04 / Privacy

Privacy

Local-first by design

Thiepn Library is guest-first: no account is required to browse, import, or read. Reading progress, saved works, bookmarks, highlights, notes, reader settings, and personal-book records remain browser-local by default. If THIEPN Account is already signed in, Library can attach that existing account automatically through first-party SSO; a signed-out visitor remains a guest. Reading-state upload still does not begin until sync is enabled for this device. When enabled, Library stores a private account-scoped snapshot of portable reading state in the THIEPN Account Supabase project so the same state can be reconciled across devices.

When you import an EPUB or PDF into My Library, the file is inspected and stored locally in this browser’s IndexedDB storage. Ordinary Account reading-state sync never uploads personal EPUB/PDF bytes or local cover blobs. Portable personal-book metadata may be synchronized so another device can identify and organize the same book. That metadata can include edited title/creator/language plus shelves and tags; it does not include the publication bytes or extracted cover blob.

Personal book cloud is a separate, sensitive, opt-in Account permission. If you explicitly allow it, Library may upload private EPUB/PDF bytes up to 50 MB per book to an owner-scoped private Supabase Storage bucket so another signed-in device can restore the exact SHA-256-matched file. Files over that cloud limit and all extracted local cover blobs remain device-local. Revoking the permission stops Library access but does not itself delete retained cloud files; cloud-data deletion remains centralized in THIEPN Account.

Manual JSON backups contain portable reading state and personal-book metadata, but they do not contain the bytes of your personal EPUB/PDF files or their cover blobs. Restoring on another browser may therefore ask you to re-import matching files.

Library can also expose a small, revocable reading summary to THIEPN Home. This sharing is off until you choose its purposes in Library. Account-synced reading is a second explicit choice: Library verifies the same THIEPN Account and may read its existing owner-scoped cloud snapshot before sharing only title/publication identity and normalized progress. Library labels the result account-synced only when the cloud and current-device reader progress already match; a newer or divergent cloud copy falls back to device-local reporting until normal Library sync runs. A Hub read never pushes Library state, restores local state, resolves conflicts, or accesses personal-file Storage. Home never receives Library’s Account token, raw cloud snapshot, book files, exact reader anchors, highlights, notes, annotations, shelves, or tags.

Normal guest use makes ordinary network requests for the public website, published book media, and the Google Fonts styles/font files used by the interface. If Account sync is enabled, authenticated requests are also made to the THIEPN Account Supabase project for identity verification and owner-scoped reading-state synchronization. If Personal book cloud is separately allowed, authenticated private Storage requests are also made for those personal book files. There is no advertising or behavioral analytics path in the reader.

Clearing browser site data, browser storage eviction, device loss, or browser-profile removal can delete local state and personal imports. Use the Backup page for portable state and keep your original personal EPUB/PDF files separately even when optional cloud continuity is enabled.

The optional Ask Library service, if enabled separately, is outside the local reader path and must be explicitly invoked. Its provider/network behavior is not required for ordinary public reading.