Privacy
Updated 18 September 2026
Pagetime counts your reading time and keeps what you think about books. This page says what of that stays on the phone, what goes to the server, who else sees it and how to wipe all of it at once.
The short version
- The library, the time and the notes live on your phone and work with no account and no internet.
- The server shows up in four cases: signing in, syncing between your own devices, talking to the AI and fetching book details from Apple Books.
- Photographed pages never leave the phone. The text on them is recognised by the phone itself.
- No analytics and no counters in the app or on the site, no ads, nothing sold on. We make money on the subscription.
- Deleting your account wipes everything from the server, conversations included, and takes one button in settings.
Who is responsible
Pagetime is made by Eduard Abdullin, an independent developer enrolled in the Apple Developer Program as an individual. He decides why and how the data is processed, which makes him the controller under the GDPR.
About your data, write to [email protected]. About anything else, [email protected].
This document covers the Pagetime app for iPhone, the pagetime.net site and the api.pagetime.net server. There is nothing else.
What stays on the phone
Everything you do in the app is written to the phone first, and with no account that is where it ends. The tracker, the notes, the statistics and the widgets all work on a plane.
- Books, reading sessions, thoughts, quotes and ideas — in the app’s own storage.
- Photographed pages — as files inside the app. They never reach your camera roll and never reach the server.
- Text recognition runs on the phone itself, with the system’s own tools. The photo is not sent anywhere, not even for a second.
- The daily goal and its history, the streak, the exact reminder time, the theme and the ink colour — in the app’s settings. Reminders are scheduled by the phone; we send no push notifications at all. After sign-in, the time zone, the first day of the week and the selected reminder hour are also copied to the server as described under Sync.
- The sign-in token — in the Keychain, marked “this device only”, so it does not travel into an iCloud backup.
Sign in with Apple
There is nothing to register: the only way in is Apple ID, and we never see or store a password. Apple gives us a permanent identifier issued to this app alone, and an address — either your real one or a hidden “[email protected]” if you chose to hide it.
The server then keeps: that Apple identifier, the address, your name if Apple passed it at the first sign-in, the device name, a fingerprint of the session token, the dates the session was created and last used — and a token Apple issues at sign-in, kept for one purpose only: to revoke Pagetime’s access at Apple when you delete your account.
The session token itself is not on the server, only its hash. A leaked database does not let anyone sign in as you.
Sync
Sync starts once you are signed in and puts a copy of your library on the server, so that it survives a lost phone and reaches a second device.
What travels: books (title, author, genre, cover, page count, shelf, rating, tags, dates), reading sessions (start, end, length, pages, the note you left on the session) and notes (kind, text, page, chapter, tags, favourite, text recognised from a photo). Deletion marks travel too — otherwise a deleted book would come back from the other device.
The phone also sends its time zone, the first day of its week and the selected reading-reminder hour. The server uses the time zone to reset the daily AI limit at local midnight and the time zone and first day of the week for reading-day and streak calculations. The reminder itself is still scheduled on the phone, and its exact minute stays there.
Photographed pages do not travel. If a note was made from a photo, only the text reaches the server.
Talking to the AI
A conversation about a book, a book summary, a month in review and a thought about a quote do not run on the phone: the request goes to our server and from there to an outside model. This is the only place where someone other than us sees your words.
What goes into the model: your message, the book’s details (title, author, genre, page, how long you have been reading it) and your notes on that book — up to forty quotes and up to forty thoughts. For a month in review: the month’s statistics, the titles you finished and that month’s notes. Individual reading sessions, your email address, your name and your IP address never go.
We route the requests through OpenRouter with training refused: the router only picks providers that do not keep requests and do not train on them. The conversations themselves are stored by us — otherwise you could not open one tomorrow — and are wiped along with the account.
Before your first request the app asks your permission and shows what goes and where. Without it nothing reaches a model, and the rest of the app works as usual. You can withdraw the permission at any time in Settings, under “AI and sync”.
The answer is written by a model, not by a person. We do not read your conversations to improve them and we build no recommendations on them.
The subscription
Apple takes the money. We never see the card, the address or anything else about the payment.
What reaches us from Apple is a signed purchase, and from it we keep: the purchase identifier, the plan (monthly or yearly), the expiry date and a record of the event — bought, renewed, refunded. The same record is how we notice a purchase being claimed a second time from another account.
How we check that the free answers work
Everyone who signs in gets a number of AI answers for free. To know whether that is worth it, we count on the server how many of the people who signed up in a given week went on to subscribe, and what happened after their last free answer: whether they subscribed within a week, within a month, or not at all.
Nothing new is collected for this, and nothing is read from your phone. The count is made from records the server already keeps for other reasons: the date of your first sign-in, the record of AI requests that the daily limits need, and the subscription record from Apple. It uses dates and totals only, never the text of your notes or conversations, and what comes out is a table of numbers by week, not a profile of anyone. The table is not stored: it is worked out again each time we open it.
The grounds are our legitimate interest, described below. If you would rather not be counted, write to [email protected] and we will leave your account out. Nothing else about the app changes.
Looking a book up
When you search for a book or paste a link from Apple Books, the search string goes from our server to Apple to retrieve book details. Apple does not see your IP address: the request comes from our machine, not from your phone.
What comes back — title, author, genre, cover, page count — is written into your library. The cover itself is later fetched by the phone straight from Apple’s servers.
The email form on the site
The form on pagetime.net collects an email address, the language of the page it was left on, and the tag from the link if you came through one: for “pagetime.net/de/?from=tt-de-03” that is “tt-de-03”. The tag is the same for everyone who opened that link — it says which video worked, not who you are. No name, no IP address, no browser fingerprint.
The promise under the form is one letter on the day the app ships, and it holds: there is no newsletter and the address goes to nobody else. Write to [email protected] and it is struck off the list straight away.
Server logs
The web server records requests: the IP address, the time, the address requested, the app or browser version. That is what a broken thing is diagnosed with and what keeps bots and password guessers out; we build no profile from it and count no visitors.
Logs live on the server for no longer than fourteen days and are then rotated away.
Crashes go nowhere: Pagetime has no crash reporter and sends no error reports.
What we do not collect
- No analytics and no counters, in the app or on the site: third-party scripts on the site are blocked by a security policy the browser enforces, not by a promise.
- No ads and no advertising identifiers. The app never asks for tracking permission because it does not track.
- We do not ask for location, contacts, calendar, microphone or health data, and we do not use them.
- We do not buy data about you and we do not sell yours.
Who else gets data
This list is complete. Each of them gets exactly what their job needs.
- Apple — Sign in with Apple, App Store purchases and book details from Apple Books. Apple handles that data as its own controller, under its own policy.
- Hetzner Online GmbH, Germany — the machine that runs the server, the database and the backups. The data sits in Nuremberg.
- Cloudflare — DNS and delivery for the pagetime.net site. The site goes through it; the app does not: api.pagetime.net points straight at our machine.
- OpenRouter, USA — routing requests to a model, and the model provider it picks. Only what the AI section lists, and only with training refused.
The legal grounds
- Our contract with you — the account, sync, the subscription and the AI answers you asked for. Without this the app cannot do the thing it was installed for.
- Your consent — the letter about the launch, if you left your address on the site. It can be withdrawn in one line by email.
- Our legitimate interest — keeping the server safe, daily limits, backups, diagnosing failures, the tag of the link that brought someone to the site, and counting in weekly totals whether the free AI answers lead to subscriptions. We weighed that against your privacy and keep it inside the limits described above.
How long it is kept
- Account data and the copied device settings — for as long as the account exists. Delete the account and the server wipes it all at once: books, sessions, notes, conversations, usage records, subscription history, time zone, first day of the week and reminder hour.
- Database backups — fourteen days. Deleted data is gone from them within that time.
- Server logs — fourteen days.
- A sign-in session — ninety days without use, and never more than a year from the sign-in, even if you open the app daily.
- The address from the site form — until the launch letter, or until you say the word.
- On the phone, everything stays until you delete a note or the app. Deleting the account clears the server, not the phone — and the button says so.
Your rights
You can ask for a copy of your data, for a correction, for deletion, for processing to be restricted, you can object to it, and you can take your data with you in a portable form. Consent can be withdrawn at any time, and withdrawing it does not undo what was done before.
Two of these need no letter. To delete your account: Settings, the Account section, Delete Account; the server is wiped immediately. To take your notes: Settings, Export Notes — the app builds a file with every thought, quote and idea, arranged by book.
For anything else write to [email protected]. We answer within a month, usually sooner. If the answer does not satisfy you, you may complain to the data protection authority where you live.
Children
Pagetime is meant for people aged sixteen and over. We do not knowingly collect children’s data; if it turns out an account belongs to someone younger, we will delete it on the first letter.
Where the data goes
The server and the database stand in Germany, that is, inside the European Union. Everything that leaves the phone lands there.
Two things leave the EU: AI requests (OpenRouter, USA) and everything Apple-related — signing in and purchases. Those transfers are covered by the European Commission’s standard contractual clauses.
How it is protected
Connections are HTTPS only. The sign-in token lives in the phone’s Keychain and the server holds only its hash. Someone else’s record answers “not found” rather than “not allowed”: otherwise guessing identifiers would tell a stranger about your library. Ports are closed by a firewall, the database and the app listen to the machine itself only, and the service runs with cut-down privileges.
One thing is worth saying plainly: notes on the server are not encrypted with a key only you hold. With such a key the AI could not read your notes, and the very reason the server exists would be gone. The developer has access to the database, and nobody else does.
Cookies
The site sets one cookie, pagetime_lang. It appears only if you switch language by hand and lives for a year: without it the site would put your phone’s language back over your choice on every visit. Permission is not required for that, and the counters permission is usually asked for do not exist here.
Cloudflare may add a technical cookie of its own that tells a person from a bot. The app sets no cookies at all.
If this policy changes
The date at the top is the date of the last edit. Substantial changes will be announced in the app before they take effect, not after.