Privacy Policy
Effective Date: August 1, 2026
Rishi Reader ("Rishi", "the App") is developed and operated by Fidexa ("we", "us", "our"). This Privacy Policy explains what information Rishi handles, why it is handled, which service providers receive information when you use AI features, and the choices available to you.
1. Information We Collect
The information handled by Rishi depends on the features you use. It may include:
Phone numbers and SMS consent: If you voluntarily provide a phone number or opt in to Fidexa customer-care SMS, we may use that number and your consent status to send account, support, and service-update messages. SMS consent is optional and is not a condition of purchase. We do not sell, rent, or share mobile numbers or SMS consent data with third parties or affiliates for their own marketing or promotional purposes. Message frequency varies based on account activity, and message and data rates may apply. We may share the information with messaging infrastructure providers, such as Twilio, only as needed to deliver requested messages and operate the service.
- Account information: your email address, authentication information, and account identifiers used to sign in and associate your data with your account.
- Library and book data: books and documents you add for cloud access, titles, authors, file identifiers, file sizes, and cover images or other library metadata.
- Reading data: reading position and progress, bookmarks, highlights, selected text, notes, and other annotations you create.
- Conversation data: conversation titles and the messages or transcripts associated with conversations you save or sync.
- AI feature data: prompts and queries, book or page context, narration text, microphone audio, speech-to-text transcripts, generated responses, and generated narration audio when you use the relevant feature.
- Operational data: technical information needed to operate, secure, troubleshoot, and measure the reliability of the App and its services.
2. Cloud Sync and App Storage
When you use an account and cloud sync, Rishi stores and syncs account identity, books and documents, cover images, library metadata, reading progress, bookmarks, highlights and annotations, conversation titles, and conversation messages. We use this information to make your library and reading activity available across your signed-in devices. Book files and covers are stored in cloud object storage, while sync records are stored in our application database. Some device-local files and reader state remain on your device and are not part of the sync record.
3. AI Features and Service Providers
AI features are optional. When you use one, the App sends the data needed for that request to the applicable provider. AI requests are subject to the data-use consent shown in the App. We do not sell this information or use it for advertising.
- OpenAI: receives prompts and queries, book or page text used as context, narration text, microphone audio and transcripts for real-time voice features, and other request data needed to return AI responses, speech, embeddings, or voice-session output. We use OpenAI for AI conversations, book-aware assistance, text-to-speech, and real-time voice interactions.
- ElevenLabs: receives the narration text and selected voice, model, or speed settings when you choose ElevenLabs narration. It returns generated speech audio for playback.
- Deepgram: receives the microphone audio submitted for speech-to-text transcription and returns a transcript. The transcript may then be used in the conversation feature and saved as a conversation message when you choose to save or sync it.
These providers are independent service providers. Their own privacy policies and terms govern their handling and retention of information they receive. This policy does not promise a specific retention period for data held by OpenAI, ElevenLabs, Deepgram, or other providers.
4. Narration Audio Caching
To avoid repeating the same text-to-speech request, generated narration audio may be cached in Cloudflare R2. The cache is content-addressed using the narration text and voice settings, rather than being tied to a particular account. A matching request can therefore use cached audio instead of making another provider request. We do not state a fixed expiration period for these cache entries; they may remain until they are removed or replaced as part of service operation.
5. Microphone and Voice Features
Rishi requests microphone access only when you use a voice or transcription feature. Microphone audio may be sent to OpenAI for a real-time voice conversation or to Deepgram for transcription. Rishi does not intentionally store raw microphone bytes in its conversation database. Voice transcripts and conversation messages may be stored and synced when they become part of a conversation. We make no claim about how long an independent provider may retain audio or transcripts. You can revoke microphone permission through your device's system settings.
6. Operational Telemetry and Sentry
We use Sentry on the web service and worker for operational error reporting, logs, sampled performance traces, and sampled session replay. Depending on the event, Sentry may receive technical information such as browser or device details, request and error context, and interactions visible in a replay. We configure Sentry's automatic personal-information collection setting off (sendDefaultPii: false), but information included in an error, log, or replay can still be transmitted as part of troubleshooting. Provider-use telemetry is designed to contain accounting facts such as counts, durations, model identifiers, and outcomes—not book text, narration text, audio bytes, transcripts, or secrets. We do not use this telemetry for advertising or sell it.
7. How We Use Information
- Provide reading, library, narration, and voice features.
- Sync your account data across signed-in devices.
- Process AI requests and return responses or audio.
- Authenticate accounts and enforce access and usage limits.
- Monitor reliability, prevent abuse, and fix errors.
- Respond to support requests and comply with legal obligations.
8. Data Sharing and Selling
We do not sell, rent, lease, or trade personal data. We share information with the service providers named in this policy only when needed to provide the feature you requested, with infrastructure and security providers that support the service, or when required by law. We do not share reading data with advertisers or data brokers for commercial purposes.
9. Data Storage and Security
We use access controls and encryption in transit and at rest where supported by the services we operate. No system can guarantee absolute security. The security practices and retention rules of independent providers are governed by their own policies.
10. Data Retention and Deletion
You can permanently delete your account directly from the App's account settings. The deletion request is authenticated, can be retried if a network or service error occurs, and removes the account identity, Sign in with Apple linkage and stored authorization credential, synced books and covers, reading position, bookmarks, highlights, conversations and messages, registered devices, subscription and entitlement records, usage records, and the account-scoped database and object-storage data controlled by Rishi. We retain a keyed entitlement and anti-abuse record for up to 24 months after deletion (or the end of the last paid period, if later). That record contains only trial aggregates, paid entitlement status, and hashed Apple transaction references; it does not contain raw Apple subjects or transaction identifiers. We use it to prevent repeated trials and to restore valid paid access if you recreate the account. After the server confirms deletion, the App clears its credentials and local account data from that device.
Deletion does not remove shared content-addressed narration cache entries, copies already held by independent AI providers, or operational backups and logs retained for security, accounting, fraud prevention, or legal obligations during their normal lifecycle. Once the account row is deleted, Rishi retains no account deletion marker or tombstone. A repeated deletion request is treated as an idempotent no-op when the account is already absent. Deleting a Rishi account also does not cancel an Apple App Store subscription; manage that subscription through Apple's subscription settings. We do not publish a fixed retention period here for every data type or independent service.
11. Children's Privacy
Rishi Reader is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
12. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Request a portable copy of your data.
- Withdraw consent for data processing where applicable.
To exercise these rights, contact us using the information below.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective Date" at the top indicates when it was last revised. If we make material changes, we will notify you through the App or by another appropriate means.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact:
Fidexa
Email: [email protected]