TOMELIGHT
Privacy Policy.
1. Who we are
Tomelight is an EPUB and FB2 reader published by CodeEnsis Ltd. ("we", "our", "us"), a company registered in Cyprus. This policy explains what the Tomelight mobile application collects, what it does with that data, and the rights you have.
2. What stays on your device
The following lives in Tomelight's own storage on your phone and is never transmitted to us:
- The book files you add, and the covers and metadata extracted from them.
- Your reading position, bookmarks and reading progress.
- Your highlights, the notes you attach to them, the words you save and your review schedule for them.
- Words you look up and the dictionary entries shown for them.
- Reading preferences: font, size, theme, margins, hyphenation, voice and speech rate.
- Offline dictionary files you chose to download.
If you uninstall Tomelight, this data is removed with the app. We perform no cloud backup of it.
3. What we never collect
- No CodeEnsis account or login is created or required.
- No book text, book titles, file names or cover images are sent to us or to anyone else.
- No words you look up are sent anywhere: the dictionary search runs on your device, against a file you downloaded.
- No passage you translate is sent anywhere: translation runs on your device (see section 7).
- No payment card or bank details: payment is handled entirely by Google Play or the App Store.
- No advertising identifiers. No third-party advertising SDKs.
- No contacts, location, microphone, camera or photo library access is requested.
4. Folders you connect
Tomelight can watch a folder you pick — on the phone itself, on an SD card, or in a cloud provider such as Google Drive, Dropbox or OneDrive that exposes its files through the Android file picker. Access is granted by you, folder by folder, through the system picker; Android, not Tomelight, decides what the app can reach.
- Tomelight only reads the folder. It never writes, renames or deletes anything in it.
- It copies EPUB and FB2 files it finds into its own storage on your device. Other file types are ignored.
- The folder is read on your device. The list of files and their contents are not sent to us.
- We receive no access to your cloud account and no token for it. You can revoke the folder at any time, in the app or in Android's system settings.
5. Dictionaries
Offline dictionaries are downloaded on your request from dicts.codeensis.com, hosted on Cloudflare R2. The request contains only which dictionary file you asked for. As with any web request, the serving infrastructure processes your IP address to deliver the file; we keep no record tying a download to a person, and the app sends no identifier of any kind with the request.
6. Reading aloud
Read-aloud uses the speech engine already installed on your device (for example Google Speech Services or Samsung TTS). The passage being read is handed to that engine by the operating system. Which engine you use, and whether it processes speech on the device or in the cloud, is decided by that engine's own settings and privacy policy, not by Tomelight. Tomelight sends no text to any server of ours.
7. Sentence translation
Sentence translation, a Tomelight Pro feature, uses Google ML Kit on-device translation. The text you translate is processed on your phone and is not sent to Google or to us.
- The first time you translate into a language, the app downloads that language’s translation model (around 30 MB) from Google’s servers. As with any download, Google processes your IP address to deliver it.
- ML Kit may contact Google’s servers to receive updates to its models, and it sends Google metrics about how the translation feature performs, such as device model, operating system version, app version and error information. According to Google, these metrics do not include the text being translated. See developers.google.com/ml-kit/terms and policies.google.com/privacy.
8. Purchases (Tomelight Pro)
Purchases are made through Google Play or the App Store. They take the payment; we never receive your card details, name or email address from them.
To confirm a purchase and keep Tomelight Pro active on your device, the app uses RevenueCat (RevenueCat, Inc.), a service that verifies store receipts on our behalf. RevenueCat receives:
- a random identifier it creates for your app installation, not linked to your name or email;
- the store’s purchase token or receipt, the product bought, its price and currency, the store country, and the purchase, renewal and cancellation dates;
- technical details such as app version, device model and operating system version, and your IP address as part of the network request.
We use this only to provide Pro, to restore a purchase, and to see aggregate sales figures. RevenueCat’s practices are described at revenuecat.com/privacy.
9. Export
When you export saved words or highlights, Tomelight creates the file on your device and hands it to the Android share window. Where it goes next (Anki, a notes app, email, cloud storage) is your choice and is governed by that app’s own terms. Tomelight itself does not upload it anywhere.
10. Analytics and crash reporting
Tomelight includes Google Firebase Analytics and Firebase Crashlytics so we can see whether the app works and where it breaks.
What is recorded is limited to the fact that something happened, plus short technical labels: a book was added (and whether from files or from a folder), a book was opened, read-aloud was started, a word was looked up, a highlight was made, a translation or review session was started, the Pro screen was opened or a purchase completed, a screen was viewed, together with app version, operating system version, device model, coarse region, and crash stack traces.
What is not recorded: book titles, authors, file names, book text, the words you look up, the passages you highlight or translate, your notes, the folders you connected, or anything else that could identify what you read.
Firebase is a service of Google LLC. Google's practices are described at policies.google.com/privacy. Firebase assigns the installation a random identifier; it is tied to the app installation, not to you, and it is discarded when you uninstall the app.
11. Permissions Tomelight asks for
- Internet — to download dictionaries and translation models you ask for, to verify purchases, and to send analytics and crash reports.
- Billing (Google Play): to offer Tomelight Pro through Google Play. It gives the app no access to your payment details.
- Foreground service (media playback) — to keep reading aloud while the screen is off, with controls in the notification shade.
- Modify system settings — asked for only on e-ink readers, and only if you use the front-light slider. It is granted by hand in a system window and is used for nothing else.
- Access to a folder you pick — granted per folder through the Android file picker, revocable at any time.
You can revoke any permission at any time in your device's system settings.
12. Children
Tomelight is a general-purpose reader. It is not directed at children under 13, and we do not knowingly collect data from children under 13.
13. Your rights
Because we hold no personal data on our servers, there is no CodeEnsis-side account to access, export or delete. At any time you can:
- Remove individual books, or disconnect any folder, from inside the app.
- Delete downloaded dictionaries in Settings → Dictionaries.
- Delete highlights and notes in a book’s Highlights list, and saved words in the Words tab.
- Clear the app's data, or uninstall Tomelight, to remove everything.
If you want the Firebase analytics and crash records, or the RevenueCat purchase records, associated with your app installation deleted, write to us and we will pass the request through the provider's data deletion process. Deleting purchase records does not cancel an active subscription; cancel it in your store account first.
14. Changes to this policy
We may update this policy as Tomelight evolves. Material changes will appear here with an updated "Effective" date above. Continuing to use Tomelight after a change means you accept the updated policy.
15. Contact
Questions or requests about this policy: [email protected]. A human reads every message.