Valpr Reader
Privacy Policy
User Privacy & Data Protection

Valpr Reader Privacy Policy

Last Updated: September 8, 2026 • Effective Date: September 8, 2026

Core Privacy Summary

  • • Local-First Architecture: Valpr Reader runs entirely in your web browser. All book processing, reading progress, and statistics are stored locally on your device.
  • • No Proprietary Backend Servers: Valpr Reader operates no backend application servers, databases, or analytics services. We never collect, track, or sell your personal data.
  • • Direct Cloud Connections: When optional Google Drive or OneDrive sync is enabled, your browser communicates directly with Google/Microsoft APIs via encrypted HTTPS connections.

1. Overview of Valpr Reader

Valpr Reader is a free, open-source, web-based e-book reader designed specifically for Japanese language learning and immersion (supporting EPUB, HTMLZ, and TXT formats), Yomitan dictionary popups, and reading statistics.

This Privacy Policy explains how Valpr Reader handles your information when you access or use the application hosted at https://valpr.github.io/ or https://valpr.github.io/reader, or self-host your own instance.

2. Information We Process & How It Is Used

Valpr Reader processes the following types of information strictly to provide reader functionality:

Book & Library Data

E-book files (EPUB, HTMLZ, TXT) and cover images imported by you are stored in your browser's IndexedDB. They never leave your device unless you choose to sync them to your personal cloud storage.

Reading Progress & Stats

Reading positions, bookmarks, character counts, reading speed, and session times are calculated and stored locally in your browser to resume reading and display personal statistics.

Reader Preferences

Fonts, colors, themes, margins, reading orientation (horizontal or vertical-rl), and reader profiles are stored locally in your browser's LocalStorage and IndexedDB.

Cloud Authentication Tokens

When you connect Google Drive or OneDrive, OAuth access and refresh tokens are stored locally in your browser. Tokens may optionally be encrypted with a password of your choice.

3. Google API Services & Google Drive User Data

Valpr Reader provides an optional cloud synchronization feature powered by Google Drive. Connecting Google Drive is entirely optional; Valpr Reader functions with full feature parity locally without signing in to Google.

A. Requested Google OAuth Scopes

When you choose to connect Google Drive in Valpr Reader Settings, the application requests the following scope:

https://www.googleapis.com/auth/drive.file

What this scope allows: Per Google's official scope definition, this scope only grants access to files and folders that were created by or opened with Valpr Reader.

B. What Google Data We Access

  • Valpr Reader only reads and writes files within the designated application folder (by default named valpr-reader-data) created by the app in your Google Drive.
  • These files include synced reading progress, bookmarks, reading statistics, user settings/profiles, and optional book archives uploaded by you.
  • What we DO NOT access: Valpr Reader cannot access, view, modify, or delete any other files, documents, photos, spreadsheets, emails, or personal information in your Google Drive or Google Account. We do not request or store your Google profile, contact lists, or personal identity information.

C. How Google Data Is Handled and Transferred

  • All communication with Google APIs is initiated directly from your web browser to Google endpoints (https://accounts.google.com, https://oauth2.googleapis.com, and https://www.googleapis.com) via secure Transport Layer Security (TLS/HTTPS).
  • No intermediary server is used. Data is never routed through, processed by, or cached on any server operated by Valpr Reader.
  • Google user data is never used for advertising, marketing, analytics, or profiling.
  • Google user data is never sold, rented, or transferred to any third party.

Google API Services User Data Policy Compliance

"Valpr Reader's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

4. Microsoft OneDrive Integration

Similar to Google Drive, Valpr Reader optionally supports synchronizing reading progress and books with Microsoft OneDrive using the Files.ReadWrite.AppFolder and User.Read scopes. Access is strictly confined to Valpr Reader's sandboxed application folder on your OneDrive account. Transfers occur directly from your browser to Microsoft Graph APIs via HTTPS.

5. Data Security & Encryption

We implement strong client-side security measures to safeguard your data:

  • Local Storage Isolation: All reading data is stored within your browser's origin sandbox (IndexedDB, LocalStorage) and cannot be accessed by other websites.
  • Encrypted Connections: All API communications with Google and Microsoft use standard HTTPS/TLS encryption in transit.
  • Optional Token & Profile Encryption: You can configure Valpr Reader with a master password to encrypt OAuth tokens and profiles using AES encryption before persisting them in IndexedDB.
  • No Server Vulnerabilities: Because Valpr Reader has no central database or backend server, there is no centralized database to breach.

6. Data Retention & User Deletion Rights

You have absolute control over your data at all times. Here is how you can manage, delete, or revoke access:

1

Delete Books & Reading Data In-App

In the Book Manager, select books and click the Delete icon to permanently delete books, reading progress, and bookmarks. In Settings > Data > Danger Zone, “Reset everything” wipes all local books, data, and settings, disconnects all clouds, and restores factory defaults.

2

Delete Synced Files in Google Drive

Open your Google Drive at drive.google.com and simply delete the valpr-reader-data folder. This permanently wipes all synced data from Google servers.

3

Disconnect & Revoke Google Access

You can disconnect Google Drive at any time under Settings > Storage Sources in Valpr Reader. You may also immediately revoke Valpr Reader's authorization at any time by visiting Google Account Security Permissions.

4

Browser Storage Deletion

Clearing your browser's cookies and site data for the application's domain will immediately erase all local application state, cached books, and stored tokens.

7. Children's Privacy

Valpr Reader does not knowingly collect or solicit any personal information from children under the age of 13. Since Valpr Reader collects no personal information on remote servers, no child data is ever stored.

8. Changes to this Privacy Policy

We may occasionally update this Privacy Policy to reflect changes in functionality, third-party API requirements, or legal compliance. Any changes will be posted on this page with an updated revision date.

9. Contact Us & Open Source Repository

Valpr Reader is developed as an open-source project. If you have any questions, feedback, or concerns regarding this Privacy Policy or our privacy practices, please contact us or open an issue on our GitHub repository:

Application Name: Valpr Reader

GitHub Repository: https://github.com/valpr/reader

Issue Tracker: https://github.com/valpr/reader/issues