DualRead

Legal

Privacy Policy

Last updated: 2026-08-04 · Effective: 2026-08-04

DualRead is a reading app that translates whole books with AI and shows the original and the translation side by side. This policy explains what we collect, why, and the choices you have. In short: we collect the minimum needed to run your account and translate your books, we never sell your data, and you can delete your account at any time. For cookies used on this website, see our Cookie Policy.

1. Who we are

DualRead (“we”, “us”) is operated by Aloshyna Anastasiia, a registered individual entrepreneur (FOP) in Ukraine. For privacy questions, contact us at support@dualread.app.

2. What we collect

Account data

When you sign in with Google, we receive a stable account identifier and your email address. We store the identifier to recognise you on return, and we store your email only as a one-way hash (SHA-256) so we can match you to a support request without keeping the address itself. We also store a label for each signed-in device (for example “Pixel 8”) and its platform. You can see the list in Settings → Account and end a session on any other device — useful if a phone is lost or sold; ending it also erases that device’s label.

Book content you translate

When you translate a chapter, the text is sent to an AI translation provider on our behalf to produce the translation, and the result is held on our servers until your device retrieves it. The original chapter text is erased from our servers the moment the chapter is finished; the translation is kept for up to 30 days — so you can still fetch it if your device was offline — and is then deleted automatically. We do not log book text in our access logs (those record only technical metadata: method, path, status and timing). Book files themselves stay on your device; what is copied to your own Google Drive is described below.

Usage and billing

We keep a record of your coin balance and transactions (translations, refunds, bonuses, subscription grants) and your subscription status. Payments are processed by Google Play; we do not receive or store your card or payment details.

Bring-your-own-key (BYOK)

If you use your own AI provider API key instead of coins, that key is stored locally on your device and used to talk to that provider directly. We do not receive your BYOK key on our servers.

Google Drive sync

Once you sign in with Google, the app syncs through your own Google Drive so your library follows you across devices. Sync starts automatically with sign-in; it is not a separate switch.

Copied to your Drive: your app settings, reading positions, bookmarks, library metadata and your translations. Book files are handled separately — a book you translated is stored together with its translation, while a book added for reading only is uploaded only if you enable “Sync books to cloud” in settings.

All of this lives in a hidden application folder inside your own Drive, under your Google account; we only facilitate the transfer. You can erase it when deleting your account, or at any time via Drive → Settings → Manage apps.

Error reports (diagnostics)

So that we learn about failures nobody would otherwise report, the app sends us technical error reports. A report contains the error description and call stack, the last lines of the app’s technical log (no more than 20 KB), the app version, your device model, the Android version, and a device identifier — derived from the Android system identifier, it survives reinstalling the app and contains neither your name nor your address. If you were signed in when the error happened, the report is linked to your account; if not, it stays anonymous.

What a report never contains: book text, translations, book titles, or quotations from your bookmarks. All that reaches us from a book is its internal identifier and a chapter number. API keys, access tokens and email addresses are stripped from the log automatically on your device, before anything is sent.

If you send a report yourself — Settings → Help and diagnostics → Report a problem — we also receive the text you wrote.

You can turn this off: Settings → Help and diagnostics → Send diagnostics. It is on by default. When you switch it off, any reports still waiting to be sent on your device are deleted.

Advertising (free version only)

The free version shows ads served by Google AdMob. To serve them, Google may access your device’s advertising identifier in line with Google’s Privacy Policy. We do not receive this advertising data ourselves. Subscribers see no ads. If you are in the EEA or the UK, the app shows you a Google consent form on first launch, before any ad is loaded, and asks whether ads may be personalised. You can change that decision at any time in Settings → General → Ad privacy settings. Outside those regions the form is not shown. You can also reset or opt out of personalised ads in your device settings.

3. Legal basis for processing (GDPR)

If you are in the European Economic Area or the United Kingdom, our legal bases for processing your personal data are:

4. How we use your data

We do not use your book content to train models, and we do not sell or rent your personal data to anyone.

5. Third parties we share data with

We do not share your data with advertisers, data brokers or analytics providers beyond those listed above.

6. International data transfers

Storage. Our servers and database are located in the European Union (Finland), so your account data is held inside the EEA.

Translation. Text sent for translation carries no account data. The AI provider receives the chapter text plus a technical tag derived from the book’s own content — never your account identifier, your email hash, your device labels or your IP address. It cannot link a request to you. (If a book itself contains personal data, that is content you chose to translate.)

Google services. Sign-In, Drive, Play Billing and AdMob do receive personal data and may process it outside the EEA, including in the United States. These operate under Google’s data processing terms, which incorporate the EU Standard Contractual Clauses.

Administration. DualRead is operated from Ukraine, which has no EU adequacy decision, so administrative access to the servers happens from outside the EEA. That access is limited to the operator, protected by two-factor authentication, and covers only the account data described in section 2.

Diagnostics. Error reports are stored on the same servers in the EU, and the daily summary is delivered to our mailbox on that same server — it never leaves it.

Questions about any of this: support@dualread.app.

7. Retention and deletion

The original text of a chapter is erased as soon as its translation is finished — it is needed only while the translation is running. The translation itself is deleted 30 days after the chapter is completed. Account data is kept while your account exists. You can delete your account from within the app: we remove your sign-in identities, revoke your sessions and anonymise your account. For financial integrity, transaction (ledger) records are retained in an anonymised, faceless form for 3–7 years, as required by tax and accounting law.

Error reports are kept for 14 days and then deleted automatically. Only de-identified statistics live longer: how often each error occurred, when it was first and last seen, and in which app versions — device identifiers are stripped from those statistics under the same 14-day rule. Reports sent before you signed in are not linked to anyone, so deleting your account does not affect them; they expire under the general 14-day rule. Reports linked to your account are deleted together with it.

Encrypted database backups are kept for up to 30 days and then deleted automatically. A deleted account therefore disappears from the live database immediately, while any copy of it inside a backup is gone within that window.

8. Security

All traffic between the app and our servers is encrypted in transit (HTTPS/TLS). Sensitive values on our servers (such as provider keys and second-factor secrets for administrators) are encrypted at rest. No system is perfectly secure, but we take reasonable measures to protect your data and will notify you of any breach affecting your personal data as required by law.

9. Children

DualRead is not directed to children under 13. We do not knowingly collect personal data from children under 13 (or under 16 in EU/EEA countries where a higher age of digital consent applies). If you believe a child has provided us with personal data, please contact support@dualread.app and we will delete it promptly.

10. Your rights

You can delete your account directly in the app (Settings → Account → Delete account) — see how to delete your account for what is removed and how to request it by email if you have already uninstalled. For all other requests below, email support@dualread.app. We respond within 30 days.

EEA and UK (GDPR / UK GDPR)

You have the right to access, correct, delete or export the personal data we hold about you; to object to or restrict certain processing; and to withdraw consent where processing is based on it.

What we hold on our servers is short: your account identifier, the hash of your email, labels of your signed-in devices, your coin balance and your transaction history. Ask us and we will send it in a machine-readable form within 30 days. Separately, the app has a one-tap backup export (Settings → Account) for your library, settings, bookmarks and reading positions — that is data already on your device, offered for convenience rather than as an answer to a data request.

The only processing we base on consent is personalised advertising in the free version; you can change that choice at any time in Settings → General → Ad privacy settings. You also have the right to lodge a complaint with your local supervisory authority (in the EU: your national data protection authority; in the UK: the ICO at ico.org.uk).

California, USA (CCPA / CPRA)

California residents have the right to know what personal information we collect and how we use it, to delete their personal information, to correct inaccurate information, and to opt out of the sale or sharing of personal information. We never sell your personal information for money. However, showing personalised ads through Google AdMob may itself count as “sharing” for cross-context behavioural advertising under the CPRA. If you are in a US state where this applies, the app shows you a Google privacy notice that lets you opt out; you can also change the choice later in Settings → General → Ad privacy settings, or limit ad tracking in your device settings. Opting out does not remove ads — they simply stop being personalised. For any other request, contact support@dualread.app. We will not discriminate against you for exercising these rights.

Canada (PIPEDA)

Canadian residents have the right to access and correct their personal information held by us, and to withdraw consent to its collection or use (subject to legal or contractual restrictions). To make a request or to file a complaint, contact support@dualread.app. You may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Australia (Privacy Act 1988)

Australian residents may request access to or correction of their personal information. If you believe we have breached the Australian Privacy Principles, you may contact us first, and if unresolved, lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.

11. Changes to this policy

We may update this policy as the app evolves. We will post the new version here and update the “Last updated” date. We will announce material changes in the app or by email at least 14 days before they take effect.

12. Contact

Questions about this policy or your data: support@dualread.app.