Walnut Reader · Legal
Privacy policy
Walnut Reader collects nothing about you and sends nothing anywhere. Everything below is the detail behind that one sentence — what the app keeps, where it keeps it, and what it has no way of doing.
Contents
01
The short version.
We do not know who you are, what you read, or even that you opened the app. Nothing you read leaves your device unless you send it yourself.
There is no Walnut Reader account to create and no Walnut Reader server to talk to. The app has no analytics, no advertising, no crash reporting and no third-party code of any kind. Your books, your place in them, your bookmarks and your reading statistics live in the app's own database, in the app's own sandbox, on the device in your hand.
02
What the app keeps, and where.
Walnut Reader is only useful if it remembers things, so it does — on your device, in your own copy of the app. All of the following stays there:
- Your library. Each book's title, author, cover thumbnail, file name and format — the metadata that draws the shelf.
- Your place in each book. How far in you are, plus the exact chapter-and-character position the reader restores to, so a font change never loses your line.
- Bookmarks. The saved position and the label the app captured for it when you tapped the ribbon.
- Collections. The shelves you named, and the order you arranged them in.
- Reading history. One record per session: when it started, how long the reader was actually on screen, and how many pages you moved forward. The clock runs only while the app is in the foreground and the reader is open.
- Reader settings. Theme, typeface, text size, margins, alignment, reading mode, page-turn style, portrait lock, and how your library is sorted and laid out.
- Fonts you import, kept beside the app's data so your typeface stays in the menu.
- The book files themselves — EPUBs and PDFs, as ordinary files in the app's folder (On My iPhone → Walnut Reader, visible in the Files app).
None of it is transmitted anywhere. There is no copy on a server, because there is no server.
03
What we never collect.
The absence is the policy, so here it is explicitly, category by category:
- Contact details. No name, email address, phone number, or account of any kind. The app has no sign-up and no login.
- Identifiers. No advertising identifier (IDFA), no device or vendor identifier sent anywhere, no fingerprinting, no hashed email.
- Location. The app never asks and has no way to know where you are.
- Usage and diagnostics. No telemetry, no crash reports sent to us, no event funnels, no session recording, no A/B testing service.
- Your content. Your books, bookmarks and reading history are never uploaded, scanned, mined or read by us. Searching inside a book happens on your device.
- Advertising and cross-app tracking. No ad network, no ad SDK, and no App Tracking Transparency prompt — there is nothing to track with and nothing to ask permission for.
- Third-party SDKs. None. The app is Apple's frameworks plus its own code.
04
Does the app use the network?
The app itself makes no network requests. Nothing is fetched at launch, nothing is phoned home, and no Walnut Reader server exists to receive it. The app contains no networking code, so this is a property of the build rather than a promise about behaviour.
The one place the wider internet appears is Find Books. Tapping Standard Ebooks or Project Gutenberg hands the address to Safari — iOS opens your browser and Walnut Reader steps aside. From that moment the destination site's own privacy policy, and Apple's, apply: they see a normal browser visit, the same as if you had typed the address yourself.
An EPUB you download there lands in your Files app, and you add it to the library with Add Books — exactly like a file you copied over yourself. Nothing about your library or your reading is shared with those sites, because the app never talks to them; it only opens a page for you.
05
iCloud, backups and copies.
Walnut Reader 1.0 does not use iCloud. There is no Walnut account, no cloud sync, and no server-side copy of your library — a book you add on your iPhone stays on that iPhone.
iOS itself, though, backs devices up. If iCloud Backup is on, or you back up to a computer, the app's data can be part of that device backup. That copy is made and stored by Apple under your Apple ID, governed by Apple's privacy policy and your own iCloud settings — not by us, and not visible to us. You can leave an app out of iCloud Backup under Settings → your name → iCloud → Manage Account Storage → Backups (the exact wording moves between iOS versions).
If a future version adds sync, this policy will be updated before that version ships — not after.
06
Sharing and export.
Nothing leaves the app unless you send it. Settings → Export App State builds a single JSON file containing your progress, bookmarks, Continue Reading and Finished state, collections, reading history and reader settings — not the book files — and hands it to the standard iOS share sheet.
Where it goes from there is your decision: Save to Files, AirDrop, Mail, a note-taking app. Whatever you pick then handles that file under its own privacy policy. Import App State reverses it, reattaching that state to the books already in your library.
07
Permissions the app asks for.
None. Walnut Reader has no notification permission, no location, no camera, no photo library, no contacts, no microphone, and no tracking prompt. You will never see a permission dialog from this app.
Files-app access is switched on, which is what makes the library folder visible in Files so you can drop a book into it — that folder is yours, on your own device.
08
Children's privacy.
Walnut Reader collects no personal information from anyone, of any age — including children under 13. There is no account to make, no profile to fill in, no advertising, no in-app purchase and no user-generated content, so there is nothing a child could submit and nothing for us to hold.
The sixteen bundled classics are public-domain editions, and they arrive only when you ask for them.
09
Your control over your data.
Because everything is local, you already hold the controls a privacy page usually has to promise you:
- Change or remove anything. Long-press a book to rename it or file it onto a shelf; delete it and its file goes too.
- Reset Settings puts every reading preference back to its default. Books, progress, bookmarks and history are untouched.
- Reset All Data, on its own confirmation screen, wipes the library, the book files, imported fonts, reading history, caches and settings — a fresh install, deliberately two taps away.
- Reset All Statistics clears the reading record alone; books, shelves and bookmarks stay where they are.
- Delete the app and everything it holds goes with it.
- Move it — Export App State carries your reading life to another device as a file you control.
10
Changes to this policy.
This policy is dated, and the date at the top of the page is the version in force. If it changes, the new version appears here with a new effective date, and any material change is described in the App Store release notes for the version that makes it.
This page will not be quietly rewritten to permit collection that it rules out today. A future version that collected anything would have to say so plainly, here and in the App Store listing, before it shipped.
11
This website.
These pages are plain HTML, CSS and a little JavaScript. There are no cookies, no analytics, no advertising, no tracking pixels, and no third-party scripts, fonts or images — the typefaces are the ones already on your device.
The one thing stored in your browser is the colour theme you picked (Auto, Light, Sepia or Dark), held in your browser's own local storage under the key wr-theme and shared with the app's marketing page. Clearing site data removes it. Nothing about it is sent anywhere.
If this site is served from a hosting provider, that provider may keep ordinary server logs — IP address, time, page requested — as every web server does. Those logs are theirs to hold and are not used to build profiles.
12
Contact.
Questions, corrections, or a formal request about this policy: walnut@benfrancis.me. A person reads that inbox.
Walnut Reader is made by one developer. There is no privacy team, no data processor to name, and no data transfer to describe — because there is no data. If that ever stops being true, this page will be the first thing to change.
That is the whole policy.
No account, no server, no tracking, no analytics — and no fine print waiting further down the page. If you want to check it against the app itself, the marketing site explains what the reader does with your books; this page explains what it does with everything else.