Privacy policy
Your book is not our data.
A book file never reaches Berilo’s servers. If you enable sync, we store only data you create while reading: highlights, notes, vocabulary, reading position, and basic book metadata. Everything stays private until you publish individual items yourself.
Effective 25 July 2026
What we store
An account needs an identifier, display name, and handle. Sync carries a book’s title and author, content hash, language pair, progress, passages, your notes, and vocabulary. Book files, complete book text, and API keys are not uploaded. Your OpenAI or Anthropic key stays in a local file on your device.
Who processes data and where
Clerk provides sign-in and may process your email address, session, device, and security signals on infrastructure in the United States; it uses applicable legal transfer mechanisms for EU data. Supabase stores Berilo’s synchronized data in the project’s primary West EU region in Ireland. Both providers act as processors needed to deliver the service and use subprocessors under their published terms.
Export, correction, and deletion
Settings let you change your public name and handle, download a complete account export as JSON, and permanently delete the account. Deletion removes the profile and all its rows from Berilo’s database and closes the Clerk account. We do not delete books because we never received them. Contact Berilo’s controller to exercise any additional legal rights of access, correction, restriction, or objection.
Retention and security
We retain data while your account exists or until you delete it through sync. Deleted synchronized rows may temporarily remain as tombstones so deletion reaches other devices, then leave under the retention schedule. Database row-level security limits access. No web system is risk-free, so we collect as little as possible.