Skip to content
Auris Reader
AurisReader
  • Features
  • Pricing
  • Download
  • About
  • Contact
  • Log in
  • Sign up
  • EN
  • FR
  • DE
  • IT
  • PT
  • ES
  • Features
  • Pricing
  • Download
  • About
  • Contact
  • Log in
  • Sign up

Privacy Policy

Summary: This Privacy Policy explains how we process your personal data when you browse aurisreader.com, contact us, create an account, purchase a license or use the Auris Reader applications (desktop and Android). Crucially, the content of the books and PDFs you open with Auris Reader is never sent to our servers. Two features do send text from your documents to a third party, directly from your device: the online voices, which are the default voice engine and receive the sentence being read, and online translation, only if you choose it, which receives the passage being translated. Section 12 explains both, and how to keep translation entirely on your device. The service is provided from the Canary Islands (Spain) and primarily uses infrastructure located in the European Union.

Last update: 23/09/2026
Contents
  • 1. Data controller
  • 2. Personal data we process
  • 3. Purposes and legal bases
  • 4. Recipients and data processors
  • 5. International transfers
  • 6. Retention periods
  • 7. Your rights
  • 8. Complaints
  • 9. Marketing and commercial communications
  • 10. Cookies
  • 11. Children
  • 12. Auris Reader apps — what stays on your device
  • 13. Changes to this Policy

1. Data controller

Trade name: Auris Reader
Controller: Jésica Carballo Yanes
Spanish Tax ID (NIF): 78633820-V
Registered address: Calle Santa Rosalía, 49, 1C, 38002, Santa Cruz de Tenerife, Spain
Email: info@aurisreader.com
Data Protection Officer (DPO): Not applicable

Information provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and, in Spain, Articles 11 and 12 of Organic Law 3/2018 (LOPDGDD).

2. Personal data we process

2.1. All visitors

When you browse the website, even without creating an account, we may process:

  • Contact form data: name, email address, subject area, message and the language you write to us in.
  • Anti-abuse data (reCAPTCHA): technical data collected by Google reCAPTCHA v3 in the registration, sign-in and contact forms.
  • Browsing and analytics data: if and when you accept the corresponding cookie category, we may collect data such as pages visited, time on page, device type and screen resolution. Such data is pseudonymised and used exclusively for the purposes described in section 3.7.
  • Security data: pseudonymised technical connection data used to prevent unauthorised access and abusive use.

2.2. Registered users

If you create an account or purchase a license, we additionally process:

  • Identification and contact data: name, email address and, optionally, country of residence.
  • Social sign-in data: if you choose to register or sign in with “Sign in with Google”, we receive from Google your email address, your name and a unique Google account identifier, solely to create or link your Auris Reader account. We never receive your Google password.
  • Account data: internal identifiers, hashed credentials and account status.
  • Subscription data: plan purchased, subscription status and transaction identifiers issued by the payment processor.
  • Payment data: handled directly by our external payment processor. We do not store full card numbers or bank account details on our servers.
  • License data: license keys, device tokens generated when you activate the app on a device, activation date and last validation timestamp.
  • Session logs: date and result of sign-in events and session tokens, for security purposes.
  • Support data: content of technical-support enquiries and replies.

2.3. Desktop and Android application usage data

When you use an Auris Reader application — the desktop app (Windows and Linux) or the Android app — it communicates with our servers only to sign in to and validate your account and subscription, to download the catalogues and packs you request (voices, interface languages, OCR and translation) and, on desktop, to retrieve software updates (the Android app is updated through Google Play). The application never sends to our servers:

  • The content of the EPUB or PDF files you open.
  • The audio generated by the text-to-speech engine.
  • The translations produced while you read.
  • Your reading positions or your library.

None of the above reaches our servers. What the online voices and online translation send to third parties is explained in section 12.

3. Purposes and legal bases

We process your data for the following purposes, based on the legal grounds set out in Article 6 GDPR:

3.1. Account management and service delivery

  • Purpose: account creation, authentication (including the optional “Sign in with Google” social login), pairing of your devices, license activation, account management, delivery of the downloadable packs (voices, interface languages, OCR and translation) and associated technical support.
  • Legal basis: performance of a contract or implementation of pre-contractual measures (Art. 6.1.b GDPR).

3.2. Subscription, payment and invoicing management

  • Purpose: processing of one-off and recurring payments, invoicing, plan changes and handling of payment incidents.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR) and, where applicable, compliance with legal obligations (Art. 6.1.c GDPR).

3.3. Customer enquiries and technical support

  • Purpose: to respond to enquiries and technical-support requests.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR) for registered users; legitimate interest of the controller in responding to the enquiry (Art. 6.1.f GDPR) for unregistered visitors.

3.4. Compliance with legal obligations

  • Purpose: to retain accounting and invoicing records, respond to requirements from public authorities and comply with applicable tax and consumer-protection legislation.
  • Legal basis: compliance with a legal obligation (Art. 6.1.c GDPR).

3.5. Security, fraud prevention and access logging

  • Purpose: to protect the website, the licensing API and the Auris Reader applications against unauthorised access, bots and abusive use, by means of technical security measures and, where applicable, verification through Google reCAPTCHA v3.
  • Legal basis: legitimate interest in ensuring the security of the service (Art. 6.1.f GDPR). The controller has assessed that this legitimate interest does not override the rights and freedoms of data subjects, given the technical and non-invasive nature of the data processed and the pseudonymisation measures applied.

3.6. Software-update delivery

  • Purpose: to inform the desktop application about the availability of new versions and to deliver patched releases.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR), as an integral feature of the licensed service, and legitimate interest in the secure maintenance of the software (Art. 6.1.f GDPR).

3.7. Web analytics and campaign measurement

  • Purpose: to analyse the use of the website in order to improve the service, measure the effectiveness of marketing campaigns and, where applicable, to display targeted advertising or build remarketing audiences on third-party platforms.
  • Legal basis: express consent (Art. 6.1.a GDPR), granted through the cookie banner by category. No analytics, marketing or advertising cookies — whether first-party or third-party — are installed without prior, specific acceptance of the corresponding category.
  • Tool and safeguards: for website analytics we use Google Analytics 4 (GA4), loaded with Google Consent Mode v2 with all storage categories defaulting to “denied”. No analytics cookie or identifier is set until you accept the analytics category in the cookie banner.
  • Automated decisions: audience segmentation, where applied, is indicative and used internally to prioritise communications. It does not produce legal or significant effects on the data subject (Art. 22 GDPR): it does not condition access to the service or the contractual terms.

3.8. Marketing and commercial communications

  • Purpose: to send communications about product updates, new features and promotions of the service and to measure their effectiveness through delivery, open and click-through tracking.
  • Legal basis: express consent of the data subject (Art. 6.1.a GDPR), granted at the moment of subscription, with the right to withdraw it at any time without affecting the lawfulness of processing carried out before such withdrawal (Art. 7.3 GDPR).
  • Opt-out: every commercial email contains a free unsubscribe link with immediate effect.

3.9. Promotional eligibility checks (free trial)

  • Purpose: to apply the condition that promotional offers are limited to one per user (section 13 of the Terms and Conditions), by checking whether the free trial has already been used with the same email address. The check determines only whether a subscription starts with a trial period or with payment from the first day; it never prevents the user from subscribing.
  • Data processed: a pseudonymised identifier derived from the email address (keyed HMAC-SHA256, never the address itself), the subscription identifier, the plan and the relevant dates. No name, no IP address and no account identifier are stored.
  • Legal basis: legitimate interest in preventing the abuse of a promotional offer and in the economic sustainability of the service (Art. 6.1.f GDPR). The controller has assessed that this interest does not override the rights and freedoms of data subjects: the identifier cannot be reversed without the key, which is not stored in the database; the least intrusive alternative (processing nothing at all) would make a published contractual condition impossible to apply; the user is informed of this verification before entering into the contract; and the outcome does not deny access to the service.
  • Retention: 24 months from the date the trial was granted, after which the record is deleted automatically. It is kept even if the account is closed, because otherwise the condition could not be applied (see section 6).
  • Automated decision-making: this is not a decision within the meaning of Art. 22 GDPR: it produces no legal effects and does not similarly significantly affect the user, since the service can be contracted in either case.

3.10. Reading aloud and translation in the applications

  • Purpose: to read aloud, with the online voices, the sentence you are reading and, if you choose an online translation engine, to translate the passage you are reading. The data involved are the text of that sentence or passage and, as with any internet connection, the IP address of your device; never an identifier of your account or information about which document you are reading.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR): reading aloud with neural voices is the core feature of the plan you subscribe to, and online translation is a function you decide to use.
  • Recipients: Microsoft for the voices; Google and, as a fallback, Translated Srl (MyMemory) for online translation. See sections 4, 5 and 12.

4. Recipients and data processors

Your data may be processed by the following providers, which act as data processors (Art. 28 GDPR) or as independent controllers, as indicated in each case:

  • Stripe Payments Europe, Ltd. (Ireland, EU) — payment processing and subscription management.
  • OVH SAS (France, EU) — web hosting, licensing-API infrastructure and delivery of the updates and of the other packs the apps download.
  • Amazon Web Services EMEA SARL (Luxembourg, EU) — storage and delivery of the translation packs the apps download, from a data centre in Paris (France). It receives the IP address of the device making the download and no account data, and acts as a data processor (Art. 28 GDPR).
  • Microsoft Ireland Operations, Ltd. (Ireland, EU) — Microsoft Edge online text-to-speech, the default voice engine in the desktop and Android apps. Each request contains only the sentence being read and the identifier of the chosen voice; Microsoft also receives, as with any internet connection, the IP address of your device. No user identifier and no information about which book you are reading is sent. Microsoft processes it as an independent controller, under its own privacy statement.
  • Google LLC (United States) — Google reCAPTCHA v3 in the registration, sign-in and contact forms; and “Sign in with Google” (OAuth) when you choose to register or sign in with your Google account, in which case Google, as the independent controller of your Google account, provides us with your email address, name and account identifier.
  • Google Ireland Limited (Ireland, EU, with possible technical sub-processors in Google LLC, USA) — Google Analytics 4 (GA4) for website analytics, loaded with Consent Mode v2 (storage denied by default) and active only after you accept the analytics cookie category. Data is collected in pseudonymised form.
  • Translated Srl (Italy, EU) — MyMemory, used by the applications as an automatic fallback for online translation when the selected provider does not respond, and only if you have selected an online translation engine. MyMemory is a public translation memory: the passages sent may be stored by the provider and served to other users of its service. See section 12 for what is sent and how to avoid it entirely.

Data may also be disclosed to public authorities or judicial bodies where there is a legal obligation to do so.

5. International transfers

Most of the providers used are established in the European Union and do not involve transfers outside the European Economic Area (EEA).

Processing by Google LLC (reCAPTCHA, “Sign in with Google”, Google Analytics and, in the applications, Google Translate when you select it as your online translation engine) may involve incidental transmission of data to servers in the United States. Such transfers are carried out under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, subsidiarily, under the standard contractual clauses approved by the European Commission. Transfers will only be activated to providers offering appropriate guarantees under Chapter V of the GDPR.

Microsoft Ireland Operations, Ltd. and Amazon Web Services EMEA SARL are established in the European Union. Where their parent companies in the United States (Microsoft Corporation and Amazon.com, Inc.) take part in the processing, the transfer is covered by the same EU-US Data Privacy Framework, under which both are certified.

Two clarifications about the online voices and online translation, because they are the only features in which text from your documents leaves your device. The transmission is made from your own device to the provider, at the moment you read: it does not pass through our servers, and we neither see nor store it. Consequently we cannot control or limit how long each provider keeps what is sent, and in the case of MyMemory — a public translation memory — it may remain available to other users of that service indefinitely. For translation, the offline engine avoids all of this: see section 12.

6. Retention periods

We retain personal data for as long as is necessary for the purposes described and, after the contractual relationship ends, for the periods legally required:

  • Accounting and invoicing records: minimum 4 years, in accordance with Law 58/2003 of 17 December, on General Taxation, and Royal Decree 1619/2012 of 30 November, on invoicing obligations. During that period these records may remain blocked, with restricted access (Art. 32 LOPDGDD). They are kept separately from operating data and survive account closure, because the right to erasure does not extend to data the provider must retain to comply with a legal obligation (Art. 17.3.b GDPR). They are deleted from our systems once the period expires; any records held by our payment processor (Stripe) are retained in accordance with its own retention policies.
  • Account operating data: for the duration of the account and up to 30 days after closure, during which the user may export their data or reactivate the account. After that period the data is deleted or anonymised.
  • License records: for the duration of the license and up to 24 months after expiry, to allow re-activation in case of disputes, and to comply with statutory limitation periods for warranty claims.
  • Security and access logs: up to 12 months, except where a legal obligation or an ongoing investigation requires longer retention.
  • When an account is closed, its security and access logs are deleted in full, without waiting for the 12-month period. All that is kept is a note that the deletion took place, with its date, with no user identifier, no IP address and no associated data: it cannot be linked to any person and exists only to evidence that the process works (Art. 5.2 GDPR).
  • Contact-form data:24 months from the date we receive the message in our database, from which it is deleted automatically once that period elapses. The copy that remains in the mailbox the enquiry is delivered to is kept for up to 24 months from our last reply. You may ask us to delete both at any time before then by writing to info@aurisreader.com (section 7).
  • Marketing data: until you withdraw consent or unsubscribe.
  • Newsletter subscription requests that are never confirmed:14 days from the request. A subscription only takes effect when you click the confirmation link we email you; that link is valid for 7 days, and we allow a further 7 so that you can request a new one. If it is never confirmed, the address is deleted outright — not merely flagged — because consent was never completed and keeping the data would run against the data minimisation principle (Art. 5.1.c GDPR).
  • Analytics and advertising data: while the user keeps the relevant cookies active. Withdrawal of consent through the cookie banner stops the collection of new data; data already collected by analytics or advertising providers will be retained in accordance with their own retention policies.
  • Consent evidence: for the time necessary to demonstrate that consent was lawfully obtained (accountability principle, Art. 5.2 GDPR).
  • Suppression list: minimum identifier (typically a hash of the email address) necessary to ensure that a person who has exercised the right to object is not contacted again; retained indefinitely as a proactive accountability measure (Art. 5.2 GDPR).
  • Promotional eligibility records: pseudonymised identifier derived from the email address, retained for 24 months from the date the free trial was granted, in order to apply the “one promotional offer per user” condition (section 13 of the Terms). It is kept even if the account is closed — otherwise the condition would be impossible to apply — and is deleted automatically once that period elapses.

7. Your rights

You may exercise the rights granted by the GDPR: access, rectification, erasure, objection, restriction of processing and portability, as well as withdrawing consent where applicable (Arts. 15 to 22 GDPR).

To exercise your rights, write to info@aurisreader.com stating which right you wish to exercise and attaching a copy of an identity document or any other means that allows us to verify your identity. We will reply within one month, which may be extended in the cases provided for by the GDPR.

Registered users can also delete their account and associated personal data directly from their account dashboard at aurisreader.com/account/, without writing to us.

8. Complaints

If you believe that the processing of your data does not comply with applicable law, you may file a complaint with the Spanish Data Protection Agency (AEPD) via its electronic site at aepd.es, or with the supervisory authority of your EU country of residence, without prejudice to any other administrative or judicial remedy.

9. Marketing and commercial communications

Auris Reader will only send you commercial communications if you have given express consent when creating your account or by subscribing to our newsletter (Art. 6.1.a GDPR and Art. 21.1 of Spanish Law 34/2002, LSSI-CE). Withdrawing consent does not affect the lawfulness of communications sent beforehand.

Every commercial email contains a free and easy-to-use unsubscribe link. You may also request unsubscription by writing to info@aurisreader.com with the subject line “Unsubscribe”. Objection takes effect immediately and the address is added to a suppression list to avoid future contact.

10. Cookies

The website uses strictly necessary technical cookies and, with your consent, analytics and marketing cookies where applicable. No non-essential cookie is installed without your prior acceptance through the cookie banner. You can accept, reject or configure each category independently and change your choice at any time through the cookie-management link in the footer.

For a detailed list of cookies, including provider, purpose, duration and how to manage them, see our Cookie Policy.

11. Children

The service is not directed at children under the age of 16 (or the equivalent age of consent under Article 8 GDPR in the user’s country of residence). We do not knowingly collect personal data from children without verifiable parental consent. If you believe that a child has provided us with personal data, please contact us at info@aurisreader.com and we will take appropriate action to delete that data.

12. Auris Reader apps — what stays on your device

Auris Reader runs as an application on your own device: the desktop app (Windows and Linux) and the Android app. Documents are opened and read on your device, and speech and translation are generated there too, except with the online voices and online translation described below. The following data is never sent to our servers, and none of it leaves your device except as explained below for those two features:

  • The content of the EPUB or PDF files you open.
  • The audio generated locally by the device’s text-to-speech engine.
  • The translations generated on your device (offline models on desktop; Google ML Kit on-device translation on Android).
  • Your reading position in each document and your library of recent documents.
  • The metadata of files stored on your device (titles, authors, covers).
  • A local copy of the translations already produced, so that re-reading a page or reopening a book does not have to request them again. It stores the translated fragments on your disk, deletes itself after 90 days without use and is size-capped. It is never sent anywhere; you can remove it at any time by clearing the application cache.

The only outbound communications the apps establish with our servers are:

  • Account sign-in and subscription validation: to sign in, both apps pair the device with your account — sending your account identifier and a device token generated locally — so we can authenticate you and confirm that your subscription is active. Periodic background validations confirm that it remains active.
  • Software-update checks (desktop only): the desktop app periodically queries our update server to determine whether a newer version is available; the query includes only the current version number and the operating system family, and no identifiers of the books you have opened. The Android app is updated through Google Play and does not query our update server.
  • Downloads you request: the catalogues of voices, interface languages, OCR and translation, and the packs you choose to install. These requests carry no account identifier. Translation packs are served from Amazon Web Services storage in Paris (section 4). On Linux, installing the offline translation engine also downloads its libraries from the Python Package Index (pypi.org), a public repository that receives the IP address of your device, as any download does.

The apps also communicate with the following third parties:

  • Microsoft Edge online text-to-speech (Microsoft Ireland Operations, Ltd.), the default voice engine in both apps. Each request contains the sentence to be read and the voice ID; Microsoft also receives the IP address of your device, as with any connection. No user identifier and no metadata about the book is included. If the connection drops, on Windows and Android the app switches to the voice installed on your device, which needs no network; on Linux, reading stops. If you open confidential documents, bear in mind that every sentence read aloud with the online voices reaches Microsoft.
  • Online translation providers (only if you select an online translation engine in the settings). On desktop, what is sent is the passage to be translated — the current sentence together with up to three preceding sentences, which are included so that the translation stays coherent — and the language pair. No user identifier, no account data and no information about which book you are reading is sent.

    Two providers may be used, and the app switches between them on its own. The engine you select is tried first (Google Translate, via Google LLC). If it does not respond, the app automatically falls back — to the offline engine when it is installed and covers that language pair, and otherwise to MyMemory (Translated Srl, Italy, EU) — so that reading is not interrupted, and tells you in the status bar which provider is in use. It does not ask you again each time.

    MyMemory is a public translation memory. This matters and we state it plainly: the passages sent to MyMemory may be stored by that provider and made available to other users of its service, which is how a shared translation memory works. Google Translate does not operate as a public memory, but it is still a third party outside our control. Do not use online translation on documents containing confidential information or personal data about identifiable people.

    How to avoid this completely. Select the offline engine (Opus-MT) in the app’s settings. It runs on your own computer, sends nothing anywhere, is free for every plan, and once selected the app will never fall back to an online provider behind your back. On Android, the default on-device translation uses Google ML Kit: the first time you use a language pair the app downloads the translation model files from Google (the model files only — the text you translate is not sent in that download), after which translation runs entirely on the device. Online translation on Android is off by default: if you turn it on, it is used only when the on-device model does not cover the language pair or fails, it uses Google Translate only, and it sends the paragraph being translated together with the last sentence of the previous one.

If you would like more detail about any of these communications, write to info@aurisreader.com.

13. Changes to this Policy

We may update this Privacy Policy to adapt it to legal, technical or service changes. The current version will always be published on this page with its last-update date. Where changes are significant, we will inform you through the channels available in the service.

Auris Reader updates

Get new features, voices and offers. No spam; unsubscribe anytime.

Product

  • Features
  • Pricing
  • Download
  • EPUB read aloud
  • PDF read aloud
  • For Windows and Linux
  • For Android
  • Reading guides

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Legal Notice
  • Cookie Policy
  • Cookie settings
Auris Reader

EPUB & PDF read aloud, with contextual translation.

© 2026 Auris Reader. All rights reserved.

Cookies and analytics We use Google Analytics cookies, only if you accept them, to understand how the site is used and improve it. We do not use advertising cookies. You can change your choice at any time from “Cookie settings” at the bottom of every page.
Cookie Policy