Privacy policy
Atlas Unread has no advertising, no analytics SDK and no tracking. Nothing about you is sold or shared for advertising.
You can use the app without an account. If you make one, you can delete it and everything in it from inside the app, in Settings.
This policy covers the Atlas Unread Android app (app.dxnstudio.atlasunread), published by DXN Studio. It describes what the app actually does, not a general template.
What the app collects
If you create an account
Your email address, a display name you choose, and a password. Accounts are handled by Supabase Auth. Your password is stored as a salted hash, never in readable form, and it is never visible to us.
If you use the app without an account
Atlas Unread supports anonymous sessions. In that mode there is no email address and no display name. The app creates an anonymous identifier so your reading data has somewhere to live, and that identifier is all it has.
Your reading data
The books you add, your reading log, the countries and genres attached to those books, and any suggestions or votes you submit. This is the substance of the app, and it is stored against your account so it survives reinstalling.
Purchases
If you buy anything, Google Play processes the payment. We never see your card details. Subscription and entitlement state is managed through RevenueCat, which receives your account identifier and what you are entitled to, not your payment information.
Crash reports
When the app crashes it sends a diagnostic report through Sentry so the fault can be found and fixed. These reports are configured to carry as little as possible:
- Personally identifying information is switched off at the SDK level.
- Any user identifier attached to an event is replaced with redacted before the event is sent.
- Navigation breadcrumbs, which would otherwise record the screens you moved through, are dropped.
- Crash reporting is disabled entirely in development builds.
What remains is the technical picture of the fault: the error, where in the code it happened, the device model and the operating system version.
Test feedback, in test builds only
Builds given to testers before public release carry a FEEDBACK tab on the edge of the screen. Nothing is sent unless you open it and submit a report. A report holds the text you type, the category you pick (bug, suggestion or question), the app version, the platform, and your account identifier so a follow-up question can reach the right report.
If you tap the button to attach a screenshot, the app captures the screen you were on at that moment and uploads it with the report. It is optional and you can remove it before sending. Screenshots are kept in private storage that only we can view, and they are used only to understand and fix the problem you reported.
The public release of the app does not include the FEEDBACK tab. To have your test feedback removed, email [email protected].
What stays on your device
Several things the app does never leave your phone at all, and are worth naming because they look like they might:
- The camera. Atlas Unread can scan a book's barcode to identify it. It reads EAN and UPC barcodes only. It does not take photographs, and no image from the camera is stored or transmitted anywhere.
- Share images. When you share a badge or a card, the image is drawn on your device and handed to the Android share sheet. You choose where it goes. It is not uploaded to us.
- Your reading list export. Exporting to CSV writes the file on your device and passes it to the share sheet.
- Reminders. Notifications are scheduled locally by the app. There is no push service and no push token, so nothing about your device is registered with a notification server.
- Your session. Login tokens are held in the Android encrypted keystore, not in ordinary app storage.
What the app never collects
- No advertising. The app contains no ad SDK and does not touch the Android advertising ID.
- No analytics or product-measurement SDK of any kind.
- No location. The app does not request or use location permission.
- No contacts, no microphone. The microphone permission is explicitly blocked in the app's manifest.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Who else receives data
Atlas Unread relies on these services. Each one is listed with what it actually receives.
| Service | What it receives | Why |
|---|---|---|
| Supabase | Your account details, all of your reading data, and any test feedback you send | Hosts the database and handles sign-in |
| RevenueCat | Your account identifier and purchase status | Manages subscriptions and entitlements |
| Google Play | Your payment details, which we never see | Processes purchases |
| Sentry | Crash diagnostics, with the user identifier redacted | Finding and fixing faults |
To find book details, the app also queries public reference sources: the Google Books API, Open Library, Wikipedia, Wikidata, the Library of Congress and Fantlab. These requests go directly from your device and carry the title, author or ISBN being looked up. They do not carry your account, your email or your reading list. As with any direct request, the service receiving it can see your device's IP address. Fantlab is a Russian site: the app asks it only when a scanned or typed ISBN is from the group for Russia and the former USSR (it starts 978-5, or 5 on older books) and Open Library and Google Books have nothing, and it sends only the ISBN.
How long data is kept, and deleting it
Your account and reading data are kept until you delete them. You can do that yourself, in the app: Settings, then Delete account. It asks you to confirm, then removes the account and its associated data from the database.
If you would rather we did it, or you have lost access to the account, email [email protected] and we will handle it.
Crash reports expire on Sentry's own retention schedule and are not linked to your account.
Legal bases, for users in the UK and the EEA
Where the UK GDPR or the EU GDPR applies, we rely on these bases:
- Performance of a contract, for your account and the reading data that is the service itself. Without it the app cannot do what you installed it to do.
- Legitimate interests, for crash reporting and for keeping the service secure and working. Our interest is in shipping an app that does not crash. The reports are minimised as described above so that interest does not override your rights.
- Consent, for anything you volunteer, such as a suggestion you submit. You can withdraw it by deleting the content or your account.
Your rights
You have the right to access your data, correct it, delete it, restrict or object to how it is used, and to receive a copy in a portable form. The in-app CSV export covers the last of those for your reading list, and deletion is in Settings. For anything else, write to [email protected].
If you think we have handled your data badly, you can complain to your national data protection authority. In the UK that is the Information Commissioner's Office.
If you are in California
Under the CCPA and CPRA you may request the categories and specific pieces of personal information we hold, request deletion, and request correction. The categories collected are identifiers (email address, display name, account identifier), commercial information (purchase status) and internet activity limited to crash diagnostics.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. Exercising any of these rights will not get you worse service, since there is no tier of the app that depends on your data being used differently.
Children
Atlas Unread is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email [email protected] and it will be removed.
Security
Traffic between the app and our services uses HTTPS. Passwords are stored as salted hashes by Supabase Auth. Session tokens are kept in the Android encrypted keystore. No system is perfectly secure, and we will not pretend otherwise, but data is not collected where it is not needed, which is the part most within our control.
Changes to this policy
If this policy changes in a way that affects what is collected or who receives it, the effective date at the top will change and the app listing will point at the updated page. Material changes will be called out in the app's release notes rather than made quietly.
Contact
Questions, requests and complaints: [email protected].