Privacy Policy

Last updated

Who is responsible

Arina Prokhorenko, an individual based in Spain, operates Versera and is the controller of personal data described here. Contact [email protected]. See the legal notice for identification and postal contact details.

Data we use and why

DataPurpose
Email, sign-in provider identifiers and account datesCreate and secure your account; deliver verification and recovery emails
Language choices and onboarding answersSet up your reading and translation experience
Uploaded EPUBs, file metadata, custom covers and library membershipStore your library and make books available on your devices
Reading position, activity, saved words, translations, source sentences and learning statusResume reading, sync progress and provide vocabulary practice and statistics
Reader settings and sync changesPreserve your preferences and support offline use
App Store transactions, subscription status and usage countersValidate purchases, restore access and enforce plan limits
Messages you send to supportRespond to feedback, requests and reports
Network and technical information, including IP addressesDeliver requests, secure the service and investigate failures

Passwords pass securely to Supabase Authentication; we do not store plaintext passwords. Apple and Google may provide profile information when you sign in. Versera requests no name and removes name fields from its authentication records; other provider identifiers remain necessary for sign-in. Apple handles payment details. Versera does not receive your card number.

EPUB layout is processed on your device. The original upload and metadata are stored on our servers. Words can also be sent to our backend's language-processing service to identify their base forms. Identical EPUB files can share storage without exposing one person's library to another. Your uploads and custom covers are private; catalog covers are public.

OpenAI: translation, speech and book preparation

Depending on the feature, our backend sends a selected word and its sentence, a selected passage, text to read aloud, a book excerpt for language detection, or chapter headings, subtitles and word counts for finding the story's start. We do not attach your account ID or email. Text you choose can itself contain personal information; avoid submitting sensitive or confidential material you do not have permission to share.

Translation and read-aloud process the text you request; personal uploads also use automatic language and chapter detection. You can read downloaded books and practice saved vocabulary without requesting new translations or audio. New translations, generated speech and upload preparation require a connection.

Our text requests disable Responses API storage. This does not establish zero retention: OpenAI's separate abuse-monitoring rules may still apply. OpenAI states that API data is not used for model training by default and that abuse-monitoring logs may be retained for up to 30 days, with exceptions. See OpenAI's data controls.

Optional app analytics

Analytics and diagnostics are off until you enable Share analytics and diagnostics in More → Settings → Privacy. PostHog then receives feature usage, app/build and device information, request performance and periodic system performance/diagnostic counts. Events use a random identifier that changes when the app restarts; they do not include your account ID, email, language profile, book text or saved words. Persistent device/session identifiers are removed from event properties. Screen recording, automatic screen tracking, person profiles and raw crash capture are disabled. These are limited, pseudonymous events, not a claim that network connections are anonymous: PostHog still receives connection information such as an IP address. Disabling the setting stops future collection on that device; contact us to request deletion of previously collected data.

The website separately measures visits and waitlist outcomes using PostHog with identifiers held in memory for the current visit, without analytics cookies or persistent browser identifiers. Network requests still expose technical connection information. We do not sell personal data, show advertising, or use these data to track you across other companies' apps for advertising.

Feature requests and reports

New feature requests are visible to you and the moderation team until reviewed. Approved titles and descriptions are public to signed-in readers, with vote counts; your email and account ID are not displayed on the board. Rejected requests remain visible only to you. We store votes, your blocked-author choices and private reports. Use a request's menu to report it or block its author; blocked authors' requests are hidden across devices. Moderators can remove inappropriate posts.

Service providers

ProviderRole and data involved
SupabaseAccount authentication, application database and file storage
RailwayHosts the API, language-processing service and website
OpenAIProcesses the text described above and generates audio
RevenueCatReceives app user identifiers and purchase information to validate subscription access
PostHogOptional app analytics/diagnostics and website visit analytics
ResendAccount emails and website waitlist contacts
Apple and GoogleSign-in services; Apple also handles distribution and subscription billing
CloudflareDNS, delivery and network security
Grafana CloudOperational service metrics and availability monitoring

Providers may process data outside Spain or the EEA. Applicable safeguards depend on the provider, processing location and contract, including adequacy decisions or standard contractual clauses. Contact us for information about the safeguards relevant to your data. Apple and Google also process information under their own policies when you use their services.

We process account, library, sync and subscription data to provide the service you request; security, abuse prevention and limited website measurement serve our legitimate interests in operating a reliable service. Book processing, translation and audio provide the features you request. Optional app analytics and launch emails rely on your consent. You can withdraw consent without affecting the lawfulness of earlier processing. Providing account information is necessary to use the account-based app; analytics is optional. We do not use your data for automated decisions that produce legal or similarly significant effects.

Joining the website waitlist supplies your email, chosen language and signup source to Resend for launch updates. Use the unsubscribe link in those emails or contact us to leave the list.

Retention and deletion

We keep account and reading data while your account exists. More → Settings → Delete Account removes the account and associated application records. File cleanup, Apple authorization revocation and deletion requests to RevenueCat and PostHog run separately and retry on failure; they may finish later. An identical EPUB remains while another library or the catalog still references it.

Backups, security records, provider logs and records needed for legal obligations can remain beyond account deletion under their applicable retention schedules. We do not promise immediate erasure from every backup or provider. Waitlist contacts remain until you unsubscribe or request deletion, or until they are no longer needed for launch communications; suppression records may be needed to respect an unsubscribe. Contact us for retention information about a particular record.

Offline copies on other devices cannot be remotely erased while those devices remain offline. Deleting Versera does not cancel Apple subscription billing. See account deletion.

Your rights

Where applicable, you may request access, correction, deletion, a portable copy, restriction or objection to processing, and withdraw consent. Email us; we may need proportionate information to verify that the request concerns your account. Do not send passwords or complete identity documents unless a specific verification need has been explained. You may complain to the Spanish Data Protection Agency or your competent local authority.

Versera is intended for people aged 14 or older, or the higher age required to consent to these services where they live. Contact us if a younger child has supplied personal data.

We update the date above when this policy changes. Material changes to consent-based processing require appropriate notice and, where necessary, renewed consent before that processing begins.