Privacy policy

stowely is a reading app. We try to collect as little as possible and never sell any of it. This page is the plain-language version of what we actually do with your data.

Effective June 5, 2026.

Who runs stowely

stowely is an independent project. Contact: contact@stowely.com.

What we collect

  • Account info. Email address and a password hash (we never store passwords in plain text). If you verify your email, we record the verification timestamp.
  • Your library. Anything you upload (EPUB, PDF, TXT) and the parsed text we extract from it. These files are stored on our servers so you can read them on any device you sign in from.
  • Reading data. Your reading sessions — which text you read, your progress (word index), your reading speed (WPM), and the timestamps when you read.
  • Session metadata. When you sign in we store a session record with the User-Agent string and IP address so you can see your active sessions in Settings and revoke any device that isn't you.
  • Payment info (Pro subscribers). We use Stripe for payments. We see your subscription status and Stripe customer ID, but never your card number. Stripe's own privacy policy applies to card data.
  • Product analytics. Server-side events about signup, upload, and reading-session creation, sent to PostHog so we can understand which parts of the funnel work. These events are tied to your user ID, not your email or library contents.
  • Push notification tokens (mobile only). If you install the Android app, we register a push token so we can remind you to come back to a book you're partway through. You can revoke this by uninstalling the app.

What we don't collect

  • No advertising trackers, no third-party ad networks.
  • No location data.
  • No microphone, camera, or contacts access.
  • No selling of any data to anyone, ever.

Who we share data with

Only the third-party processors we need to run the service:

  • Stripe — payment processing.
  • PostHog — product analytics.
  • Our SMTP provider — to deliver verification and password-reset emails to your inbox.
  • Our hosting provider (Hetzner, Germany) — to store your account, library, and reading sessions.

Each of these is bound by their own contractual obligations and privacy policies. We share only what's needed to deliver the service.

How long we keep it

Account, library, and reading data live as long as your account does. If you ask us to delete your account, we remove your account record, all uploaded texts, all reading sessions, and all session records within 30 days. Stripe retains billing records as required by tax law.

Your rights

You can:

  • See and revoke active sessions in Settings.
  • Delete any uploaded text from your library at any time.
  • Request a copy of your data, or full account deletion, by emailing contact@stowely.com. See the account deletion page for details. We'll respond within 30 days.

If you're in the EEA, UK, or California, you have the rights granted to you under GDPR / UK GDPR / CCPA respectively (access, correction, erasure, portability, objection). The same email address handles those requests.

Children

stowely is not directed at children under 13. We don't knowingly collect data from anyone under 13. If you believe a child has signed up, email us and we'll delete the account.

Security

All traffic to stowely.com is over HTTPS. Passwords are hashed using a one-way function. Database backups are encrypted at rest. No system is bulletproof — if we ever have a breach that affects you, we'll notify you within 72 hours, as required by GDPR.

Changes to this policy

If we change how we handle data in a way that affects you, we'll update this page and the "Effective" date at the top. Material changes will also be emailed to you.