Privacy Policy

Last updated: June 28, 2026

Effective: June 28, 2026

Summary (TL;DR)

  • ✓ Text-to-speech and processing happen entirely on your device
  • ✓ Your reading content and history are never sent to our servers
  • ✓ No account required, no tracking, no advertising ID collection
  • ✓ iCloud sync is off by default; you enable it manually
  • ✓ Your input is never used to train any AI model
  • ✓ Premium purchases are handled by App Store / Google Play. We never receive your credit card details.
  • ✓ Android version coming soon (this policy applies equally)

1. Introduction

AityTech ("we", "our", "us") provides the Yomite mobile application ("the App", for iOS / iPadOS / macOS, with Android version in development) and the website at yomite.app (together, "the Service"). This Privacy Policy explains how we collect, use, and protect information when you use the Service.

We comply with:

  • Japan: APPI (Act on the Protection of Personal Information, 2022 amendment), AI Promotion Act (May 2026)
  • EU / UK: GDPR, EU AI Act Article 50 transparency requirements (applies from August 2026)
  • US: CCPA / CPRA (California), COPPA (Children's Online Privacy Protection Act)
  • Apple: App Store Review Guidelines, Privacy Manifest (PrivacyInfo.xcprivacy)
  • Google: Google Play Developer Program Policy, Data Safety form (for Android version)

2. Core principle — on-device processing

Yomite's core functionality runs entirely on your device (iPhone / iPad / Mac / Android coming). The following data never leaves your device for our servers:

  • Source text being read (EPUB / Aozora Bunko / web article bodies)
  • Generated audio output
  • Reading history, bookmarks, resume positions, listening stats
  • Your pronunciation dictionary entries
  • File names, titles, and author information from imported content

3. AI-generated audio disclosure (EU AI Act Article 50)

Yomite uses AI text-to-speech synthesis. All audio generated by Yomite is AI-synthesised — not recorded from natural human speech.

  • Audio generation happens entirely on your device
  • We do not provide voice cloning or deepfake technology. The App does not replicate the voices of real people
  • Your input text and any audio are never used to train or improve any AI model
  • This disclosure satisfies EU AI Act Article 50(2) transparency requirements
  • On first launch, an explicit AI-generated audio disclosure modal is shown and you must acknowledge it before use

4. Information we collect

4.1 In-app

  • Optional diagnostic logs and crash reports (opt-in, default off) — anonymous, not linked to device identifiers. If routed through Apple's MetricKit, Apple's privacy terms apply.
  • Voice model download events — CDN access logs only (IP, User-Agent, URL, timestamp). Raw logs are anonymised into aggregate stats after 30 days.

4.2 Website yomite.app

  • Google Analytics 4 — anonymised IP, Consent Mode v2 default-deny.
  • Cloudflare access logs — for security and performance monitoring.

4.3 Information we do NOT collect

We collect none of the following:

  • Name, address, phone number, email (except contact form), date of birth
  • Payment info, credit card or bank account numbers
  • Location, movement history
  • Device identifiers (IDFA / IDFV / Google Advertising ID / device serial)
  • Contacts, photos, camera, microphone, calendar, health data
  • App Tracking Transparency (ATT) consent is never requested
  • Voice input or recordings — the App outputs audio; it does not record audio

5. About user content

Yomite is "a tool that reads text aloud" — we are not a content provider. All books, articles, and text you import come from sources you choose.

  • EPUB / TXT import: files on your device are imported by your action. Our servers are not involved.
  • Aozora Bunko: your device connects directly to aozora.gr.jp on your request. We do not log or relay these requests.
  • Web Reader: your device fetches the URL you provide and extracts body text locally. Nothing routes through our servers.
  • Web-novel sites: your device accesses these only when you tap "next chapter". We do not perform automated crawling.

Copyright and usage rights for imported content belong to the content's original source or to you. You are responsible for ensuring you have the right to use any text you import (see Terms of Service §3).

6. Third parties & processors

We do not share collected information with third parties except as required by law or with your consent. We use the following sub-processors:

Sub-processorLocationPurpose
Cloudflare, Inc.USACDN, DNS, voice model distribution
Google LLCUSAWebsite analytics (GA4, Consent Mode v2)
Apple Inc.USAApp Store distribution, crash aggregation, iCloud / CloudKit sync
Google LLCUSAGoogle Play distribution (Android version)

We do NOT send user data to third-party AI services (OpenAI, Google AI, Anthropic, Azure, etc.). All speech synthesis is on-device (compliant with Apple App Store Review Guideline 5.1.2(i)).

6.1 In-app purchases (Yomite Premium, one-time lifetime)

Yomite Premium in-app purchases are processed by your chosen store's payment system (Apple StoreKit or Google Play Billing). The current price is shown on the App Store / Google Play product page. We never receive or store any of the following:

  • Credit card numbers, expiry dates, CVV codes
  • Bank account details, debit card information
  • Billing address, name, or other payment profile data
  • Per-user purchase amounts or detailed billing history

What we receive from the store is only the signed purchase receipt (StoreKit Transaction), which contains no information that uniquely identifies you. Receipts are validated on-device and never sent to our servers. Payment data handling is governed by the Apple Privacy Policy or Google's privacy policy as applicable.

7. Network hosts (full transparency)

The App contacts only the following external hosts:

  • assets-gateway.aitytech.com — voice model and speech-synthesis resource downloads (TLS, our CDN)
  • aozora.gr.jp — only when you choose an Aozora Bunko title (direct from your device)
  • web-novel sites you specify — only when you provide a URL (direct from your device)
  • docs.google.com — on first launch, downloads the community-maintained website parsing rules (public spreadsheet), then cached locally
  • icloud.com / p**-ckdatabase.icloud.com — only if you enable iCloud sync (via Apple)

No ad networks, no analytics services, no telemetry servers. Ad and tracker domains (google-analytics.com, etc.) are blocked in WebView.

8. International data transfer (APPI Art. 28)

Our sub-processors are located in the United States and some user data is processed there. Although the US data protection regime differs from Japan's, we maintain the following safeguards:

  • APPI-compliant Data Processing Agreements (DPAs) with each sub-processor
  • Verified technical and organisational security measures (TLS 1.3, AES-256 at rest, access controls)
  • Preference for sub-processors certified under the EU–US Data Privacy Framework

9. iCloud sync (you enable it manually)

If you enable "Settings → iCloud Sync", the following data syncs across devices on the same Apple ID via Apple's CloudKit:

  • Library (book metadata: title, author, source URL, chapter list)
  • Imported chapter text (full body) — synced data includes the actual prose
  • Reading progress (per-chapter playback position)
  • Bookmarks
  • Your pronunciation dictionary entries
  • UI preferences (font size, theme, etc.)

Synced data is stored in your Apple ID private container. We have no access to it. Sync is off by default and can be disabled in Settings. See Apple's Privacy Policy for Apple's handling.

10. Backup files

"Settings → Backup" lets you export a .novelvoice backup file. This file contains the same data as §9 (including full chapter text).

  • Backup files are not encrypted (JSON format)
  • Once a backup file leaves your device (share, AirDrop, email, external storage), the handling is your responsibility
  • Handle with care

11. Web Reader & third-party content

The Web Reader feature fetches the URL you provide and processes article extraction on-device.

  • Fetching is performed by your device directly; nothing goes through our servers
  • You are responsible for complying with the terms of service and copyright of any third-party website you access
  • The App does not bypass DRM
  • Inappropriate content can be reported via Settings → Support in the App (compliant with App Store Guideline 1.2)

12. Aozora Bunko content

The built-in Aozora Bunko reader displays and reads aloud public-domain works published at aozora.gr.jp. These transcriptions are produced by Aozora Bunko volunteers; please respect the Aozora Bunko terms of use.

13. Cookies & tracking

The App itself uses no cookies or SDK-based tracking. No App Tracking Transparency (ATT) permission request. No Google Advertising ID collection.

The yomite.app website uses Google Analytics 4 cookies, gated behind a consent banner shown on first visit. By default, Google Consent Mode v2 keeps all advertising and analytics cookies in a denied state until you accept.

14. Data retention

Data typeRetention
Diagnostic logs (opt-in)Up to 2 years
CDN access logs30 days raw / 2 years aggregate
Google Analytics 414 months (default)
Support emails3 years after resolution
In-app data (on device)Until you delete it

15. Security measures

We maintain the following safeguards against unauthorised access, loss, or alteration of personal information:

  • Organisational: Designated Personal Information Protection Administrator, internal policies, periodic audits
  • Human: Employee training, confidentiality agreements, access revocation on departure
  • Physical: Cloud providers meeting SOC 2 / ISO 27001 standards
  • Technical: TLS 1.3 in transit, AES-256 at rest, least-privilege access, periodic vulnerability scans, TLS certificate pinning

16. Children's privacy (COPPA / APPI)

The Service is not directed to children under 13. We do not participate in Google Play's "Designed for Families" programme.

The App displays an age confirmation gate on first launch. Users under 13 cannot use the App. Age data is stored only on your device and is never transmitted to our servers.

If we learn we have inadvertently collected information from a child under 13, we will delete it promptly. Parents who believe their child is using the Service should contact support@yomite.app.

17. Your rights

You have the following rights regarding your personal information held by us:

  • Access
  • Correction / addition / deletion
  • Suspension of use, erasure, or third-party disclosure
  • Lodging complaints regarding our handling
  • EU / UK residents: GDPR rights including data portability and objection to automated decision-making
  • California residents: CCPA / CPRA rights to opt out of "sale" and "share" (we do neither)

Send requests to support@yomite.app. After identity verification, we will respond within 14 days. Since the App requires no account, deleting on-device data is achieved by uninstalling the App or clearing app data in OS settings.

18. Apple Privacy Manifest

The App complies with Apple's Privacy Manifest requirements. The privacy disclosures shown on App Store Connect (Privacy Nutrition Labels) match this policy, and all required-reason APIs are properly declared:

  • NSPrivacyAccessedAPICategoryFileTimestamp — reading user-selected files via UIDocumentPicker
  • NSPrivacyAccessedAPICategoryUserDefaults — storing user preferences

We do not send user data to third-party AI services (compliant with App Store Review Guideline 5.1.2(i)). On App Store Connect we declare "No data collected / No tracking" in the privacy nutrition label.

19. Google Play Data Safety (Android version)

For the Android release we will declare the following on the Google Play Console Data Safety form:

  • Personal data collected: None (except optional iCloud-equivalent sync)
  • Data shared with third parties: None
  • User data encryption: TLS (in transit), AES-256 (at rest, for sync)
  • No user account; data deletion completed by app uninstall
  • Not "Designed for Families"

20. Open source attribution

The App uses several open-source libraries. The full licence inventory is available in-app under Settings → Licences.

21. Personal Information Protection Administrator

AityTech Personal Information Protection Administrator
Contact: support@yomite.app

22. Complaint handling

For complaints or questions about this policy or our handling of personal information:
Email: support@yomite.app
Hours: Mon–Fri 10:00–18:00 JST
Response target: 5 business days.

Supervisory authority: Personal Information Protection Commission (PPC) Japan

23. Changes

We may amend this policy due to legal changes or Service changes. Material changes will be announced on the website and in the app. The amended policy takes effect on the "Last updated" date shown above.

24. Contact

AityTech
Email: support@yomite.app
Web: aitytech.com