Legal · Voltaire Reader
Privacy Policy (Personal Data Processing Policy)
Last updated: July 2026The mobile application Voltaire Reader (hereinafter referred to as the “Application”) is designed with an emphasis on maximising privacy protection, maintaining zero knowledge of user data (Zero-Knowledge), and minimising the scope of processed data. The Application operates primarily locally on the user's device.
- Business Name
- Simon Štefanka
- Registered Office
- Štúrova 16/12, 811 02 Bratislava-Staré Mesto
- Company Registration Number
- 36 925 144
- Tax ID
- 1024962433
- VAT Registration Number
- Not VAT registered
- D-U-N-S
- 524963738
- Registration
- Trade Licensing Register of the Slovak Republic, District Office Bratislava, No. 104-18315
- Contact Email
- [email protected]
1. Identity, User Accounts and Processing of Google OAuth Data
The Application distinguishes between two operational modes depending on the subscription level:
- A. Basic Mode (Free Version): This mode does not require registration or the creation of a user account. All subscriptions, settings, and reading history data are stored exclusively locally in the respective device's memory. In this mode, cloud translations and cloud backup features are not available. The user is only able to perform local exports of lists in OPML format to the device storage.
-
B. Voltaire Pro Mode (Subscription and Trial): To make advanced features available (synchronisation layer, cloud translations), the Application integrates sign-in using Google Sign-In (Google OAuth).
When verifying identity via Google OAuth, the Application gains access exclusively to the following basic data (Non-sensitive Scopes):
- Email address (
userinfo.email) - Name and surname / Public profile (
userinfo.profile) - Unique user identifier (
openid/ Google ID)
This data is processed exclusively for the following purposes:
- Subscription Verification and Management (Google Play Billing): Checking the status of an active licence or an ongoing 7-day trial period associated with the respective Google account.
- Voltaire Cloud & Translations: Verification and authorisation of access to the translation module (Gemini 2.5 Flash Lite) and monitoring of API token consumption to prevent technical abuse of the infrastructure.
- Cross-device sync (end-to-end encryption): Syncing of subscribed feeds, read and saved articles, labels, podcast positions and selected settings across the user's devices runs through cloud infrastructure on the Cloudflare platform (EU data centres). The process uses full end-to-end encryption (E2EE, AES-256-GCM). The encryption key is generated and stored exclusively on the user's devices and is never sent to the server; it is transferred directly between devices (QR code). Neither the operator, nor the cloud infrastructure provider, nor any third party has access to the content of synced data or is technically able to decrypt it. A consequence you should know up front: if the user loses all their devices and has no key backup, the synced data on the server can no longer be read — not even by the operator. There is no recovery. The app states this explicitly when sync is switched on and offers a key export.
- Sync metadata (what the operator can see): Although the content is unreadable, the server necessarily processes technical envelope metadata: the account identifier (derived from the Google account), a pseudonymous device identifier, the time of each sync, and the sequence number and size of the encrypted package. The operator therefore does not know which feeds the user reads or what they saved, but does know that and when a sync happened and from how many devices. This metadata is necessary for the service to work (ordering changes, abuse protection) and is not used for profiling or analytics.
- Retention period: Encrypted sync data is kept on the server for at most 90 days from receipt and is then deleted automatically (the app periodically uploads a fresh full snapshot, so functionality is unaffected). The account record (identifier and time of the last sync) persists until the user requests erasure — without it the app would, after the data expires, incorrectly treat a device as the first one and generate a second key. Erasure under the following section removes everything immediately.
- Email address (
Limited Use Data Statement (Google API Limited Use Policy)
The Controller strictly adheres to the Google API Services User Data Policy. We do not provide, sell, transfer, or share data obtained through Google API interfaces with any third parties (including advertising platforms, data brokers, or other information networks). This data is not used for marketing purposes, user profiling, or displaying personalised advertisements.
The user's Google account access passwords are never stored on the Controller's servers.
2. Diagnostics, Analytics, and Third Parties
The Application does not perform passive data collection in the background. Technical data processing is carried out solely for the purpose of optimising stability.
- Analytical Tools: No third-party analytics or marketing tools (e.g., Google Analytics, Firebase Analytics, Sentry, Facebook SDK) are integrated into the Application to track behaviour, preferences, or duration of application usage.
- Voluntary Error and Feedback Reporting: The user has the option to submit an error report manually (in the settings) or by activating the device shake function. The report includes a textual description provided by the user and a screenshot. Along with this, only technical, anonymised data is sent: device type, Android SDK version, operating system overlay version, and launcher type.
- Translation Infrastructure: Translation services are provided via the Voltaire Cloud interface (protected by Cloudflare). Texts of article titles and excerpts are sent for one-time processing by the Gemini 2.5 Flash Lite model and are deleted immediately after the translation is generated. No texts are stored or archived on our servers.
- System Crash Reports (Crash logs): In the event of a critical application failure, an anonymised technical error log may be made available to the Controller via the Google Play Console platform, but only if the user has granted global consent in the Android operating system for sharing diagnostic data with developers.
3. Legal Basis and Data Subject Rights (GDPR)
The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) on the basis of the following legal grounds:
- Performance of a contract (Article 6(1)(b) GDPR): Google authentication and the processing of the account identifier for the Voltaire Pro version are necessary for the provision of the contractually agreed service (translations, licence management, cloud synchronisation).
- Legitimate interests (Article 6(1)(f) GDPR): Processing of voluntarily submitted error reports for the purpose of enhancing the Application's stability and security.
Rights of Users (Data Subjects):
-
Right to Erasure (Right to be Forgotten):
- Local data: Can be removed at any time by uninstalling the Application or by clearing Application data in the Android system settings.
- Cloud data: Voltaire Pro users can permanently and irreversibly delete their server data (the account record, encrypted sync data and token consumption history) at any time directly in the app — Settings → Sync → My data → “Delete my server data” — or by request to the operator's contact e-mail. Deletion takes effect immediately and cannot be undone; data on the user's device is left untouched.
- Right to data portability: The user may export their subscribed feed lists to the standard OPML format at any time. Server-side sync data can be downloaded in the app (Settings → Sync → My data → “Download my data”) as JSON; because it is encrypted, only the user can read it using their own key, which can be exported from the same screen.
- Right of Access: The scope of processed data is fully transparent and accessible directly within the Application's user interface.
4. Geographical Scope and Territorial Limitation
The Voltaire Reader Application is developed, localised, and distributed exclusively for users residing or established within the territory of the European Union (EU), the United Kingdom (UK), and Ukraine.
The Application is not intended for markets outside the regions defined above (e.g., USA, Canada, China) and does not actively offer its services there. The Controller does not guarantee compliance with personal data protection legislation applicable in other third countries (e.g., California Consumer Privacy Act – CCPA).
5. Protection of Minors' Privacy
The Application is not intended for individuals under the age of 13. The Controller does not knowingly process the personal data of minors. In the event of discovering that personal data of a minor has been inadvertently acquired without verifiable consent from the holder of parental responsibility, such data will be promptly deleted.
6. Android Operating System Permissions
For the proper functioning of its features, the Application requires the granting of the following system permissions, which the user may revoke at any time in the system settings:
- Storage Access (Storage Space / Disk): Required exclusively for the purpose of local import and export of channel lists in OPML format to/from the device memory. The Application does not access any other files, photos, or multimedia.
- Sending Notifications (Notifications): Used for delivering notifications regarding content updates, important system messages, or information about subscription status and trial periods.
The Application neither requests nor utilises any other sensitive hardware or system permissions (location, camera, microphone, contacts).