Privacy Policy — LibriLink for Calibre

Effective date: September 28, 2026 · Applies to: iOS, iPadOS, Android, and macOS

LibriLink for Calibre connects your device to libraries and services you choose. We do not operate an application backend that receives your library or account credentials. The app stores data on your device and communicates directly with the providers you use. Optional sharing, uploads, support messages, and web hosting are described below.

1. What this policy covers

This policy describes information handled by LibriLink for Calibre (the “app”). LibriLink does not require a separate LibriLink account. Websites, cloud providers, stores, email services, and reader apps have their own privacy practices.

2. Libraries and information on your device

The app stores library settings, downloaded catalog metadata, cover images, downloaded books, reading status, shelves, saved views, and preferences on your device. The random-book feature selects a book from the current library or available results; it does not send your selection to us or use a remote recommendation service.

You can connect local folders, Google Drive, Dropbox, Microsoft OneDrive (including shared folders you can access), WebDAV, Calibre Content Server, and supported OPDS catalogs. The app reads catalog information, covers, and books as needed for the features you use. Local-folder access uses the permissions you grant through the operating system.

3. Authorization and saved credentials

Google Drive, Dropbox, and OneDrive use provider authorization. WebDAV, Calibre Content Server, and some OPDS catalogs use the server address and credentials you provide. Production versions store saved credentials through the operating system’s secure storage, including Apple Keychain on Apple platforms and platform-protected storage on Android.

Credentials are sent to the relevant provider or configured server when needed to authorize requests. They are not sent to an application backend operated by us. OAuth sign-in uses your system browser, your system authentication session, or, for Google Drive libraries on Android, Google Play services. Signing out of LibriLink does not necessarily sign you out of that browser, your device’s Google account, or the provider’s website.

Use HTTPS server addresses where possible. If you choose an HTTP server connection after the app’s warning, that connection does not provide HTTPS transport encryption.

4. Google user data and Limited Use

LibriLink for Calibre’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

For Calibre library access, the app requests drive.readonly. Google’s permission allows read-only access to Drive files available to your account. LibriLink uses this access for the library folder you select or connect, including its catalog, nested book folders, covers, and ebook files. Selecting a folder limits the app’s intended use; it does not narrow the OAuth permission itself to that folder. Library access does not modify, upload, or delete Google Drive library files.

The optional Google Drive Send to Kobo feature uses separate authorization and separately stored tokens with drive.file. This permission covers files created by the app or explicitly opened or selected for use with it. The app can create a destination folder or let you select a destination through Google Picker. This is not whole-Drive access, but neither is it a write-only permission. The library connection’s read-only token is not used to upload books.

Google data is used to provide the library and transfer features you request. We do not sell it, use it for advertising, or use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. Books can be transferred to another service or reader when you explicitly choose a sending or sharing feature, as described below.

Google user data at a glance

What the app accesses With drive.readonly: the names of folders in My Drive, Shared with me, and shared drives while you browse for your library; then the selected library folder’s Calibre catalog (metadata.db), cover images, and the ebook files you download. With drive.file (optional Send to Kobo): the destination folder the app creates or you pick, and the book files you send. The app also saves which Google account you chose, so it can renew access.
How it is used Only to show your library, download the books you ask for, and upload the books you choose to send to your Kobo. Never for advertising, profiling, or sale, and never to train AI or machine-learning models.
Where it is stored On your device. Access tokens and the chosen account are kept in the operating system’s secure storage: Apple Keychain on Apple platforms, and encrypted storage protected by the Android Keystore on Android. Catalog data, cover images, and downloaded books are kept in the app’s private storage. Books you send to Kobo are stored in your own Google Drive.
How it is protected Every request to Google uses HTTPS and goes directly between your device and Google. No LibriLink server receives your Google data or tokens. The library authorization is read-only and cannot change or delete Drive files.
Who it is shared with No one, unless you explicitly send, open, or share a book, as described in section 7. We never receive it.
How long it is kept Access tokens: until you sign out, disconnect Send to Kobo, choose to delete the saved sign-in when removing an account’s last library, or uninstall. Catalog copies and cover images can remain in the app’s storage after a library is removed, so re-adding the same folder restores it; clearing the app’s storage or uninstalling removes them. Downloaded books: until you delete them.
How to delete it or revoke access Settings → Sign Out of Accounts; Send to Kobo → Disconnect; delete downloads in the app; clear the app’s storage or uninstall. To revoke Google’s grant itself, remove LibriLink for Calibre at myaccount.google.com/connections.

5. Google sign-in and web hosting

Version 1.6.8 and later. Google Drive sign-in happens on your device. On Android, library sign-in uses Google Play services and Send to Kobo signs in through your browser; on iOS, iPadOS, and macOS, both use the system authentication session. You choose the library folder in the app’s own folder browser. Choosing an existing Send to Kobo folder opens Google’s folder picker, which Google provides. These versions do not use web pages hosted by us. After updating from an earlier version, the app asks you to reconnect Google Drive once; your library, downloads, shelves, reading progress, and saved views are kept.

Versions 1.6.2 through 1.6.7. Google Drive setup uses static pages hosted on Google Firebase Hosting at librilink-redirect.web.app. One page forwards the sign-in response to the app; another displays Google’s folder picker. The pages do not provide a library database or a server-side token-exchange service. These pages stay online for installed copies of those versions.

In that flow, authorization response parameters and the Picker access token are passed to these pages in URL fragments, which browsers do not send in HTTP requests to the hosting server. The app exchanges the authorization code directly with Google. The older sign-in redirect remains supported for compatibility; older app versions may send response parameters in a request URL instead.

Loading hosted pages and contacting online services still involves ordinary network information, such as an IP address and request metadata. Hosting and service providers may process this information to deliver and protect their services. The fragment-based flow does not mean that no web requests or hosting logs exist.

6. Optional reading-status synchronization

Reading status is stored locally. If you enable reading-data synchronization for a Calibre Content Server library and choose the existing custom columns to use, the app can read and write the mapped reading status and optional date-read information on that server. Automatic synchronization can perform those updates after you enable it. Cloud-folder metadata.db files remain read-only; this feature does not request Google Drive write access.

7. Sending, opening, and sharing books

  • Send to Kobo: after you configure a destination and choose to send a book, the app uploads the selected file directly to your Google Drive or Dropbox destination. Your cloud provider and connected Kobo service/device then handle the file. Kobo authorization is separate from library authorization. Dropbox permission boundaries depend on its provider configuration; we do not describe them as identical to Google’s per-file scope.
  • Send to Kindle: the app passes the selected book, its filename or title, and your saved Kindle address to your device’s email composer. You choose whether to send the message. If sent, your email provider and Amazon process it. LibriLink does not ask for your email account password or send the message through our servers. An available system sharing option may also be used.
  • Open, share, or export: when you choose another reader, app, recipient, or folder, the selected file is made available to that destination. Files exported to shared or cloud-synced folders may be accessible to other apps or synchronized by that service.

8. Public catalogs and other services

Project Gutenberg browsing uses Gutendex and book-hosting services. OPDS browsing contacts the catalog you choose. Requests can include search terms, filters, book identifiers, and normal network information such as your IP address. These requests are not anonymous to the receiving service merely because no sign-in is required.

Relevant third-party policies include Google, Dropbox, and Microsoft. Your chosen server, email provider, Amazon, Kobo, reader app, Apple, and Google Play govern the data they receive under their own terms and privacy policies.

9. Purchases

Apple or Google Play processes purchases. LibriLink uses store purchase and entitlement information to enable purchased features and restore access. We do not receive your payment-card details. Purchase records held by the store remain subject to the store’s own retention and account controls.

10. Diagnostics and support

The app keeps bounded diagnostic logs on your device to help investigate problems. Logs can include app and operating-system versions, device model information, actions, error details, and book or library references. The app redacts common credential, address, URL, and path patterns, but redaction is not a guarantee that every personal detail is removed.

Logs are not automatically uploaded to us. “Share Debug Log” opens the system share sheet so you can choose a recipient or destination. Review the contents before sharing. If you email support or send us a log, we receive your message, email address, and the information you choose to include. We use that information to respond and investigate the issue. You can request deletion of support information by contacting us; information may need to be retained where required by law or to resolve an outstanding matter.

We do not use advertising networks or automatic usage-analytics or crash-reporting services in the app.

11. Sign-out, removal, and retention

  • Signing out of a library provider removes its saved library sign-in and associated library entries. Downloaded books and reading progress are retained unless you delete them separately. Optional Kobo connections have separate account controls.
  • Removing one library is different from signing out of the provider. If it is the last library for that provider, the app offers a choice about removing the saved sign-in.
  • In-app sign-out removes local credentials; it does not revoke the provider-side OAuth grant. To revoke that grant, use your provider’s connected-app or account-permissions settings. For password-based servers, use the server’s account and password controls.
  • Catalog copies and cover images for a removed library can stay in the app’s storage, so re-adding the same folder restores it. Clearing the app’s storage or uninstalling removes them.
  • Use the app’s download-management controls to remove downloaded books. Local diagnostic logs rotate automatically. Copies you exported, shared, emailed, or uploaded must be managed at their destinations.
  • Uninstalling removes app data according to the operating system’s rules. Do not rely on uninstalling to revoke cloud access or erase exported files, provider copies, backups, or credentials that the operating system may retain. Sign out and use provider controls when your intention is to remove access.

There is no separate LibriLink account or library database on our servers to delete. This does not include support correspondence you voluntarily sent to us or information held by your chosen third-party services.

12. Children and policy changes

The app is not directed at children under 13. We do not knowingly solicit personal information from children. Contact us if you believe a child has sent us personal information so we can address it.

We will update the effective date when this policy changes. Material changes to data handling will be reflected in the app’s disclosures or other notices as appropriate.

13. Contact

For privacy questions or requests concerning support information you sent to us, email support@sahollen.com.