Shadow Reader
There is no Shadow Reader account, and no library of ours. Your books, your place in them and your notes are kept in the app's own private storage on your device. Nothing you read is uploaded to us — we run no server that could receive it.
The app does reach the network, and every one of those uses is listed in §3. Two of them are on by default: crash reporting, and the Google Play services the store itself needs. Usage statistics are off until you switch them on. Both switches are in Settings › Privacy.
1. What the app stores on your device
All of it lives in app-private storage, readable by Shadow Reader and not by other apps. Uninstalling takes every bit of it with you.
Your library
- The folders you handed the app, and an index of the book files in them — title, authors, series, language, publisher, format, size, page or chapter count and a cover image
- Collections, tags, favourites, archive state and your own metadata edits
- A note of files that could not be imported, and why
Books are indexed where they are. The app copies a file into its own storage only when you import it that way, download it from a catalogue, or open it from a cloud source.
Your reading
- Where you are in each book, and where you have been
- Highlights, underlines, notes and bookmarks, with the passage each one refers to
- Reading sessions — how long you read or listened, and to what — and the streak and daily goal built on them
- Per-book settings: font, size, spacing, theme, voice, speed
Settings and identifiers
- Your app settings, including the two privacy switches
- A random identifier generated on first launch, used to tell your own devices apart when sync merges their changes. It is not derived from any hardware ID and identifies nothing outside your own sync folder.
- Whether Pro has been bought, as last reported by Google Play. This is kept device-local and deliberately outside anything that syncs.
Credentials
- For a cloud source or a WebDAV server you connect: the account name and a token or password, sealed by the app and kept in its private storage
- For a catalogue that needs a login: the credentials you entered, in the app's private database
That is proof against other apps on the device. It is not proof against someone holding your unlocked phone, or against a rooted device. Disconnecting an account deletes what was stored for it.
2. Permissions, and exactly what each one is for
| Permission | What Shadow Reader does with it |
|---|---|
| Folder access you pick each one |
Android's own document picker hands the app the folders and files you choose, and nothing else. Shadow Reader does not ask for all-files access, and cannot see storage you have not handed it. |
| Internet Network state |
Only for the things in §3: a cloud source or sync folder you connected, a catalogue you added, an opt-in metadata lookup, a language pack download, crash reporting, and Google Play's own billing, update and review services. Reading a local book uses no connection at all. |
| Foreground service media playback |
Keeps read-aloud running with the screen off, with the media notification and headset controls Android requires for it. |
| Notifications | The read-aloud media notification, and progress for a download or an import. Declining it costs those notices and nothing else. |
| Wake lock | Stops the device sleeping mid-sentence while it is reading aloud to you. |
There is no permission for contacts, location, the camera, the microphone or the phone, and none for enumerating the other apps you have installed.
3. What leaves the device, and when
Every case below is something you switch on. None of it happens on a fresh install except the crash reporting in §4 and Google Play's own services.
Sync, if you turn it on
Sync copies your positions, highlights, notes and bookmarks into a folder you nominate — a private area of your own Google Drive that only this app can see, your own WebDAV server, or a local folder. Book files and covers are not copied. The destination is yours: we hold no keys, run no server in the path, and never see the contents. Your devices read each other's changes from that folder.
Cloud sources, if you connect one
Connecting Google Drive, OneDrive, Box or a WebDAV server lets the app read books out of it. Shadow Reader issues no write of any kind — it cannot upload, rename, move or delete anything in your cloud. What it sends is the request for a file listing or a download, to that provider, using the account you signed into. A downloaded book is cached on the device and can be cleared without losing the book.
Catalogues you add
An OPDS catalogue is a server you chose. Browsing, searching or downloading from it sends those requests to that server, with any credentials you gave for it. We are not party to it.
Metadata lookup, per book, if you ask
Asking the app to fetch details for a book sends that book's title, author or ISBN to Open Library and Google Books, and nothing else. It is never automatic, and never happens for a book you did not ask about.
Language packs for translation
On-device translation downloads its language models from Google the first time you use a language pair. The passage itself is translated on the phone and is never sent anywhere. Text recognition on a scanned page is on-device too.
Google Play
Buying or restoring Pro goes through Google Play Billing; the app never sees or stores a card, and there is no licence check afterwards. Play's in-app update and review prompts are the same kind of thing — Google's own components, doing Google's own network calls. What those services collect is governed by Google's privacy policy, not this one.
4. Crash reports and usage statistics
These are two separate switches in Settings › Privacy, and they start in opposite positions.
- Crash reporting is on on a fresh install. When the app crashes or hits an error, a stack trace and basic device information — model, Android version, app version — go to Firebase Crashlytics so it can be fixed. A crash report describes the app failing, not what you were reading.
- Usage statistics are off until you switch them on. They describe which screens and features get used, and are what tells us whether a change helped. Performance measurement rides the same switch and is off with it.
Neither may carry a book title, an author, a file path or a passage from your books, and none of it is used for advertising or shared with advertisers. The app contains no advertising SDK and requests no advertising ID. Google acts as our processor for these reports; their handling is covered by Google's own privacy terms.
Turning either switch off stops collection from that moment. Both choices are remembered across updates.
5. What you can do with your data
- Export your notes. Every highlight, note and bookmark, out to a file you choose. Free on every plan.
- Back up the library. A copy of the database to a folder you pick, by hand whenever you like.
- Disconnect an account — the stored token or password for it is deleted.
- Clear caches in Settings › Storage & backup, including books downloaded from a cloud source.
- Delete the sync folder in your own Drive or WebDAV server, at any time, without asking us.
- Uninstall. That removes everything the app kept on the device. Because we never held a copy, there is no server-side data to request the deletion of. Crash reports already sent can be deleted on request — write to the address in §8.
6. Children
Shadow Reader is a reading app for a general audience and is not directed at children under 13. It has no social features, no messaging, no user profiles and no advertising, and it collects no personal information from anyone, of any age.
7. Changes to this policy
If what the app stores or sends changes, this page changes with it and the date at the top is updated. The policy is kept deliberately in step with what the code actually does — a policy that claims more than the app does would be worth nothing.
8. Contact
Questions about this policy, or about anything Shadow Reader stores: support@crackoncloud.com