Privacy policy

What Codex Reader stores, what leaves your device, and who it goes to.

Last updated July 28, 2026

The short version

Codex Reader is a reader and player for books you already own. It connects to servers you run or subscribe to. We do not host your books, we do not have accounts, and we do not have a server that your library is uploaded to.

Your books, your bookmarks, and your place in every book are stored on your device. Three things leave it: crash reports, purchase records, and — if you turn it on — reading progress synced through your own iCloud account. Each is described below.

What stays on your device

Your library, your reading and listening progress, bookmarks, highlights, reading lists, shelves, downloaded files, and every setting you choose are held in a database on your device. None of it is transmitted to us. Uninstalling the app deletes it.

Search and browsing inside the app happen locally against that database. We do not receive your searches or a record of what you read.

Your servers and credentials

When you connect a source — Plex, Audiobookshelf, an OPDS catalog, or a Storyteller instance — the address and your credentials are stored in the iOS keychain on your device. They are sent only to that server, to authenticate you and fetch your books.

Those servers are operated by you or by whoever runs them. Their handling of your data is governed by their own policies, not this one.

iCloud sync (Codex Premium)

If you subscribe to Codex Premium and enable sync, your reading progress is written to a private database inside your own Apple Account using Apple's CloudKit. It moves between your devices because they share your Apple Account.

That data lives in your iCloud storage. We cannot read it, and it is not sent to any server we operate. Turning sync off stops further writes; deleting the app's iCloud data in iOS Settings removes what is there.

Purchases

Subscriptions are processed by Apple. We never see your payment details. To know which subscription you hold, we use RevenueCat, which records an anonymous identifier it generates for your install along with your purchase and subscription history, and validates your receipt with Apple.

That identifier is not tied to a name, an email address, or an account with us — there is no account with us. It exists to unlock the features you paid for.

Crash reports and diagnostics

Codex Reader uses Sentry to collect crash reports and error diagnostics so that bugs can be found and fixed. A report can include the stack trace, your device model and iOS version, the app version, an install identifier, a trace of the actions leading up to the failure, and performance timing from a sample of sessions.

During the TestFlight beta, crash reports also carry your identity. If you have signed in to Plex, the app attaches your Plex account identifier and, where available, your email address and username. If you have not, it attaches the username from a connected Audiobookshelf or OPDS server instead. This is used only to match a crash to the beta tester who reported it, and it will be removed when the app leaves TestFlight.

Crash data is used to fix the app. It is not sold, not used for advertising, and not used to track you across other apps or websites.

Notifications

Notifications about new books and reading reminders are scheduled on your device from your own library. There is no push server, and no notification data is sent anywhere.

What we never do

We do not sell your data. We do not use it for advertising. We do not track you across other apps or websites, and the app shows no ads. We do not upload your books.

Children

Codex Reader is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes in a way that affects what leaves your device, the date at the top of this page will change and the revision will be described here.

Contact

Questions about this policy, or a request to have data removed: [email protected].