Privacy Policy
Applies to the Kabbik Reads Android application (com.kabbik.ebook_app)
and the Kabbik Reads service.
Last updated: 8 August 2026 · Effective: 8 August 2026
This policy explains what personal and sensitive user data Kabbik Reads collects, why we collect it, how we secure it, how long we keep it, and how you can have it deleted. Kabbik ("we", "us") is the data controller for the information described here. If anything below is unclear, write to support@wondersoftsolution.com.
In short: we collect the account details needed to sign you in, the purchase records needed to give you the books you paid for, and the reading positions needed to sync your place across devices. We do not sell your data, we do not run advertising or analytics SDKs, and we never receive your card or mobile-wallet credentials.
1. Data we collect
| Category | What it includes | Why we collect it |
|---|---|---|
| Account identity | Your name; your mobile number if you sign in by phone; your email address, Google account identifier, and profile picture URL if you sign in with Google. | To create and authenticate your account, and to restore your library when you sign in on another device. |
| Sign-in credentials | A one-time verification code sent to your phone, stored only in hashed form with an expiry and attempt counter. If you set a password, only a hash of it is stored. | To verify it is you signing in, and to limit brute-force attempts. |
| Profile preferences | Preferred categories you pick during onboarding, app language, theme, and whether onboarding is complete. | To set up the app the way you chose and to order the home feed. |
| Library and purchases | Books in your library and cart; order records containing amount, currency, status, payment method name, and the reference and transaction identifier returned by the payment gateway. | To give you access to the books you bought and to support refunds and billing queries. |
| Reading activity | Your position in each book, percentage complete, last-read time, per-day minutes read and pages turned, and any bookmarks, highlights, and saved quotes you create. | To sync your place across devices and to show your reading statistics. |
| Diagnostics | Crash reports and a sampled share of performance traces — stack traces, device model, OS version, and app version. | To find and fix crashes. Collected through Sentry with personally identifying request data disabled. |
What we do not collect
Kabbik Reads declares no runtime Android permissions. It does not access your location, contacts, camera, microphone, photos, files outside its own storage, SMS, call logs, or the list of apps installed on your device. The app contains no advertising SDK and no third-party analytics SDK. We do not collect data from children, and the app is not directed at children under 13.
2. How we secure your data
These are the specific measures that protect personal and sensitive user data in Kabbik Reads:
In transit
- All traffic between the app and our servers travels over HTTPS with TLS. The app makes no plaintext HTTP requests.
- The connection between our API and its database requires SSL in production.
At rest
- Passwords and one-time codes are never stored in readable form. Both are hashed with bcrypt before they are written to the database; we cannot recover the original value, and staff cannot read it.
- Your data is held in a managed PostgreSQL database on infrastructure that applies encryption at rest and is not exposed to the public internet.
- Books you download for offline reading are cached in the app's own private storage on your device, which other apps cannot read. Removing the app removes that cache.
Access control
- Every request for your data is authorised by a signed token bound to your account. One account cannot read another account's library, reading positions, or orders.
- Google sign-in tokens are verified on our server against Google's public keys before an account is matched or created. A token supplied by a client is never trusted on its face.
- Administrative access to the production database is limited to named Kabbik staff who need it to operate the service, over a separate credential set from the one the app uses.
Payments
- We never receive, process, or store your card number, PIN, OTP, or mobile-wallet credentials. Payment is completed on the payment provider's own page. We store only the outcome — the amount, the status, and the reference the provider returns — which cannot be used to charge you again.
3. How we share data
We do not sell your personal data, and we do not share it for advertising. We disclose it only to the service providers required to run Kabbik Reads, each acting on our instructions:
- Hosting and database — to run the API and store your account, library, and reading data.
- Payment gateway — to take payment for a purchase you initiate. They receive the transaction, not your reading data.
- Google — if, and only if, you choose Google Sign-In, to verify your identity.
- Sentry — to receive crash and performance diagnostics.
We may also disclose data where we are legally required to, or to investigate fraud or a violation of our terms. If Kabbik is ever involved in a merger or acquisition, we will give notice in the app before your data becomes subject to a different policy.
4. How long we keep it
- Account, library, and reading data — kept while your account is active, so your purchases and place in each book remain available.
- One-time verification codes — short-lived; they expire within minutes and are marked consumed once used.
- Order records — retained after account deletion where we are required to keep financial records, in a form no longer linked to your reading activity.
- Crash diagnostics — retained on a rolling window by our diagnostics provider and then discarded.
5. Deleting your data
You can ask us to delete your account and the personal data associated with it at any time. Email support@wondersoftsolution.com from the address or with the mobile number registered to the account, with the subject "Delete my account". Full instructions, including exactly what is deleted and what is retained, are on the account deletion page.
We will confirm the request, delete your account identity, library, cart, reading positions, sessions, statistics, bookmarks, highlights, and saved quotes within 30 days, and confirm in writing when it is done. Financial records we are obliged to retain are kept as described in section 4. Deleting your account ends access to books purchased under it.
You can also remove the locally cached copies of your books at any time by uninstalling the app or clearing its storage from Android Settings.
6. Your rights
You may ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, or delete it. You can edit your name, profile picture, and category preferences directly in the app under Profile. For anything else, contact support@wondersoftsolution.com and we will respond within 30 days.
7. Changes to this policy
If we change how we handle personal or sensitive user data, we will update this page and change the "Last updated" date above. Material changes will be announced in the app before they take effect.
8. Contact
Kabbik
Email: support@wondersoftsolution.com
Application: Kabbik Reads (com.kabbik.ebook_app) on Google Play