Readive 개인정보 처리방침

1. 방침의 적용 범위

데브모어(이하 “운영자”)는 모바일 독서 앱 Readive(이하 “Readive” 또는 “앱”)를 운영합니다. 이 방침은 iOS, iPadOS 및 Android용 Readive에서 개인정보와 관련 정보를 어떻게 처리하는지 설명합니다.

Readive는 별도의 Readive 회원가입이나 자체 클라우드 계정을 요구하지 않습니다. 사용자가 가져온 도서·문서·오디오 파일과 대부분의 독서 기록은 사용자의 기기 안에서 처리되며, 운영자가 운영하는 서버로 업로드되지 않습니다.

다만 무료 버전의 광고, 구독 상태 확인, 오류 진단, 사용자가 선택한 플랫폼 계정 동기화·클라우드·원격 서버 연결, 웹 카탈로그 및 외부 검색·기기 내 번역 기능을 이용할 때는 아래에 설명한 외부 사업자가 관련 정보를 처리할 수 있습니다. 따라서 Readive가 어떠한 정보도 처리하지 않는다는 의미는 아닙니다.

2. 기기 안에서 처리하는 정보

다음 정보는 원칙적으로 앱의 로컬 데이터베이스, 앱 전용 파일 저장소 또는 운영체제의 보안 저장소에 보관됩니다. 운영자는 이 정보를 자체 서버로 수집하지 않습니다.

구분처리 항목이용 목적보관기간
도서 및 파일사용자가 선택한 파일, 파일명, 파일 형식, 크기, 로컬 위치, 원본 위치, 표지·썸네일, 페이지 수, 오디오 메타데이터파일 가져오기, 보관함 구성, 형식 판별, 렌더링과 재생사용자가 해당 항목을 삭제하거나 앱의 관련 저장소 데이터를 삭제할 때까지
독서 활동최근 읽은 위치, 진행률, 북마크, 하이라이트와 하이라이트한 문구, 읽기 이력, 세션 시간, 페이지 이동 수, 완독 상태, 오디오 재생 위치·배속·북마크읽던 위치 복원, 북마크·하이라이트, 독서 통계와 오디오북 재생사용자가 독서 기록·통계를 초기화하거나 관련 앱 데이터를 삭제할 때까지
앱 설정언어, 테마, 글꼴, 보기 방식, 썸네일 수, 리더·TTS·오디오북·다운로드 설정 등사용자 설정 유지사용자가 설정을 초기화하거나 관련 데이터를 삭제할 때까지
원격 서비스 연결정보연결 별칭, 서비스 종류, 서버 주소, 사용자명, 사용자 지정 헤더, 최근 연결 상태와 시각사용자가 등록한 원격 원본의 탐색과 다운로드사용자가 연결을 삭제하거나 관련 데이터를 삭제할 때까지
인증정보FTP·SMB·WebDAV 등의 비밀번호, Dropbox·OneDrive의 접근 토큰과 갱신 토큰원격 서비스 인증과 토큰 갱신사용자가 연결을 삭제하거나 인증정보를 제거할 때까지 운영체제 보안 저장소에 보관
다운로드 정보다운로드 대상, 진행 상태, 부분 파일과 재시도에 필요한 기술 정보백그라운드 다운로드와 중단 후 재개다운로드 완료, 취소 또는 해당 다운로드 데이터 삭제 시까지
오프라인 TTS 모델사용자가 내려받은 Supertonic 음성 모델, 설치 상태와 합성한 임시 WAV 파일기기 내 오프라인 음성 합성과 재생사용자가 저장소 관리에서 모델을 삭제하거나 앱 데이터를 삭제할 때까지. 임시 합성 파일은 재생 종료, 캐시 삭제 또는 모델 삭제 시 제거
기기 내 제목 번역웹 카탈로그 원제, 감지한 언어, 앱의 목표 언어, 번역 결과와 설치된 언어 모델원제 아래 참고용 번역 표시번역 결과는 앱 실행 중 최대 256개를 메모리에만 보관. 모델은 앱 데이터 또는 운영체제의 모델 관리 정책에 따라 별도 보관되며 번역을 끄는 것만으로 삭제되지 않음
선택형 동기화 정보임의의 논리 도서·기기 식별자, 기기 표시 이름, 파일명·제목·형식·크기·페이지 수·재생시간·콘텐츠 지문·원격 출처 별칭·위치, 파일 보유 상태, 읽기 진행률·북마크·하이라이트 문구·컬렉션 이름·구성, 독서 날짜·날짜별 독서 시간·페이지 이동 수, 통계 초기화 시각, 64KiB 이하 WebP 미리보기, 변경·삭제 표시와 동기화 시각같은 플랫폼의 사용자 기기 사이에서 보관함과 독서 상태를 복원하고 활동 통계를 통합하며, 원격 다시 다운로드 또는 파일 다시 연결 지원사용자가 동기화를 끄는 것만으로는 삭제되지 않으며, 관련 항목이나 Apple iCloud·Google Drive의 Readive 앱 데이터를 삭제할 때까지. 재등장을 막기 위한 최소 삭제 표시가 남을 수 있음
기기 및 앱 환경기기 유형, 제조사·브랜드, 시스템 언어, 사용 가능·전체 저장공간, 오디오 출력과 CarPlay 연결 여부, 로컬 웹 서버용 기기 IP 주소기기별 화면 구성, 기본 언어 설정, 저장공간 표시, 오디오 출력과 로컬 업로드 주소 제공기능 실행 중 일시적으로 처리하거나 관련 앱 설정과 진단정보의 보관기간 동안

Readive는 주민등록번호, 건강정보와 같은 민감정보나 고유식별정보를 요구하도록 설계되어 있지 않습니다. 사용자가 파일명, 하이라이트 또는 연결 별칭에 이러한 정보를 직접 입력하면 기기 안의 앱 데이터에 포함될 수 있으므로 입력에 주의해야 합니다.

2.1 기기 기능과 권한

Readive는 사용자가 요청한 기능을 제공하기 위해 다음 기기 기능 또는 권한을 사용할 수 있습니다. 실제 권한 이름과 승인 방식은 운영체제와 기기에 따라 다를 수 있습니다.

  • 사용자가 선택한 도서 파일을 가져오거나 다운로드 위치를 지정하기 위한 시스템 파일·폴더 선택기
  • 기기 내 웹 업로드 서버, 근거리 직접 전송과 북매니저 연동을 사용하기 위한 iOS 로컬 네트워크 접근
  • 근거리 직접 전송을 사용하기 위한 Android의 근처 기기·Bluetooth·근거리 Wi-Fi 및 운영체제 버전에 따른 로컬 네트워크 또는 위치 권한
  • 사용자가 북매니저 연결 QR 스캔을 선택했을 때 연결 코드를 인식하기 위한 카메라 접근
  • 오디오북을 재생하기 위한 백그라운드 오디오
  • 원격 원본·웹 카탈로그 연결, 번역 모델 설치, 광고와 구독을 위한 인터넷 접근 및 Android의 스토어 결제·포그라운드 데이터 동기화
  • 선택형 동기화를 위한 iOS의 iCloud 계정 상태·CloudKit과 Android의 Google 계정 승인·Drive 앱 데이터 접근

QR 스캔은 사진·동영상이나 음성을 저장하지 않습니다. 북매니저를 QR로 새로 연결하려면 카메라 권한이 필요합니다. 권한을 거부하거나 운영체제 설정에서 철회해도 기존 북매니저 연결과 앱의 다른 기능은 계속 사용할 수 있고, 연결 정보를 직접 입력하여 새로 연결할 수도 있습니다. Readive는 마이크 녹음이나 연락처 접근 권한을 요청하지 않으며 위치 좌표를 읽지 않습니다.

다만 이전 Android 버전에서는 Nearby Connections가 근처 기기를 찾기 위해 운영체제의 위치 권한을 요구할 수 있습니다. 근거리 전송 기능은 위치 좌표를 읽거나 Readive 서버에 수집하도록 구현되어 있지 않으며, 사용자가 직접 전송을 시작한 경우에만 필요한 근거리 권한을 요청합니다.

3. 네트워크를 통해 처리될 수 있는 정보

3.1 오류 진단

프로덕션 버전에서는 앱 안정성 개선을 위해 Sentry를 사용할 수 있습니다. 오류가 발생하면 다음 정보가 전송될 수 있습니다.

  • 오류 메시지와 스택 추적
  • 앱 버전, 운영체제와 기기 플랫폼
  • 오류가 발생한 기능, 작업 종류와 같은 제한된 진단 문맥

Readive는 계정정보, 비밀번호, 인증 토큰, 파일명, 파일 경로, 서버 주소, URL, 검색어, 도서 제목·저자와 본문을 전송 전에 제거하도록 구성되어 있습니다. 스크린샷, 화면 구조, 세션 재생, 네트워크 본문, 성능 프로파일링은 사용하지 않습니다. 다만 예기치 않은 오류 문자열에 사용자가 입력한 값이 포함될 가능성을 완전히 배제할 수는 없으며, 발견 시 필터를 보완합니다.

3.2 광고와 개인정보 선택

무료 버전에서 프리미엄 구독이 활성화되지 않은 경우 Google AdMob 및 User Messaging Platform(UMP)을 사용할 수 있습니다. 동의 상태와 운영체제 설정에 따라 광고 SDK가 다음 정보를 처리할 수 있습니다.

  • 광고 또는 기기 식별자
  • IP 주소 등 네트워크 정보와 IP 주소로부터 추정될 수 있는 대략적인 위치
  • 기기 종류, 운영체제, 앱 버전과 언어
  • 광고 노출, 클릭 등 광고 상호작용
  • 광고 개인정보 선택과 동의 상태
  • 광고 SDK의 진단 정보

Readive는 UMP가 광고 요청을 허용한 뒤 광고 SDK를 초기화합니다. 프리미엄 구독이 활성화되거나 광고 없는 유료 빌드를 사용하는 동안에는 Readive가 광고를 요청하지 않습니다. 사용 가능한 지역에서는 설정의 광고 개인정보 메뉴에서 선택을 다시 검토할 수 있습니다.

3.3 구독과 결제

프리미엄 구독의 상품 조회, 구매, 복원과 권한 확인에는 Apple App Store 또는 Google Play와 RevenueCat을 사용합니다. 다음 정보가 처리될 수 있습니다.

  • RevenueCat이 생성한 익명 앱 사용자 식별자
  • 스토어, 상품 식별자, 가격·통화와 상품 기간
  • 거래·영수증 정보, 구매와 갱신 상태
  • 프리미엄 권한의 활성 여부와 만료 정보
  • 구매·복원 과정의 기기 유형, 운영체제 등 기술정보와 오류정보

Readive는 RevenueCat SDK의 자동 기기 식별자 수집을 비활성화하도록 구성합니다. 결제 카드번호나 스토어 계정 비밀번호는 Apple 또는 Google이 직접 처리하며 운영자와 RevenueCat은 이를 받지 않습니다.

3.4 클라우드와 원격 원본

사용자가 설정에서 동기화를 직접 켜면 iOS·iPadOS에서는 같은 iCloud 계정의 Apple CloudKit 비공개 데이터베이스에, Android에서는 사용자가 승인한 Google 계정의 Drive appDataFolder에 동기화 정보를 저장합니다. Readive 자체 동기화 서버나 계정은 없으며 iOS와 Android 사이에는 동기화되지 않습니다. CloudKit 비공개 데이터는 해당 사용자의 iCloud 저장공간에, Drive 앱 데이터는 해당 Google 계정의 저장공간과 정책에 따릅니다.

동기화되는 정보에는 논리 도서와 기기의 임의 식별자, 기기 표시 이름, 파일명·도서 제목·형식·크기·페이지 수·재생시간·콘텐츠 지문, 자격증명 없는 원격 출처 별칭·종류·주소·경로, 해당 기기의 파일 보유 여부, 읽기 진행률·북마크·하이라이트한 문구·컬렉션 이름·구성, 독서 날짜·날짜별 독서 시간·페이지 이동 수, 통계 초기화 시각, 변경·삭제 시각과 64KiB 이하 WebP 미리보기가 포함될 수 있습니다. 독서 활동 통계는 원시 독서 세션 전체가 아니라 기록한 기기의 날짜별 집계 형태로 동기화됩니다. 저장된 책 수·전체 페이지 수·파일 용량·형식 분포, 즐겨찾기와 연결 수를 합산한 기기별 통계 결과 자체는 다른 기기와 통합하지 않습니다. 원본 도서 파일, 페이지·오디오 본문, 로컬 파일 URI, FTP·SMB·WebDAV 비밀번호, Dropbox·OneDrive 토큰, 사용자 지정 요청 헤더는 이 동기화 저장소에 업로드하지 않습니다. 현재 WebDAV에서 가져온 원격 책은 이전 버전과의 동기화 호환성을 위해 원격 출처 metadata 등록 대상에서도 제외됩니다.

원격 출처에서 다운로드한 항목은 다른 기기에 같은 출처와 자격증명이 등록되어 있으면 다시 다운로드할 수 있습니다. 시스템 파일 선택기나 PC 로컬 웹 업로드로 가져온 항목은 다운로드 주소 대신 미리보기와 파일 없음 상태를 표시하며, 이용자가 다른 기기에서 같은 콘텐츠 지문의 파일을 다시 선택하거나 원본이 있는 같은 플랫폼 기기에서 직접 전송할 수 있습니다.

사용자가 근거리 직접 전송을 시작하면 iOS는 필수 암호화를 적용한 MultipeerConnectivity를, Android는 Google Play services Nearby Connections를 사용하고 양쪽 기기에 같은 확인 코드를 표시해 수신자가 승인하도록 합니다. 수신 파일은 앱의 임시 캐시에만 둔 뒤 예상 콘텐츠 지문과 일치하는지 확인한 경우에만 보관함으로 가져옵니다. 이 직접 전송은 Readive 서버, CloudKit 또는 Google Drive에 원본 파일을 저장하는 방식이 아닙니다.

Android에서 Google 계정 이름과 단기 access token은 승인·철회와 Drive 요청 중 일시적으로 처리될 수 있습니다. access token은 Readive 앱 상태나 데이터베이스에 영구 저장하지 않습니다. 동기화 연결 해제는 이 기기의 동기화를 멈추고 Android에서는 승인 범위를 철회하지만, 다른 기기의 복원을 위해 Apple 또는 Google 저장소의 기존 동기화 정보는 자동으로 삭제하지 않습니다.

사용자가 직접 연결한 다음 서비스와 서버에 앱이 기기에서 직접 접속할 수 있습니다.

  • Dropbox
  • Microsoft OneDrive
  • 사용자가 등록한 HTTP(S)·OPDS·FTP·SMB·WebDAV 서버
  • 사용자가 직접 켠 기기 내 로컬 웹 업로드 서버

Dropbox와 OneDrive 연결에는 OAuth Authorization Code와 PKCE를 사용하며 파일 목록과 콘텐츠를 읽기 위한 범위로 권한을 제한합니다. 접근·갱신 토큰은 기기의 운영체제 보안 저장소에 보관되지만, 인증과 파일 요청 시 해당 공급자에게 전송됩니다.

WebDAV 연결은 사용자가 입력한 아이디와 비밀번호를 HTTP Basic 인증에 사용하며 비밀번호는 운영체제 보안 저장소에 보관합니다. 앱은 읽기 전용 폴더 조회와 파일 다운로드만 수행하고, 인증 헤더는 등록한 서버와 같은 origin에만 전송합니다. Digest·NTLM 인증과 자체 서명·만료·호스트명 불일치 HTTPS 인증서는 지원하지 않습니다.

사용자가 등록한 서버의 주소, 자격증명, 요청 헤더, 폴더·파일 정보와 다운로드한 콘텐츠는 해당 서버 운영자가 처리할 수 있습니다. 운영자는 사용자가 등록한 서버를 운영하거나 그 보안 수준을 통제하지 않습니다.

사용자 지정 헤더의 값은 비밀번호·OAuth 토큰과 같이 운영체제 보안 저장소에 보관합니다. 일반 로컬 데이터베이스에는 헤더 이름과 순서 및 값이 분리 보관되었음을 나타내는 정보만 남기고, 사용자 지정 헤더를 플랫폼 동기화 대상에 포함하지 않습니다. 이전 버전의 일반 로컬 데이터베이스에 저장된 헤더 값은 해당 연결을 다음에 읽을 때 보안 저장소 쓰기가 성공한 경우에만 일반 데이터베이스에서 제거합니다. 요청을 보낼 때에는 해당 값이 사용자가 등록한 서버로 전송되므로 서버와 전송 프로토콜의 보안을 확인하세요.

HTTP, FTP, HTTP 방식의 WebDAV 및 현재의 로컬 웹 업로드 서버는 전송이 암호화되지 않을 수 있습니다. 로컬 웹 업로드 서버는 경로 토큰, 비밀번호 또는 확인 코드 없이 http://기기 IP:포트/ 주소로 직접 접속합니다. 서버가 실행 중이면 이 주소에 도달할 수 있는 같은 로컬 네트워크의 누구나 폴더명, 파일명과 파일 크기를 보고 폴더 생성이나 파일 업로드를 시도할 수 있습니다. 앱이 백그라운드로 이동하거나 요청과 업로드 데이터가 15분 동안 없으면 서버를 자동으로 종료합니다. CORS를 허용하지 않고 Origin이 있는 요청은 같은 HTTP origin으로 제한하며 no-referrer, no-store, CSP와 프레이밍 차단 헤더를 사용하지만, 이 조치는 접속자를 인증하지 않습니다. 업로드는 파일당 8GiB, 서버 실행당 12GiB, 동시 2개로 제한하고 업로드 뒤 64MiB 이상의 여유 공간을 확보하며 중단된 부분 파일을 정리합니다. 공용·공유 네트워크에서는 사용하지 말고, 신뢰할 수 있는 사설 네트워크에서 필요한 동안만 켠 뒤 즉시 중지하세요.

3.5 외부 검색·사전·번역, 복사·공유와 음성 읽기

사용자가 리더에서 외부 검색·사전·번역 기능을 직접 선택하면 선택한 단어나 문구가 선택한 서비스의 URL에 포함되어 다음 사업자 중 하나로 전송될 수 있습니다.

  • NAVER 사전
  • Google 검색 또는 Google 번역
  • DeepL

이 화면은 웹뷰를 사용하므로 해당 사업자의 쿠키, 웹 저장소와 개인정보 처리방침이 적용될 수 있습니다. 외부 서비스로 보내기 전에 전송할 문구를 확인해야 합니다.

복사 기능을 선택하면 사용자가 선택한 문구가 운영체제 클립보드에 저장됩니다. 클립보드 내용은 사용자가 덮어쓰거나 운영체제가 지울 때까지 남을 수 있으며, 다른 앱의 접근 여부는 운영체제 정책과 권한에 따릅니다. Readive는 클립보드 내용을 운영자의 서버로 별도 전송하지 않습니다.

운영체제 공유 기능을 선택하면 사용자가 선택한 문구가 사용자가 고른 앱으로 전달됩니다. 시스템 TTS 음성은 기기에 설치된 운영체제의 음성 엔진을 사용하며, 음성 엔진 공급자의 설정에 따라 텍스트가 처리될 수 있습니다. 운영자는 클립보드에 접근하는 다른 앱, 공유 대상 앱이나 시스템 음성 엔진의 처리를 통제하지 않습니다.

사용자가 Supertonic 음성 다운로드를 선택하면 고정된 모델 파일을 GitHub Releases에서 HTTPS로 내려받습니다. 이때 IP 주소, 기기·네트워크 정보와 다운로드 요청은 GitHub의 정책에 따라 처리될 수 있습니다. 설치 후 Supertonic 합성은 기기 안에서 실행되며 합성할 문구는 GitHub나 운영자의 서버로 전송되지 않습니다. 생성된 임시 WAV 파일도 앱 전용 캐시에만 저장됩니다.

3.6 북매니저 LAN 연동과 QR 스캔

사용자가 북매니저 PC와 연결하면 승인한 PC 파일·폴더와 표지·메타데이터를 가져오고 독서 진행 기록을 같은 로컬 네트워크에서 동기화합니다. 연결 인증정보는 운영체제 보안 저장소에 보관하고, PC의 인증서 지문을 고정한 HTTPS를 직접 연결된 Wi-Fi·Ethernet의 사설 IPv4 주소로만 사용합니다. 북매니저 연동의 인증정보와 전송 데이터는 이 연결을 통해서만 주고받으며 Readive 운영자의 서버나 QR 인식 사업자에게 보내지 않습니다. 앱이 백그라운드로 이동하면 진행 중인 LAN 요청을 취소합니다. 연결을 해제해도 이미 가져온 책과 PC에 저장된 기록은 자동으로 삭제되지 않습니다.

QR 스캔 화면의 이미지는 기기에서 해독하고 사진·동영상 파일로 저장하지 않습니다. QR 이미지와 해독한 연결 정보는 Google에 전송하지 않습니다. Android의 Google ML Kit는 이 입력·결과와 별도로 기기·앱 정보, 설치 단위 식별자, 인식 지연·설정·입출력 크기·오류 등의 사용·성능 통계를 Google에 HTTPS로 전송할 수 있습니다. 이 통계 처리는 북매니저 데이터의 LAN 전송과 별개입니다. ML Kit 약관·개인정보 안내와 Android 데이터 공개 안내를 따릅니다. QR 스캔 대신 PC 북매니저에서 만든 연결 정보를 직접 입력하여 새로 연결할 수 있습니다. 연결 정보를 직접 입력하는 데에는 카메라 권한이 필요하지 않으며, QR 스캔을 원하지 않으면 카메라를 허용하지 않고도 새로 연결할 수 있습니다. 기존 연결과 앱의 다른 기능도 계속 사용할 수 있습니다.

3.7 웹에서 찾기와 기기 내 제목 번역

웹에서 찾기를 이용하면 목록·검색·상세 정보는 Project Gutenberg와 LibriVox에, 파일·표지 요청은 해당 제공처 또는 Internet Archive에 HTTPS로 전송됩니다. 제공처는 검색어, 선택한 언어, 요청한 작품·파일 주소, IP 주소와 앱 식별 정보 등 요청에 필요한 기술 정보를 처리할 수 있습니다. 표지는 기기에 캐시되며 다운로드한 도서의 출처와 권리 확인 기록은 기기에 보관됩니다. Loyal Books 등 외부 사이트 링크를 열면 해당 사이트의 개인정보 처리방침, 쿠키와 웹 저장소 정책이 적용됩니다.

제목 번역은 사용자가 켜는 선택 기능입니다. Android에서는 Google ML Kit Translation·Language Identification, iOS·iPadOS 18 이상에서는 Apple Translation·NaturalLanguage를 사용합니다. 원제와 번역 결과는 기기 안에서 처리하며 Readive 운영자나 클라우드 번역 서버에 보내지 않습니다. 번역 결과는 앱 실행 중 제한된 메모리 캐시에만 보관하고 영구 저장하지 않습니다. 번역을 꺼도 원래 목록·검색·다운로드를 사용할 수 있습니다.

설치되지 않은 언어 모델은 사용자가 번역을 켜거나 준비를 요청할 때 내려받습니다. Android에서는 Wi-Fi를 요구하고 Google 서버에서 모델을 받으며, iOS·iPadOS에서는 Apple의 시스템 모델 준비·동의 흐름을 따릅니다. 이때 공급자는 IP 주소, 기기·네트워크 정보, 요청한 언어와 모델 등 다운로드에 필요한 정보를 처리할 수 있습니다. 모델이 설치되면 제목 번역은 기기 안에서 실행됩니다. 화면을 닫거나 번역을 꺼도 이미 시작된 Android SDK 모델 다운로드가 이어질 수 있으며, 번역을 끄는 것만으로 설치된 모델이 삭제되지는 않습니다.

Android ML Kit는 제목·번역문 자체와 별도로 감지한 언어, 원문·목표 언어, 기기·앱 정보, 설치 단위 식별자, 입출력 크기, 모델 다운로드·사용 이벤트, 지연·오류 등의 성능·사용 지표를 Google에 HTTPS로 보낼 수 있습니다. Translation SDK는 원격 설정 진단에 Firebase Remote Config·Installations도 사용합니다. 이 처리는 광고 동의와 별개이며 제목 번역을 사용하지 않을 수 있습니다. 자세한 범위는 ML Kit 약관·개인정보 안내와 Android 데이터 공개 안내를 따릅니다.

4. 처리위탁과 외부 사업자

운영자는 서비스 제공에 필요한 범위에서 다음 사업자를 이용합니다. 사용자가 직접 선택해 연결하는 클라우드·검색 서비스는 해당 사업자가 자신의 약관과 개인정보 처리방침에 따라 별도로 처리할 수 있습니다.

사업자역할과 목적처리될 수 있는 정보적용 조건
Functional Software, Inc. (Sentry)앱 오류 수집과 진단오류·스택 추적, 앱·OS·플랫폼과 제한된 진단 정보프로덕션 오류 진단이 설정된 경우
Google LLC (AdMob, UMP)광고 제공, 측정과 동의 관리광고·기기 식별자, IP·기기·광고 상호작용·동의 정보광고가 활성화된 무료 이용자
Google LLC (ML Kit)Android QR 인식·언어 식별·번역 SDK 진단·사용 통계와 언어 모델 배포기기·앱 정보, 설치 단위 식별자, 사용·성능 통계, 감지한 언어와 원문·목표 언어, 모델 요청. QR 이미지·해독 결과와 제목·번역문 자체는 제외사용자가 Android QR 스캐너나 제목 번역을 사용하거나 모델 준비를 요청할 때
Apple Inc. (Translation)iOS·iPadOS의 기기 내 번역용 언어 모델 준비시스템 동의·모델 요청과 기기·네트워크 정보. 제목·번역문은 기기에서 처리사용자가 지원되는 기기에서 번역 모델 준비를 요청할 때
Project Gutenberg, LibriVox, Internet Archive 및 사용자가 여는 외부 자료 사이트웹 카탈로그 조회, 표지 표시와 파일 제공검색어·선택 언어, 작품·파일 요청, IP 주소와 기술 정보. 외부 사이트에서는 해당 쿠키·브라우저 정보 포함사용자가 웹에서 찾기를 이용하거나 외부 사이트를 열 때
RevenueCat, Inc.구독 상품, 영수증과 프리미엄 권한 관리익명 앱 사용자 ID, 상품·거래·영수증·구독 상태, 기기·운영체제와 기술·오류 정보구독 기능을 조회·구매·복원할 때
Apple Inc. 또는 Google LLC앱 배포, 인앱 결제, 구독과 환불 처리스토어 계정, 결제·거래·구독 정보해당 스토어를 사용할 때
Apple Inc. (iCloud/CloudKit) 또는 Google LLC (Drive)사용자가 선택한 같은 플랫폼 기기 동기화 저장소와 계정 승인제2조의 선택형 동기화 정보, iCloud 또는 Google 계정·승인 관련 기술정보사용자가 동기화를 켠 경우
Apple Inc. (MultipeerConnectivity) 또는 Google LLC (Play services Nearby Connections)근거리 기기 발견, 연결 승인과 암호화된 기기 간 파일 전송기기 표시 이름, 근거리 endpoint 식별자, 확인 코드·연결 상태와 사용자가 선택한 파일사용자가 직접 근거리 전송을 시작한 경우
Dropbox, Inc.사용자가 연결한 Dropbox 파일의 탐색과 다운로드OAuth 정보, 파일·폴더 메타데이터와 요청한 콘텐츠사용자가 Dropbox를 연결한 경우
Microsoft Corporation사용자가 연결한 OneDrive 파일의 탐색과 다운로드OAuth 정보, 파일·폴더 메타데이터와 요청한 콘텐츠사용자가 OneDrive를 연결한 경우
Microsoft Corporation (GitHub)사용자가 요청한 Supertonic 음성 모델 배포IP 주소, 기기·네트워크 정보와 모델 다운로드 요청사용자가 Supertonic 모델 다운로드를 선택한 경우
NAVER, Google 또는 DeepL사용자가 요청한 검색·사전·번역사용자가 선택한 문구, IP·브라우저 정보와 쿠키 등사용자가 해당 기능을 선택한 경우

운영자는 개인정보를 판매하지 않습니다. 운영자가 독자적인 광고 목적 등으로 위 표의 범위를 넘어 개인정보를 제3자에게 제공하게 되는 경우에는 관계 법령이 요구하는 고지와 동의 절차를 거칩니다.

각 사업자의 정책은 다음 페이지에서 확인할 수 있습니다.

5. 국외 처리

외부 SDK와 사용자가 선택한 글로벌 서비스를 이용하면 정보가 대한민국 밖에서 처리될 수 있습니다. 운영자가 서비스 제공을 위해 외부 사업자에게 처리를 맡기는 경우에는 개인정보 보호법 제28조의8 제1항 제3호에 따라 이 방침에 국외 처리 내용을 공개합니다. 사용자가 직접 선택하는 스토어·클라우드·검색 서비스에는 해당 사업자의 방침과 이용 조건이 함께 적용됩니다.

이전받는 자와 연락처국가항목목적시점과 방법보유·이용기간근거와 거부 방법
Functional Software, Inc. / compliance@sentry.io독일오류·스택 추적, 앱·OS·플랫폼과 제한된 진단 정보오류 진단오류 발생 시 암호화된 네트워크 전송프로젝트 설정과 계약에 따른 이벤트 보존기간 후 삭제 또는 비식별화서비스 안정성 확보를 위한 처리위탁; 앱에는 개별 비활성화 설정이 없으며 전송된 정보에 관한 요청은 운영자 이메일로 접수
Google LLC / Google 개인정보 문의미국을 포함하여 Google 또는 그 처리자가 시설을 운영하는 국가광고·기기 식별자, IP·기기·광고 상호작용·동의 정보광고 제공, 측정과 동의 관리광고 또는 동의 요청 시 암호화된 네트워크 전송정보 유형, 사용자 설정과 Google 정책에 따른 기간서비스 제공을 위한 처리위탁 또는 적용 지역의 동의; 광고 개인정보 설정을 변경하거나 프리미엄 또는 광고 없는 유료 빌드를 이용하면 Readive의 광고 요청을 제한할 수 있음
Google LLC (ML Kit) / Google 개인정보 문의미국을 포함하여 Google 또는 그 처리자가 시설을 운영하는 국가기기·앱 정보, 설치 단위 식별자, 사용·성능 통계, 감지한 언어와 원문·목표 언어, 모델 요청QR 인식·언어 식별·번역 SDK 진단·개선과 모델 배포Android QR 스캐너·제목 번역 사용 또는 모델 준비에 따른 HTTPS 전송Google 정책에 따른 기간사용자가 선택한 QR 인식·제목 번역 기능 제공; QR 스캔 대신 연결 정보를 직접 입력하거나 제목 번역을 끌 수 있으며 기존 연결·원제 목록·다른 앱 기능은 유지
RevenueCat, Inc. / compliance@revenuecat.com미국 및 RevenueCat의 처리자가 시설을 운영하는 국가익명 앱 사용자 ID, 상품·거래·영수증·구독 상태, 기기·운영체제와 기술·오류 정보구독과 권한 관리상품 조회·구매·복원·권한 확인 시 암호화된 네트워크 전송구독 권한 관리와 법적 의무에 필요한 기간 후 삭제 또는 비식별화구독 계약의 이행을 위한 처리위탁; 구독 기능을 이용하지 않거나 운영자 이메일로 삭제를 요청할 수 있으며 거부하면 구매·복원·권한 확인이 제한됨
Apple Inc. 또는 Google LLC미국을 포함하여 선택한 스토어 사업자 또는 그 처리자가 시설을 운영하는 국가스토어 계정, 결제·거래·구독 정보앱 배포와 결제사용자가 스토어를 이용할 때 해당 사업자 시스템으로 전송각 스토어 정책과 법정 보존기간사용자가 선택한 스토어 계약의 이행; 유료 상품을 구매하지 않으면 결제 관련 전송은 발생하지 않음
Apple Inc. (iCloud/CloudKit) 또는 Google LLC (Drive) / 각 사업자의 개인정보 문의 절차미국을 포함하여 선택한 공급자 또는 그 처리자가 시설을 운영하는 국가논리 도서·기기 식별자와 기기 표시 이름, 파일 메타데이터와 지문, 출처 별칭·위치, 파일 보유 상태, 읽기 진행률·북마크·하이라이트 문구·컬렉션 이름·구성, 독서 날짜·날짜별 독서 시간·페이지 이동 수와 통계 초기화 시각, 작은 WebP 미리보기, 계정 승인 기술정보같은 플랫폼 기기 동기화, 복원과 독서 활동 통계 통합사용자가 기능을 켠 뒤 앱 시작·foreground 복귀·수동 동기화 시 암호화된 네트워크 전송각 공급자의 정책 및 사용자가 해당 공급자 저장소의 Readive 앱 데이터를 삭제할 때까지; 최소 삭제 표시가 남을 수 있음사용자가 요청한 선택 기능의 이행; 동기화를 켜지 않거나 연결 해제할 수 있으며, 완전 삭제는 앱과 공급자의 앱 데이터 관리 절차를 모두 확인해야 함
Dropbox, Inc. 또는 Microsoft Corporation미국을 포함하여 선택한 공급자 또는 그 처리자가 시설을 운영하는 국가OAuth 정보, 파일·폴더 메타데이터와 요청 콘텐츠사용자가 요청한 파일 탐색과 다운로드사용자가 연결·탐색·다운로드할 때 암호화된 네트워크 전송각 공급자의 정책 또는 사용자가 연결을 해제하고 관련 정보가 삭제될 때까지사용자가 요청한 외부 서비스의 이행; 연결하지 않거나 언제든 연결과 공급자 계정의 접근 권한을 해제할 수 있으며 해당 원격 기능만 제한됨
Microsoft Corporation (GitHub)미국 및 GitHub 또는 그 처리자가 시설을 운영하는 국가IP 주소, 기기·네트워크 정보와 모델 다운로드 요청Supertonic 음성 모델 배포사용자가 모델 다운로드를 선택할 때 HTTPS 전송GitHub 정책에 따른 로그 보유기간사용자가 요청한 선택 기능의 이행; 모델을 내려받지 않으면 전송되지 않으며 시스템 TTS는 계속 사용할 수 있음
Google LLC 또는 DeepL SE미국, 독일 및 선택한 공급자 또는 그 처리자가 시설을 운영하는 국가선택 문구, IP·브라우저 정보와 쿠키 등검색·번역사용자가 기능을 실행할 때 웹 연결로 전송각 공급자의 정책에 따른 기간사용자가 요청한 외부 조회의 이행; 기능을 실행하지 않으면 전송되지 않으며 해당 외부 조회만 제한됨

6. 자동 수집 기술과 거부 방법

Readive 자체 계정용 쿠키는 사용하지 않습니다. 다만 다음 기술이 사용될 수 있습니다.

  • AdMob·UMP의 광고 또는 기기 식별자와 동의 신호
  • Sentry의 오류 이벤트 식별자와 진단정보
  • Android QR 인식·언어 식별·제목 번역에 사용하는 ML Kit의 설치 단위 식별자, 언어 정보와 사용·성능 통계
  • RevenueCat의 익명 앱 사용자 식별자
  • 외부 검색·사전·번역 웹뷰의 쿠키와 웹 저장소

사용자는 운영체제의 추적·광고 설정, Readive의 광고 개인정보 메뉴, 외부 서비스의 쿠키 설정을 이용할 수 있습니다. 프리미엄 구독 중에는 Readive가 광고를 요청하지 않습니다. 일부 처리를 거부하면 맞춤 또는 일반 광고, 구독 확인, 외부 조회 등 해당 기능이 제한될 수 있습니다.

7. 보유기간과 파기

기기 안의 정보는 제2조 표의 기간 동안 보관됩니다. 사용자는 앱에서 도서, 기록, 캐시, 연결정보와 설정을 항목별로 삭제하거나 초기화할 수 있습니다. 삭제된 앱 전용 파일은 앱에서 복구할 수 없도록 제거하고 데이터베이스 기록은 삭제합니다.

다만 삭제 메뉴마다 범위가 다르며 다음 항목은 별도로 확인하거나 삭제해야 할 수 있습니다.

  • 사용자가 직접 지정한 외부 다운로드 폴더의 파일
  • 앱 설정과 오디오북 재생 설정
  • 중단된 다운로드 상태와 부분 파일
  • 내려받은 Supertonic 음성 모델과 앱 전용 캐시의 임시 합성 파일
  • 설치된 번역 언어 모델(번역 끄기와 모델 삭제는 별개이며, 앱 데이터 또는 운영체제의 모델 관리 범위에 따름)
  • 운영체제 백업 또는 보안 저장소에 남은 정보
  • iCloud CloudKit 또는 Google Drive appDataFolder에 남은 동기화 정보와 삭제 표시
  • 외부 사업자가 자신의 정책과 법적 의무에 따라 보관하는 정보

동기화 연결 해제는 공급자 저장소의 동기화 정보를 삭제하지 않습니다. 완전 삭제가 필요하면 iCloud 또는 Google Drive의 앱 데이터 관리 기능에서 Readive 데이터를 삭제하고, 다른 기기에서 동기화가 계속 켜져 있지 않은지 확인해야 합니다. 항목 삭제 후 오래된 기기에서 다시 나타나는 것을 막기 위해 논리 식별자와 삭제 시각 같은 최소 tombstone이 남을 수 있으며, 공급자 앱 데이터 전체를 삭제하면 이러한 표시도 제거됩니다.

원격 연결 자격증명은 해당 연결을 삭제한 뒤, 필요한 경우 Dropbox·Microsoft 또는 서버 측에서도 Readive의 접근 권한을 철회하세요. 운영체제에 따라 앱 삭제 후에도 보안 저장소, 백업 또는 플랫폼 동기화 저장소에 일부 값이 남을 수 있으므로 기기를 처분하거나 공유하기 전에는 앱 안에서 연결과 관련 데이터를 먼저 삭제하는 것이 좋습니다.

외부 사업자는 각자의 정책, 운영자의 계약상 지시와 법정 의무에 따라 정보를 삭제하거나 비식별화합니다.

8. 이용자의 권리와 행사 방법

사용자는 다음 방법으로 자신의 정보 처리를 관리할 수 있습니다.

  • 앱의 저장소 관리에서 도서, 독서 기록, 캐시, 연결정보 또는 관련 데이터를 삭제
  • 카메라 권한을 철회하여 QR 스캔을 중지(연결 정보 직접 입력을 통한 새 연결, 기존 북매니저 연결과 다른 앱 기능은 계속 이용 가능)
  • 앱 설정을 초기화
  • Dropbox·OneDrive 연결을 삭제하고 공급자 계정에서 접근 권한 철회
  • 동기화를 끄고, 완전 삭제가 필요하면 iCloud 또는 Google Drive에서 Readive 앱 데이터 삭제
  • 광고 개인정보 메뉴 또는 운영체제 설정에서 광고 선택 변경
  • App Store 또는 Google Play에서 구독 확인·해지와 환불 요청
  • 외부 검색·사전·번역 기능을 사용하지 않거나 해당 웹사이트의 개인정보 설정 이용
  • 웹 카탈로그의 제목 번역을 끄거나 모델 준비를 요청하지 않기
  • 아래 개인정보 문의처로 열람, 정정, 삭제, 처리정지 또는 동의 철회 요청

Readive 계정이 없고 대부분의 정보가 기기에만 있으므로 운영자가 특정 사용자의 로컬 데이터를 원격으로 조회하거나 대신 삭제할 수 없는 경우가 있습니다. 이때 운영자는 가능한 인앱 삭제 방법을 안내합니다. 외부 사업자가 보유한 정보에 관한 요청은 해당 사업자의 본인 확인과 절차가 적용될 수 있습니다.

만 14세 미만 아동 등 법정대리인의 동의가 필요한 이용자의 요청은 관계 법령에 따라 법정대리인이 행사할 수 있습니다.

9. 안전성 확보조치

운영자는 처리하는 정보의 성격에 맞춰 다음 조치를 적용합니다.

  • 비밀번호와 OAuth 토큰을 일반 설정 저장소가 아닌 운영체제 보안 저장소에 보관
  • Dropbox·OneDrive 인증에 Authorization Code와 PKCE를 사용하고 읽기 권한으로 범위 제한
  • iOS 동기화는 CloudKit 비공개 데이터베이스를 사용하고 Android 동기화는 비민감 drive.appdata 범위만 요청
  • 동기화 payload에서 원본 파일, 로컬 URI, 비밀번호, OAuth token과 사용자 지정 헤더를 제외하고 원격 주소의 사용자정보·query·fragment 제거
  • 지원되는 외부 사업자 API 통신에 HTTPS 사용
  • 오류 진단 전 민감한 키와 콘텐츠 관련 문맥 제거
  • 광고 동의 상태를 확인한 뒤 광고 요청
  • 앱 전용 저장소와 운영체제 샌드박스 사용

사용자가 직접 등록한 HTTP·FTP 서버와 HTTP 방식 WebDAV는 암호화 또는 충분한 인증 보호를 제공하지 않을 수 있습니다. 로컬 웹 업로드 서버도 접속 인증이나 HTTP 전송 암호화를 제공하지 않으며, same-origin 확인, CSP와 no-store 같은 브라우저 보호는 같은 로컬 네트워크의 다른 기기에서 직접 접속하는 사용자를 차단하지 않습니다. 이러한 연결은 신뢰할 수 있는 네트워크에서만 사용하고 자격증명을 다른 서비스와 재사용하지 마세요.

10. 아동의 개인정보

Readive는 만 14세 미만 아동을 대상으로 제공되는 서비스가 아니며, 만 14세 미만 아동을 위한 법정대리인 동의 절차를 제공하지 않습니다. 만 14세 미만 아동은 Readive를 이용할 수 없습니다. 운영자는 회원가입 과정에서 생년월일이나 연령을 요구하지 않지만, 만 14세 미만 아동의 개인정보가 운영자가 사용하는 외부 시스템에서 처리된 사실을 알게 되면 확인 후 관계 법령에 따라 삭제 등 필요한 조치를 합니다.

11. 개인정보 보호책임자와 문의처

개인정보 관련 문의, 권리 행사와 고충 처리는 위 이메일로 접수합니다. 운영자는 관계 법령에 따라 본인 여부와 요청 내용을 확인하고 처리 결과를 안내합니다.

개인정보 침해에 관한 상담이나 분쟁조정이 필요한 경우 개인정보침해 신고센터, 개인정보분쟁조정위원회 등 관계 기관에 도움을 요청할 수 있습니다.

12. 방침의 변경

운영자가 이 방침을 변경할 때에는 시행일 전에 앱 또는 공개 웹페이지를 통해 변경 내용과 시행일을 알립니다. 이용자의 권리에 중대한 영향을 미치는 변경은 관계 법령이 요구하는 기간과 방법에 따라 별도로 알리고 필요한 경우 동의를 받습니다.

앱 안의 문서와 공개 웹 문서가 일시적으로 다를 경우, 더 최근의 시행일과 문서 버전이 표시된 공개 웹 문서를 최신 방침으로 봅니다. 다만 관계 법령상 이용자에게 더 유리한 내용이나 강행규정은 계속 적용됩니다.

Readive Privacy Policy

1. Scope of This Policy

devmore (the “Operator”) operates the Readive mobile reading application (“Readive” or the “App”). This Policy explains how personal information and related data are processed in Readive for iOS, iPadOS, and Android.

Readive does not require a separate Readive registration or proprietary cloud account. Books, documents, and audio files imported by the user, as well as most reading records, are processed on the user’s device and are not uploaded to a server operated by the Operator.

However, when the user accesses advertising in the free version, subscription status verification, error diagnostics, optional platform-account synchronization, a cloud or remote server selected by the user, a web catalog, or an external search or on-device translation feature, the external parties described below may process relevant information. This does not mean that Readive processes no information at all.

2. Information Processed on the Device

The following information is generally stored in the App’s local database, app-specific file storage, or the operating system’s secure storage. The Operator does not collect this information through its own server.

CategoryInformation processedPurposeRetention
Books and filesFiles selected by the user, file name, file format, size, local location, original location, cover and thumbnail, page count, and audio metadataImporting files, organizing the library, identifying formats, rendering, and playbackUntil the user deletes the relevant item or the related App storage data
Reading activityLast reading position, progress, bookmarks, highlights and highlighted text, reading history, session duration, page-turn count, completion status, and audio playback position, speed, and bookmarksRestoring the reading position, providing bookmarks and highlights, reading statistics, and audiobook playbackUntil the user resets reading records or statistics, or deletes the related App data
App settingsLanguage, theme, font, view mode, thumbnail count, and reader, TTS, audiobook, and download settingsRetaining user preferencesUntil the user resets the settings or deletes the related data
Remote service connection informationConnection alias, service type, server address, username, custom headers, and recent connection status and timeBrowsing and downloading from remote sources registered by the userUntil the user deletes the connection or related data
Authentication informationPasswords for FTP, SMB, WebDAV, and similar services, and Dropbox and OneDrive access and refresh tokensAuthenticating remote services and refreshing tokensStored in the operating system’s secure storage until the user deletes the connection or removes the authentication information
Download informationDownload target, progress status, partial files, and technical information required for retryingBackground downloads and resuming interrupted downloadsUntil the download is completed or canceled, or the related download data is deleted
Offline TTS modelSupertonic voice model downloaded by the user, installation status, and temporary synthesized WAV filesOn-device offline speech synthesis and playbackUntil the user deletes the model in storage management or deletes the App data. Temporary synthesis files are removed when playback ends, the cache is cleared, or the model is deleted
On-device title translationCatalog title, identified language, target App language, translation result, and installed language modelsDisplaying a reference translation below the original titleUp to 256 results remain only in memory while the App runs. Models are retained separately under App-data or operating-system model-management policies and are not deleted merely by disabling translation
Optional synchronization informationRandom logical book and device identifiers, device display name, file name, title, format, size, page count, duration, content fingerprint, remote source alias and location, local-file availability, reading progress, bookmarks, highlighted text, collection names and membership, reading dates, daily reading time and page-turn counts, statistics-reset time, WebP previews of no more than 64 KiB, change and deletion markers, and synchronization timesRestoring a library and reading state, combining activity statistics among the user’s devices on the same platform, and supporting remote re-download or file relinkingDisabling synchronization alone does not delete this information. It remains until the applicable item or Readive app data in Apple iCloud or Google Drive is deleted. A minimal deletion marker may remain to prevent deleted data from reappearing
Device and App environmentDevice type, manufacturer and brand, system language, available and total storage capacity, audio output and CarPlay connection status, and device IP address used for the local web serverDevice-specific layout, default language selection, storage display, audio output, and providing a local upload addressProcessed temporarily while the feature is running or retained for the applicable retention period of related App settings and diagnostic information

Readive is not designed to require sensitive information or unique identification information such as resident registration numbers or health information. If the user directly enters such information in a file name, highlight, or connection alias, it may be included in the App data stored on the device, so users should exercise caution.

2.1 Device Features and Permissions

Readive may use the following device features or permissions to provide functions requested by the user. The actual permission names and approval methods may vary depending on the operating system and device.

  • System file and folder pickers for importing book files selected by the user or selecting a download destination
  • iOS local network access for using the on-device web upload server, nearby direct transfer, and BookManager integration
  • Android nearby devices, Bluetooth, nearby Wi-Fi, and, depending on the operating-system version, local network or location permissions for nearby direct transfer
  • Camera access to recognize a connection code when the user selects BookManager QR scanning
  • Background audio for audiobook playback
  • Internet access for remote source and web catalog connections, translation model installation, advertising, and subscriptions, as well as store billing and foreground data synchronization on Android
  • iCloud account status and CloudKit on iOS, or Google account authorization and Drive app-data access on Android, for optional synchronization

QR scanning does not save photos, videos, or audio. Camera permission is required to pair a new BookManager connection using QR scanning. If permission is denied or revoked in operating system settings, existing BookManager connections and other App features remain available, and users can create a new connection by entering pairing information manually. Readive does not request microphone recording or contacts access and does not read location coordinates.

On earlier Android versions, however, Nearby Connections may require the operating system’s location permission to discover nearby devices. The nearby-transfer feature is not implemented to read location coordinates or collect them on a Readive server, and it requests the required nearby permission only when the user starts a transfer.

3. Information That May Be Processed over a Network

3.1 Error Diagnostics

The production version may use Sentry to improve App stability. If an error occurs, the following information may be transmitted:

  • Error messages and stack traces
  • App version, operating system, and device platform
  • Limited diagnostic context, such as the feature and type of operation in which the error occurred

Readive is configured to remove account information, passwords, authentication tokens, file names, file paths, server addresses, URLs, search terms, book titles and authors, and book content before transmission. Screenshots, view hierarchies, session replay, network bodies, and performance profiling are not used. However, it may not be possible to completely exclude the possibility that an unexpected error string contains a value entered by the user. If such an issue is found, the applicable filters will be updated.

3.2 Advertising and Privacy Choices

When a premium subscription is not active in the free version, Readive may use Google AdMob and the User Messaging Platform (UMP). Depending on the user’s consent status and operating system settings, the advertising SDK may process:

  • Advertising or device identifiers
  • Network information such as IP address, and approximate location that may be inferred from the IP address
  • Device type, operating system, App version, and language
  • Advertising interactions, such as impressions and clicks
  • Advertising privacy choices and consent status
  • Diagnostic information from the advertising SDK

Readive initializes the advertising SDK after UMP permits ad requests. While a premium subscription is active or an ad-free paid build is being used, Readive does not request advertisements. Where available, users may review their choices again through the advertising privacy menu in Settings.

3.3 Subscriptions and Payments

Readive uses the Apple App Store or Google Play and RevenueCat to retrieve premium subscription products and manage purchases, restoration, and entitlement verification. The following information may be processed:

  • An anonymous App User ID generated by RevenueCat
  • Store, product identifier, price, currency, and product term
  • Transaction and receipt information, and purchase and renewal status
  • Premium entitlement activation and expiration information
  • Technical and error information related to purchases and restoration, such as device type and operating system

Readive is configured to disable automatic collection of device identifiers by the RevenueCat SDK. Payment card numbers and store account passwords are processed directly by Apple or Google and are not received by the Operator or RevenueCat.

3.4 Cloud and Remote Sources

If the user directly enables synchronization in Settings, synchronization information is stored in the private Apple CloudKit database of the same iCloud account on iOS and iPadOS, or in the Drive appDataFolder of the Google account authorized by the user on Android. Readive has no proprietary synchronization server or account, and synchronization does not operate between iOS and Android. Private CloudKit data counts against the user’s iCloud storage, while Drive app data is subject to the applicable Google account’s storage and policies.

Synchronized information may include random logical book and device identifiers, device display name, file name, book title, format, size, page count, duration, content fingerprint, credential-free remote-source alias, type, address, and path, whether the device has a local file, reading progress, bookmarks, highlighted text, collection names and membership, reading dates, daily reading time and page-turn counts, statistics-reset time, change and deletion times, and a WebP preview of no more than 64 KiB. Reading activity statistics are synchronized as daily totals from the device where they were recorded, rather than as complete raw reading sessions. Per-device statistical results for counts of saved books and pages, file storage and format breakdowns, favorites, and connections are not combined across devices. Original book files, page or audio content, local file URIs, FTP, SMB, or WebDAV passwords, Dropbox or OneDrive tokens, and custom request headers are not uploaded to this synchronization storage. Remote books imported from WebDAV are also currently excluded from remote-source metadata registration for backward synchronization compatibility.

An item downloaded from a Remote Source can be downloaded again on another device if that device has the same source and credentials configured. For an item imported through the system file picker or PC Local Web Upload, the other device displays a preview and a missing-file state instead of a download address, and the user may select a file with the same content fingerprint or transfer it directly from another same-platform device that holds the original.

When the user starts nearby direct transfer, the App uses MultipeerConnectivity with required encryption on iOS and Google Play services Nearby Connections on Android, displays the same verification code on both devices, and requires acceptance by the receiving user. A received file remains in the App’s temporary cache and is imported into the library only after its expected content fingerprint is verified. This direct transfer does not store the original file on a Readive server, CloudKit, or Google Drive.

On Android, the Google account name and a short-lived access token may be processed temporarily for authorization, revocation, and Drive requests. The access token is not permanently stored in Readive application state or its database. Disconnecting synchronization stops synchronization on the device and revokes the authorization scope on Android, but it does not automatically delete existing synchronization information in Apple or Google storage because other devices may still require it.

The App may connect directly from the device to the following services and servers selected by the user:

  • Dropbox
  • Microsoft OneDrive
  • HTTP(S), OPDS, FTP, SMB, and WebDAV servers registered by the user
  • An on-device local web upload server manually enabled by the user

Dropbox and OneDrive connections use the OAuth Authorization Code flow with PKCE, and access is limited to scopes required to read file lists and content. Access and refresh tokens are stored in the operating system’s secure storage, but are transmitted to the applicable provider during authentication and file requests.

For WebDAV connections, the App uses the ID and password entered by the user for HTTP Basic authentication and stores the password in the operating system’s secure storage. The App performs only read-only folder listing and file download operations, and sends authentication headers only to the same origin as the registered server. Digest and NTLM authentication and self-signed, expired, or hostname-mismatched HTTPS certificates are not supported.

The operator of a server registered by the user may process the server address, credentials, request headers, folder and file information, and downloaded content. The Operator neither operates servers registered by users nor controls their level of security.

Custom-header values are stored in the operating system’s secure storage used for passwords and OAuth tokens. The general local database retains only header names and order and information indicating that the values are stored separately, and custom headers are not included in Platform Sync. Header values stored in the general local database by a previous version are removed from that database only after they are successfully written to secure storage when the connection is next read. The values are transmitted to the server registered by the user when a request is made, so review the security of the server and transport protocol.

Transmission through HTTP, FTP, WebDAV over HTTP, and the current Local Web Upload server may not be encrypted. The Local Web Upload server is accessed directly at http://device IP:port/ without a path token, password, or verification code. While the server is running, anyone on the same local network who can reach that address may view folder names, file names, and file sizes or attempt to create folders and upload files. The server automatically stops when the App moves to the background or when no request or upload data is received for 15 minutes. It does not allow CORS, restricts requests carrying an Origin header to the same HTTP origin, and uses no-referrer, no-store, CSP, and framing-denial headers, but these measures do not authenticate a client. Uploads are limited to 8 GiB per file, 12 GiB per server session, and two concurrent uploads, with at least 64 MiB of free space reserved after an upload, and interrupted partial files are cleaned up. Do not use it on a public or shared network. Enable it only when necessary on a trusted private network, and stop it immediately afterward.

3.5 External Search, Dictionary, Translation, Copying, Sharing, and Read Aloud

When the user directly selects an external search, dictionary, or translation feature in the reader, the selected word or phrase may be included in the URL and transmitted to one of the following providers:

  • NAVER Dictionary
  • Google Search or Google Translate
  • DeepL

Because this screen uses a webview, the applicable provider’s cookies, web storage, and privacy policy may apply. Users should review the phrase to be transmitted before sending it to an external service.

When the user selects the copy feature, the selected text is stored in the operating system clipboard. Clipboard content may remain until the user overwrites it or the operating system clears it, and access by other apps is governed by operating system policies and permissions. Readive does not separately transmit clipboard content to the Operator’s server.

When the user selects the operating system’s share feature, the selected text is transmitted to the app chosen by the user. System TTS voices use a speech engine installed on the device, and text may be processed according to the speech engine provider’s settings. The Operator does not control processing by other apps that access the clipboard, an app selected for sharing, or a system speech engine.

When the user chooses to download Supertonic voices, the App downloads a fixed model archive from GitHub Releases over HTTPS. GitHub may process the IP address, device and network information, and download request under its policy. After installation, Supertonic synthesis runs on the device, and the text being synthesized is not transmitted to GitHub or the Operator’s server. Generated temporary WAV files remain only in the App-specific cache.

3.6 BookManager LAN Integration and QR Scanning

When the user pairs a BookManager PC, approved PC files and folders, covers, and metadata are imported, and reading progress is synchronized on the same local network. Credentials remain in operating system secure storage. Requests use HTTPS pinned to the PC certificate and only private IPv4 addresses on directly connected Wi-Fi or Ethernet. BookManager integration credentials and transfer data are exchanged only over this connection and are not sent to the Operator's server or the QR recognition provider. Active LAN requests are cancelled when the App enters the background. Disconnecting does not automatically delete imported books or records stored on the PC.

QR preview images are decoded on the device without saving photo or video files. QR images and decoded connection information are not sent to Google. Separately from those inputs and results, Google ML Kit on Android may send device and app information, per-installation identifiers, and usage and performance metrics such as recognition latency, configuration, input/output size, and errors to Google over HTTPS. This SDK processing is separate from the LAN transfer of BookManager data. See ML Kit Terms and Privacy and Android data disclosure information. Instead of QR scanning, users can create a new connection by manually entering pairing information generated in BookManager on their PC. Manually entering pairing information does not require camera permission. Users who do not wish to scan QR codes can create a new connection without granting camera access. Existing connections and other App features remain available.

3.7 Find on the Web and On-device Title Translation

When Find on the Web is used, catalog, search, and detail requests are sent to Project Gutenberg and LibriVox, and file and cover requests are sent to the applicable provider or Internet Archive over HTTPS. Providers may process the search query, selected language, requested work or file address, IP address, App identification, and other technical information needed for the request. Covers are cached on the device, and downloaded-book source and rights-check records remain on the device. Opening a link to Loyal Books or another external website is subject to that site's privacy, cookie, and web-storage policies.

Title translation is optional and enabled by the user. Android uses Google ML Kit Translation and Language Identification; iOS and iPadOS 18 or later use Apple Translation and NaturalLanguage. Original titles and translation results are processed on the device and are not sent to the Readive Operator or a cloud translation server. Results are kept only in a limited in-memory cache while the App runs, not in persistent storage. Original catalog browsing, search, and downloads remain available when translation is disabled.

Missing language models are downloaded when the user enables translation or requests model preparation. Android requires Wi-Fi and downloads models from Google servers; iOS and iPadOS follow Apple's system model-preparation and consent flow. The provider may process IP address, device and network information, requested languages and models, and other information needed for the download. Once models are installed, title translation runs on the device. An Android SDK model download already started may continue after the screen closes or translation is disabled. Disabling translation does not itself remove installed models.

Separately from the title and translated text themselves, Android ML Kit may send identified languages, configured source and target languages, device and App information, per-installation identifiers, input/output size, model-download and usage events, and performance metrics such as latency and errors to Google over HTTPS. The Translation SDK also uses Firebase Remote Config and Installations for remote-configuration diagnostics. This processing is separate from advertising consent, and users may refrain from title translation. See ML Kit Terms and Privacy and Android data disclosure information.

4. Service Providers and External Parties

The Operator uses the following providers to the extent necessary to provide the service. Cloud and search services that the user directly selects and connects may process information separately under their respective terms and privacy policies.

ProviderRole and purposeInformation that may be processedWhen applicable
Functional Software, Inc. (Sentry)App error collection and diagnosticsErrors and stack traces, App, OS, and platform information, and limited diagnostic informationWhen production error diagnostics are configured
Google LLC (AdMob, UMP)Advertising delivery, measurement, and consent managementAdvertising and device identifiers, IP address, device, advertising interaction, and consent informationFor free users when advertising is enabled
Google LLC (ML Kit)Diagnostics and usage analytics for Android QR recognition, language identification, and translation SDKs, and distribution of language modelsDevice and App information, per-installation identifiers, usage and performance metrics, identified and source/target languages, and model requests; excludes QR images, decoded results, and the title and translated text themselvesWhen the user uses the Android QR scanner or title translation, or requests model preparation
Apple Inc. (Translation)Language-model preparation for on-device translation on iOS and iPadOSSystem consent, model requests, and device and network information; titles and translations are processed on the deviceWhen the user requests translation model preparation on a supported device
Project Gutenberg, LibriVox, Internet Archive, and external content websites opened by the userCatalog retrieval, cover display, and file deliverySearch query, selected language, work/file requests, IP address, and technical information; external websites may also process cookies and browser informationWhen the user uses Find on the Web or opens an external website
RevenueCat, Inc.Subscription products, receipts, and premium entitlement managementAnonymous App User ID, product, transaction, receipt, subscription status, device and operating system, and technical and error informationWhen subscription features are retrieved, purchased, or restored
Apple Inc. or Google LLCApp distribution, in-app payments, subscriptions, and refundsStore account and payment, transaction, and subscription informationWhen the applicable store is used
Apple Inc. (iCloud/CloudKit) or Google LLC (Drive)Storage and account authorization for optional same-platform device synchronization selected by the userOptional synchronization information described in Section 2 and technical information related to the iCloud or Google account and authorizationWhen the user enables synchronization
Apple Inc. (MultipeerConnectivity) or Google LLC (Play services Nearby Connections)Nearby-device discovery, connection approval, and encrypted device-to-device file transferDevice display name, nearby endpoint identifier, verification code, connection state, and the file selected by the userWhen the user directly starts a nearby transfer
Dropbox, Inc.Browsing and downloading Dropbox files connected by the userOAuth information, file and folder metadata, and requested contentWhen the user connects Dropbox
Microsoft CorporationBrowsing and downloading OneDrive files connected by the userOAuth information, file and folder metadata, and requested contentWhen the user connects OneDrive
Microsoft Corporation (GitHub)Distribution of the Supertonic voice model requested by the userIP address, device and network information, and model download requestWhen the user chooses to download the Supertonic model
NAVER, Google, or DeepLSearch, dictionary, or translation requested by the userText selected by the user, IP and browser information, cookies, and similar informationWhen the user selects the applicable feature

The Operator does not sell personal information. If the Operator provides personal information to a third party beyond the scope of the table above, such as for the Operator’s own independent advertising purposes, the Operator will provide notice and obtain consent as required by applicable law.

The policies of each provider are available at:

5. Cross-Border Processing

External SDKs and global services selected by the user may process information outside the Republic of Korea. When the Operator entrusts processing to an external provider to deliver the service, the cross-border processing details are disclosed in this Policy under Article 28-8(1)(3) of the Personal Information Protection Act of Korea. The policies and terms of a Store, cloud, or search service directly selected by the user also apply.

Overseas recipient and contactCountryInformationPurposeTiming and methodRetention and use periodLegal basis and how to refuse
Functional Software, Inc. / compliance@sentry.ioGermanyErrors and stack traces, App, OS, and platform information, and limited diagnostic informationError diagnosticsEncrypted network transmission when an error occursDeleted or de-identified after the event-retention period set by the project settings and agreementProcessing entrusted for service stability; the App has no separate disable setting, and requests regarding transmitted information may be submitted to the Operator by email
Google LLC / Google privacy inquiryThe United States and countries where Google or its processors operate facilitiesAdvertising and device identifiers, IP address, device, advertising interaction, and consent informationAdvertising delivery, measurement, and consent managementEncrypted network transmission when an advertisement or consent request is madeFor periods determined by the information type, user settings, and Google policyProcessing entrusted to provide the service or consent where applicable; users may change advertising privacy settings or limit Readive ad requests by using Premium or an ad-free paid build
Google LLC (ML Kit) / Google privacy inquiryThe United States and countries where Google or its processors operate facilitiesDevice and App information, per-installation identifiers, usage and performance metrics, identified and source/target languages, and model requestsDiagnostics and improvement for QR recognition, language identification, and translation SDKs, and model distributionHTTPS transmission associated with Android QR scanner or title translation use or model preparationFor periods determined by Google policyProvision of user-selected QR recognition and title translation; users may manually enter pairing information instead of scanning or disable title translation while retaining existing connections, original catalog titles, and other App features
RevenueCat, Inc. / compliance@revenuecat.comThe United States and countries where RevenueCat’s processors operate facilitiesAnonymous App User ID, product, transaction, receipt, subscription status, device and operating system, and technical and error informationSubscription and entitlement managementEncrypted network transmission when retrieving products, purchasing, restoring, or verifying entitlementDeleted or de-identified after the period necessary for entitlement management and legal obligationsProcessing entrusted to perform the subscription contract; users may refrain from subscription features or request deletion by emailing the Operator, and refusal limits purchasing, restoration, and entitlement verification
Apple Inc. or Google LLCThe United States and countries where the selected Store provider or its processors operate facilitiesStore account and payment, transaction, and subscription informationApp distribution and paymentTransmitted to the provider’s systems when the user accesses the StoreUnder each Store’s policy and statutory retention periodPerformance of the Store contract selected by the user; no payment-related transmission occurs if the user does not purchase a paid product
Apple Inc. (iCloud/CloudKit) or Google LLC (Drive) / each provider’s privacy inquiry processThe United States and countries where the selected provider or its processors operate facilitiesLogical book and device identifiers and device display name, file metadata and fingerprint, source alias and location, file availability, reading progress, bookmarks, highlighted text, collection names and membership, reading dates, daily reading time and page-turn counts, statistics-reset time, small WebP previews, and account-authorization technical informationSame-platform device synchronization, restoration, and combination of reading activity statisticsEncrypted network transmission after the user enables the feature, when the App starts, returns to the foreground, or the user manually synchronizesUnder each provider’s policy and until the user deletes Readive app data in the provider storage; a minimal deletion marker may remainPerformance of the optional feature requested by the user; the user may refrain from enabling or may disconnect synchronization, while complete deletion requires review of both the App and provider app-data controls
Dropbox, Inc. or Microsoft CorporationThe United States and countries where the selected provider or its processors operate facilitiesOAuth information, file and folder metadata, and requested contentFile browsing and downloading requested by the userEncrypted network transmission when the user connects, browses, or downloadsUnder each provider’s policy or until the user disconnects and the related information is deletedPerformance of the external service requested by the user; the user may choose not to connect or may disconnect and revoke provider-account access at any time, and only the applicable remote feature will be limited
Microsoft Corporation (GitHub)The United States and countries where GitHub or its processors operate facilitiesIP address, device and network information, and model download requestDistribution of the Supertonic voice modelHTTPS transmission when the user chooses to download the modelFor the log-retention period specified by GitHub’s policyPerformance of the optional feature requested by the user; no transmission occurs if the model is not downloaded, and system TTS remains available
Google LLC or DeepL SEThe United States, Germany, and countries where the selected provider or its processors operate facilitiesSelected text, IP and browser information, cookies, and similar informationSearch or translationTransmitted through a web connection when the user runs the featureFor the period specified in each provider’s policyPerformance of the external lookup requested by the user; no information is transmitted if the feature is not run, and only the applicable lookup will be limited

6. Automatic Collection Technologies and Choices

Readive does not use cookies for a proprietary Readive account. However, the following technologies may be used:

  • Advertising or device identifiers and consent signals used by AdMob and UMP
  • Sentry error event identifiers and diagnostic information
  • ML Kit per-installation identifiers, language information, and usage and performance metrics for Android QR recognition, language identification, and title translation
  • RevenueCat anonymous App User IDs
  • Cookies and web storage used in the external search, dictionary, and translation webview

Users may use the operating system’s tracking and advertising settings, Readive’s advertising privacy menu, and the external service’s cookie settings. Readive does not request advertisements while a premium subscription is active. Refusing certain processing may limit the applicable feature, such as personalized or general advertising, subscription verification, or an external lookup.

7. Retention and Deletion

Information stored on the device is retained for the periods specified in the table in Section 2. Users may delete or reset books, records, caches, connection information, and settings individually in the App. Deleted app-specific files are removed so that they cannot be recovered within the App, and the related database records are deleted.

However, each deletion menu has a different scope, and the following items may need to be checked or deleted separately:

  • Files in an external download folder directly selected by the user
  • App settings and audiobook playback settings
  • Interrupted download status and partial files
  • Downloaded Supertonic voice model and temporary synthesis files in the App-specific cache
  • Installed translation language models, which are managed through App-data or operating-system model controls separately from disabling translation
  • Information remaining in operating system backups or secure storage
  • Synchronization information and deletion markers remaining in iCloud CloudKit or the Google Drive appDataFolder
  • Information retained by an external provider under its own policy and legal obligations

Disconnecting synchronization does not delete synchronization information in provider storage. For complete deletion, the user must delete Readive app data through the applicable iCloud or Google Drive app-data controls and ensure that synchronization is not still enabled on another device. To prevent a deleted item from reappearing from an older device, a minimal tombstone such as the logical identifier and deletion time may remain. Deleting all provider app data also removes those markers.

After deleting a remote connection’s credentials, revoke Readive’s access through Dropbox, Microsoft, or the applicable server as necessary. Depending on the operating system, certain values may remain in secure storage, a backup, or platform synchronization storage even after the App is removed. Before disposing of or sharing a device, users should first delete connections and related data within the App.

External providers delete or de-identify information according to their own policies, the Operator’s contractual instructions, and statutory obligations.

8. User Rights and How to Exercise Them

Users may manage processing of their information in the following ways:

  • Delete books, reading records, caches, connection information, or related data through storage management in the App
  • Revoke camera permission to stop QR scanning (new connections through manual entry of pairing information, existing BookManager connections, and other App features remain available)
  • Reset App settings
  • Delete a Dropbox or OneDrive connection and revoke access through the provider account
  • Disable synchronization and, if complete deletion is required, delete Readive app data from iCloud or Google Drive
  • Change advertising choices through the advertising privacy menu or operating system settings
  • Review or cancel a subscription and request a refund through the App Store or Google Play
  • Refrain from using an external search, dictionary, or translation feature, or use the privacy settings on the applicable website
  • Disable catalog title translation or refrain from requesting model preparation
  • Request access, correction, deletion, suspension of processing, or withdrawal of consent through the privacy contact below

Because Readive has no user account and most information exists only on the device, the Operator may be unable to remotely access or delete a particular user’s local data on the user’s behalf. In that case, the Operator will provide guidance on available in-App deletion methods. Requests regarding information retained by an external provider may be subject to that provider’s identity verification and procedures.

Where consent from a legal representative is required, including for a child under 14 years of age, the legal representative may exercise the applicable rights in accordance with applicable law.

9. Security Measures

The Operator applies the following measures appropriate to the nature of the information processed:

  • Storing passwords and OAuth tokens in the operating system’s secure storage rather than in the general settings storage
  • Using the Authorization Code flow with PKCE for Dropbox and OneDrive authentication and limiting scopes to read access
  • Using the CloudKit private database for iOS synchronization and requesting only the non-sensitive drive.appdata scope for Android synchronization
  • Excluding original files, local URIs, passwords, OAuth tokens, and custom headers from synchronization payloads, and removing user information, queries, and fragments from remote addresses
  • Using HTTPS for supported external provider API communications
  • Removing sensitive keys and content-related context before error diagnostics
  • Checking advertising consent status before requesting advertisements
  • Using app-specific storage and the operating system sandbox

HTTP or FTP servers and WebDAV over HTTP registered directly by a user may not provide encryption or adequate authentication protection. The Local Web Upload server also provides neither access authentication nor HTTP transport encryption. Browser protections such as same-origin checks, CSP, and no-store do not block a user who connects directly from another device on the same local network. Use these connections only on trusted networks, and do not reuse credentials from other services.

10. Children’s Personal Information

Readive is not directed to children under 14 and does not provide a legal-representative consent process for them. Children under 14 may not use Readive. The Operator does not request a date of birth or age through a registration process, but if it learns that personal information of a child under 14 has been processed through an external system used by the Operator, it will review the matter and take necessary measures, including deletion, in accordance with applicable law.

11. Privacy Officer and Contact

Privacy inquiries, rights requests, and complaints may be submitted through the email address above. The Operator will verify the requester’s identity and the request as required by applicable law and provide the result.

For assistance with a personal information infringement or dispute, users may contact relevant Korean authorities, including the Personal Information Infringement Report Center and the Personal Information Dispute Mediation Committee.

12. Changes to This Policy

If the Operator changes this Policy, it will notify users of the changes and effective date through the App or the public webpage before the effective date. A change that materially affects user rights will be separately announced for the period and by the method required by applicable law, and consent will be obtained where necessary.

If the in-App document and the public web document temporarily differ, the public web document displaying the more recent effective date and document version will be considered the current Policy. However, provisions more favorable to the user and mandatory provisions of applicable law will continue to apply.