Privacy policy
stowely is a reading app. We try to collect as little as possible
and never sell any of it. This page is the plain-language version
of what we actually do with your data.
Effective June 5, 2026.
Who runs stowely
stowely is an independent project. Contact:
contact@stowely.com.
What we collect
-
Account info. Email address and a password hash
(we never store passwords in plain text). If you verify your
email, we record the verification timestamp.
-
Your library. Anything you upload (EPUB, PDF,
TXT) and the parsed text we extract from it. These files are
stored on our servers so you can read them on any device you
sign in from.
-
Reading data. Your reading sessions — which text
you read, your progress (word index), your reading speed (WPM),
and the timestamps when you read.
-
Session metadata. When you sign in we store a
session record with the User-Agent string and IP address so you
can see your active sessions in Settings and revoke any device
that isn't you.
-
Payment info (Pro subscribers). We use Stripe
for payments. We see your subscription status and Stripe customer
ID, but never your card number. Stripe's own privacy policy
applies to card data.
-
Product analytics. Server-side events about
signup, upload, and reading-session creation, sent to PostHog so
we can understand which parts of the funnel work. These events
are tied to your user ID, not your email or library contents.
-
Push notification tokens (mobile only). If you
install the Android app, we register a push token so we can
remind you to come back to a book you're partway through. You
can revoke this by uninstalling the app.
What we don't collect
- No advertising trackers, no third-party ad networks.
- No location data.
- No microphone, camera, or contacts access.
- No selling of any data to anyone, ever.
Who we share data with
Only the third-party processors we need to run the service:
- Stripe — payment processing.
- PostHog — product analytics.
-
Our SMTP provider — to deliver verification and
password-reset emails to your inbox.
-
Our hosting provider (Hetzner, Germany) — to
store your account, library, and reading sessions.
Each of these is bound by their own contractual obligations and
privacy policies. We share only what's needed to deliver the
service.
How long we keep it
Account, library, and reading data live as long as your account
does. If you ask us to delete your account, we remove your account
record, all uploaded texts, all reading sessions, and all session
records within 30 days. Stripe retains billing records as required
by tax law.
Your rights
You can:
- See and revoke active sessions in Settings.
- Delete any uploaded text from your library at any time.
-
Request a copy of your data, or full account deletion, by
emailing contact@stowely.com.
See the account deletion
page for details. We'll respond within 30 days.
If you're in the EEA, UK, or California, you have the rights
granted to you under GDPR / UK GDPR / CCPA respectively (access,
correction, erasure, portability, objection). The same email
address handles those requests.
Children
stowely is not directed at children under 13. We don't knowingly
collect data from anyone under 13. If you believe a child has
signed up, email us and we'll delete the account.
Security
All traffic to stowely.com is over HTTPS. Passwords are hashed
using a one-way function. Database backups are encrypted at rest.
No system is bulletproof — if we ever have a breach that affects
you, we'll notify you within 72 hours, as required by GDPR.
Changes to this policy
If we change how we handle data in a way that affects you, we'll
update this page and the "Effective" date at the top. Material
changes will also be emailed to you.