Privacy policy
Effective date: 28 September 2026
Read Rebel is a reading app for PC (as an installable web app) and Android. We designed it so that your reading life stays on your device. This policy explains what personal data we process, why, how long we keep it, who helps us, and the rights you have wherever you live. It also serves as our notice under India's Digital Personal Data Protection Act, 2023, the EU and UK GDPR, and US state privacy laws.
1. Who we are
Read Rebel is provided by Siddharth Macker, sole proprietor trading as Read Rebel, New Delhi, India ("we", "us"). For the personal data described here, we are the data fiduciary (India) and the controller (EU/UK GDPR). You can contact us at hello@readrebel.app.
If you are in the EU or UK, you can send any privacy request to hello@readrebel.app.
2. The short version
- There's no Read Rebel account. You don't need to sign up to read.
- Your books, highlights, notes, vocabulary, reading progress and streaks are stored on your device only. We never receive them.
- We don't sell your data, show ads, or use advertising or tracking cookies.
- We only process personal data when you buy Rebel Plus, subscribe to our newsletter, contact us, or load our website and servers (standard hosting logs).
3. Data that stays on your device
Imported books, and everything you create in Read Rebel, are saved in your browser's storage (IndexedDB and localStorage) or in the Android app's private storage. That includes highlights, notes, vocabulary and flashcards, reading time, streaks, achievements, settings, alarms, your trial status, and your reading-coach data: your diagnosis answers (why reading stops, language, interests, available time), book suggestions, session schedule, check-ins and weekly reflections. This data isn't sent to us. Clearing site data or uninstalling the app deletes it. You can export a copy at any time with Settings → Export backup.
Some features connect directly from your device to third parties when you use them. We don't receive this data.
- Word definitions: the word you look up is sent to the Free Dictionary API (dictionaryapi.dev).
- "Explain": the term you select is sent to Wikipedia's public API (Wikimedia Foundation).
- Read-aloud: uses your device's or browser's voices. Most run on your device, but some "online" or "natural" voices provided by your browser or operating system may send the text being spoken to that company's speech service. Choose an offline voice if you prefer.
- Reading buddy and share cards: when you choose to share a card or invite a buddy (for example via WhatsApp), your device's share sheet sends what you chose to the app you picked. That app's privacy policy applies. We don't receive a copy, and there are no public leaderboards.
- Fonts: the app and this website load fonts from Google Fonts, so your browser requests font files from Google.
These providers receive your IP address as part of any internet request, and their own privacy policies apply.
4. Data we process, why, and our legal basis
| What | Why | Legal basis |
|---|---|---|
| Plus purchases: email address (and phone number if you give it at checkout), order and payment IDs, plan, price, currency, country, payment status, timestamps, licence ID and expiry | To take payment, issue and restore your Plus licence, send receipts and invoices, handle refunds and support, and prevent fraud | Performance of a contract. Legal obligation (tax and accounting records). India: consent and legitimate uses for the purpose you provided the data for. |
| Newsletter: email address, consent record (date, time, source, confirmation click), and whether you open or click emails if our email provider measures this | To send "One good page" and product news you asked for, and to keep proof of your consent | Consent, which you can withdraw at any time with the unsubscribe link |
| Your approximate country, derived from your IP address when you view prices or check out | To show fair regional prices and apply the correct taxes. We don't use it to build a profile and don't store it except as part of a purchase record. | Legitimate interests (fair pricing) and legal obligation (tax) |
| Hosting and security logs: IP address, browser and device type, pages or API endpoints requested, timestamps | To deliver the website and app, keep them secure, and fix problems | Legitimate interests (security and reliability) |
| Support messages: your email and what you write to us | To answer you and resolve complaints and grievances | Legitimate interests. Legal obligation (consumer grievance handling). |
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects, and we don't sell or "share" personal data for cross-context behavioural advertising.
Payment card, UPI and bank details are entered on our payment provider's checkout. We never see or store your full card or bank details.
5. Service providers
We use a small number of providers who process personal data for us under contracts (data processing agreements) that require them to protect it and use it only on our instructions:
- Vercel Inc. (USA): website, app and API hosting, and server logs.
- Razorpay Software Pvt. Ltd. (India): payment processing for Plus. For some payment steps, Razorpay also acts as an independent data fiduciary or controller under its own privacy policy and regulatory obligations.
- Buttondown (USA): sending the newsletter and managing subscriptions.
- ImprovMX (email forwarding) and Google (Gmail): our hello@readrebel.app mailbox.
We may disclose data if the law requires it, to protect our rights or users' safety, or as part of a business transfer. In that case, the successor must follow this policy.
6. International transfers
We're based in India, and our providers may process data in India, the United States, the EU and other countries. When we transfer personal data from the EU, EEA, UK or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA) or the EU–US Data Privacy Framework where a provider is certified. Transfers out of India follow the DPDP Act and any restrictions the Government of India notifies. You can ask us for a copy of the relevant safeguards.
7. How long we keep data
- Purchase and invoice records: for as long as tax and accounting laws require (in India typically up to 8 years), then deleted.
- Licence records: while your pass is active, and for up to 24 months afterwards so we can restore purchases and handle disputes.
- Newsletter data: until you unsubscribe. After that, we keep only your email address on a suppression list so we never email you again, plus the consent record for as long as we may need to show it.
- Support emails: up to 24 months after the conversation ends.
- Hosting logs: kept by our host for a short period (typically days to a few weeks) under its retention settings.
- On-device data: stays on your device until you delete it. We have no copy.
8. Your rights
Depending on where you live, you have some or all of the following rights. We honour these requests for everyone, wherever the law allows.
- Access: get a summary or copy of the personal data we hold about you and how we use it.
- Correction and completion: fix inaccurate or incomplete data.
- Erasure: ask us to delete your data, unless we must keep it (for example tax records).
- Portability: receive your data in a machine-readable format. Your reading data is already portable through Export backup.
- Withdraw consent at any time (for example, unsubscribe). This doesn't affect processing that has already happened.
- Object or restrict: object to processing based on legitimate interests, or ask us to restrict it.
- Nominate (India): nominate someone to exercise your rights if you die or become incapacitated.
- US state rights: know, access, delete, correct, and opt out of sale, sharing or targeted advertising. We don't do any of the last three. We won't discriminate against you for using your rights.
- Complain: to our Grievance Officer (section 13), and to a regulator: the Data Protection Board of India, your EU/EEA supervisory authority, the UK Information Commissioner's Office, or your state Attorney General or privacy agency.
To make a request, email hello@readrebel.app or our Grievance Officer. We may need to verify your identity, usually by confirming the email address used for your purchase or subscription. Authorised agents may act for you where the law allows. We'll respond within the time the law requires, and within one month at most unless we tell you why we need longer.
9. Children
Read Rebel isn't directed to children under 13, and we don't knowingly collect personal data from them. In India, anyone under 18 needs the verifiable consent of a parent or lawful guardian before buying Plus or subscribing to the newsletter. Elsewhere, users below the local age of digital consent (13 to 16 in the EU, depending on the country) need a parent's consent to subscribe. We don't track, profile or target advertising at children. If you think a child has given us personal data without the required consent, contact us and we'll delete it.
10. Security
We use reasonable security safeguards, including HTTPS everywhere, secrets kept only on the server, cryptographically signed licences, restricted access to purchase records, and providers with strong security practices. No system is perfectly secure. If a personal data breach affects you, we'll notify you and the relevant authorities as the law requires, for example the Data Protection Board of India and affected users under the DPDP Act, or the supervisory authority within 72 hours where GDPR applies.
11. Cookies and local storage
This website doesn't use advertising, analytics or tracking cookies. The Read Rebel app uses your browser's local storage only to provide the features you ask for (storing your books, progress, settings and licence). This is strictly necessary and needs no consent banner. If we ever add optional analytics, we'll ask for your consent first and update this policy.
12. Notice for US residents
In the past 12 months we've collected the categories of personal information described in section 4: identifiers (email, IP address), commercial information (purchase records) and internet activity (server logs). We use them for the business purposes described in section 4. We don't sell personal information or share it for cross-context behavioural advertising, and we don't use or disclose sensitive personal information for purposes that require a right to limit. We keep each category for the periods in section 7.
13. Grievance Officer (India) and contact
In accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules under it, and the Consumer Protection (E-Commerce) Rules, 2020, our Grievance Officer is:
Siddharth Macker, Grievance OfficerRead Rebel
New Delhi, India
Email: hello@readrebel.app
Hours: working days, 10:00–18:00 IST
We acknowledge every grievance within 24 hours and aim to resolve it within 15 days of receipt. If you're not satisfied with our response, you can escalate to the Data Protection Board of India or the consumer forums available to you.
For anything else, write to hello@readrebel.app.
14. Changes to this policy
We'll update this policy when our practices change, for example before optional cloud sync or an AI book companion launches. We'll change the effective date above and, for material changes, tell you in the app, on this website, or by email if you've given it to us. Where the law requires consent for a new purpose, we'll ask for it first.