中文

HeRao Privacy Policy (International)

Effective: August 15, 2026
Last updated: August 15, 2026

This Policy applies to the international edition of HeRao Reader (“HeRao” or the “App”) distributed through Google Play. The data controller and App operator is HeRao Software Studio (“we,” “us,” or “our”). The currently intended download regions are Hong Kong, Taiwan, and the United States, primarily for users who read in Chinese.

Summary: HeRao is a local-first ebook reader with no advertising or built-in bookstore. Accounts, cloud reading archives, WebDAV, cloud speech, purchase verification, and diagnostic submission are online features. You may use the App offline without creating an account.

Book-content exception: We do not upload your book files, book titles, or body text to the developer server. However, when you actively select a system or cloud speech service, the text segments to be spoken are sent directly to that speech engine or to the server you configured. If you create a custom cloud voice, the reference audio and corresponding text you select are also sent to that server.

1. Information We Process

1.1 Local reading and local files

TXT and EPUB books, fonts, and other files you import or open, together with your shelf, reading position, table of contents, search history, bookmarks, notes, reading preferences, local speech models, and local voice-profile material, are primarily stored on your device or in a location you select and are processed locally. HeRao does not intentionally upload this information to the developer server.

Depending on your Android and Google Account backup settings, App databases and files not excluded by the App's backup rules may be backed up or transferred by Android. That processing is controlled by the operating system and account provider. The App excludes its dedicated account-session and entitlement preference files, WebDAV password files, cloud-speech credential files, and crash diagnostic packages, but other local data not excluded by those rules may still enter a system backup. You can manage system backup in Android or your Google Account settings.

1.2 Optional account and account security

When you register, sign in, or manage an account, we process your username, nickname, salted password hash, security question, hashed security answer, session token, a shortened hash derived from the Android device identifier, device name and model, registration and sign-in/sync timestamps, bound devices, and account status. Our server also receives the IP address normally accompanying a network request. IP addresses are recorded for registration, installation/trial checks, and diagnostic submissions.

We do not require your real name, telephone number, or email address. An account is not required for local reading.

1.3 Installation, trial, entitlement, and service requests

To prevent repeated trials, verify realm codes or entitlements, deliver remote catalog rules, and protect the service, the App may send the developer server a shortened hashed device identifier, OS version, App version, distribution flavor, rule-pack version/hash, first-online timestamp, and request IP address. These requests do not include book text, titles, or file paths.

1.4 Cloud “Reading Archive” (optional account feature)

The current international edition uploads only a lightweight aggregate snapshot: total reading time, total characters read, consecutive reading days, last reading date, cumulative digested characters, number of completed books, and number of touched books. A device identifier is included for device authorization. The current upload does not contain book files, titles, book identifiers, body text, chapter text, bookmarks, notes, per-book progress, or reading-footprint ranges.

1.5 Google Play purchases and subscriptions

When you buy or restore Pro benefits, Google Play processes your payment account and payment method. The App obtains the product ID, purchase token, and purchase type from Google Play and sends them, together with a device identifier, to the developer server to verify the purchase with Google, acknowledge the transaction, prevent token reuse, and synchronize your entitlement. The server may retain the Google order identifier, purchase and expiry times, transaction state, and account-linked entitlement. We do not receive your full payment-card number.

1.6 Crash diagnostics (submitted only by your choice)

After an abnormal exit, the App creates a minimized diagnostic package locally and asks you to Submit or Dismiss it. It is uploaded only after you tap Submit. If submission fails after you have expressed that intent, the App may retry automatically over Wi-Fi.

An international-edition diagnostic package may include the crash type and stack frames (without the exception-message text), device model/manufacturer/OS/CPU architecture, App version and flavor, numeric reading-state summary such as chapter/page, recent engineering event types and times, and parser-mode summary. The upload server also records receipt time, IP address, package name, version, file size, and checksum. The package does not include book body text, original book titles, original filenames, file paths, account passwords, or raw native crash dumps.

1.7 Cloud speech, system speech, and custom voices (actively enabled by you)

Cloud-speech API keys, secrets, tokens, and service addresses are stored in App-private storage, with Android encrypted storage used where available. On devices where the system encrypted store is unavailable, some credentials may fall back to private App storage. An AngeVoice key is not saved if encrypted storage is unavailable.

1.8 WebDAV and Wi-Fi transfer (actively enabled by you)

Your WebDAV server address, username, directory, and password/token are stored on the device; the password/token uses Android encrypted storage where available. When you choose to import, back up, or migrate, books, reading archives, or migration packages are transferred directly between your device and the WebDAV service you selected. The developer server does not handle them. Public WebDAV endpoints must use HTTPS; HTTP is accepted only for private LAN addresses.

Wi-Fi transfer temporarily starts a local HTTP file service after you enable it. A browser on the same LAN sends the selected file and filename directly to your device. The transfer does not pass through the developer server. Use this feature only on a trusted network and stop it when finished.

2. Why We Process Information

Where applicable, we rely on performance of the service contract, your consent, our legitimate security and operational interests, or legal obligations. Processing related to an optional feature occurs when you enable, configure, or submit that feature. You may choose not to use it.

3. Permissions

4. Sharing and Third Parties

We do not sell personal information, serve advertising, or share personal information for cross-context behavioral advertising. Where a feature requires it, information may be processed by:

Information processed directly by a third party is governed by that party's terms and privacy policy. In particular, confirm that your selected cloud speech, system TTS, WebDAV, or self-hosted service is appropriate for the content of your books.

5. International Transfers and Security

If you are outside Mainland China, account, purchase-verification, diagnostic, and other developer online services involve an international transfer. Google, cloud-speech, WebDAV, and model-hosting providers may also process information outside your country or region, depending on your selected provider and service region.

The principal transfer arrangements are:

The international edition uses HTTPS for public developer and built-in cloud services. Public WebDAV connections and international-edition AngeVoice addresses must also use HTTPS. Local Wi-Fi transfer uses HTTP within the LAN. We use access controls, hashed credentials, App-private/encrypted storage, minimized diagnostic fields, and backup exclusions, but no storage or transmission method can guarantee absolute security.

6. Retention and Deletion

To delete your account in the App, go to Settings → Account & security → Delete current account, or see the account-deletion instructions. Deleting the HeRao account does not automatically cancel a Google Play subscription; manage the subscription separately in Google Play.

7. Your Choices and Rights

At first launch, you may accept this Policy to enable online features or choose offline use. You may stop using cloud speech, WebDAV, Wi-Fi transfer, or account sync, revoke microphone permission, and clear the corresponding settings and local data.

You may view or change your nickname, password, and security information in the App and may delete your account. To request access to, correction of, deletion of, or a copy of other personal information we hold, or to object to or restrict processing or withdraw consent, contact us below. We may need to verify the account or request. Withdrawal does not affect processing already lawfully performed.

8. Notices for Intended Regions

9. Children

HeRao is a general-audience reading tool and is not directed to children under 13. Users under 13 must not independently create an account or use features that transmit data to external services. A higher local age applies where required by law. A parent or guardian who believes a child provided us personal information may contact us to request deletion.

10. Changes to This Policy

We may update this Policy when features, processing, or legal requirements change. We will change the date above and, where a change materially affects your rights, provide an in-App or other appropriate notice and obtain renewed consent where required.

11. Contact Us