Privacy policy
Your book is not our data.
If you translate at home, the book file never reaches Berilo's servers. If you choose cloud translation, we receive it only for the length of the translation and delete it immediately afterwards. If you turn on sync, we store the data you create while reading: highlights, notes, vocabulary, reading position and basic book metadata. Everything stays private until you publish an item yourself.
Effective 25 July 2026
What we store
An account needs an identifier, a display name and a username. Book title and author, the content hash, the language pair, progress, passages, your notes and vocabulary are synced. For a cloud translation we hold the uploaded file and the book's text for the length of that translation, and delete both when it finishes. The API key is stored encrypted, and only so the translation can run without you; it is never returned to the browser.
Who processes data and where
Clerk provides sign-in and may process your email address, session, device, and security signals on infrastructure in the United States; it uses applicable legal transfer mechanisms for EU data. Supabase stores Berilo’s synchronized data in the project’s primary West EU region in Ireland. Both providers act as processors needed to deliver the service and use subprocessors under their published terms.
Export, correction, and deletion
Settings let you change your public name and handle, download a complete account export as JSON, and permanently delete the account. Deletion removes the profile and all its rows from Berilo’s database and closes the Clerk account. We do not delete books on your devices, because we have no access to them; a file uploaded for a cloud translation is already gone when that translation ends. Contact Berilo’s controller to exercise any additional legal rights of access, correction, restriction, or objection.
Retention and security
We retain data while your account exists or until you delete it through sync. Deleted synchronized rows may temporarily remain as tombstones so deletion reaches other devices, then leave under the retention schedule. Database row-level security limits access. No web system is risk-free, so we collect as little as possible.