LAST UPDATED · JULY 31, 2026
Privacy Policy
TomeLeaf is designed around a local-first reading experience. This policy explains what information is handled when you use the website, cloud services, or native desktop applications.
Information we handle
- Account information: name, email address, verification state, membership, and account creation time.
- Reading data: EPUB files you choose to upload, book metadata, reading position, highlights, notes, translations, and saved AI results.
- Service usage: storage and feature quota totals needed to operate your plan.
- Payments: plan, amount, currency, status, and processor reference. Card and wallet credentials are collected by Stripe and never reach TomeLeaf servers.
Desktop editions
In Local and Notes Sync editions, EPUB files remain on your device. Notes Sync sends only supported notes and reading data after you sign in and enable synchronization. Cloud Library uploads books only when you explicitly use cloud storage. Windows account sessions and user-provided AI keys are encrypted for the current Windows user with DPAPI.
AI and text-to-speech
When you request an AI explanation, summary, organization, or translation, the relevant selected text and prompt are sent to the configured AI provider. If you connect your own compatible API, requests go to the endpoint you configure. Text sent for online speech generation is processed to produce audio. Do not submit sensitive personal information in book notes or prompts.
How information is used
We use information to authenticate accounts, provide reading and synchronization features, process purchases, enforce quotas, prevent abuse, troubleshoot failures, and improve reliability. We do not sell personal information.
Service providers
We use service providers only where needed to operate TomeLeaf, including hosting, email delivery, AI processing selected by the user, speech processing, and payment processing. These providers process information under their own contractual and privacy obligations.
Security and retention
Network traffic uses HTTPS. Credentials are hashed or encrypted as appropriate. Data is retained while your account is active and as reasonably required for security, accounting, dispute resolution, and legal obligations. Local data remains until you remove it or uninstall the application.
Diagnostic logs
The Windows application keeps a small rotating diagnostic log on your device to record startup state and technical failures. It is designed to redact session tokens, API-key and password fields, and email addresses, and it does not intentionally record EPUB or note text. Logs are sent to TomeLeaf only when you explicitly export and share them for support.
Your choices
You can export or delete books and notes through TomeLeaf features, sign out of devices, avoid cloud synchronization by using the Local edition, and request account or hosted-data deletion by contacting us. Some payment records may be retained where legally required.
Contact
For privacy questions or deletion requests, email hello@tomeleaf.com.