Legal
Privacy Policy
How Reflow collects, uses, stores and protects your information.
Effective date: 10 October 2026
This Privacy Policy explains how Effileap Technologies Pvt Ltd (“we”, “us”, “our”) handles information when you use the Reflow mobile app for iPhone, iPad and Android, this website, and related services (together, the “Service”). Effileap Technologies Pvt Ltd is responsible for the personal information processed through the Service.
We have tried to write it plainly. If anything is unclear, please contact us.
The short version
- Your books are private to your account. We use them to build your reading copy and to provide the features you use — not for advertising, and we do not sell your information.
- The app does not contain third-party advertising, analytics or crash-reporting SDKs.
- Your information is stored on servers in India.
- Optional AI features use Microsoft Azure OpenAI Service. We do not use your data to train AI models, and AI never rewrites your book.
- You can delete books, annotations and your account in the app.
1. Information we collect
Account information
When you create an account we collect your name, email address and password. Your password is stored only as a one-way Argon2id hash — we never store or see it in readable form. You may optionally add a phone number and a profile photo. Sign-in is by email and password; we do not currently offer sign-in through third-party providers.
Account security records
We keep records needed to protect your account: whether your email address is verified, when you last signed in and were last active, when your password was changed, and the number of recent failed sign-in attempts (accounts are temporarily locked after repeated failures).
Devices and sign-in sessions
Each time you sign in on a device we create a sign-in session and record the device name, the app’s user-agent string, the IP address and the time. We use this to show you your active sessions, to let you sign out of a device, and to detect stolen or reused sign-in tokens.
Books you upload
When you import a PDF we store the original file, its file name and size, and a SHA-256 fingerprint of the file (used to recognise when you upload the same file twice to your own library). We process the file to extract its text, images and structure and store the result: chapters, sections, paragraphs and other content blocks, images, a cover image, and page-level data. We also store book details such as title, subtitle, author, publisher, ISBN, language, category, a short description and page count. Some of these details may be suggested by AI (see section 4); details you enter yourself are never overwritten.
Reading activity and annotations
To sync your reading and show your statistics we store: your reading position in each book; reading sessions (start and end time, duration, the positions you read between, the number of words read, and an app-generated device identifier); daily reading totals; your library organisation (reading status, favourites, collections); your bookmarks, highlights and notes; and your reader preferences (font, size, spacing, margins, theme, reading mode and alignment).
Ask the book
When you use Ask the book or Explain, your question is sent to our servers and, with relevant excerpts of the book, to our AI provider to generate an answer (see section 4). We do not save your questions or the answers in our database.
Information stored on your device
Your sign-in tokens are stored in your device’s secure keychain (iOS Keychain or Android Keystore). Books you download for offline reading, cached chapters, your reader settings and changes you make while offline are stored in the app’s storage on your device until they are synchronised, you remove them, or you sign out.
Server logs and audit records
Our servers keep technical logs of requests — such as the time, the endpoint, the response status, errors and the IP address — to operate, debug and secure the Service. Passwords, sign-in tokens and authorisation headers are automatically redacted from these logs. Security-relevant and administrative actions are recorded in an audit log, which may include the IP address.
Emails
We send emails needed to run your account, such as email verification and password reset messages. If you contact us, we receive the information you choose to share.
This website
This website does not use analytics, advertising or tracking cookies; see our Cookie Policy. If you use the contact form, we receive the details you enter.
2. How we use information
- Provide the Service — create and secure your account, store your library and let you read it.
- Process books — extract text (including by OCR for scanned pages), detect structure and build your reading copy.
- Sync — keep reading positions, annotations, library organisation and preferences consistent across your devices.
- Provide features you use — search, reading statistics, Ask the book, Explain, chapter summaries and dictionary look-ups.
- Keep the Service secure — rate-limit requests, lock accounts after repeated failed sign-ins, detect reuse of sign-in tokens, investigate abuse.
- Support and improve the Service — diagnose processing failures and fix problems.
- Communicate with you — account emails and replies to your messages.
- Comply with legal obligations.
We do not sell your personal information, we do not show ads, and we do not use the contents of your books to build advertising or marketing profiles.
We process your personal data on the basis of the consent you give when you create an account and use the Service, and for legitimate uses permitted by law — for example, to comply with legal obligations or to respond to a legal request. You can withdraw your consent at any time by deleting your account (section 9) or contacting us; this does not affect processing that took place before you withdrew it.
3. How your books are processed
Uploaded PDFs are processed in stages on our servers: the file may be checked for malware; text is extracted from the PDF; pages without a text layer are recognised with optical character recognition (OCR); and the content is analysed to identify chapters, headings, paragraphs, lists, quotes, tables, footnotes and images.
OCR runs on our own servers using open-source software (Tesseract); page images are not sent to any third party for OCR. Malware checks, where performed, also run on our own servers.
Your original PDF is never modified. If a book is reprocessed (for example after an improvement to our processing), your reading position, bookmarks, highlights and notes are carried over to the new version and the old version is deleted.
4. AI features
AI is used in Reflow in three ways. AI never rewrites the text of your book.
During processing
To improve structure detection, our AI provider may receive bounded excerpts of a book — never the whole book: short passages that might be headings with a little surrounding text, the list of chapter titles, and the first part of the opening chapter (about 1,200 characters). From these it classifies headings, suggests details such as the title, author and category, and may write a short description. Its suggestions are checked against the source text; suggested OCR corrections are stored as suggestions only and are not applied to your text.
Preparing Ask the book
So that Ask the book can find relevant passages, the text of each processed book in your library is divided into passages and converted into embeddings (numerical representations of meaning), which we store with the book. This happens in the background, not only when you ask a question. Embeddings are generated by our AI provider, so the book’s text is sent to it, passage by passage, for this purpose.
When you ask
When you use Ask the book, Explain or a chapter summary, your question and the most relevant excerpts of that book are sent to our AI provider, and the answer is returned to you with citations to the passages it used. We do not store your questions or the answers.
Our AI provider is Microsoft Azure OpenAI Service, used through our own Azure account. Microsoft processes this content on our behalf to provide the service, under its terms for Azure. We do not use your books, questions, answers or any other data to train AI models.
6. Access by our team
A small number of authorised staff have administrator access to the Service. Where necessary to provide support you have asked for, to diagnose failed processing, to investigate abuse or security incidents, or to comply with the law, they can view account details and the books and content stored in the Service. Administrative actions are recorded in an audit log.
7. Security
We protect your information with measures including:
- encrypted HTTPS connections between the app and our servers (release builds of the app connect only over HTTPS);
- passwords stored only as Argon2id hashes, and sign-in, verification and reset tokens stored only as SHA-256 hashes;
- short-lived access tokens (15 minutes) and rotating refresh tokens (valid for up to 30 days) with reuse detection, kept in your device’s secure keychain;
- temporary account lockout after repeated failed sign-ins, and rate limits on sign-in, upload and other requests;
- private file storage, with images delivered through signed links that expire after a short time;
- automatic redaction of passwords and tokens from server logs, and an audit log of administrative actions.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you and the authorities where the law requires.
8. How long we keep information
- Account and reading data — for as long as your account is active.
- Books — until you delete the book or your account. When a book is deleted, its database records (content, reading positions, sessions, bookmarks, highlights, notes and Ask the book index) are deleted immediately and its stored files are removed by a background job shortly afterwards.
- Email verification links expire after 24 hours and password reset links after one hour; expired and used tokens are purged daily.
- Sign-in sessions last up to 30 days unless you sign out or they are revoked; expired session records are purged.
- Backups of the database and stored files are kept for 14 days and then deleted.
- Server logs — kept for one month, then deleted.
We may keep information longer where the law requires it or where it is needed to resolve disputes or investigate abuse.
9. Deleting your data and your account
You can delete individual books (together with their bookmarks, highlights and notes), individual annotations and offline downloads in the app. See our Data Deletion page for step-by-step instructions.
You can delete your account in the app under Profile → Account → Delete account. When you do:
- every book you uploaded is deleted, together with its content, reading positions, sessions, bookmarks, highlights, notes and Ask the book index, and its stored files are removed;
- your profile photo, sign-in sessions and tokens are deleted;
- your name, email address, phone number and password are permanently removed from your account record, so the account can no longer be used or linked to you;
- remaining records — such as reading preferences, daily reading totals, collections, audit entries, and any reading history or annotations on books we have made available to all readers — are kept only in de-identified form, attached to a random identifier rather than to your name or email address.
Copies in backups are deleted when those backups expire (after 14 days). If you would like these de-identified records erased as well, contact us at info@effileap.com.
10. Your rights and choices
Under India’s Digital Personal Data Protection Act, 2023, you have the right to obtain a summary of the personal data we process about you and how we process it; to have it corrected, completed, updated or erased; to withdraw your consent; to nominate another person to exercise your rights if you die or become incapable; and to have your grievances addressed by us. If you are not satisfied with our response, you may complain to the Data Protection Board of India. If you live elsewhere, you may have additional rights under your local law.
You can update your name and profile in the app, and exercise your other rights by contacting us at info@effileap.com. We may need to verify your identity before responding, and we will respond within the time required by applicable law.
11. Children’s privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, please contact us and we will delete it.
12. Where your information is processed
Your information — including your account, your books, your reading data and our backups — is stored and processed on servers in India. Some service providers may process limited information in other countries: for example, the word you look up with Define is sent to the Free Dictionary API, and account emails pass through our email delivery provider. Where the law requires, we take appropriate steps to protect information transferred outside India.
13. Changes to this policy
We may update this Privacy Policy as the Service changes. We will post the updated version here with a new effective date and, if the changes are significant, tell you in the app or by email before they take effect.
14. Contact
For questions, requests or complaints about this Privacy Policy or your information, contact us:
- Effileap Technologies Pvt Ltd
- 1st Floor, Carnival Technopark, Technopark Phase 1 Campus, Trivandrum, Kerala, India
- Email: info@effileap.com
- Phone: +91 73547 73577
