Weaver privacy policy

Effective September 30, 2026.

Weaver is developed and operated by RENATO MORAES PINHEIRO LTDA (trading as Glossa Apps). For privacy, account deletion, or support inquiries, contact lmreader.dev@gmail.com.

Data we process

Weaver processes its account UUID and app-generated device identifiers, sign-in identifiers supplied by Google or Apple when available, and optional email, email-verification status, and display-name information. Weaver session refresh tokens are stored as one-way hashes. When Apple sign-in authorization-code exchange is used, Weaver can retain Apple's refresh token to revoke sign-in access when the account is deleted.

When you use online reading assistance, the app sends your selected word, phrase, or passage and bounded nearby context, which can include a recap window or prior-mention excerpts. It also sends relevant book metadata (such as title, author, format, language, and identifiers), reading location or heading, dictionary-sense evidence, and answer or language preferences. The server processes these requests, generated answers, derived dictionary or image results, subscription status and purchase history, and limited technical and usage information.

Imported EPUB and PDF files, local reading progress, bookmarks, and highlights stay on your device. Weaver does not upload entire publication files. Book registration sends metadata, not the publication file.

To choose a dictionary language when metadata is insufficient, the app may send up to five book-text samples of up to 3,000 characters each after its excerpt-sharing disclosure. Weaver processes these samples with a packaged language detector on its backend. This endpoint does not persist or log the samples or send them to an external inference provider.

Why we process it

We use this data to authenticate accounts, answer reading questions, stream and reconnect answers, enforce entitlements and abuse limits, support purchases, secure the service, and diagnose reliability. We do not sell personal data or use book text for advertising.

App-to-service connections use HTTPS and account data is access-controlled. Operational logs use identifiers, timing, sizes, status, and bounded error categories rather than reading excerpts, prompts, or generated answers. Limited network and request metadata is processed to operate and protect the service.

Safety and content reports

Weaver bounds generated answers before they are stored or shown. External safety evaluation is currently disabled. When enabled, it can send the complete candidate to a separately configured content-safety evaluator; blocked or unavailable candidates are not stored or streamed and safety processing can delay or prevent an answer.

An authenticated owner may report a visible answer or stored image. A report contains a reason, an optional comment of up to 500 Unicode characters, and an opaque client report id; an image report also contains the exact image id. The service stores at most 8,000 characters of answer evidence, or image metadata (id, title, license, dimensions), for review. The report form has no dedicated fields for a new reading selection, recap window, book body, bitmap, URL, or prompt. Your optional comment is stored and can contain the text you choose to submit. Report records are retained for up to 90 days, with removal on the next operational purge after that period. Backup handling is described below.

Processors and transfers

Apple and Google process sign-in and store purchases when available. RevenueCat processes purchase history, transaction identifiers, subscription status, and technical app and device information to verify purchases and access. Its App User ID is the Weaver account UUID. Weaver keeps a subscription-status mirror; reading excerpts are not sent to RevenueCat.

Weaver's backend is hosted on Hetzner infrastructure. Reading assistance uses its private inference service or the external fallback described here. When the private inference service is unavailable, Weaver may send reading context, dictionary-term selections, or bounded book metadata and source excerpts used for enrichment to the Inkling Small model through an OpenRouter-selected inference provider. Fallback requests require zero-data-retention endpoints and exclude providers that collect prompt or response data using OpenRouter's routing controls. OpenRouter and the selected provider process requests under their data-handling policies, including any retained request metadata. The independent image path is not routed through this fallback.

Optional book enrichment is currently enabled. When enabled, it can query Open Library using book titles, authors, and identifiers. Google Books is used only when its API key is configured; a configured SearXNG search service can query its search providers using bounded book-search terms. Bounded public source excerpts and book metadata may then be used by the inference services described above.

Optional image search is currently enabled. When enabled, a separate private inference path derives a short visual-search query from reading context. Only that query is sent to Openverse; the selected passage and account ID are not sent to Openverse. It supplies allow-listed public-domain or CC0 image metadata; Weaver checks access and proxies thumbnails from image sources. Provider URLs and image bytes are not included in reports. These services may process data in countries other than yours under their respective data-handling policies.

Retention and deletion

For completed reading-assistance tasks, request context is purged after 7 days. Generated answer text and derived image/dictionary payloads are purged after 7 days. Both retention periods are measured from when the reading-assistance task finishes. The purge runs periodically, so removal occurs on the next purge after the retention period. Report retention is separate from answer retention. Limited account-linked task and usage metadata, authentication state, and subscription rows remain while the account exists; content-free records of processed billing events and completed reconciliation jobs follow a separate 90-day purge policy. Operational and security records can outlast the content payloads.

Account deletion removes the live account, sign-in identities, book registrations, reading data, usage and subscription rows, and reports with their comments and bounded evidence. Shared public book metadata remains while another account references it. Deidentified content fingerprints and quarantine state can remain to prevent blocked generated content from being published again.

Restricted recovery backups may still contain deleted data. Account deletion does not rewrite existing backups; those copies remain until rotated or removed and are kept for disaster recovery. Server-account deletion does not erase publication files or reading state on your device. Account deletion does not cancel a subscription through Apple or Google Play; cancel it with the store before deleting your account.

Use Account deletion to delete an account or request help. Questions can be sent to lmreader.dev@gmail.com.

Changes

Material changes will be posted here with a new effective date.