rely on the data processing terms published by each of the providers named in section 7, which impose obligations on them consistent with the requirements of the Personal Data Protection Law, and we limit each transfer to the minimum personal data needed for the purpose concerned.

We select only providers that offer the necessary guarantees to implement the Personal Data Protection Law and its Implementing Regulations. Our arrangements with them specify the purpose of the processing, the categories of personal data involved and the duration of the processing; require them to notify us without undue delay of any personal data breach; and identify any further party to whom personal data may be disclosed. We review their compliance periodically. Where we determine that a provider can no longer meet these requirements, we suspend the transfer concerned and notify the parties to whom the data was transferred.

The Personal Data Protection Law continues to apply to any onward transfer of your personal data by a provider to a further party outside the Kingdom.

In making these transfers we ensure that they cause no prejudice to national security or to the vital interests of the Kingdom.

10. HOW LONG WE KEEP DATA

We destroy personal data without undue delay once it is no longer necessary for the purpose it was collected for. We keep it beyond that point only where a law requires us to keep it for a set period, or where it relates to a case before a judicial authority — in which case we destroy it when that period lapses or those proceedings conclude.

Subject to that, these are our retention periods:

Account data (email address, account identifier) Kept for as long as your account exists. Destroyed when you delete your account, except as described in section 11.

Content you create Kept for as long as your account exists. We do not apply a time limit to your own work while your account is active — keeping it is the service. Destroyed when you delete your account.

Content you delete inside Read-flow Moved to a recoverable state and destroyed 30 days later. This applies to notes and folders you delete, and to characters, places, concepts, timeline events, relationship groups and library entries you remove.

Content generated by the artificial intelligence features Kept for as long as your account exists, and destroyed when you delete your account. It is not removed when the material it was generated from is deleted, because it forms part of your accumulated work.

Preferences Kept for as long as your account exists.

Subscription status Kept for as long as your account exists.

Detailed usage and billing records 90 days.

Records of accounting adjustments applied to a subscription Kept indefinitely, for audit purposes. See section 11.

Application activity records 90 days.

Security event records, including IP address 12 months.

Messages you send us, and the reason you give when deleting an account 24 months from the date we close the matter.

Server request records held by our hosting provider Retained by that provider for a limited period and then overwritten. It is currently no longer than 30 days.

Reports of artificial intelligence content, including the reported content 90 days.

Short-lived operational records Between 10 minutes and 90 days, depending on their purpose. The shortest are the locks that stop the same request running twice, at 10 minutes. The longest are the records that stop a payment notification being processed twice, at 90 days.

The diagnostic log file on your device Overwritten in rotation once it reaches its size limit. It is not transmitted anywhere, and you can remove it by uninstalling Read-flow.

Where it is not possible to fix a period in advance, we keep the data for as long as the purpose continues to exist, judged by the life of your account and your agreement with us, the period during which a claim relating to Read-flow could still be brought, and any period another law imposes on us.

Destruction means the data becomes permanently and irrecoverably inaccessible. We delete it irreversibly from our live systems, after which it expires from our encrypted backups within 30 days. Data held in backups is not treated as destroyed while it remains in them, and stays protected by this policy until it has expired from them.

We destroy your personal data when you ask us to; when it is no longer necessary for the purpose it was collected for; when you withdraw consent and that consent was the only basis for the processing; and if we become aware that it has been processed unlawfully.

11. WHAT HAPPENS WHEN YOU DELETE YOUR ACCOUNT

Deleting your account is irreversible. We want you to know exactly what it does and does not reach.

11.1 What is destroyed

Everything you wrote and everything Read-flow generated for you. Your notes and the blocks they are built from, manuscripts, documents, characters, places, concepts, timelines, relationships, routes, library, reading progress, preferences, privacy settings, device records, subscription record, usage records, activity records, the searchable index of your material, your pinned answers, and every outline, analysis, synthesis, essay, dossier and theme page generated for you.

Your sign-in record with Google is deleted at the same time. If that deletion cannot be completed at the moment you ask — for example because the sign-in service is temporarily unreachable — the deletion of everything else still proceeds, and we complete the sign-in deletion afterwards.

On the device you deleted the account from, the contents of the encrypted database are deleted. What remains there is described in 11.5.

11.2 What we keep, and why

Messages you sent us, including support requests, bug reports and the reason you gave when deleting your account. These carry your email address, your account identifier and whatever you wrote. Kept for 24 months so that a record of your request and how we handled it exists. Your email address is stored on the message itself, which means it remains readable after your account is gone.

Security event records, including your account identifier, IP address and device identification string. Kept for 12 months from the date of the event, for security and abuse investigation.

Records of accounting adjustments applied to your subscription. Kept indefinitely, for audit purposes. These contain your account identifier and monetary amounts, and no content. They are written automatically by the database itself, which is why they are not reached by the deletion of your account.

Reports you made about generated content, including the reported content. Kept for 90 days from the report.

Short-lived operational records containing your account identifier. These expire on their own, between 10 minutes and 90 days. One of them, the record used to prevent a request being processed twice, can contain the answer an artificial intelligence feature returned to you; it expires within 24 hours.

Records in our background job system, which can contain your account identifier and the details of a payment notification. These are cleared by that system on its own schedule.

11.3 What remains with third parties

Your purchase record with RevenueCat, including your authentication identifier and purchase history, is not deleted by us. If you want it removed you should contact us and we will make the request.

Your purchase record with Google Play remains with Google, subject to Google's own policies.

Diagnostic and analytics records already sent to Crashlytics, Google Analytics and Sentry remain until those services' own retention periods expire.

11.4 What survives with your identity removed, or was never linked to you

Books, genres and sub-genres you created remain in the shared catalogue, with your identity removed from them. They are no longer personal data.

Entries in the public book catalogue created when you added a book, and the cover images we re-host, remain. They contain no reference to you and are shared by all users.

The cached outline described in 3.3 remains. It holds generated text only and has never carried any reference to your account.

11.5 What remains on your device

Deleting your account empties the encrypted database but does not remove the database file itself, and does not remove the key used to encrypt it. Both are replaced if a different account signs in on that device.

Also remaining: the diagnostic log file described in 3.8, application settings that record which steps you completed, and a record of what your subscription was.

Uninstalling Read-flow removes all of it. If you want the device clean, we recommend deleting the account and then uninstalling.

11.6 Signing out is not deleting

Signing out leaves everything on your device where it is, including any work that had not yet reached our servers. This is deliberate: it means signing back in does not have to download your library again, and it means unsynchronised work is not lost. If you want the data off the device, use account deletion or uninstall Read-flow.

11.7 How to delete your account

Inside Read-flow: Account, then Account Actions, then Delete Account. You will be asked to confirm, and to sign in again before it proceeds.

Or through the page at https://read-flow.app/delete-account, which works without installing the application.

Or by writing to support@read-flow.app.

If you have a paid subscription, cancel it through Google Play first. Deleting your Read-flow account does not cancel a subscription held by Google, and you would continue to be charged.

12. HOW WE PROTECT YOUR DATA

We apply the organisational, administrative and technical measures necessary to protect your personal data, including while it is being transferred, and in particular against loss, unauthorised access, disclosure, alteration and unlawful destruction. Those measures include:

No set of measures makes a service immune. We tell you what we do so you can judge it, not to suggest that nothing can go wrong.

We follow recognised cybersecurity practice and apply the relevant controls issued by the National Cybersecurity Authority of the Kingdom of Saudi Arabia to the extent they apply to us. The level of protection reflects the sensitivity and volume of the data concerned.

Anyone processing personal data on our behalf is bound to keep it confidential, including after their relationship with us ends.

13. PERSONAL DATA BREACHES

A personal data breach means any incident leading to the disclosure or destruction of, or unauthorised access to, personal data, whether deliberate or accidental.

If we become aware of one, we notify the Competent Authority within 72 hours of becoming aware of it, where the incident may harm the data or you, or conflict with your rights or interests.

That notification describes the incident, when and how it happened, the categories and approximate number of people affected, the type of data involved, the risks arising, what we have done to limit and mitigate those risks and prevent recurrence, whether affected users have been told, and our contact details. If we cannot provide all of that within 72 hours we provide it as soon as we can afterwards, with the reasons for the delay.

We also notify you directly, without undue delay, of any breach affecting your personal data where it may damage that data or conflict with your rights or interests. We write to you in plain language and tell you what happened, what the risks are, what we have done, how to contact us, and anything you can do to protect yourself.

We keep a copy of every report we make and a record of the corrective measures taken.

14. YOUR RIGHTS

Under the Personal Data Protection Law you have the following rights.

To be informed To know the legal basis on which we collect your personal data and the purpose of collecting it. This policy is how we tell you.

To access To find out whether we hold personal data about you and to see it.

To obtain a copy To receive your personal data in a clear, readable format.

To correct To have your personal data corrected, completed or brought up to date.

To restrict processing Where you dispute the accuracy of your personal data, to have us stop processing it for anything except storage while we check.

To have your data destroyed Where it is no longer needed by you, subject to the cases described in section 11 in which we are required or permitted to retain it.

To withdraw consent Where processing is based on your consent. Withdrawal does not affect the lawfulness of what we did before you withdrew it.

To complain To bring a complaint to us, and to the Competent Authority.

To seek compensation To apply to the competent court for compensation for material or moral damage caused by a breach of the Personal Data Protection Law.

Getting a copy of your data

Inside Read-flow you can export your written work as a document, one book at a time, in Word, PDF or EPUB format, and share individual notes as plain text.

A complete copy of everything we hold about you — your content, library, preferences, subscription history and activity records — is provided on request. Write to support@read-flow.app and we will send it in a commonly used electronic format within the period in section 15. You may ask for a printed copy where that is practical.

When we give you access to your data we make sure it does not disclose personal data identifying anyone else. These rights do not extend to information whose disclosure would harm the rights of others, including intellectual property rights and trade secrets.

If we ask you for documents to verify your data before correcting it, we destroy those documents once the check is complete.

15. HOW TO EXERCISE YOUR RIGHTS

Write to us at support@read-flow.app.

You can also delete your account and all the personal data associated with it directly inside Read-flow, at Account, then Account Actions, then Delete Account, without making a request to us at all.

Requests are free. We act on a request without delay and within 30 days of receiving it. If acting on it would take disproportionate effort, or if you have made several requests, we may extend that by up to a further 30 days — we will tell you before we do, and why.

We may decline a request that is repetitive, clearly unfounded, or that would take disproportionate effort. If we do, we will tell you that is the reason.

To protect your personal data we may ask for information reasonably necessary to confirm that you are who you say you are.

If you do not have full legal capacity, these rights are exercised on your behalf by your legal guardian.

Two of these rights can be exercised without contacting us. Deleting your account, as above, exercises the right to destruction. Exporting a book, at the book's menu inside Read-flow, gives you your written work as a Word, PDF or EPUB document. Everything else — access, correction, a complete copy of all your data, restriction of processing, and objection — is exercised by writing to support@read-flow.app. We would rather tell you that plainly than describe controls that do not exist.

16. COMPLAINTS

If you believe we have not let you exercise your rights, if you object to how we process your personal data, or if you think we have not complied with the Personal Data Protection Law, write to us at support@read-flow.app.

We acknowledge every complaint when we receive it and respond within 7 days, telling you the outcome and the reasons for it.

If you are not satisfied with our response, or we do not respond within 7 days, you may complain to the Competent Authority.

The Competent Authority is the Saudi Data and Artificial Intelligence Authority (SDAIA), established by Council of Ministers Resolution No. 292 dated 27/4/1441H. Complaints may be submitted through the channels at sdaia.gov.sa and through the National Data Governance Platform at dgp.sdaia.gov.sa.

A complaint should be submitted within 90 days of the date the incident happened or the date you became aware of it. The Competent Authority may still accept a later complaint where there were reasonable causes for the delay.

Your complaint should state where and when the violation occurred, your name, identification, address and telephone number, information about us, and a clear and specific description of the violation with any supporting evidence.

You are welcome, but not required, to contact us first.

17. CHILDREN AND PEOPLE WHO LACK LEGAL CAPACITY

Read-flow is not directed at anyone under the age of 18, and we do not knowingly collect personal data from anyone under 18.

Where a person does not have full legal capacity, the consent required under the Personal Data Protection Law must be given by their legal guardian. Where a guardian gives consent, we take appropriate measures to check that the guardianship is valid. A legal guardian may exercise the rights in section 14 on that person's behalf, must act in their best interests, and may not give consent that harms their interests. Where the person later attains legal capacity, they may exercise those rights themselves.

If we become aware that we hold personal data belonging to someone who lacks the legal capacity to consent, and no valid guardian consent exists, we will stop the processing and destroy that data without undue delay.

A guardian who believes we hold personal data about someone in their care may contact us at support@read-flow.app.

We do not photograph or copy official identity documents, except where a law requires it or a competent public authority requests it. If we do obtain such a document we protect it and destroy it once the purpose has ended, unless a legal requirement obliges us to keep it.

18. MARKETING

We do not send advertising, awareness-raising material or direct marketing.

Emails about your account, your purchases, your subscription, or the operation of Read-flow are necessary to perform our agreement with you and are not marketing.

If we introduce marketing communications in future we will ask for your consent first, we will identify ourselves clearly as the sender, and every message will carry a clear and free way to stop receiving them that is as simple as the way you agreed to receive them. If you ask us to stop, we stop without undue delay.

19. ADDITIONAL INFORMATION FOR USERS IN THE EUROPEAN UNION

If you are in the European Union, the General Data Protection Regulation gives you rights alongside those in section 14. In particular you have the right to withdraw consent at any time; to object to processing carried out on a basis other than consent; to access your data; to have it corrected; to restrict processing; to have it erased; to receive it in a structured, commonly used and machine-readable format and have it transmitted to another controller where technically feasible; and to lodge a complaint with your national data protection authority.

Where we process your personal data for our legitimate interests, you may object by explaining the grounds arising from your particular situation.

The legal bases in section 5 map to the GDPR as follows: performance of a contract (Article 6(1)(b)); legitimate interests (Article 6(1)(f)); compliance with a legal obligation (Article 6(1)(c)); and consent (Article 6(1)(a)).

We answer requests as early as possible and always within one month. Where we correct, erase or restrict your personal data we tell every recipient it was disclosed to, unless that proves impossible or would take disproportionate effort. If you ask, we will tell you who those recipients are.

20. CHANGES TO THIS POLICY

We may change this policy. When we do, we will publish the new version on this page and notify you inside Read-flow, and where it is technically and legally feasible we will also send you a notice using contact details we hold.

Please check the date at the top of this page from time to time.

If a change affects processing that was based on your consent, we will ask for your consent again where the law requires it.

21. CONTACT

Read-flow
5215 Omar Ibn Ahmad Al Aqili
Jeddah 23814
Kingdom of Saudi Arabia

Email: support@read-flow.app
Phone: +966 58 223 6355
Website: https://read-flow.app

Questions and requests about personal data should be sent to support@read-flow.app.

22. DEFINITIONS

Personal data Any information that, on its own or together with other information, allows a natural person to be identified.

Processing Any operation carried out on personal data by any means, manual or automated, including collecting, recording, storing, indexing, organising, modifying, updating, retrieving, using, disclosing, transmitting, publishing, sharing, linking, blocking, erasing and destroying.

Data Controller The person who determines the purposes and means of processing personal data. For Read-flow, that is us.

Data Processor A person who processes personal data on behalf of the Controller. The providers in section 7 are our processors.

Destruction Any action on personal data that makes it unreadable and irretrievable, or that makes it impossible to identify the person it relates to.

Disclosure Enabling anyone other than the Controller or Processor to access, collect or use personal data, by any means and for any purpose.

Transfer Moving personal data from one place to another for processing.

Personal data breach Any incident leading to the disclosure or destruction of, or unauthorised access to, personal data, whether deliberate or accidental, and by any means.

Sensitive data Personal data revealing racial or ethnic origin, religious, intellectual or political belief; data relating to security criminal convictions and offences; biometric or genetic data used to identify a person; health data; and data indicating that one or both of a person's parents are unknown.

Explicit consent Direct and explicit consent given in a form that clearly indicates acceptance of the processing in a way that cannot be interpreted otherwise, and that can be proven afterwards.

Legitimate interest A necessary interest of the Controller requiring the processing of personal data for a specific purpose, provided it does not adversely affect the rights and interests of the person concerned.

Direct marketing Communicating with a person by any direct physical or electronic means in order to direct marketing material at them.

Anonymisation Removing the direct and indirect identifiers that indicate someone's identity, in a way that permanently makes it impossible to identify them.

Personal Data Protection Law The Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations, as amended.

Competent Authority The authority overseeing the implementation of the Personal Data Protection Law, currently the Saudi Data and Artificial Intelligence Authority (SDAIA).

Kingdom The Kingdom of Saudi Arabia.

This policy relates solely to Read-flow.

We are established in the Kingdom of Saudi Arabia and the processing described here is governed by the Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations.

Related document: the Terms and Conditions of Read-flow.