Hardcover - Reader Privacy Policy

Effective September 14, 2026.
Publisher: Steas Software · hello@steassoftware.com

Hardcover is a local-first reading application. The app does not integrate a separate product-analytics service and does not sell personal information. The free version uses Google Mobile Ads for non-personalized banner advertising outside the reader. A one-time In-App Purchase removes advertising.

Information stored on the device

Hardcover stores the user's settings, declared birth date, repositories, installed-extension metadata, library, collections, reading history, reports, and offline downloads on the device. Extension credentials or other values designated as secure are stored in the iOS Keychain. The app keeps rotating on-device recovery points. Exported backups are created and shared only at the user's request.

Optional iCloud Sync

In versions that support iCloud Sync, this feature is off by default. If enabled, library metadata, linked-source identifiers and repository addresses, collections, chapter completion and reading positions, reading history, bookmarks, notes, reading status, and personal ratings are stored in the user's private CloudKit database, operated by Apple. Devices signed in to the same Apple Account can merge this data. Apple's iCloud terms and privacy policy apply.

Extension code, permissions, logins, downloaded chapters, imported book files, reading-time statistics, and device settings are not sent through this sync feature. It does not refresh source websites or download chapters. Turning sync off retains the local library and iCloud copy. Deleting synced items propagates to other synced devices; deletion metadata may remain to prevent stale devices from restoring them. Deleting the app does not itself delete its iCloud copy. Users can manage cloud storage in their Apple Account's iCloud storage controls.

Network activity and third parties

The app starts with no extension repositories and does not bundle, recommend, or automatically install one. A user may manually enter the HTTPS address of an independently operated repository. After explicit permission, an installed extension can request data only from the HTTPS domains listed during installation. Those operators receive ordinary network information such as the IP address, user-agent string, requested URL, and any credentials or cookies the user supplies. Their privacy policies and practices apply independently. Hardcover does not control those services.

The visible login/browser feature uses the iOS WebKit website data store. Cookies can be passed to the selected extension when the user taps “Use Session.” Reports are stored locally and, with user action, prepared for delivery through the user's configured mail application.

Advertising and purchases

If App Tracking Transparency authorization has not been decided, Hardcover asks for permission before starting Google Mobile Ads. If permission is denied, the app does not access the advertising identifier. Hardcover then uses Google's User Messaging Platform to determine whether a consent message or privacy-options control is required.

Hardcover configures Google Mobile Ads to disable ad personalization and limits requested ad content to Google's general-audience classification regardless of the user's ATT choice. Google and participating advertising services may still process coarse location (including location inferred from an IP address), device identifiers when permitted, device and app information, advertising data, product interactions, diagnostics, consent choices, and advertisement impressions or interactions to deliver, secure, and measure advertisements. Their privacy policies apply to that processing.

The Remove Ads purchase is processed by Apple. Hardcover requests the product and verifies the current entitlement through StoreKit; the publisher does not receive the user's payment-card details. When StoreKit reports a valid Remove Ads entitlement, Hardcover does not request or display banner advertisements.

Children and content controls

Hardcover is not directed to children under 13. Safe content is the default. Mature extensions require both an adult age declaration and a separate iOS Settings control. Explicit-adult extensions are unavailable in the App Store build.

Retention and deletion

Users can remove repositories and extensions, delete offline chapters, remove library entries, clear app data by deleting the app, and control backups in the destinations they selected. Removing an extension deletes its downloaded script files and extension-scoped state from the device. Advertising and purchase providers retain information according to their own policies and legal obligations.

Rights and requests

Because Hardcover does not operate an account service in this build, the publisher generally cannot access data stored only on a user's device. Contact hello@steassoftware.com for privacy questions or legally applicable requests.

Changes

Material changes will be posted on this page with an updated effective date.

Support · App Review source information