Bookwren by Paperleaf Studio
Privacy Policy
This is the privacy policy for Bookwren, a reading journal app for Android made by Paperleaf Studio. It explains what Bookwren keeps on your phone, what leaves your phone, who receives it, when and why.
The short version
- No Bookwren account. Your books, notes and quotes live on your phone, never on our servers.
- Book search and covers come from Open Library, which receives what you search for and the books Bookwren looks up.
- Crash reports go to Sentry. They never include your books or notes, and you can turn them off in Settings.
- The barcode scanner uses Google’s ML Kit, which sends Google technical data when you scan.
- No ads, no advertising ID and no analytics SDK. We never sell your data or share it for advertising.
Who we are
Paperleaf Studio is the name under which an independent developer in the Philippines publishes apps. In this policy, “we” and “the studio” mean that developer. Google Play shows the studio’s contact details on Bookwren’s store listing.
For privacy questions and requests, write to support@studiopaperleaf.com.
What stays on your phone
Bookwren keeps your library in a database in its own private storage on your phone. Other apps cannot read it. We have no server that holds a copy. Your library is:
- your books, with their titles, authors, ISBNs, page counts, formats, series and tags;
- your reading history: start and finish dates, and each page or percent update you log;
- your ratings, notes, quotes and reviews;
- your yearly goals and your settings.
Bookwren also keeps these on your phone:
- safety copies of your library, made before an import, a restore, a bulk delete or an update that changes how your data is stored, so the change can be undone;
- drafts of notes and edits you have not finished, so what you typed is still there when you come back;
- covers it has already shown, in a cache, so they still appear offline;
- two counts that show where Open Library has gaps: scanned ISBNs it could not find, and books you added by hand after a search;
- if Android brings back a copy of your library that Bookwren cannot read, that copy, which Bookwren keeps on your phone for 30 days and then deletes.
The next sections list every way data leaves your phone.
What leaves your phone, and who receives it
Bookwren sends data to three outside services, each for one job, and Android can back up part of it to your own Google account. Every request Bookwren makes uses HTTPS, so it is encrypted on the way.
Open Library (Internet Archive), for book search and covers
Open Library is a free, open catalogue of books run by the Internet Archive, a nonprofit library in the United States. Bookwren uses it to find books and show their covers.
- What it receives
-
- the text you search for in “Search Open Library”, including a book’s title and author when you use “Find on Open Library”;
- ISBNs you scan or type;
- requests for book details, editions and cover images, which name a book by its ISBN or its Open Library ID;
- your phone’s IP address, as any website does, and a short tag that names the app, its version and the studio’s email address, which Open Library asks apps to send.
- When
-
- when you search, scan, look at other editions of a book, or use “Find on Open Library”;
- in the background, when Bookwren looks up covers and missing details for books that already have an ISBN or an Open Library ID. This happens after you restore a backup, when you continue from the “Welcome back” screen after Android brings your library back on a new phone, after you scan a book while offline, and from Bookwren 0.1.1, after an import if you leave “Find covers on Open Library after import” on. It is on unless you turn it off. Bookwren never searches by title in the background;
- when a cover appears on your screen and is not already saved on your phone. After that, the cover is kept on your phone.
- Never sent
- Your notes, quotes, reviews, ratings, dates and reading progress.
- Good to know
- Because these lookups name books, Open Library’s servers can see which books Bookwren asked about, and from which IP address. Whatever Open Library keeps is handled under the Internet Archive’s terms of use and privacy policy. We cannot see or delete it.
- Without it
- Search and covers need Open Library and a connection. You can always type a book in by hand instead.
Google ML Kit, inside the barcode scanner
The barcode reader inside Bookwren’s scanner is ML Kit, made by Google. The first time you tap Scan, Bookwren explains why it needs the camera, and Android asks for your permission. Camera images are processed on your phone and never saved or sent.
- What Google receives
- Device and app information, such as the phone’s maker, model and Android version; identifiers for this installation, which Google says are not intended to uniquely identify you or your phone; performance metrics; details of each scan request, such as the feature version, the event type and the size of its input and output; and error codes.
- When
- Only when you use Scan. Searching for a book or typing it in does not use ML Kit.
- Why
- Google says it uses this data for ML Kit’s diagnostics and usage analytics, sends it over HTTPS and does not pass it to third parties. See Google’s ML Kit data disclosure and the Google Privacy Policy. We cannot see or delete this data.
Sentry, for crash reports
Sentry is a service that collects crash reports for app makers. Crash reports help us find and fix bugs.
- When
-
When Bookwren crashes or hits an error, it sends a crash report to Sentry, but only while “Send crash reports” is on in Settings, About. The switch is on when you install Bookwren, and you can turn it off at any time. While it is off, Bookwren does not start Sentry and sends no reports.
One exception is always your choice. If Bookwren ever shows its error screen (“Something went wrong. Your books are safe.”), you can tap “Send report” there to send that one report, even with the switch off.
- What a crash report contains
- What went wrong and where in Bookwren’s code it happened; technical details about the phone and the app, such as the phone’s maker and model, the Android version, Bookwren’s version, the language and time zone settings, and the phone’s memory, storage and battery state; and a random ID that Sentry makes for this installation of Bookwren.
- What it never contains
- Your books, notes, quotes, reviews or search text, the contents of any file, or web addresses with search terms. Bookwren also keeps Sentry’s other features off: no screenshots, no screen recordings, no app logs, no usage sessions, no performance tracing, and no record of the taps you make or the screens you visit.
- Your IP address
- Like any server, Sentry sees your phone’s IP address when a report arrives. Bookwren’s Sentry project is set not to store IP addresses.
- How long, and who sees it
- Crash reports are deleted automatically within 30 days. Only the studio uses them, to fix bugs. Sentry stores them for the studio as a service provider; see the Sentry privacy policy.
Your Google account, through Android backup
Android can back up app data to your own Google account when backup is turned on in your phone’s settings. Bookwren limits what Android may back up to two things at most:
- one complete copy of your library, which Bookwren refreshes on your phone after you make changes, and
- your “Send crash reports” choice, so a new phone keeps it.
The same two things can also move straight to a new phone during Android’s phone-to-phone transfer. Android backup never includes Bookwren’s working database, safety copies, covers or temporary files. The backup goes to your Google account under Google’s terms and the Google Privacy Policy. The studio never receives it. On Android 9 and later, with a screen lock set, Google encrypts it end to end. Without a screen lock, Google still encrypts it, but not end to end. If your library grows too large for Android backup, Bookwren says so in Settings, Your data, and you can use “Back up now” instead.
Files you choose to share
Backup files
“Back up now” in Settings, Your data writes a backup file of your library to the place you pick in Android’s save screen, such as Google Drive or a folder on your phone. “Send a copy” shares the same file through Android’s share sheet, for example to your own email. The file goes only where you send it, and the service you choose handles it under its own terms. The studio never receives your backup files unless you choose to send one to us.
A backup file is plain text (JSON). It holds your books, reading history, ratings, notes, quotes, reviews, tags, goals and settings. It does not hold covers, drafts, safety copies or books in Recently deleted. It is not encrypted, so keep it somewhere you trust.
Restoring a backup
When you restore, Bookwren reads the file you pick on your phone, and the restore itself uploads nothing. Afterwards, Bookwren gets covers and missing details from Open Library, as described above.
Importing from Goodreads or The StoryGraph (from Bookwren 0.1.1)
From Bookwren 0.1.1, you can import a Goodreads or The StoryGraph export file (CSV). Bookwren reads the file on your phone, and the import itself makes no network requests. A temporary copy of the file stays on your phone until the import finishes or is undone, and is then deleted. Covers and missing details for the imported books come from Open Library afterward, as described above, if you leave that option on.
Goodreads and The StoryGraph are trademarks of their owners. Bookwren is not affiliated with or endorsed by them.
Emails you send us
If you write to us, we receive your email address, your message and anything you attach.
“Report a problem” in Settings, About opens your own email app with a message that already holds Bookwren’s version, your Android version and your phone model. In test versions of Bookwren, it also holds the two Open Library gap counts described above. It never includes your library. You can read and change the email before you send it, and nothing is sent until you send it yourself.
We use emails only to answer you and to fix what you report. Our mailbox is hosted by Google (Gmail), and mail to support@studiopaperleaf.com reaches it through Cloudflare’s email routing. We keep emails for 12 months after our last reply, then delete them, or sooner if you ask.
Google Play and testing
Google Play installs and updates Bookwren under Google’s own terms, and installing it needs a Google account, which Google manages. Google gives app makers summary statistics, such as installs by country and by device, and crash reports from people who chose to share usage and diagnostics data with Google.
If you join Bookwren’s closed test, we have the email address you gave us to add you to the test. We use it only to run the test. We delete the tester list within 30 days after Bookwren leaves closed testing.
Permissions
Bookwren asks for two permissions, each only when you use the feature that needs it:
- Camera, the first time you tap Scan, to read a book’s barcode. Camera images are processed on your phone and never saved.
- Notifications, from Bookwren 0.1.1, only when you turn on the reading reminder. Reminders are scheduled on your phone, and Bookwren has no push messaging. If you turn the reminder on, Bookwren can also remind you to back up, at most once a month. Bookwren 0.1 sends no notifications at all.
Bookwren never asks for your location, contacts, microphone, photos, calendar or files. It opens and saves files only through Android’s own file picker and save screen, which need no storage permission. Android also grants a few permissions without asking, such as internet access for search, covers and crash reports. Google Play shows the full list in Bookwren’s store listing.
What we never do
- No ads, and no advertising ID.
- No analytics SDK: the studio collects no statistics about how you use Bookwren. Google Play’s Data safety section lists crash reports and ML Kit’s diagnostics under “Analytics”, which is Google’s word for checking that an app works.
- No selling of your data, and no sharing of it for advertising.
- No tracking of you across other apps or websites.
- No Bookwren account, and no copy of your library on our servers.
- No use of your data to train AI.
Why we use this data
- Crash reports, to keep Bookwren working: they show us what went wrong, so we can fix it. You can object at any time by turning off “Send crash reports”.
- ML Kit’s diagnostics, which Google collects when you use Scan and uses for ML Kit’s diagnostics and usage analytics. We never see them. You can type the ISBN or search instead of scanning.
- Open Library lookups, to give you the search results, book details and covers you ask for.
- Emails, to answer you.
- The tester list, to run the closed test.
Keeping data safe
- Every request Bookwren makes uses HTTPS. Bookwren does not allow unencrypted connections.
- Your library stays in Bookwren’s private storage on your phone, which other apps cannot read.
- Before an import, a restore, a bulk delete or an update that changes how data is stored, Bookwren makes a safety copy on your phone, so a change can be undone.
- Backup files are not encrypted. Keep them somewhere you trust, such as your own Google Drive.
How long data is kept, and how to delete it
- Your library stays on your phone until you delete it. A book you delete moves to Recently deleted, and Bookwren removes it for good the next time you open the app after 30 days. Safety copies made before that can still hold it until newer safety copies replace them, or until you uninstall Bookwren. A note, quote, review or reading record you delete on its own is removed for good the next time you open the app.
- Uninstalling Bookwren removes everything it stored on your phone, including safety copies and covers.
- Backup files you saved, and Android’s backup in your Google account, are outside Bookwren. They stay until you delete them where they are kept.
- Crash reports are deleted automatically within 30 days.
- Emails are kept for 12 months after our last reply, then deleted, or sooner if you ask.
- The tester list is deleted within 30 days after Bookwren leaves closed testing.
- Data held by Open Library and Google is kept under their own policies, linked above. We cannot delete it for you.
To ask about or delete data the studio holds, write to support@studiopaperleaf.com. We reply within 30 days. Crash reports carry no name and no account ID, so we usually cannot tell which reports came from your phone, but they delete themselves within 30 days.
Your rights
Depending on where you live, for example in the Philippines, the UK, the European Union or some US states, you have rights over your personal data, such as the right to see it, correct it, delete it or object to how it is used. The only personal data the studio itself holds are crash reports, emails you send us and, if you test Bookwren, your tester email address. Write to support@studiopaperleaf.com and we will reply within 30 days. You can also complain to the data protection authority where you live.
Children
Bookwren is made for adults and is not directed at children under 13, and we do not knowingly collect personal data from children. There is no Bookwren account, and the app does not ask anyone for their name, age or contact details. If you believe a child has sent us personal data, for example by email, write to us and we will delete it.
Where data goes
The studio works from the Philippines: we read emails and run the closed test from there. Data that leaves your phone goes to these places, each under its provider’s own terms:
- Open Library: the Internet Archive, in the United States.
- Sentry: Sentry’s servers in the United States or the European Union, as chosen for the studio’s account.
- Google (ML Kit, Android backup, Google Play and the studio’s Gmail mailbox): Google’s servers, which can be in a different country from yours.
- Cloudflare carries this website and routes email to the studio’s mailbox.
Data protection laws in these places can differ from the laws where you live.
Changes to this policy
When Bookwren changes what it collects or shares, we update this page before the version with that change reaches anyone. The date at the top shows the last update, and the version history below says what changed.
Version history
- October 10, 2026: First version, for Bookwren 0.1 and 0.1.1.
About this website
studiopaperleaf.com sets no cookies of its own, runs no scripts and has no analytics. It is served by Cloudflare, which handles your IP address to deliver the pages and protect the site from attacks, and can set a short-lived security cookie if it needs to check a visitor.
Contact
Paperleaf Studio, support@studiopaperleaf.com