Privacy Policy — LibriLink for Calibre

Effective date: August 12, 2026 · Applies to: iOS, iPadOS, Android, and macOS

Short version: LibriLink for Calibre does not collect, store, or share any personal data. Your library, your credentials, and your books stay on your device. We operate no servers that receive your data.

1. What This Policy Covers

This Privacy Policy applies to the LibriLink for Calibre application (“the App”) available on the Apple App Store, the Mac App Store, and Google Play (“we”, “us”, or “our”). It describes how we handle information in connection with your use of the App.

2. Information We Do Not Collect

We do not collect, transmit, or store any of the following:

  • Personal identifiers (name, email address, phone number)
  • Location data
  • Device identifiers or advertising IDs
  • Usage analytics or crash reports
  • The contents of your ebook library or your reading history
  • Any data from the cloud accounts you connect

We have no analytics SDKs, no advertising networks, and no tracking frameworks of any kind.

3. Connecting Your Library

The App connects to a Calibre library that you already own, wherever you keep it. Depending on the source you choose, it may connect to:

  • Google DriveDropbox, and Microsoft OneDrive — via OAuth 2.0
  • iCloud Drive (iOS/iPadOS) and local device folders — via the operating system’s own file access
  • WebDAV servers and Calibre Content Servers — via a username and password you supply
  • OPDS catalogs, including Calibre-Web, Komga, and Kavita — via the catalog address and, where required, credentials you supply

Google Drive and Dropbox are the two services the App can also write to, and only through the “Send to Kobo” feature described in Section 8. That feature uses a separate, narrower permission and can only see the destination folder it creates — never the rest of your account.

For every one of these, the App:

  • Stores the resulting token or credential in your device’s secure storage (Apple Keychain on iOS, iPadOS, and macOS; Android Keystore)
  • Uses it solely to read your Calibre metadata.db catalog, fetch cover images, and download the ebook files you request
  • Communicates directly between your device and that service — never through a server of ours

Signing out within the App deletes the stored credentials from your device. You can also revoke access at any time from the service itself — for Google, at myaccount.google.com/permissions; for Dropbox and Microsoft, from their respective connected-apps settings.

4. Google User Data — Limited Use

LibriLink for Calibre’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. With your permission, the App requests the drive.readonly scope to read the Calibre library folder you select: the metadata.db catalog file, cover images, and the ebook files you choose to download. A Calibre library is a folder tree — a catalog file at the root plus a nested subfolder per book — so the App must be able to read across that folder. It reads nothing outside the folder you select, and it never modifies, uploads, or deletes anything through this scope.

The App also requests the narrower drive.file scope, used only by the “Send to Kobo” feature. That scope grants access solely to a destination folder the App creates itself, and is kept in a separate credential store from your library connection.

What we do with it. Library metadata, cover images, and downloaded books are stored only on your device, and are used only to display and open your own library inside the App.

What we never do. We do not transfer Google user data to any server we control, to any third party, or to any human for reading. We do not use it for advertising. We do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.

Deleting it. Signing out of Google Drive within the App removes the stored tokens and the associated library from your device. Downloaded books and reading progress are kept unless you delete them separately.

5. Our Infrastructure

We operate no application servers, no databases, and no logging or analytics backends. Your library data and credentials are never transmitted to us.

The one piece of web hosting involved in the App is a single static page at librilink-redirect.web.app. When you connect Google Drive, Google requires that the sign-in response return to a public web address rather than directly to an app. That page exists only to hand the response back to the App on your device. It runs no server-side code, stores nothing, and has no database. Your Google account access token is passed to it in the part of the web address that browsers never transmit to a server, so it never leaves your device.

6. In-App Purchases

The App offers one-time in-app purchases processed entirely by Apple (App Store, Mac App Store) or Google (Google Play). We do not receive, store, or process any payment information. Purchase receipts and entitlement verification are handled by the respective platform.

7. Project Gutenberg Content

The free ebook browser fetches public catalog data from the Gutendex API (gutendex.com). No personal data is sent in these requests — they are anonymous, unauthenticated queries for public-domain book metadata.

8. Downloaded Files

Books you download are saved to your device’s local storage. LibriLink has no built-in reader; when you open a book, the file is handed to the reader app of your choice. A downloaded book stays on your device unless you choose to send it: the “Send to Kobo” feature uploads a book you select to a folder in your own Google Drive or Dropbox, so your Kobo e-reader can pick it up. That upload happens only when you tap Send, and only for the book you chose. It uses a separate, narrower permission that can see only the folder it creates — never the rest of your account. Nothing is uploaded anywhere else, and nothing is ever sent to us.

9. Third-Party Services

The App interacts with the following services solely on your behalf, and only when you choose to connect them:

  • Google Drive API — to access your Calibre library files. Governed by Google’s Privacy Policy.
  • Dropbox API — to access your Calibre library files. Governed by Dropbox’s Privacy Policy.
  • Microsoft OneDrive API — to access your Calibre library files. Governed by Microsoft’s Privacy Statement.
  • WebDAV, Calibre Content Server, and OPDS catalogs — servers you specify and control. We have no relationship with them and receive nothing from them.
  • Gutendex API — to browse Project Gutenberg ebooks. No personal data is transmitted.
  • Apple App Store / Google Play — for in-app purchase processing.

10. Children’s Privacy

The App is not directed at children under 13. We do not knowingly collect any personal information from children. If you believe a child has provided personal information through the App, please contact us and we will promptly address the situation.

11. Data Retention & Deletion

Because we do not collect data, there is nothing to retain or delete on our end. Everything the App stores — OAuth tokens and credentials, downloaded books, cached cover images, reading status — is stored locally on your device. You can delete it at any time by:

  • Signing out within the App (clears the stored credentials for that provider)
  • Using the “Clear downloaded books” option in Settings
  • Uninstalling the App (removes all locally stored data)

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the App after any changes constitutes your acceptance of the updated policy.

13. Contact

If you have questions or concerns about this Privacy Policy, please contact us at support@sahollen.com.