Privacy Policy
Last updated: 2 August 2026
In short
- We are Kurba Pty Ltd, an Australian company, and we make BookCloud — a reading app for children, used by their parents.
- Children can’t sign up. Only a parent or guardian creates an account and any child profiles.
- We collect the minimum we need: a parent’s email; and, per child, a nickname, an emoji avatar, an age band, language preferences, and reading activity.
- We use one analytics tool (PostHog), for two things. Detailed usage analytics are off by default and run only if you opt in. Error reports — which contain nothing that identifies you, your child or your device — are on by default and can be switched off at any time.
- No advertising, no ad trackers, no selling your data, no cross-app tracking.
- You can delete your account and all data at any time, from within the app.
- This page covers both our website (bookcloud.app) and the BookCloud app — see the two sections below.
Languages and authoritative version
This Privacy Policy is published in more than one language so you can read it in your own. The English version is the authoritative version. If there is any discrepancy between the English version and a translation, the English text prevails — except where the law of your country of residence requires the local-language version to govern.
Who we are
BookCloud is operated by Kurba Pty Ltd (ACN 697854569), registered in New South Wales, Australia, at 1/457-459 Elizabeth Street, Surry Hills NSW 2010, Australia. You can reach us any time at admin@bookcloud.app. See International users and our representatives below for how to contact us from the EU/EEA, UK, and Türkiye.
Data Protection Officer. We have appointed a Data Protection Officer (also acting as our Privacy Officer) as your point of contact for any privacy matter — including access, correction, withdrawing consent, or a complaint. You can reach them at admin@bookcloud.app.
What this policy covers
This policy explains how we handle information in two contexts:
- Section A — Our website (bookcloud.app): the public site.
- Section B — The BookCloud app: the reading app and the accounts within it.
Where a section applies to only one context, it says so.
Governing law
This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you live in another country we make BookCloud available in, that country’s data-protection law applies to you in addition. Additional protections apply to people in the EU/EEA and United Kingdom (GDPR / UK GDPR) and in Türkiye (KVKK). See Your rights below. If you are in the United States, the federal Children’s Online Privacy Protection Act (COPPA) applies to the personal information we collect through child profiles, alongside the privacy law of your state — see United States — children under 13 (COPPA) below.
Section A — When you use our website
You can read every page of bookcloud.app without giving us anything — there is no account and no signup wall.
Analytics (consent-based)
We use PostHog (hosted in the EU) to understand how the site is used. Our lawful basis is your consent: we ask with a banner on your first visit and store and capture nothing until you choose. If you accept, PostHog receives page URLs, click events, browser and device type, and your IP address (used only to derive an approximate country). If you decline, we count your visit anonymously with nothing stored on your device. You can withdraw consent at any time via the Cookie settings link in the footer of any page.
When you email us
The "Get in touch" buttons open your email app with a pre-filled message to admin@bookcloud.app. If you send it, we receive your email address, whatever you choose to write, and any signature your email app adds automatically.
We use that to reply and — if you have asked us to — to let you know when BookCloud is available to download. We don’t sell, share, or rent your email, and we don’t pass it to advertisers or data brokers. We keep your message until you ask us to remove it or we no longer need it.
Other services your browser contacts
To render the page, your browser fetches a few files from other services. Each can see your IP address and the standard details your browser sends with any request.
- Cloudflare — serves and protects the site. May set a small security cookie (
__cf_bm) to tell humans from bots. - Google Fonts — serves the typefaces.
- Tailwind CDN — serves the page styling.
- Iconify — serves a small number of icons.
Apart from PostHog (which sends us the consent-based usage data described above), we don’t receive analytics or reports from these services, and we don’t link anything they see back to you.
Section B — When you use the BookCloud app
Parent account data
To create an account we collect your email address and a password. If you set a Parent PIN to protect restricted settings, it is stored only as a one-way hash; it is never stored in plain text and cannot be retrieved by us.
Child profile data
Parents may create profiles for their children. For each profile we collect a display name (we recommend a nickname), an emoji avatar, an age band (a range, not a date of birth), language preferences, and parent-set content rules and reading preferences. Each profile is given a pseudonymous internal identifier linked to the parent account.
Reading activity
As a child reads, we record reading sessions (book identifier and title, theme, language, timestamps, time spent, last page reached, and reading mode), favourites, and earned achievements. We treat all of this as personal data linked to the child’s pseudonymous identifier.
Usage and analytics data (opt-in)
If you enable analytics (off by default; switchable at signup or in Settings, and revocable at any time), we use PostHog (hosted in the EU) to collect: autocaptured click and page-view events; custom in-app events (such as books viewed, reading progress, and achievements) linked to your account identifier — events during a child’s reading session carry the child’s age band only, with no identifier for the child; and technical metadata (the platform only — not your device model or screen size). Faults are reported separately and without personal data; see Error reporting below. We do not collect advertising identifiers (such as IDFA) and we do not use App Tracking Transparency, because we run no third-party advertising trackers and no cross-app or cross-site tracking.
Error reporting (always on, no personal data)
Separately from analytics, the app reports its own faults so we can find and fix them — including faults that stop it starting at all. This runs for everyone, including before you sign in and if you have declined analytics, because the people most likely to hit a serious fault are the ones we would otherwise never hear from. It is not analytics: it does not record what you read, when, or for how long. Reports go to PostHog, the provider described under Sharing and subprocessors below, and are hosted in the EU.
What an error report contains:
- The fault itself — its type, its message, and the place in our code it came from.
- Which part of the app failed, using our own internal labels (for example, that a book could not be read, or that a saved reading position was rejected).
- The app version, and whether it is running on iOS, Android or the web.
- Whether your device is currently able to save settings at all — a yes or no about the browser, not about you.
What an error report never contains. Your name, email address, account or child identifiers; your location, IP address or country; your device model or screen size; or anything you or your child has typed, read or chosen. It carries no identifier that outlives the moment it is sent, so two reports cannot be linked to each other, to an earlier session, or to you. It stores nothing on your device.
Your right to object. We rely on our legitimate interests in keeping the app working and secure (GDPR Article 6(1)(f)), not on your consent — so you may object at any time and we will stop. Turn off Error reporting from the profile menu, or in Parent Area → Privacy. It is reachable without an account, so you never need to sign in to switch it off.
Infrastructure logging
For security, abuse prevention, and routing content from the nearest server, our providers (Supabase, Cloudflare, PostHog) log your IP address and browser user-agent.
Transactional email
We use your email address to send essential messages (account confirmations, password resets, security notices, and policy updates) via Resend.
On-device storage
The app stores authentication tokens and preferences (such as theme and language) in your device’s local storage, solely for app functionality — never for advertising or cross-site tracking. Before you create an account, the app also stores anonymous reading activity on your device only, to preserve your experience; if you create an account it may be associated with your profile, otherwise it stays anonymous and on-device.
If you turn analytics on, it also stores a random identifier in your device’s local storage and in a cookie. It is ours alone, is not an advertising identifier, and is never shared or matched with any other site or app — its only job is to group that browser’s own events so a single visit does not look like several. It is not written unless you turn analytics on, and turning analytics off deletes it — the identifier that was linked to your activity is discarded, not just unused.
Error reporting stores nothing on your device at all; the only thing it writes is your choice, if you turn it off.
How we use your information
To provide the service and a personalised reading experience, to improve our products, and to keep the platform secure and stable.
AI transparency. Books on our platform include content that is AI-generated or AI-assisted (illustrations, narration, and age-appropriate text).
What we never do. We never sell, rent, or trade your data, use it for advertising or behavioural marketing, or track you across apps or websites.
Legal basis for processing (EU/EEA, UK, Türkiye)
| Data | Legal basis |
|---|---|
| Parent account data | Performance of a contract |
| Child profile and reading data | Parental consent, given by the parent at account creation as a precondition for creating any child profile |
| Usage and analytics data | Consent (opt-in; revocable) |
| Error reports and infrastructure logs | Legitimate interests (keeping the app working and secure). You may object at any time — see Error reporting. |
Children’s privacy
Children cannot create their own accounts; all child profiles are created and managed by a parent or legal guardian. At account creation, the parent or guardian must affirmatively confirm their guardianship and consent to the processing of child-profile data before any child profile can be created.
We minimise the data we collect about children, link reading activity to a pseudonymous identifier, and apply full protections to it. Child profiles contain no advertising, no social features, and no third-party trackers.
Parents may review, edit, or delete child profiles at any time in the app.
United States — children under 13 (COPPA)
If you are in the United States, the federal Children’s Online Privacy Protection Act (COPPA) applies to the personal information we collect through child profiles. BookCloud is operated by Kurba Pty Ltd (ACN 697854569) of 1/457-459 Elizabeth Street, Surry Hills NSW 2010, Australia, and you can reach us about anything in this section at admin@bookcloud.app. We collect a child’s personal information only after the parent or guardian who created the account has confirmed their guardianship and given consent, and we never ask for more than the reading experience needs.
- What we collect from a child. A nickname, which does not have to be a real name; an age band; an avatar chosen from a set we provide; the reading and content languages you pick; and the reading activity the child generates in the app — books opened, pages reached, favourites and achievements. Nothing else. A child cannot type free text, upload a photo, or make any information publicly available, and there are no social, messaging or sharing features.
- How we use it. Only to run the reading experience: to show your child’s library and reading level, to keep their place in a book, to record favourites and achievements, and to show you their reading activity in the Parent Area. We do not use it for advertising, profiling, or any form of behavioural targeting.
- Who receives it, and why. We do not sell children’s personal information, and we do not disclose it to anyone for their own purposes. Supabase (Japan) stores it as our database and authentication provider, and Cloudflare delivers the app and the books — each acting only on our instructions, under a data-processing agreement, solely so the service can run. If you switch analytics on, PostHog (EU) additionally receives events from a child’s reading session that carry only a coarse age band — no name, no nickname, no identifier for the child, and no advertising identifier — so a child cannot be identified from them.
- Consenting to collection without consenting to disclosure. You can consent to our collecting and using your child’s information without agreeing that it may be disclosed to anyone else: leave analytics off, which is the default. Nothing in the app is withheld from you or your child for doing so. Error reports reach PostHog whether analytics is on or off, but they contain no information about a child — no nickname, no age band, no identifier, and nothing your child has typed, read or chosen — so leaving analytics off still means no information about your child is disclosed to anyone.
- Reviewing, deleting, and stopping further collection. At any time you can review everything held on a child profile in the Parent Area; edit or delete the profile, which deletes its reading history, favourites and achievements with it; delete the whole account under Parent Area → Account → Danger zone → Delete account; and refuse any further collection by deleting the profile or the account, or by turning analytics off. If you would rather we did it for you, email admin@bookcloud.app — we will confirm that you are the account holder before we act, and we will not ask you for identity documents.
- How long we keep it. See Data retention above. We never keep a child’s personal information indefinitely: it is deleted when you delete the profile or the account, and automatically once the account has been dormant for 24 months.
We never make a child give us more personal information than is reasonably necessary to read a book, and no part of BookCloud is withheld from a child for providing less.
Error reporting and internal operations. The app’s error reports (see Error reporting above) are collected to maintain and analyse how the app functions, and contain no identifier for you or your child, no contact information, and nothing used for behavioural advertising. This is the support for internal operations exception in COPPA §312.5(c)(7), and it does not require verifiable parental consent.
Sharing and subprocessors
We do not sell or share your data. We use the following processors, which are bound by data-processing agreements and act only on our instructions:
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Authentication and database | Japan |
| PostHog | Product analytics and error reporting | EU |
| Cloudflare | Hosting and content delivery | Global edge (EU and AU presence) |
| Resend | Transactional email | United States |
We may disclose information where required by law, or in connection with a merger or sale provided the recipient honours this policy.
Cross-border transfers
We transfer data globally to run the service. Australia: we take reasonable steps under APP 8. EU/EEA and UK: we rely on Standard Contractual Clauses (and the UK Addendum) where no adequacy decision applies; Japan benefits from an EU adequacy decision. Türkiye: transfers are handled in accordance with KVKK Article 9.
Data retention
We keep personal information only for as long as it is needed for the purpose we collected it for, and we never keep a child’s personal information indefinitely. An account is dormant when, for 24 consecutive months, nobody has signed in to it and no child profile on it has started a book, added a favourite or earned an achievement. We automatically delete a dormant account and everything on it.
- Parent account — your email address, sign-in credentials, and the sign-in session records our authentication system keeps (including the IP address and the browser or device a session was created from). Kept so you can sign in, stay signed in, and so we can investigate suspicious access; needed for as long as you have an account. Deleted when you delete your account, or automatically once it has been dormant for 24 months.
- Child profiles — nickname, age band, avatar, languages, and the content and reading settings you choose. Kept so your child’s library, reading level and language settings are there next time; without them we cannot offer a personalised library. Deleted when you delete the profile or your account, or automatically after 24 months of dormancy.
- Reading history, favourites and achievements — kept so the Parent Area can show what your child has been reading and so earned achievements are not lost. Deleted with the child profile they belong to, and in any case after 24 months of dormancy.
- Parent PIN — stored only as a one-way hash, so we can check a PIN you type without being able to read it. Kept so the parent area stays locked; deleted with your account.
- Analytics (PostHog, EU) — only if you opt in, and never linked to a child. Kept so we can see which books and features are used. Our analytics provider stores them under our plan’s retention period; we delete an account’s analytics events when the account is deleted, and our analytics provider completes the purge on its own periodic schedule — or sooner if you ask us.
- Error reports (PostHog, EU) — on by default, and switchable off at any time. Kept so we can find and fix faults, including faults that stop the app starting. They carry no account identifier and nothing that links them to you, so they cannot be traced to an account — and for that same reason they are neither deleted with your account nor findable on request, because there is nothing in them to find. Our provider stores them under our plan’s retention period.
- Platform logs — sign-in and database activity recorded by our hosting provider for security, abuse prevention and debugging. Kept for a short period set by that provider, not by us.
- Backups — we keep no backup from which deleted data could be brought back. When data is deleted it is gone, and we cannot restore it.
Account and data deletion
You can delete your account in the app under Parent Area → Account → Danger zone → Delete account (this requires re-authentication and a typed email confirmation). If you no longer have the app installed, sign in at reader.bookcloud.app and follow the same path, or see https://bookcloud.app/delete-account.html. Deletion is irreversible and removes your account, all child profiles, reading history, favourites, and achievements from our database immediately — we keep no backup we could restore them from. We also delete the analytics events associated with your account, and our analytics provider completes the purge on its own periodic schedule. We also delete accounts automatically once they have been dormant for 24 months, as described under Data retention above. To have your analytics events deleted sooner, email admin@bookcloud.app. Error reports are not covered by this deletion, and cannot be: they carry no account identifier and nothing that links them to you, so there is no way to find yours — which is also why they contain nothing to delete.
Security
We use technical and organisational safeguards, including encryption in transit and at rest and hashing of credentials. No method of transmission or storage is 100% secure.
International users and our representatives
BookCloud is operated from Australia and is available in a number of other countries. Wherever you are, you can reach us at admin@bookcloud.app and we will handle your request under this policy. The BookCloud app is not yet generally available in the EU/EEA or the United Kingdom. Before we make the app available in those regions, we will appoint a representative under Article 27 of the EU GDPR and the UK GDPR and publish their name and address here. In the meantime, EU/EEA and UK residents may exercise the rights set out below and contact us directly at admin@bookcloud.app. For Türkiye, we process personal data in accordance with the KVKK.
Your rights
- Australia: you have the right to access and correct your personal information, and may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
- EU/EEA: you have the rights of access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent at any time. You may object to error reporting — which relies on legitimate interests rather than consent — from the profile menu, without an account. You may complain to your local supervisory authority.
- United Kingdom: you have the same rights under the UK GDPR and may complain to the ICO at ico.org.uk.
- Türkiye (KVKK Article 11): you have the right to learn whether your data is processed, request information and the third parties to whom data is transferred, and request correction or destruction. Complaints go to the Kişisel Verileri Koruma Kurumu.
- United States: COPPA gives parents the right to review and delete a child’s personal information and to refuse its further collection — see United States — children under 13 (COPPA) above. Many states also give residents rights of access, correction, deletion and portability, and a right to opt out of the sale of personal information and of targeted advertising; we do neither of those things. Whichever state you are in, email admin@bookcloud.app and we will action your request.
- Everyone: we extend these rights to everyone whose personal information we process, except where a right is not recognised where you live. You can access, update, or delete your data through account settings, and withdraw consent to analytics at any time in Settings; we will not discriminate against you for exercising your rights; and we respond to requests within 30 days.
Changes to this policy
We may update this policy. We will post the new version with a refreshed date and, for material changes, give an in-app notice and re-request consent where required. Prior versions are available on request.
Contact
Kurba Pty Ltd — admin@bookcloud.app — New South Wales, Australia.
Last updated: 2 August 2026