Apace.

Legal

Privacy Policy

Last updated: July 15, 2026

DRAFT — NOT YET REVIEWED.
Drafted copy, not yet reviewed by counsel.

Who we are

Apace is operated by AAB Inventions LLC, a limited liability company organized in New Jersey, USA. This policy covers both the Apace mobile app and the apace.ink website, and explains what we collect, why, and what choices you have. If you have questions or a request about your data, write to [email protected].

What we collect

Apace is an account-based product — reading together requires knowing who "together" is. Here is everything we collect, grouped plainly:

What we don't collect

Just as important as what we collect is what we deliberately don't:

How we use your information

We use what we collect to: run the app and keep everyone's reading in sync; power friends, invites, rooms, and chat; meter the free reading allowance so it works fairly; prevent abuse and keep the service secure; respond to copyright notices under our DMCA policy; and meet our legal obligations. We do not use your information for advertising, and we do not sell it to anyone.

Legal bases for processing (EEA / UK)

If you're in the EEA or UK, here's what lets us process your data under GDPR: performing our contract with you (running the core reading, social, and chat features you signed up for); our legitimate interests in keeping Apace secure, preventing abuse, and protecting the integrity of the free tier; and your consent, specifically for sending push notifications, which you can withdraw at any time by turning notifications off.

Who processes your data

We use a small set of service providers ("processors") to run Apace. None of them may use your data for their own advertising, and we do not sell or share your personal data with anyone for advertising purposes. We disclose data to others only when the law requires it, or as described in our Copyright & DMCA policy.

Where your data lives

Apace's infrastructure is based in the United States, and your data is processed and stored there. If you're accessing Apace from outside the US, your information will be transferred to the US to be processed as described in this policy. Where a transfer requires a legal safeguard — for example, from the EEA or UK — we rely on our processors' standard contractual clauses or an equivalent mechanism.

Retention & deletion

We keep your data for as long as your account exists. You can delete your account at any time, in the app: You tab → Account → Delete account (or see delete-account.html). Deletion is immediate and permanent — there's no 30-day grace window and no way for us to undo it.

Deleting your account erases: your profile, your uploaded books and their files, your reading positions and bookmarks, your room memberships and the rooms you hosted, your friend requests and friendships, your notifications, and your push token. Two things are kept, by design, rather than deleted:

If we've taken down a book you uploaded following a valid copyright notice, the record of that strike survives account deletion too. It contains no email address or other direct identifier — just the book's title, the reason for the strike, and the fact that it occurred, kept to enforce our repeat-infringer policy.

Your rights

If you're in the EEA, UK, or a jurisdiction with similar law, you have the right to access the personal data we hold about you, correct it, request its deletion, receive a copy of it in a portable format, restrict how we process it, and object to processing based on our legitimate interests. You can also lodge a complaint with your local data protection supervisory authority.

If you're a California resident (or in a US state with similar law), you have the right to know what personal information we collect about you, to request its deletion, and to request correction of inaccurate information. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, so there is no opt-out to exercise there. We will not discriminate against you for exercising any of these rights.

To exercise any of these rights: use the in-app controls where available (like account deletion), or email [email protected] and we'll take it from there.

Children

You must be at least 13 years old, or the minimum age required in your country to use a service like Apace without parental consent, whichever is higher. If we learn that an account belongs to someone under that age, we will delete it.

Security

We encrypt data in transit (TLS/HTTPS and secure WebSockets) and require an authentication token on every request. On your device, your sign-in token is stored in the iOS Keychain or Android Keystore, not in plain app storage. Our database enforces row-level security on every table, and our servers rate-limit connections to guard against abuse. The email hash described above is salted, so it can't practically be reversed to your address. No security measure is perfect, but we take these steps seriously.

Changes to this policy

If we make a material change to how we handle your data, we'll announce it in the app. The "Last updated" date at the top of this page always reflects the current version.

Contact

Privacy questions or data-rights requests: [email protected]. Everything else: [email protected].