Legal
Privacy Policy
This policy explains how personal data is processed on the Kravion website and in the Kravion app for iOS. Kravion is designed to collect as little personal data as the product genuinely needs.
Last updated: 11 August 2026
1. Controller
Stefan Radic, trading as Scailara Labs
Graf von Stauffenberg Allee 14
60438 Frankfurt am Main, Germany
Email: stefan@scailara.com
Please address all privacy requests to the email above.
2. Scope
This policy covers this website and the Kravion iOS app. It does not cover third-party services you may reach from Kravion, such as the Apple App Store, which operate under their own policies.
3. Categories of data we process
- Server and access logs: IP address, date and time, requested resource, status code, referrer and user agent, generated automatically when the website is called up.
- Contact by email: your address, message content and any attachments.
- Account and authentication data: email address, provider identifiers where you sign in with Apple or Google, one-time codes, session tokens and sign-in timestamps.
- Profile data: the display name you choose, which is shown next to your public contributions.
- Public discussion data: comments and replies you publish on book pages, including their timestamps and your display name.
- App reading data: notes, marked actions, reading progress and related in-app state. This stays on your device unless you are signed in and use cloud synchronisation or backup, in which case the selected data is stored on our backend so it can be restored and used across your devices.
- Product analytics: privacy-preserving first-party usage measurement (for example which screens or features are used), kept as narrow as possible and not used to build advertising profiles.
- Premium status: whether an active subscription or trial exists, so paid features can be unlocked.
- AI features: when you invoke an AI feature, the prompt and the relevant context you submit, plus the generated answer.
4. Purposes and legal bases
- Providing the website, the app, your account, cloud sync, discussions and premium features: performance of a contract or pre-contractual steps, Art. 6(1)(b) GDPR.
- Operating security, preventing abuse, keeping logs, and improving the product through aggregated, privacy-preserving analytics: legitimate interests, Art. 6(1)(f) GDPR.
- Complying with legal obligations, for example commercial and tax retention duties: Art. 6(1)(c) GDPR.
- Any processing that genuinely depends on your consent — for example optional device permissions you grant in the app: Art. 6(1)(a) GDPR, withdrawable at any time with effect for the future.
5. Local-first, with deliberate synchronisation
Earlier versions of our policy stated that reading data and notes are never transmitted. That is no longer accurate and we are correcting it here. Kravion remains local-first by default: without an account, your notes and reading data stay on your device. However, if you create an account and use cloud synchronisation, backup or the web discussion, the data required for those functions is deliberately transmitted to and stored on our backend.
6. Infrastructure and recipients
Authentication, database and cloud storage run on Supabase. The Kravion project is hosted in the EU region (eu-west-1). Providers involved in operating the service may nevertheless process data outside Germany or, in limited cases, outside the EU; we therefore do not claim that all processing happens exclusively in Germany.
- Apple and Google: only if you choose their sign-in method; the provider then confirms your identity to us and we receive the associated identifier and email.
- Apple App Store: purchases, subscriptions, renewals and refunds are processed by Apple. We do not receive your payment details.
- AI API provider: AI requests are routed through Kravion's secured backend to an AI service provider that generates the answer. We deliberately do not name a specific model here, because models change; the processing purpose stays the same.
- Hosting and delivery providers for the website and backend, acting as processors.
Processors act on our documented instructions under Art. 28 GDPR. Where a transfer to a third country occurs, it is based on an adequacy decision or on EU Standard Contractual Clauses with additional safeguards where applicable, Arts. 44–49 GDPR.
7. Book cover metadata on the website
Book cover artwork and metadata on this website are retrieved from the public Open Library service (Internet Archive). When a cover is requested or displayed, technical data such as your IP address, user agent and the requested URL or referrer can become known to that provider. The curated Kravion editorial text is written by us and is independent of this provider.
8. Storage on your device (website)
The website stores your Supabase session in the browser's local storage so you stay signed in. This storage is strictly necessary to provide the service you expressly requested and therefore falls under § 25(2) no. 2 TDDDG, so no consent banner is required for it. The website uses no advertising trackers and no non-essential marketing cookies; for that reason we deliberately do not display a cookie banner. If that ever changes, we will obtain consent under § 25(1) TDDDG before setting non-essential storage.
9. Retention
We keep personal data only as long as it is needed for the purposes above. Account, profile, synchronised and premium-status data are retained while your account exists. Public comments remain visible until you delete them or we remove them under the Terms of Use. Server logs are kept for a short period for security and troubleshooting and are then deleted or aggregated. Data covered by statutory retention duties (for example commercial or tax law) is retained for the legally prescribed period and restricted from other processing. Backups are overwritten in the ordinary backup cycle.
10. Deleting your account and contributions
You can edit or delete your own comments at any time while signed in. You can delete your account through the in-app account deletion function where it is available in the Kravion app; alternatively you can request deletion by writing to stefan@scailara.com. Residual copies may persist briefly in backups and are deleted with the backup cycle.
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) under the GDPR. Where processing is based on consent, you may withdraw it at any time with effect for the future.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1, 65189 Wiesbaden
datenschutz.hessen.de
12. No automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. AI features generate text at your request; they do not make decisions about you.
13. Security
We use appropriate technical and organisational measures, including transport encryption, row-level access rules in the database, scoped access keys and least-privilege access, to protect your data. No system can be guaranteed to be perfectly secure.
14. Voluntary and required data
Browsing the website and reading discussions requires no account. Providing an email address is necessary to create an account, publish comments or use cloud features; without it those functions cannot be offered.
15. Changes and contact
We update this policy when the product or the legal framework changes; the date at the top shows the current version. Questions go to stefan@scailara.com. See also the Impressum and the Terms of Use.