Privacy policy
Who operates Afsana
Afsana is operated by Faiz Iqbal. Questions and privacy requests can be sent to faiziqbal733@gmail.com.
Information kept only on your device
Without cloud backup, Afsana stores imported EPUB files, covers, reading position and history, bookmarks, highlights, notes, saved words, reader preferences, reading statistics, AI response caches, and book-chat history in app-private storage on your device. This information is removed when you delete it in Afsana or clear/uninstall the app, subject to Android device behavior.
Optional account information
If you sign in with Google, we receive the Google account identifier and may receive your name, email address, and profile image. We also keep device/session identifiers and session times so sign-in, token refresh, session revocation, and account security work. Afsana never receives your Google password.
AI features
When you request an explanation, simplification, summary, book insight, chat response, or chapter artwork, the text or derived scene description needed for that request is sent over encrypted HTTPS to the Afsana backend and then to OpenAI. Afsana requests that provider responses are not stored through the API's no-store setting. The Afsana server records a pseudonymous actor key, model name, time, and token counts for limits, cost control, and abuse prevention; it does not store the prompt or generated text in the AI-usage table. Responses may be cached locally on your device.
Optional private backup and sync
Cloud backup is off by default. If you enable it after signing in, Afsana uploads the EPUB files you choose to keep, book metadata, reading positions and sessions, bookmarks, highlights and notes, saved vocabulary, preferences, and progression data to the Afsana server. These records are tied to your account and are used only to provide backup and synchronization.
Other network services
- Google processes Google sign-in under Google's own privacy terms.
- OpenAI processes the content needed to answer an AI request.
- dictionaryapi.dev receives the word requested for an online dictionary lookup.
- Public-domain book hosts receive normal network information when Afsana downloads a book.
- Infrastructure providers process encrypted traffic and limited operational data needed to host the service.
These services may receive ordinary connection information such as IP address, time, and user agent. Their own policies govern their independent processing.
How information is used
We use information only to provide reading, sign-in, AI, backup, sync, account support, security, quota enforcement, troubleshooting, and service operation. We do not sell personal information, use it for behavioral advertising, or share it with data brokers.
Security and retention
Network traffic uses HTTPS. Account credentials are stored as rotating hashed tokens; private EPUB downloads require authentication. Server data is retained while your account exists or as needed to provide the requested service. Limited security and request logs are rotated. Disaster recovery backups are access-restricted and expire on a rolling schedule. No internet service can guarantee absolute security.
Your choices and deletion
- Use Afsana locally without creating an account.
- Keep backup disabled or turn it off at any time.
- Export account data from the signed-in account controls.
- Delete your cloud account in Afsana or use the external request process.
Successful account deletion removes account information, active sessions, synchronized reading records, and private EPUB backups from the live service. Recovery copies expire with the backup schedule and are not used except to restore the service after a disaster. Local books remain on your device unless you delete them separately.
Account deletion optionsChildren
Afsana is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided account information.
Changes to this policy
Material changes will be reflected on this page with a new effective date and, where appropriate, communicated in the app.