Tomelet

Privacy Policy

Effective date: 23 August 2026 · Applies to the Tomelet apps, Tomelet Sync and tomelet.app

The short version

1. Who we are

Tomelet is operated by Tomelet Pte Ltd, 60 Paya Lebar Road, #06-53, Paya Lebar Square, Singapore 409051 ("Tomelet", "we"). For privacy questions, write to [email protected].

2. Data that stays on your device

The app keeps a local database of the books you import (the files themselves, their metadata and covers), your reading positions, highlights, notes, bookmarks, stylus ink, collections, tags and settings. None of this is sent to us unless you enable Tomelet Sync. Uninstalling the app removes it; you can also export it at any time from Settings → Backup.

3. Optional account and sign-in

Tomelet Sync requires an account. You create one by signing in with Google, Apple or Facebook (LinkedIn and WeChat may be added later). We receive from the provider a stable identifier for your account and — if you allow it — your email address and display name. We never see your password for that provider. We store: the identifier, email address (if shared), display name (if shared), the date you joined, your subscription state, your storage usage, and the public keys of your devices.

4. Tomelet Sync: what the server can and cannot see

Tomelet Sync is designed on the zero-knowledge model used by password managers. Before anything leaves your device it is encrypted with keys generated and kept on your device (and, optionally, your Recovery Key). Our servers and our staff cannot read your book files, titles, authors, annotations, notes, ink or reading positions.

The server does see: encrypted records and files (ciphertext), their sizes and timestamps, your device identifiers and device public keys, and which account they belong to. We use this only to store, deliver and meter your data.

If you lose access to all of your devices and your Recovery Key, your synced data cannot be recovered by us or anyone else. This is a deliberate property of the design.

5. Purchases

Tomelet Sync is sold through Google Play, the Apple App Store and, on desktop, a web checkout. Payments are handled by those stores or our payment provider; we never receive your card number. We receive confirmation of the purchase, its product, dates and state (active, expired, refunded) through RevenueCat, which we use to manage subscriptions across platforms. See RevenueCat's privacy policy for their processing.

6. Advertising in the free app

The free app shows an interstitial advertisement before a book opens, served by Google AdMob. Ads are non-personalised by default; where the law requires consent (for example the EEA, UK and Switzerland, or under US state privacy laws), you are asked first and can change your choice in Settings → Privacy. Ad content is restricted to a general-audience rating. AdMob may collect device information such as an advertising identifier, approximate location derived from IP address, and ad-interaction data according to Google's advertising policies. No ads are shown inside the reader, on your first day of use, to profiles marked as children, or to Tomelet Sync subscribers.

7. Metadata lookups (optional)

When enabled, Tomelet can look up missing book metadata (cover, series, subjects) by sending the ISBN or title and author of a book to Open Library and Google Books. This reveals to those services which titles you are looking up. The feature is off until you turn it on and can be disabled at any time in Settings → Library.

8. Security logs

For accounts, we keep a security log of sign-ins, device approvals and token refreshes, including the IP address and device identifier, for 12 months. You can view it in Settings → Security. It exists to detect account abuse.

9. The website

tomelet.app is hosted on Cloudflare. It loads no third-party fonts, scripts or trackers and sets no cookies. We use Cloudflare's cookieless, aggregate web analytics (page views by country and browser; no identifiers). If you email us, we keep the correspondence for as long as needed to help you.

10. Retention and deletion

Account data and encrypted sync data are kept while your account exists. When you delete your account (in the app, or by following the deletion instructions) we delete your profile, linked sign-in identities, devices, encrypted records and files within 30 days, and security logs within 12 months of their creation. Store subscriptions must be cancelled separately in Google Play or the App Store. Data on your devices stays until you uninstall the app.

11. Children

Tomelet is not directed at children under 13 (or the age of digital consent in your country). Profiles marked as children see no advertising. We do not knowingly collect personal information from children; contact us if you believe a child has created an account.

12. Where data is processed

Sync data is stored on Amazon Web Services. The website runs on Cloudflare's global network. AWS and Cloudflare may process data in Singapore, the United States and other locations where they operate. Where personal data is transferred outside Singapore, we require recipients to provide a standard of protection comparable to the Singapore Personal Data Protection Act through legally enforceable obligations or another permitted safeguard.

13. Your rights

Depending on where you live (for example under the GDPR, the UK GDPR, the CCPA/CPRA or Singapore's PDPA) you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Export is built into the app; deletion is described above; for anything else email [email protected]. We respond within 30 days.

14. Changes

We will post changes here with a new effective date and, for material changes, notify you in the app or by email.