HeRao Privacy Policy (International)
Last updated: August 15, 2026
This Policy applies to the international edition of HeRao Reader (“HeRao” or the “App”) distributed through Google Play. The data controller and App operator is HeRao Software Studio (“we,” “us,” or “our”). The currently intended download regions are Hong Kong, Taiwan, and the United States, primarily for users who read in Chinese.
Summary: HeRao is a local-first ebook reader with no advertising or built-in bookstore. Accounts, cloud reading archives, WebDAV, cloud speech, purchase verification, and diagnostic submission are online features. You may use the App offline without creating an account.
Book-content exception: We do not upload your book files, book titles, or body text to the developer server. However, when you actively select a system or cloud speech service, the text segments to be spoken are sent directly to that speech engine or to the server you configured. If you create a custom cloud voice, the reference audio and corresponding text you select are also sent to that server.
1. Information We Process
1.1 Local reading and local files
TXT and EPUB books, fonts, and other files you import or open, together with your shelf, reading position, table of contents, search history, bookmarks, notes, reading preferences, local speech models, and local voice-profile material, are primarily stored on your device or in a location you select and are processed locally. HeRao does not intentionally upload this information to the developer server.
Depending on your Android and Google Account backup settings, App databases and files not excluded by the App's backup rules may be backed up or transferred by Android. That processing is controlled by the operating system and account provider. The App excludes its dedicated account-session and entitlement preference files, WebDAV password files, cloud-speech credential files, and crash diagnostic packages, but other local data not excluded by those rules may still enter a system backup. You can manage system backup in Android or your Google Account settings.
1.2 Optional account and account security
When you register, sign in, or manage an account, we process your username, nickname, salted password hash, security question, hashed security answer, session token, a shortened hash derived from the Android device identifier, device name and model, registration and sign-in/sync timestamps, bound devices, and account status. Our server also receives the IP address normally accompanying a network request. IP addresses are recorded for registration, installation/trial checks, and diagnostic submissions.
We do not require your real name, telephone number, or email address. An account is not required for local reading.
1.3 Installation, trial, entitlement, and service requests
To prevent repeated trials, verify realm codes or entitlements, deliver remote catalog rules, and protect the service, the App may send the developer server a shortened hashed device identifier, OS version, App version, distribution flavor, rule-pack version/hash, first-online timestamp, and request IP address. These requests do not include book text, titles, or file paths.
1.4 Cloud “Reading Archive” (optional account feature)
The current international edition uploads only a lightweight aggregate snapshot: total reading time, total characters read, consecutive reading days, last reading date, cumulative digested characters, number of completed books, and number of touched books. A device identifier is included for device authorization. The current upload does not contain book files, titles, book identifiers, body text, chapter text, bookmarks, notes, per-book progress, or reading-footprint ranges.
1.5 Google Play purchases and subscriptions
When you buy or restore Pro benefits, Google Play processes your payment account and payment method. The App obtains the product ID, purchase token, and purchase type from Google Play and sends them, together with a device identifier, to the developer server to verify the purchase with Google, acknowledge the transaction, prevent token reuse, and synchronize your entitlement. The server may retain the Google order identifier, purchase and expiry times, transaction state, and account-linked entitlement. We do not receive your full payment-card number.
1.6 Crash diagnostics (submitted only by your choice)
After an abnormal exit, the App creates a minimized diagnostic package locally and asks you to Submit or Dismiss it. It is uploaded only after you tap Submit. If submission fails after you have expressed that intent, the App may retry automatically over Wi-Fi.
An international-edition diagnostic package may include the crash type and stack frames (without the exception-message text), device model/manufacturer/OS/CPU architecture, App version and flavor, numeric reading-state summary such as chapter/page, recent engineering event types and times, and parser-mode summary. The upload server also records receipt time, IP address, package name, version, file size, and checksum. The package does not include book body text, original book titles, original filenames, file paths, account passwords, or raw native crash dumps.
1.7 Cloud speech, system speech, and custom voices (actively enabled by you)
- System TTS: Text to be spoken is handed to the Android speech engine selected on your device. The engine may process it locally or online under its own policy.
- Cloud TTS: If you select Qwen/DashScope, Tencent Cloud, Volcengine, Alibaba Cloud NLS, Microsoft Azure, or a custom AngeVoice service, the App sends text segments, voice/model/rate parameters, and required credentials directly to that service. Returned audio is received on the device and may be cached locally under your settings. The developer server does not relay or retain these text segments or user-supplied cloud credentials.
- Custom cloud voices: When you explicitly create one, the App uploads your recorded or imported reference audio, reference text, voice name, and voice ID to the AngeVoice service you configured. Storage and deletion are controlled by that service's operator.
- Local Sherpa/ZipVoice: Model inference, microphone recordings, reference text, and local voice profiles are processed on the device. A model host receives ordinary network information, such as IP address and request time, when you download a model, but not your book text.
Cloud-speech API keys, secrets, tokens, and service addresses are stored in App-private storage, with Android encrypted storage used where available. On devices where the system encrypted store is unavailable, some credentials may fall back to private App storage. An AngeVoice key is not saved if encrypted storage is unavailable.
1.8 WebDAV and Wi-Fi transfer (actively enabled by you)
Your WebDAV server address, username, directory, and password/token are stored on the device; the password/token uses Android encrypted storage where available. When you choose to import, back up, or migrate, books, reading archives, or migration packages are transferred directly between your device and the WebDAV service you selected. The developer server does not handle them. Public WebDAV endpoints must use HTTPS; HTTP is accepted only for private LAN addresses.
Wi-Fi transfer temporarily starts a local HTTP file service after you enable it. A browser on the same LAN sends the selected file and filename directly to your device. The transfer does not pass through the developer server. Use this feature only on a trusted network and stop it when finished.
2. Why We Process Information
- To provide local reading, account access, synchronization, speech, backup, purchasing, and support features you request;
- To verify trials and paid entitlements and prevent fraud, abuse, and purchase-token reuse;
- To diagnose faults when you choose to submit diagnostics and to maintain App stability and security; and
- To comply with applicable accounting, transaction, consumer-protection, and legal obligations.
Where applicable, we rely on performance of the service contract, your consent, our legitimate security and operational interests, or legal obligations. Processing related to an optional feature occurs when you enable, configure, or submit that feature. You may choose not to use it.
3. Permissions
- Files: Android's system picker is used to read books, fonts, models, backups, or audio you explicitly select and to write to a directory you select.
- Microphone: Requested only when you actively record reference audio for a local or custom voice. Denying it does not affect ordinary reading.
- Network and Wi-Fi state: Used for online features, WebDAV, model downloads, and LAN transfer.
- Notifications, foreground services, and wake lock: Used for speech playback, transfer/sync progress, floating or notification controls, and playback while the screen is off.
4. Sharing and Third Parties
We do not sell personal information, serve advertising, or share personal information for cross-context behavioral advertising. Where a feature requires it, information may be processed by:
- Developer servers and hosting/network providers: Account, entitlement, reading-archive, purchase-verification, and submitted diagnostic data. The primary developer server is currently hosted in Mainland China.
- Google Play / Google: App distribution, updates, Billing, subscription management, and purchase verification. Under some network conditions, purchase verification may reach Google through a verification relay hosted in Hong Kong.
- Your selected speech provider: Microsoft Azure, Alibaba Cloud and DashScope, Tencent Cloud, Volcengine, your system TTS provider, or an AngeVoice service you configure.
- Your selected storage and model host: Your WebDAV provider, GitHub, ModelScope, or another model source displayed in the App.
- Required legal disclosure: Only where reasonably necessary for legal process, security, or protection of rights.
Information processed directly by a third party is governed by that party's terms and privacy policy. In particular, confirm that your selected cloud speech, system TTS, WebDAV, or self-hosted service is appropriate for the content of your books.
5. International Transfers and Security
If you are outside Mainland China, account, purchase-verification, diagnostic, and other developer online services involve an international transfer. Google, cloud-speech, WebDAV, and model-hosting providers may also process information outside your country or region, depending on your selected provider and service region.
The principal transfer arrangements are:
- Developer online services — Mainland China: Recipients are HeRao Software Studio and its server hosting/network providers. When you register, sign in, synchronize a Reading Archive, check a trial or entitlement, verify a purchase, or submit diagnostics, the applicable account and security information, hashed device identifier, IP address, aggregate reading data, purchase-verification data, or diagnostic data is transmitted over HTTPS. Purposes and retention are described in Sections 2 and 6.
- Google Play purchase verification — Hong Kong and Google's processing locations: When you purchase or restore an entitlement, product ID, purchase token, purchase type, and device identifier may pass through the Hong Kong verification relay before being sent to Google. Order and entitlement records are retained as described in Section 6.
- External services selected by you — selected service location: When you enable system/cloud speech, WebDAV, model download, or a custom AngeVoice service, the data identified in Section 1 is sent directly by your device to the provider you select or configure. The recipient, country/region, and retention depend on the provider and endpoint you choose and that provider's policy. You do not have to enable these features.
The international edition uses HTTPS for public developer and built-in cloud services. Public WebDAV connections and international-edition AngeVoice addresses must also use HTTPS. Local Wi-Fi transfer uses HTTP within the LAN. We use access controls, hashed credentials, App-private/encrypted storage, minimized diagnostic fields, and backup exclusions, but no storage or transmission method can guarantee absolute security.
6. Retention and Deletion
- Local data: Generally retained until you delete it in the App, clear App data, or uninstall. Copies you place in an external directory, WebDAV, or system backup must be deleted separately.
- Account and Reading Archive: Generally retained while your account exists. After successful account-deletion verification, current server logic deletes the main account record, account device bindings, and associated cloud Reading Archive.
- Installation/trial, anti-abuse, and transaction records: Device-first-seen/trial records, purchase verification, and order status may be retained independently of the account for entitlement reconciliation, fraud prevention, disputes, and legal obligations, for as long as reasonably necessary for those purposes.
- Diagnostics: An unsubmitted local package is kept for no more than seven days or deleted immediately when you dismiss it. Uploaded diagnostics and associated IP/metadata are retained only as reasonably necessary for fault analysis and security and can be deleted by operations staff.
- Third-party data: Google, speech providers, WebDAV, system backup, and model hosts retain information under their own policies. Deleting your HeRao account does not automatically delete those copies.
To delete your account in the App, go to Settings → Account & security → Delete current account, or see the account-deletion instructions. Deleting the HeRao account does not automatically cancel a Google Play subscription; manage the subscription separately in Google Play.
7. Your Choices and Rights
At first launch, you may accept this Policy to enable online features or choose offline use. You may stop using cloud speech, WebDAV, Wi-Fi transfer, or account sync, revoke microphone permission, and clear the corresponding settings and local data.
You may view or change your nickname, password, and security information in the App and may delete your account. To request access to, correction of, deletion of, or a copy of other personal information we hold, or to object to or restrict processing or withdraw consent, contact us below. We may need to verify the account or request. Withdrawal does not affect processing already lawfully performed.
8. Notices for Intended Regions
- United States: We do not sell or “share” personal information for cross-context behavioral advertising and do not conduct third-party advertising tracking. Because the App does not perform such tracking, browser Do Not Track or Global Privacy Control signals do not change the App's processing. If a U.S. state privacy law applies to us, you may use Section 7 to request access, correction, deletion, a copy, or opt-out of applicable processing. We will not discriminate against you for exercising applicable rights.
- Hong Kong: Providing account, device-identifier, diagnostic, or other online data is voluntary. If you do not provide it, only the corresponding online feature is unavailable; offline reading remains available. Purposes, data classes, possible recipients, and access/correction procedures are in Sections 1, 2, 4, and 7.
- Taiwan: This Policy states our identity, purposes, personal-data categories, period, regions, recipients, methods of use, and the effect of not providing data. Through Section 7, you may request inquiry or review, a copy, supplementation or correction, cessation of collection/processing/use, and deletion, subject to legal and service-performance exceptions.
9. Children
HeRao is a general-audience reading tool and is not directed to children under 13. Users under 13 must not independently create an account or use features that transmit data to external services. A higher local age applies where required by law. A parent or guardian who believes a child provided us personal information may contact us to request deletion.
10. Changes to This Policy
We may update this Policy when features, processing, or legal requirements change. We will change the date above and, where a change materially affects your rights, provide an in-App or other appropriate notice and obtain renewed consent where required.