Effective date: 9 June 2026 · Last updated: 20 June 2026
This Privacy Policy explains how HushBook ("HushBook", "we", "us", "our") handles information when you use (a) the HushBook mobile application (the "App") and (b) our website https://hushbook.app (the "Website").
Your audio does not leave your phone, and we do not receive your audio. HushBook has no accounts and no server of its own; your audiobooks, transcripts, quotes and listening data are created and stored only on your device.
Data controller. HushBook is operated by Rakesh Aditya. For any privacy question, request, or complaint, you can contact us at aditya@hushbook.app.
1. Information stored
A. Information stored on your device. The App creates and stores the following only on your device:
- downloaded audiobooks and associated files;
- word-level transcripts generated by the HushBook Engine on-device;
- saved quotes;
- listening data such as progress, goals, streaks, badges, "neuron score", and accessibility profile.
Your audio does not leave your phone, and we do not receive your audio.
B. Crash & performance diagnostics. When the App crashes or is running slowly, the App sends diagnostic data to help us identify and fix the issue. We use Sentry (a crash-reporting and performance monitoring service) for this purpose. Diagnostics may include:
- crash stack traces and error logs (technical traces showing where code failed);
- device and app information (device model, operating system version, App version, language/locale);
- performance metrics (e.g., how long a screen took to load, app responsiveness);
- a randomly generated, per-installation identifier used only to group related reports (this is not your device's advertising ID or a stable hardware identifier).
The App is configured so that diagnostics do not attach your IP address by default, and so that file paths and book titles are stripped from reports before they are sent. Diagnostics do not include your audio, the content of your transcripts, your saved quotes, screenshots, or the titles you are listening to or reading (except where such information is inadvertently included in an error message you choose to send us).
Diagnostic data is transmitted over an encrypted connection (encrypted in transit). Sentry acts as our data processor for diagnostics under a data-processing agreement and processes this data on servers in the European Union. See Sentry's privacy policy at sentry.io/privacy.
C. Information you provide when contacting us. If you contact us at aditya@hushbook.app, we collect:
- your email address;
- the contents of your message and any attachments you choose to send;
- any information you include to help resolve your issue (for example, device details).
D. Website information. Our Website is a marketing site and we do not intentionally run analytics or tracking scripts. However, our hosting provider/CDN may automatically process basic server logs (e.g., IP address, user-agent, timestamp, and requested URL) for security, abuse prevention, and reliable delivery of the site.
E. App permissions. The App requests only the permissions needed for its features: access to audio files you choose to import (to play and transcribe your own files on your device); camera or photo access (only when you set a profile picture or create a shareable quote image); and notifications (to show playback and download/transcription progress). The App does not request microphone or location access.
2. How we use information
We use information only for the purposes below:
- to operate the App on your device (on-device data is used by the App locally);
- to maintain and improve reliability (crash and performance diagnostics);
- to respond to you (support emails and troubleshooting);
- to protect the Website and App (security, fraud/abuse prevention, and ensuring availability).
We do not sell personal data, and we do not use it for targeted advertising.
3. Legal basis / lawful use
Where the Digital Personal Data Protection Act, 2023 (the "DPDP Act") applies, we process personal data:
- for purposes for which you have consented (for example, when diagnostics are enabled by your device/App settings, or when you email us); and/or
- for legitimate uses permitted under applicable law (such as responding to requests, maintaining security, and preventing fraud), as applicable.
Where the EU/UK General Data Protection Regulation ("GDPR") applies, our legal bases under Article 6 are:
- Crash & performance diagnostics and server logs — our legitimate interests (Article 6(1)(f)) in app reliability, security, and abuse prevention. We have weighed these interests against your rights, and you may object at any time;
- Responding to your support emails — taking steps at your request and our legitimate interests in providing support (Article 6(1)(b)/(f));
- Any future paid in-app purchases or subscriptions — performance of a contract with you (Article 6(1)(b)).
4. Sharing and third parties
We may share limited information with the following categories of service providers solely to run and support HushBook:
- Crash/performance provider: Sentry, acting as our processor for diagnostics (described above).
- Platform providers: Apple App Store and Google Play. When you make a paid purchase, they act as independent controllers and process payment and purchase-related information under their own policies (Apple, Google). We do not receive your full payment-card details.
- Subscription management: RevenueCat processes purchase/receipt data and an anonymous app-user identifier on our behalf to manage your entitlements when you make a paid purchase (RevenueCat privacy).
- Model hosting: speech-recognition models are downloaded to your device from Hugging Face (huggingface.co) when you set up on-device transcription. That host receives standard request information (such as your IP address and the model file requested) under its own policy, and receives no HushBook account or app content.
We only engage service providers that are contractually bound to protect this data to a standard equivalent to this policy and to use it solely to provide their service to us. Some providers may process data outside your country, including outside the EEA/UK; where that happens we rely on appropriate safeguards (such as the provider's standard contractual clauses or equivalent transfer mechanism).
4.1 Public-domain catalogue (LibriVox & Internet Archive). If you choose to browse, search, view details, stream, or download titles from the App's public-domain catalogue, the App must connect to third-party services such as LibriVox and the Internet Archive (archive.org) to fetch search results, metadata, and files. These services act as independent controllers of any information they receive. When the App makes these requests, those third parties will receive certain information as part of standard internet communications, and they will process it under their own privacy policies and terms. HushBook does not control how those third parties use or retain that information.
What can be shared with archive.org:
- IP address;
- User-Agent header;
- search query text;
- applied filters;
- sort preference;
- pagination/page number;
- book identifier (sourceId).
What is not shared:
- no user account, email, or device ID;
- no authentication tokens;
- no app-internal analytics back to archive.org.
Requests to third-party providers are subject to their own terms and privacy policies, and we do not control how those third parties process data. HushBook does not add advertising identifiers or create a HushBook-side profile for these requests. However, because these requests go directly to third-party services, those services may be able to associate requests using network and device information (such as IP address and user-agent) in accordance with their own policies.
5. Data retention
- On-device App data: stored on your device until you delete it within the App or uninstall the App.
- Crash/performance diagnostics: retained for up to 90 days and then automatically deleted, unless a longer period is required to investigate a recurring issue or to comply with a legal obligation.
- Support emails: retained for up to 24 months after your request is resolved, unless a longer period is required to maintain reasonable support records or by law.
6. Your choices and rights
Depending on applicable law, you may have rights such as:
- access to personal data we hold about you;
- correction of inaccurate personal data;
- erasure of personal data;
- restriction of processing;
- data portability;
- objection to processing based on our legitimate interests;
- withdrawal of consent at any time, without affecting processing already carried out before withdrawal;
- grievance redressal.
To exercise any of these, email us at aditya@hushbook.app; we aim to respond within a reasonable time and in line with applicable law. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner's Office (ICO)).
7. How to delete your information
- App data: delete individual books, transcripts and quotes inside the App (where available), reset in-App data (if provided), or uninstall the App to remove locally stored data.
- Diagnostics: uninstalling the App stops future diagnostics from being sent. To request deletion of diagnostic data already received, email aditya@hushbook.app; we will action verified requests within a reasonable period.
- No account: HushBook has no user accounts, so there is no account to delete; removing the App and requesting deletion of diagnostics (above) clears the data associated with you.
8. Security & data breaches
We use reasonable technical and organizational measures, including encryption in transit, to protect the limited personal data we process. No method of transmission or storage is completely secure; however, if a breach affecting your personal data occurs, we will notify you and the relevant authorities where required by applicable law (including the DPDP Act and, where it applies, the GDPR).
9. Children
The App is not directed to children and is not intended for those below the applicable age of digital consent in their jurisdiction. We do not knowingly collect personal data from children without verifiable parental or guardian consent, and our diagnostics are not used to profile or target children. If you are a parent or guardian and believe a child has provided personal data to us, please contact aditya@hushbook.app and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above. Material changes may be communicated through the Website or App release notes where appropriate.
11. Grievance / Contact
For questions, requests, or complaints, contact us by email at aditya@hushbook.app.
Response timeline: we aim to acknowledge and respond within a reasonable time and in line with applicable law.
We process personal data only occasionally and on a small scale, and have concluded that we are not required to appoint an EU/UK Article 27 representative or a Data Protection Officer. If this changes, we will update this policy with the relevant details.