Privacy policy

Last updated: 2 October 2026

This policy describes the data the Oratella app and the website oratella.app handle. It applies to the app on iPhone and on Android.

Who is responsible

The controller is Brilliance Apps Finland, Finland. Write to support@oratella.app with any question about your data.

In short

Data that stays on your phone

The files you add, the text of saved web articles, covers, reading positions, bookmarks and settings are stored on your phone. We have no access to them.

Voices

The voices of your phone are provided by Apple on iPhone and by your speech engine on Android, usually Google. They run on the phone. Natural voices also run on the phone. Their voice files are downloaded once from GitHub, where the voice models are published. The download sends no book text. GitHub sees your IP address, as with any download.

Web articles

When you add a web article, Oratella loads that page on your phone, as a browser would. The website sees the request and may set its own cookies in that view. Oratella then keeps the text of the article on your phone.

Sync

Sync is off until you turn it on. It copies your library, places, bookmarks and settings to a cloud you choose. The copy is stored in your own account with that cloud.

You can protect the synced copy with a password. It is then encrypted on your phone with AES-256-GCM before it is uploaded, and the cloud cannot read it. We do not receive your synced data or your password. The cloud's own privacy policy applies to what it stores.

Usage statistics

Oratella uses Google Firebase Analytics to see how the app is used, so we can improve it. A book's ID is a random code made on your phone. It says nothing about the book. The app sends these events:

Firebase Analytics also records an app instance ID, the device model, the operating system, the app version, the language and an approximate location derived from the IP address. Oratella shows no ads and uses this data for no advertising. Google keeps analytics data for the period set in our Google Analytics account, at most 14 months.

Purchases

Premium is bought in the App Store, on Google Play or on oratella.app. Apple, Google or Stripe process the payment. We do not receive your card details.

RevenueCat keeps the record of your purchases for us, so the app can tell whether Premium is on. It stores the purchase receipts, the products, the dates and the store, under an anonymous ID made on your phone. If you link Premium to an email, the record moves to a random Premium ID. RevenueCat never receives your email address from us.

Buying on the website

On oratella.app you enter an email address and pay with Stripe Checkout. Stripe receives the email and the payment details. We keep the email, the plan and a Premium ID while the payment is open. If you do not pay, that record is deleted after 2 days. If you pay, the email is kept as described under "Premium on more devices".

Premium on more devices

Lite needs no account. Premium also needs none until you link it to an email. You do that to use Premium on another device. Linking happens when you enter a 6-digit code we email to you, or when you sign in to Google Drive or Dropbox for sync.

When you link, we store:

This data is stored in Google Cloud Firestore in the European Union (Belgium, europe-west1). A linked device reports once a week that it is still in use. A device unused for 60 days is removed from the list the next time a device links.

For a Google or Dropbox sign-in, our server checks the sign-in token with Google or Dropbox to read your verified email address. The token is not stored. When you sync with Google Drive or Dropbox on a device without Premium, the app asks our server once a week whether that email has Premium. If it has none, nothing is stored.

Codes are sent by email through SMTP2GO. We store a keyed hash of the code, never the code itself, and delete it within an hour. To limit abuse, we count the codes sent to each email address and from each IP address. We store only a hash of the IP address, and the count is deleted within an hour.

Email to us

Mail sent to an oratella.app address is forwarded by Cloudflare to our mailbox at Google. We keep it as long as we need to answer and to keep a record of support requests.

How long we keep data

For anything else, write to support@oratella.app.

Legal bases

Service providers

These companies process data for us, each for the purpose named:

Some of these companies process data outside the European Economic Area, mainly in the United States. Those transfers rely on the EU-US Data Privacy Framework where the company is certified, and on the European Commission's standard contractual clauses otherwise.

Your rights

You can ask for a copy of your data, and ask us to correct it, delete it, restrict its use or send it to you in a portable form. You can object to processing based on legitimate interests. Write to support@oratella.app. We answer within a month.

You can also complain to the Finnish Data Protection Ombudsman, tietosuoja.fi, or to the authority where you live.

Children

Oratella is not directed at children under 13. We do not knowingly collect their data. If you think a child has given us data, write to us and we will delete it.

Changes

When this policy changes, we update it here and change the date at the top. For important changes, we also tell you in the app.