Privacy Policy
Last updated: 1 September 2026
Logia is built to keep your data on your device. This policy explains exactly what is collected, what isn't, and who has access to what. If anything here is unclear, email ekaterina@logia.page.
Data that stays on your device
Your reading files live on your phone and are never uploaded to any server. They hold:
- Your vocabulary state (every word you've seen, tapped, or marked, and how well Logia thinks you know it)
- Your place in each book and the paragraphs you've seen
- Your CEFR self-declared level and quiz answers
- The list of books you have open
These files never leave your device. There are no Logia accounts and no Logia server that stores your reading data — there is nowhere for it to be uploaded to. Two things are separate from the files themselves: anything you deliberately choose to send us using one of the in-app forms, and the anonymous usage analytics — both described below. The analytics do record events such as a page turn (with the book and your position in it) and a quiz answer, but never anything that identifies you.
If your iPhone has iCloud Backup switched on, these files are included in your device's normal encrypted Apple backup, like any other app's data. That is what lets your vocabulary and progress return if you reinstall Logia or set up a new phone. The backup is between you and Apple; we have no access to it and no way to read it. If you delete the app and have no iCloud backup, this data is gone for good.
Downloading books
Books are not included in the app itself — the app downloads them as you open them, from our file storage on Cloudflare R2. This is plain file hosting: it holds the book files and nothing about you. There is no account, no login, and nothing identifying you is attached to the request.
As with any download from any website, Cloudflare's servers necessarily see the request itself — your device's IP address and which file it asked for — in order to send the file back, and may log it briefly for security and abuse prevention. We don't build reading profiles from it and we don't combine it with anything else. See Cloudflare's privacy policy.
Things you choose to send us
Logia has four in-app forms: send feedback, request a book or language, report a problem with a word, and join the e-ink device waitlist. Nothing is sent unless you fill one in and tap Send. When you do, we receive:
- What you wrote
- Your email address, only if you chose to enter one — it is required for the waitlist and optional everywhere else
- For a word report: the book, the word you tapped, its dictionary form, and which languages you were reading in. All of it is shown to you on the form before you send, so you always see exactly what is attached
- The app version, build, platform and locale, so we can reproduce the problem
We add the time we received it, the country the request came from, and a salted, one-way hash of your IP address, used only to stop the form being abused. Your raw IP address is never stored.
If you are offline, the form saves what you wrote on your device and delivers it when it next can — that is why it works on a plane or underground. Nothing is removed from your device until the server confirms it arrived.
Submissions travel over HTTPS to logia.page and are stored in a private Cloudflare R2 bucket that only the developer can read. They are not shared with, or processed by, any third-party form or mailing service, and they are never used for advertising or profiling. Stored submissions are deleted automatically after 24 months.
Waitlist addresses are used for exactly one thing: telling you when the e-ink reader is ready. To have a submission or a waitlist entry deleted sooner, email the address at the bottom of this page.
Anonymous usage analytics
To understand which features people use, Logia sends a small number of anonymous events to TelemetryDeck, a privacy-focused analytics provider based in Germany. These events include things like "a book was opened", "a page was turned" (with the book and the position in it), how many words were tapped on that page, quiz answers, and the time you spent in the app per session.
What is not sent:
- Your name, email, or any identifier that could be tied back to you — an email you type into a form is sent to us directly, never to the analytics provider
- Anything you read, type, or report. When you send a word report, analytics records only that a report happened and in which language — never the word, the book, or what you wrote
- Your IP address (TelemetryDeck does not store it)
- Advertising or marketing identifiers (no IDFA, no cookies)
TelemetryDeck assigns a one-way hashed identifier per app install so that repeat sessions from the same install can be counted as one user, but this identifier cannot be reversed into anything that identifies you. It is derived from Apple's per-vendor device identifier, hashed with a salt on your device before anything is sent — the identifier itself never leaves your phone. You can read TelemetryDeck's own privacy policy at telemetrydeck.com/privacy.
Technical context sent with every event
Alongside each event above, the analytics library attaches a standard set of technical details about the device and the app. We do not choose these individually and there is no way to switch them off short of turning analytics off entirely, so they are listed here in full:
- Device model, operating system version, processor architecture, screen size and scale, and screen orientation
- Your time zone, language, region and whether you use light or dark mode
- The Logia version and build number, and whether the app came from the App Store or TestFlight
- Counts describing how often the app has been used — the date of the first session, the number of sessions, and how many distinct days it has been opened
- System accessibility display settings: reduce motion, bold text, invert colours, darker system colours, reduce transparency, differentiate without colour, and your preferred text size
We want to be direct about that last line, because it is the one that could matter to you. These are display preferences, not health information, and Logia does not ask about or store anything about your health or abilities. But some of them are settings a person may turn on because of a disability, and you deserve to know they are sent rather than find out later. They are never linked to you, never used to build a profile, and never shared or sold. If you would rather none of it were sent, the switch below turns off analytics completely — including everything in this list.
How to turn analytics off
Open Settings → Help improve Logia in the app and switch it off. Analytics are on by default; the switch is a real kill switch, not a preference we consult later. Switching it off stops everything on the spot — events stop at the source and the analytics SDK is shut down immediately, so not even the session pings it sends on its own continue. Open the app again with the switch off and it is never started at all.
Subscriptions and payment
Logia's subscription is sold through Apple's In-App Purchase system. Apple handles the entire transaction: we never see or receive your card details, billing address, or Apple Account. Apple's own privacy policy governs the payment.
All Logia receives is the answer to a single yes/no question, checked on your device — does this device have an active subscription? That check decides whether the full library is unlocked. There is no purchase history, no receipt, and no subscriber list held by us. The anonymous analytics described above do record that a subscription started, lapsed or was restored, and which plan it was — never the price you paid, never a receipt, and never anything that identifies you. Apple provides us with aggregate, anonymous sales reports, which cannot identify individual buyers.
This website
This site collects nothing. There is no sign-up form, no newsletter, no analytics and no cookies — every page is static and the only thing your browser sends is the request for the page itself. The in-app forms described above are the only way anything reaches us, and they are in the app, not here.
Third parties
- Apple
- If you installed Logia via the App Store or TestFlight, Apple receives standard install and crash data on Logia's behalf. See apple.com/legal/privacy.
- TelemetryDeck
- Anonymous product analytics as described above. See telemetrydeck.com/privacy.
- Cloudflare
- Hosts this website, the book files the app downloads, and — in a separate private bucket — the in-app submissions described above. Cloudflare acts as our processor and does not use any of it for its own purposes. See Cloudflare's privacy policy.
- Project Gutenberg
- Some of the books in Logia are public-domain texts from Project Gutenberg and its German sibling projekt-gutenberg.org; others are original works written for Logia. Either way, these sources are never contacted by the app — every book is downloaded from our own file storage, as described above.
Children
Logia is rated 16+, and has no social features, no advertising and no profiling. We do not knowingly collect personal data from children: nothing is collected unless someone deliberately fills in one of the forms described above, and no form requires an email address except the e-ink waitlist.
Changes to this policy
If this policy changes in a material way, the "Last updated" date above will change. This page is the authoritative version; it is worth a look if you want to know what has changed since you last read it.
Contact
Questions or complaints about this policy: ekaterina@logia.page.