Privacy and data processing
This page describes how FluentShelf handles account data, private books, device copies, optional AI requests, deletion, and backups. It states operational boundaries rather than legal or security certifications.
Data in the active service
While your account is active, FluentShelf can store account data, private EPUBs and covers, book metadata, reading positions, saved words, reader preferences, AI results, credit records, and operational records needed to provide and protect the service.
Your library, reading state, saved words, and AI results are scoped to your account; FluentShelf does not return another user's private resources.
Word practice stores schedules, answer history, daily streaks and your timezone in your account. A loaded study session and unsent answers are also stored in this browser for offline practice. They follow the same account isolation and device cleanup rules as reading data.
Private books and covers
Your EPUB and any extracted cover are stored in private application storage and delivered only through an authenticated request that checks ownership.
Data on this device
After you open a book online, this browser keeps an account-scoped EPUB copy so that book can open offline. An uncached book cannot open on this device without a connection.
Reading position can sync through the server across devices. While offline, the latest position stays on the device and is reconciled when a connection becomes available.
Private browser data uses one account namespace. On logout or account change, FluentShelf clears or makes the previous account's data inaccessible before another account can use the private application view.
AI assistance
AI assistance is optional: when you use it, selected text is sent to an external AI provider, and the resulting responses may be stored by FluentShelf and are scoped only to your account.
When you request a visual hint, FluentShelf sends the word and its translation through the configured FluentShelf relay to OpenRouter and the model provider. The book title and source sentence are not sent for image generation. One private encrypted image per word and meaning is retained for reuse; a successful regeneration replaces it. Study records and images are deleted with the account. Existing backups follow the backup boundary below.
Account deletion
When you confirm account deletion with your password, account access ends immediately and relational private records are deleted in the same transaction that records durable private-object cleanup work.
Reachable private EPUB and cover objects on active servers are normally erased within 24 hours. An incomplete erasure at 24 hours triggers an operational alert; this target does not mean every failure is already resolved.
The initiating device clears or durably schedules cleanup of its account-bound browser data before private UI is unblocked. Another device clears that account's local data when it reconnects and discovers the account is invalid. A device that never reconnects cannot be remotely wiped.
Backup boundary
FluentShelf does not use an older backup as routine recovery for an individually deleted account. An approved disaster-recovery restore must reconcile later account erasures and AI cleanup before restored data may serve traffic. FluentShelf does not promise immediate removal from existing backups or a fixed backup expiry deadline.
EPUB files
FluentShelf supports DRM-free EPUB files up to 95 MiB. Malformed, unsafe, or remote-dependent files may be rejected or look incomplete; books opened online are kept on this device for offline reading.
Contact
Use this monitored public inbox for support, privacy, or security questions. No response-time SLA is currently published.
Updates to this page
The effective date changes only with an approved material update to this Privacy section, together with review of both translations, traceability, and whether the AI disclosure version must change.