Privacy policy

Last updated 2026-10-11

A small amount of data, with clear purposes.

Who is responsible

Posterity Finance Ltd is responsible for personal data processed to provide Commonplace. For privacy requests, contact commonplace.support@icloud.com. This policy covers the app, narration requests, membership, support, and the public support/legal website. It describes the current implementation; the draft must be checked against the actual hosting and billing configuration before commercial release.

Company number 14743318; registered in England and Wales. Registered office: 19 Thornhope Close, Washington, NE38 8DU, United Kingdom.

What stays on your device

Your notes, saved passages, reading and listening progress, bookmarks, theme, font size, and onboarding preference are saved locally. We do not upload your notebook or library progress record to Commonplace, RevenueCat, or Google Gemini. Requesting narration does send the current work and text position to our narration service so it can resume, as explained below. The web version uses browser storage for these essential features; the mobile version uses local app storage. Device or browser backup features may copy local data according to your Apple, Google, or browser settings.

There is no advertising, advertising identifier collection, cross-app tracking, sale of personal data, or separate reading/listening analytics service in the current app. RevenueCat provides purchase, subscription and membership paywall statistics for the publisher to operate and assess the membership. These reports are not shown to readers.

Optional accounts

Commonplace uses Google Firebase Authentication for email and password accounts, verification and password reset. Firebase receives your email, password, account identifier and sign-in security information. You can explore without an account. Sign-in connects membership; your notebook stays local, with separate reading data for guests and each account.

Native session tokens use protected Keychain or Keystore storage; web sessions use browser storage. Signing out removes the session on this device while retaining its reading data for your next sign-in. Firebase Authentication processes account data in US data centres. Google documents security IP logs lasting a few weeks and removal of other authentication data from live and backup systems within 180 days of user deletion. Applicable processor and transfer arrangements require review before release.

Membership & billing includes Delete account. Your password and final confirmation are required. The service deletes the Firebase sign-in and requests RevenueCat profile removal; provider processing can take time. Local account reading data is erased on this device. Remove other-device data, exports and backups separately. Store subscriptions require separate cancellation. Account deletion is temporarily unavailable in this local preview; contact commonplace.support@icloud.com for help.

Public support and legal website

Our public support and legal website is hosted with OpenAI Sites, using Cloudflare infrastructure. Visiting a page exposes your IP address, requested URL, browser information and request time to the hosting infrastructure for delivery, operation and security. These static pages do not request your reading data, contain sign-in forms, or include a Commonplace analytics or advertising script. The hosting providers process technical information under their applicable privacy policies and service terms; the publisher must confirm relevant retention and transfer arrangements before commercial launch.

Narration and audiobook streaming

When you request AI narration, the configured service receives the work identifier, reading section and passage, the saved word position when resuming, voice and model choice, and, for membership checks, a RevenueCat reader identifier and Firebase sign-in token. The service verifies paid access using your Firebase identity; it does not send that token to the speech-generation provider. Your connection exposes an IP address and standard request information to the server and any hosting provider. The service uses the app's source text rather than your own notes or a recording of your voice.

The narration server sends the public-domain book passage and chosen voice/style to Google Gemini to generate speech. It does not forward your notes, RevenueCat reader identifier, or device IP address to Google. Google receives our server connection and account/API information and processes requests under the Gemini API terms and applicable privacy terms. We make stateless synthesis requests without a conversational history; this does not promise zero provider retention. Google's paid-service terms describe limited abuse-prevention retention and no use of prompts/responses to improve its products. Production must use paid API services for UK users. Generated audio is cached by exact text, model, voice and output settings so readers share the prepared recording. The included server does not keep a database of individual listening habits. Fish Audio remains an optional development adapter and is only used when explicitly configured; it is not an automatic fallback.

Human recordings stream from Internet Archive, which receives your IP address and standard stream-request information. Links to source websites, store support, and Send to Kindle open external services whose privacy policies apply. The app does not access your microphone, contacts, camera, precise location, or photo library.

Opening an Amazon book search shares the public title, author and edition search terms with Amazon, along with ordinary connection information. The link contains no Commonplace reader identifier or notebook data. The app does not embed Amazon advertising or affiliate tracking software. The retailer’s privacy and account settings apply after you open it.

Subscriptions

When billing is enabled, RevenueCat and Apple or Google process transactions, purchase history, subscription status, expiry, product identifiers, a randomly generated guest identifier or, when you sign in, your Firebase account identifier, and relevant app/store technical information to validate and restore membership. RevenueCat also receives a fixed identifier for our native membership paywall, its offering context and SDK event information when that paywall is displayed, to report membership performance. We do not attach a work identifier, reading position, notebook content, name or email to paywall reporting. Payment-card details are handled by the store; Commonplace does not receive them.

When you sign in, RevenueCat membership is associated with your Firebase account identifier. We do not send your name or email as RevenueCat subscriber attributes. Because that identifier relates to an email account, associated membership information is linked to your account. Support emails can identify you. We do not use store purchase history for advertising or tracking across other companies’ apps.

Crash reporting

Where enabled in the native app, Google Firebase Crashlytics receives installation identifiers, technical app and device information, crash traces and fixed error codes to help us diagnose failures. Commonplace does not attach your account ID, email, notebook content, book choices, passwords, tokens or arbitrary server error messages to handled diagnostic reports. We do not use these reports for advertising. Google documents retention of crash traces and associated identifiers for 90 days before starting removal from live and backup systems.

Crash reporting is separate from membership analytics. Browser previews do not send Crashlytics reports. See Google’s Firebase privacy information at https://firebase.google.com/support/privacy.

Support

If you email commonplace.support@icloud.com, we receive your address, message, and any attachments you choose to send. The support inbox uses Apple iCloud Mail. Share only what is needed to investigate your request; never send a password, full payment-card number, or store sign-in code. We use support information to answer you, resolve problems, and handle legal requests.

Why we process data

Where UK data-protection law applies, we process account sign-in, membership and requested narration information to perform our service contract. We rely on legitimate interests for proportionate security, fraud prevention, support, and aggregate subscription operations, balancing those interests against your rights. Legal obligations may require transaction or complaint records. If a future optional feature needs consent, we will request it separately; refusing will not disable unrelated features.

Recipients and international processing

Recipients include Google Firebase Authentication for accounts and verification/reset emails, the configured narration host, Google Gemini for speech generation, RevenueCat, the relevant app store, Internet Archive when streaming a recording, Apple for support email, and OpenAI Sites with Cloudflare infrastructure for the public website. We do not disclose your notes to them. Firebase Authentication processes account data in the United States; other providers may also process data outside the UK. Before a commercial launch, the publisher must establish applicable processor agreements and lawful transfer safeguards, such as an applicable adequacy arrangement or approved contractual safeguards. This draft does not claim those agreements are already signed.

Retention and security

Local reading data stays until you remove it, clear app/browser storage, or uninstall the app, subject to platform backups. The included narration service does not persist reader identifiers or a listening-history table. Audio caches contain public book passages and can be removed without deleting a reader account. Production network-log retention must be set and disclosed before launch.

We retain support information only as needed for the enquiry and applicable legal obligations, with a documented review schedule required before launch. Purchase and store records may be retained by the relevant providers according to their policies and legal duties. Deleting local data cannot delete store transaction records.

Release builds must use HTTPS for narration and protect service credentials on the server. Local app storage is not an encrypted vault. The development preview runs on this computer and must not be treated as a deployed service.

Your choices and rights

About → Privacy & data lets you export your local reading data or erase notes, progress, saved works, and preferences on this device. This does not cancel membership or remove already exported files and backups. Manage or cancel your subscription through the relevant store. When accounts are enabled, use Membership & billing → Delete account to remove your sign-in; the confirmation screen explains what is removed and how to cancel billing separately.

Contact commonplace.support@icloud.com to request access, correction, deletion, portability, restriction, or objection to processing where those rights apply. We may need proportionate proof of identity, and some legal records may have to be retained. For anonymous purchases, include your RevenueCat reader ID shown in Support so we can locate relevant service records without requesting your store password.

UK residents may complain to the Information Commissioner's Office. We do not discriminate against readers for exercising privacy rights. There is no personal-data sale, sharing for targeted advertising, or automated decision-making producing legal or similarly significant effects in the current service.

Children and changes

Commonplace is intended for a general adult readership and is not submitted in the Kids category. We do not knowingly collect children's data. If you believe a child has supplied personal information to us, contact commonplace.support@icloud.com. We will review and remove it where appropriate.

We will update this policy if the app's data practices change and provide notice of material changes. The date above identifies the policy version.

Useful links