Biblio is a reader and player for books. This policy describes what happens to information about you — when something leaves your device, where it goes, and how long we keep it. We have tried to write a text you will read in full, rather than a list of legal formulas.
Who is responsible
Biblio is developed and published by BRAILCOM, o.p.s., a Czech non-profit research organisation in the field of assistive technology (founded 22 July 1996, company ID 25066803). BRAILCOM is also the data controller — it decides what happens with your information, and it is the party to contact with any request.
BRAILCOM, o.p.s.Náměstí 5
267 27 Liteň
Czech Republic
Contact: biblio@brailcom.org
The servers on which Biblio processes data
(bibliobackend.oui.technology, itsng.oui.technology,
biblio.oui.technology) are operated by
OUI Technology Ltd (United Kingdom, Company Number 10905437) as
a processor, that is, on our instructions and only for the purposes described
below. OUI Technology also holds the copyright to the app. Both organisations are
part of the
Accessibility Expert Group.
What Biblio does not do
We start here, because it matters and there is a lot of it:
- We do not measure how you use the app. Biblio contains no analytics tool, no third-party behaviour-tracking library, and nothing that reports statistics about your reading.
- We show no advertising and use no advertising identifiers. Biblio never requests the identifier for advertisers (IDFA) and has no way to use one.
- We do not track you across apps or websites, and we do not combine your information with information from elsewhere.
- We do not build a profile of you and make no automated decisions about you.
- We do not sell your information and do not pass it to anyone for their own purposes.
- We keep no account for you. Biblio never asks for your name, e-mail address, or phone number.
What stays on your device only
Most of what Biblio creates is never sent anywhere:
- Your library — which biblions you have, which series you filed them under, what you have started reading.
- Where you stopped in a book, your bookmarks, and their labels.
- Transcripts you have had made, and the text of books.
- Your declaration under the Marrakesh Treaty. It is stored nowhere outside your device and is sent to no server. It exists only so that Biblio, on your phone, knows what to offer you.
- Library sign-in details are stored in the iOS Keychain, a vault that neither we nor anyone but you can reach.
Your iCloud storage
If you have iCloud storage enabled, Biblio synchronises part of your library across your own devices — bookmarks, reading positions, the list of biblions, your conversation history with the librarian, and any recordings you chose to publish. It is your iCloud storage, belonging to your Apple account. We cannot see into it and have no access to it. Apple's terms apply to it.
What leaves your device, and when
Biblio talks to the network only when you ask it to. Specifically:
Searching catalogues and downloading biblions
When you search, your query is sent to the library catalogue you are searching. When you download a biblion, a request for its files is sent. Depending on which sources you have enabled, this means our servers (Biblio, Camelot) or third-party services (the Library of Digital Documents, the Czech National Digital Library, Project Gutenberg, iTunes for podcast search, the RSS servers of individual podcasts, Wikipedia and Wikidata). Each of them learns your query and your IP address, as with any other request made over the internet.
For library collections reserved for people with reading disabilities you also sign in with your membership details, which are sent to that library. Those details are not ours and we do not keep them; they are stored only in your device's Keychain.
The librarian (chat)
When you ask the librarian something, the text of your question and the conversation so far in that thread are sent to our server, bibliobackend.oui.technology. The librarian needs the context in order to give a relevant answer.
In our operational log we store only a cryptographic fingerprint of your question, not the text itself. The fingerprint lets us tell that the same question recurs, so that we can improve how we decide which model answers it.
If you save your own Anthropic or Google Gemini key in settings, questions for which you select such a model go directly to that provider under your own account and do not involve our server. That provider's terms then apply.
When you rate an answer with a thumb up or down, we receive the rating, any comment you choose to write, which model was used, and the app version. You can turn this off in the librarian's settings.
Transcribing a recording into text
A transcript is made only when you ask for one, and there are two options. Either it runs on the device, in which case no audio is sent anywhere. Or our server does the work, in which case the audio recording in question is sent to bibliobackend.oui.technology.
We handle the audio as follows: we delete the recording from the server immediately after processing, in every case — when the transcript completes successfully, when it fails, and when you cancel it.
We delete the finished transcript text the moment your device downloads it and confirms that it has it. That usually takes a few minutes. If the device does not check in for a long time, because it is switched off, has no signal, or you do not open the app, the text waits for you — for at most 7 days, after which we delete it even uncollected. The same 7 days apply to failed transcripts. Until then it is stored under the random identifier described below, without your name.
Reporting problems
When you report a bug or send a suggestion, we receive the text of your report, together with whichever attachments you consented to: environment details (Biblio version, iOS version, device model, language, whether VoiceOver is on), a description of the situation you were in when writing the report, and a screenshot.
You send no name and no e-mail address, and we keep nothing further about you. Your report is filed under a random code that only your device holds, and of which we store only a unique fingerprint. That fingerprint tells us only that a further message is from the same person. It is stored in your iCloud Keychain so that you do not lose the history of your reports when you reinstall.
A screenshot and a description of the situation may contain some form of personal data, typically the title of the book you are reading. That is why you can have the recognised contents of the screenshot read out to you before sending, and leave the attachment off. The report will send without it. When a case is closed, we delete its attachments.
Notifications
If you allow notifications, the identifier that Apple issued to your device for this purpose (a token) is sent to our server. We use it to let you know that a transcript is ready, that a reply to your report has arrived, or that new help content has been published. We use the token for nothing else and do not connect it with the contents of your library.
YouTube
Video channels are optional and work only if you sign in with a Google account
yourself and grant youtube.readonly access. Biblio then reads, through
the YouTube interface, the list of channels you follow and public data about them.
Channel metadata (identifier, title, thumbnail address) stays on your device and
syncs to your own iCloud storage — it is never transferred to our server. The
access credential for your Google account (the refresh token) stays in your
device's Keychain and is never sent to us.
You can revoke access at any time at myaccount.google.com/permissions. Google's terms apply in respect of Google.
Identifiers we hold about you
These are not identifiers from Apple or from the device manufacturer, but random numbers created on your device:
- A random identifier for our server, stored in the Keychain. It lets us tell that several requests came from the same installation. It contains no information about you or about your device.
- The reporter code for problem reports, described above.
- A notification token, if you allowed notifications.
None of these identifies you as a person, and we have no way to get from them to your name.
How long the information you send stays with us
We keep problem reports for as long as the case is needed for work on the app. We delete the attachments of closed reports. We keep fingerprints of librarian questions and ratings of answers for as long as they serve to improve the app. We delete a notification token when it stops being valid. We delete audio recordings sent for transcription immediately after processing. We delete the finished transcript text the moment your device collects it, and after 7 days at the latest.
Children
Biblio is not directed at children and we collect no information about age. Its content comes from library collections and public catalogues.
Your rights
You have the right to know what information we hold about you, to have it corrected or deleted, to restrict processing, and to object to it. If you have questions, write to gdpr@brailcom.org.
Be prepared for one limitation that follows from the way Biblio is built: because we hold no name and no e-mail address for you, we have nothing by which to find you in our records. For problem reports it can be done if you tell us your reporter code. In other cases there is usually nothing to delete, because no personal data about you is retained. You may also lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, Prague 7.
Changes
If we change this policy we will update the effective date at the top and describe any significant change in the app. Earlier versions are available on request.