The short version
- You can import and read books without creating an account. Core reading, search, annotations, contextual definitions, and spoiler boundaries work on your device.
- HonPaca Cloud is optional. If you sign in, subscribe, and accept the cloud disclosure, it can store your library and reading data for cross-device use and process bounded text with OpenAI for Luna-powered features.
- Fixed-layout page images are not sent to Supabase or OpenAI. Optical character recognition (OCR) runs on your device; only bounded usable OCR text may be sent when you ask for a cloud feature.
- We do not sell personal information, use it for targeted advertising, or use advertising trackers in the app.
Information that stays on your device
Unless you enable HonPaca Cloud, imported EPUB files, reading progress, bookmarks, highlights, notes and other annotations, extracted text, search indexes, embeddings, OCR data, generated local images, reading history, and feature history stay on your device.
Some local data is intentionally never synchronized, even when HonPaca Cloud is enabled. This includes full-text search indexes, E5 vectors, OCR caches, page rasters, local model files, device logs, and the local authority that prevents future passages from being used before you reach them.
Local data remains until you remove it in HonPaca, delete the app, or erase the device. Your device backup settings may separately cause Apple to back up eligible app data.
Information processed when you enable HonPaca Cloud
HonPaca Cloud requires Sign in with Apple, an active subscription, and your acceptance of the cloud-processing disclosure. Depending on the features you use, we process:
- Account information: a Supabase user ID, Apple's account-linked sign-in identifier, and an email or private relay address if Apple makes one available.
- Cloud library content: private EPUB copies, reading position and status, preferences, collections and tags, bookmarks, highlights, notes and other annotations, Ask conversations and cited evidence, Story Guide results and corrections, and generated visual assets.
- AI requests: your question or requested task and a limited packet of book text selected and authorized on your device. HonPaca sends this through a Supabase Edge function to the OpenAI API for Ask, Story Guide, generated Who text, and gloss translation. HonPaca does not send the EPUB file to OpenAI, but Story Guide may send bounded portions from throughout a book over multiple requests, and those portions can collectively cover much of its text.
- Purchase information: a pseudonymous Supabase user ID, product and entitlement status, transaction and receipt information, renewal or expiry status, and limited device/service information needed by RevenueCat. Apple handles payment details; HonPaca does not receive your full card number.
- Security and service information: App Attest keys and assertions, app/device integrity signals, IP address and request metadata processed by infrastructure providers, plus content-free operational records such as a pseudonymous account ID, operation type, status, latency, token counts, cost, and provider request ID.
HonPaca's operational logs are designed not to contain book titles or text, OCR text, questions, prompts, answers, reading locators, or local file paths.
How we use information
We use information only to:
- authenticate your account and protect it from abuse;
- synchronize and restore the cloud content you choose to store;
- provide the Luna-powered feature you request;
- verify subscription access, purchases, renewals, and restores;
- enforce quotas and fair-use limits;
- diagnose content-free service failures and maintain reliability;
- process deletion requests and meet legal, security, and fraud-prevention obligations.
Where applicable law requires a legal basis, we process information to provide the service you requested, with your consent where required, for legitimate security and reliability interests that do not override your rights, or to comply with legal obligations.
Service providers
We use the following providers to operate HonPaca:
- Supabase provides authentication, private database and file storage, synchronization, and server functions. HonPaca's primary production project is intended to store data in the US East region.
- OpenAI processes bounded text for Luna-powered features. API inputs and outputs are not used to train OpenAI models by default unless the account owner opts in. Under ordinary API data controls, abuse-monitoring logs may retain prompts and responses for up to 30 days, or longer when legally required.
- RevenueCat processes subscription, receipt, transaction, entitlement, and restore information using a pseudonymous HonPaca account ID.
- Apple provides Sign in with Apple, App Attest, App Store purchases, device services, and any Apple-managed backup you enable.
- Cloudflare serves honpaca.com and may process network and security information needed to deliver and protect the website.
These providers process information for their stated services under their own terms and privacy commitments. We require providers handling HonPaca user data to protect it consistently with this policy and applicable law. We do not permit them to use HonPaca content for our advertising.
Storage, transfers, and security
HonPaca Cloud encrypts data in transit and relies on its providers' encryption at rest. HonPaca Cloud is not end-to-end encrypted. Authorized administrators and service providers can technically access cloud content when required to operate, secure, support, or delete the service.
Cloud data may be processed in the United States and other places where our providers operate. We use reasonable technical and organizational safeguards, but no internet service can guarantee absolute security.
Each EPUB may be up to 1 GiB, and an account has a disclosed 25 GiB fair-use safety ceiling. Large book transfers use Wi-Fi by default unless you choose to allow cellular transfers.
Retention and deletion
- Active cloud account: cloud content is kept while needed to provide the service and until you delete it or the retention rules below apply.
- Subscription expiry: new generation and uploads stop immediately. Existing cloud content remains available for viewing or download for 30 days, after which it is scheduled for deletion. Local books and reading data remain on your device.
- Delete a synced book: HonPaca first records an online deletion so another device cannot silently restore the book, then deletes the cloud object asynchronously. The app explains why deletion cannot complete while offline.
- Delete cloud account: cloud access is disabled immediately, local cloud bindings are cleared, and a monitored job is designed to purge the account's Supabase Storage, database, and authentication data within 27 hours. Local books and reading data remain on the device. Deleting your HonPaca account does not cancel an Apple subscription; subscriptions must be managed separately through Apple.
- Synchronization deletion records: tombstones are retained until active devices acknowledge them and for at least 90 days. A device inactive for 180 days must perform a complete resynchronization.
- Short-lived service records: pending generation results are retained for up to 24 hours or until acknowledged. Content-free per-minute rate-limit records are removed after 24 hours. Billing-period usage totals and necessary generation receipts are retained longer to operate quotas and resolve disputes.
We may retain limited content-free security, billing, fraud-prevention, legal, or deletion-completion records where reasonably necessary or legally required. If an Apple subscription is still valid when you delete a cloud account, a content-free billing claim may temporarily remain so Restore Purchases can associate that subscription with a recreated account. It cannot access your cloud content and expires under the service's retention rules. Our providers may retain their own required records under their policies.
Your choices and rights
You can:
- use the local reader without an account;
- decline or stop cloud processing;
- choose whether large transfers may use cellular data;
- sign out, download cloud books during the available download window, or delete individual synced books;
- delete your HonPaca cloud account from Settings;
- manage or cancel your subscription in Apple's subscription settings;
- request access, correction, deletion, or a portable copy of personal information, and exercise any additional privacy rights available where you live.
Stopping cloud processing prevents new uploads, sync changes, and OpenAI generation. It does not delete local data or automatically delete already stored cloud data. Use the deletion controls or contact us for help.
To make a privacy request, email privacy@honpaca.com. We may need to verify that you control the relevant account before completing a request.
Children
HonPaca Cloud is not directed to children under 13, or the equivalent minimum age where they live. We do not knowingly collect a child's personal information without the authorization required by applicable law. A parent or guardian who believes a child provided personal information can contact us to request its deletion.
Website cookies and analytics
We do not add advertising or analytics trackers to honpaca.com. Cloudflare may process request information and use strictly necessary security technologies to deliver and protect the site.
Changes to this policy
We may update this policy when HonPaca's features, providers, or legal obligations change. We will post the updated date here and provide additional notice when required. Material changes do not retroactively expand consent you previously declined.
Contact
HonPaca is provided by Bacus Lee, the developer identified on HonPaca's Apple App Store listing. For privacy questions or requests, contact:
- Email: privacy@honpaca.com
- Website: https://honpaca.com