Legal
Privacy Policy
Last updated: July 15, 2026
Drafted copy, not yet reviewed by counsel.
Who we are
Apace is operated by AAB Inventions LLC, a limited liability company organized in New Jersey, USA. This policy covers both the Apace mobile app and the apace.ink website, and explains what we collect, why, and what choices you have. If you have questions or a request about your data, write to [email protected].
What we collect
Apace is an account-based product — reading together requires knowing who "together" is. Here is everything we collect, grouped plainly:
- Your account: email address, display name, @username, an avatar color, your chosen reading theme, and your plan (free or, in future, a paid tier).
- Your reading: your position in each book, your bookmarks, and how much shared reading time you've used against the free allowance.
- Friends & sessions: friend requests and friendships, which reading rooms you're a member of, invitations you send or receive, and the notifications that come from all of the above.
- Messages: the text of chat messages you send, and an optional "here's where I am in the book" position stamp you can attach to one. Typing indicators are shown live to the people you're chatting with but are never stored.
- Books you upload: the file itself, the text we extract from it so it can be read word-by-word, and a cover image. An uploaded book is private — visible only to you and the people you invite into a room to read it with you.
- Notifications: if you turn on push notifications, a device push token so we can deliver them.
- Technical: your IP address, used transiently in memory to cap how many connections one address can open (abuse prevention) — it is never written to our database.
What we don't collect
Just as important as what we collect is what we deliberately don't:
- No advertising, and no advertising identifiers.
- No analytics or tracking SDKs, and no crash-reporting SDKs.
- No tracking you across other apps or websites.
- No sale of your personal data, ever.
- No location data.
- No access to your contacts.
- No access to your camera or microphone.
- No cookies on apace.ink.
How we use your information
We use what we collect to: run the app and keep everyone's reading in sync; power friends, invites, rooms, and chat; meter the free reading allowance so it works fairly; prevent abuse and keep the service secure; respond to copyright notices under our DMCA policy; and meet our legal obligations. We do not use your information for advertising, and we do not sell it to anyone.
Legal bases for processing (EEA / UK)
If you're in the EEA or UK, here's what lets us process your data under GDPR: performing our contract with you (running the core reading, social, and chat features you signed up for); our legitimate interests in keeping Apace secure, preventing abuse, and protecting the integrity of the free tier; and your consent, specifically for sending push notifications, which you can withdraw at any time by turning notifications off.
Who processes your data
We use a small set of service providers ("processors") to run Apace. None of them may use your data for their own advertising, and we do not sell or share your personal data with anyone for advertising purposes. We disclose data to others only when the law requires it, or as described in our Copyright & DMCA policy.
- Supabase — handles sign-in (email codes and Sign in with Apple) and hosts our production database.
- Cloudflare — stores the books you upload (as private objects) and serves the apace.ink website.
- Fly.io — hosts the Apace backend server.
- Expo — delivers push notifications to your device, if you've turned them on.
- Resend — sends the sign-in code emails, on Supabase's behalf.
- Apple — only if you choose to sign in with Apple, to verify your identity.
Where your data lives
Apace's infrastructure is based in the United States, and your data is processed and stored there. If you're accessing Apace from outside the US, your information will be transferred to the US to be processed as described in this policy. Where a transfer requires a legal safeguard — for example, from the EEA or UK — we rely on our processors' standard contractual clauses or an equivalent mechanism.
Retention & deletion
We keep your data for as long as your account exists. You can delete your account at any time, in the app: You tab → Account → Delete account (or see delete-account.html). Deletion is immediate and permanent — there's no 30-day grace window and no way for us to undo it.
Deleting your account erases: your profile, your uploaded books and their files, your reading positions and bookmarks, your room memberships and the rooms you hosted, your friend requests and friendships, your notifications, and your push token. Two things are kept, by design, rather than deleted:
- Chat messages you sent are not removed, so the conversation stays intact for the friends you were talking to — your name is replaced with "Deleted user" and the message can no longer be tied back to your account.
- We keep a cryptographic hash of your email address — not the email itself, and not reversible back to it — together with your lifetime free-allowance usage. This exists solely so that deleting and re-creating an account with the same email can't be used to reset the free reading pool.
If we've taken down a book you uploaded following a valid copyright notice, the record of that strike survives account deletion too. It contains no email address or other direct identifier — just the book's title, the reason for the strike, and the fact that it occurred, kept to enforce our repeat-infringer policy.
Your rights
If you're in the EEA, UK, or a jurisdiction with similar law, you have the right to access the personal data we hold about you, correct it, request its deletion, receive a copy of it in a portable format, restrict how we process it, and object to processing based on our legitimate interests. You can also lodge a complaint with your local data protection supervisory authority.
If you're a California resident (or in a US state with similar law), you have the right to know what personal information we collect about you, to request its deletion, and to request correction of inaccurate information. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, so there is no opt-out to exercise there. We will not discriminate against you for exercising any of these rights.
To exercise any of these rights: use the in-app controls where available (like account deletion), or email [email protected] and we'll take it from there.
Children
You must be at least 13 years old, or the minimum age required in your country to use a service like Apace without parental consent, whichever is higher. If we learn that an account belongs to someone under that age, we will delete it.
Security
We encrypt data in transit (TLS/HTTPS and secure WebSockets) and require an authentication token on every request. On your device, your sign-in token is stored in the iOS Keychain or Android Keystore, not in plain app storage. Our database enforces row-level security on every table, and our servers rate-limit connections to guard against abuse. The email hash described above is salted, so it can't practically be reversed to your address. No security measure is perfect, but we take these steps seriously.
Changes to this policy
If we make a material change to how we handle your data, we'll announce it in the app. The "Last updated" date at the top of this page always reflects the current version.
Contact
Privacy questions or data-rights requests: [email protected]. Everything else: [email protected].