Privacy policy

What Codex Reader stores, what leaves your device, and who it goes to.

Last updated September 18, 2026

The short version

Codex Reader is a reader and player for books you already own. It connects to servers you run or subscribe to. We do not host your books, we do not have accounts, and we do not have a server that your library is uploaded to.

Your books, your bookmarks, and your place in every book are stored on your device. Three things leave it: crash reports, purchase records, and (if you turn it on) reading progress synced through your own iCloud account. Each is described below.

What stays on your device

Your library, your reading and listening progress, bookmarks, highlights, reading lists, shelves, downloaded files, and every setting you choose are held in a database on your device. None of it is transmitted to us. Uninstalling the app deletes it.

Search and browsing inside the app happen locally against that database. We do not receive your searches or a record of what you read.

Your servers and credentials

When you connect a source (Plex, Audiobookshelf, an OPDS catalog, or a Storyteller instance) the address and your credentials are stored in the iOS keychain on your device. They are sent only to that server, to authenticate you and fetch your books.

Those servers are operated by you or by whoever runs them. Their handling of your data is governed by their own policies, not this one.

iCloud sync (Codex Premium)

If you buy Codex Premium and enable sync, your reading progress is written to a private database inside your own Apple Account using Apple's CloudKit. It moves between your devices because they share your Apple Account.

That data lives in your iCloud storage. We cannot read it, and it is not sent to any server we operate. Turning sync off stops further writes; deleting the app's iCloud data in iOS Settings removes what is there.

Purchases

Purchases are processed by Apple. We never see your payment details. To know what you have bought, we use RevenueCat, which records an anonymous identifier it generates for your install along with your purchase history, and validates your receipt with Apple. Codex Premium is a one-time purchase.

That identifier is not tied to a name, an email address, or an account with us; there is no account with us. It exists to unlock the features you paid for.

Crash reports and diagnostics

Codex Reader uses Sentry to collect crash reports and error diagnostics so that bugs can be found and fixed. A report can include the stack trace, your device model and iOS version, the app version, an install identifier, a trace of the actions leading up to the failure, the structure of the screen at the moment of the error, performance timing from a sample of sessions, and the crash, hang and power reports iOS itself produces through Apple's MetricKit.

Screenshots are deliberately never captured: they would photograph whatever book you are reading. When a network request fails, the report can carry the address it was made to, which for a self-hosted source is the address of your own server.

Some TestFlight beta builds also attach your identity to crash reports. Most builds do not. When a bug needs it, a beta build can be made that does: if you have signed in to Plex, it attaches your Plex account identifier and, where available, your email address and username; if you have not, it attaches the username from a connected Audiobookshelf or OPDS server instead. This is used only to match a crash to the beta tester who reported it. Builds released on the App Store never attach it; the difference is fixed when each build is made, not decided while the app runs.

Crash data is used to fix the app. It is not sold, not used for advertising, and not used to track you across other apps or websites.

Notifications

Notifications about new books and reading reminders are scheduled on your device from your own library. There is no push server, and no notification data is sent anywhere.

What we never do

We do not sell your data. We do not use it for advertising. We do not track you across other apps or websites, and the app shows no ads. We do not upload your books.

Children

Codex Reader is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes in a way that affects what leaves your device, the date at the top of this page will change and the revision will be described here.

Contact

Questions about this policy, or a request to have data removed: [email protected].