Skip to content
Glossa Apps

Weaver · Privacy

  • Privacy
  • Terms
  • Support

On this page

ScopeLocal dataData and purposesAssistant processingProvidersRetentionYour choicesSecurityInternational processingChildrenChanges and contact

Weaver

Privacy Policy

Effective and last updated August 26, 2026

Weaver is a reading app provided by RENATO MORAES PINHEIRO LTDA, operating as Glossa Apps in Brazil (“Glossa,” “we,” or “us”). This policy explains what Weaver processes, why, and the choices you have.

Scope and summary

This policy covers Weaver’s iOS and Android apps, related account and assistant services, and this website. It does not replace the privacy terms of the Apple App Store, Google Play, or third-party services you choose to use.

The short version: your reading library remains on your device by default. Weaver only sends limited information when you choose a connected feature, such as signing in, asking the assistant, searching for an image, reporting generated content, or making/restoring a purchase.

Books and reading data on your device

Imported EPUB and PDF files, their covers, reading progress, bookmarks, highlights, and notes stay on your device by default. Weaver does not operate a library-sync service or upload your full library for its own use.

On iOS, operating-system backup or device migration may include some app data under your Apple settings. On Android, Weaver excludes app-data backups. These platform processes are not a Weaver-managed library sync. Your local library is separate from any account and is not removed merely because you delete an account.

Data we process and why

Category and collectionPurpose
Account data. A pseudonymous device ID; Apple or Google identity subject when you sign in; optional verified email address or display name; and hashed or rotating session credentials.Create and protect an account, authenticate requests, provide account features, prevent abuse, and support deletion.
Current-book registration. Weaver may register limited book metadata: title, author, format, language, validated identifiers, and a local random book UUID. Depending on the platform, this metadata-only registration can happen after import, when the app starts or returns to the foreground, or before the first real assistant request for that book. It is separate from the just-in-time disclosure shown before an excerpt is first sent off device.Associate assistant use with the current book and support spoiler-aware/context features. We do not send book text, the file, or your full library inventory for registration.
Preferences and context. Reading/assistant preferences, stated intent, coarse location or contextual settings where a feature needs them.Tailor a requested response, language, and feature behavior.
Diagnostics. IP/network information, device or service identifiers, timestamps, status, timings, counts, and error categories.Operate, secure, debug, and measure reliability. Diagnostics do not include selected text, prompts, answers, report comments, credentials, or purchase tokens.
Subscriptions. Store order, status, and purchase-token data.Check entitlement, restore purchases, prevent fraud, and maintain subscription records. Payment card and billing-address data do not reach Weaver.

We do not sell personal data, show targeted advertising, or engage in cross-app tracking. Weaver does not use third-party advertising, analytics, or crash-reporting SDKs.

Assistant, recap, and report processing

When you actively ask Weaver’s assistant for help, it sends the selected text or bounded recap/context/evidence needed for that request, plus bounded book metadata, your preferences, and intent. It does not send the complete publication file, cover, annotations, or original images. A recap is bounded to the relevant reading context rather than the whole book.

Assistant outputs may be stored with the request so the feature can work, be secured, and investigated when needed. Normal assistant request and result payloads are retained for up to 7 days.

If you report generated content, Weaver sends controlled identifiers, a target, a reason, and an optional comment of up to 500 characters. The service may retain up to 8,000 characters of answer evidence or bounded image metadata to investigate the report. Reports are retained for up to 90 days.

Processors and third parties

We use providers only as needed to provide the requested service. Their own privacy terms can apply to their processing.

  • Cloudflare hosts this website and processes ordinary website request and network data.
  • Google Fonts supplies the website’s typefaces and receives an ordinary network request when those fonts load.
  • Apple and Google for sign-in and store billing.
  • Glossa-operated backend and private inference for the assistant and account service.
  • OpenRouter, only if a fallback route is enabled; that route is pinned to BaseTen and configured for zero data retention.
  • Openverse for bounded image search and thumbnails when you request that feature.
  • Open Library, Google Books, Wikipedia, and Wikidata for bounded catalog metadata.

Provider use and routing can change as features or availability require; this list does not mean every provider receives every request or is always active.

Retention

We retain account and live service data while your account is active, then remove it through the process below. Security, aggregate, and legally required records can remain as needed. Access-restricted disaster-recovery backups are recovery-only and rotate daily for up to 7 days and weekly for up to 35 days. Deletion does not promise immediate or complete removal from every backup, legal record, or provider copy.

Google Play purchase tokens are retained as needed to verify entitlement and prevent fraud. Terminal purchase tokens may remain for up to 90 days before removal; a one-way digest may remain afterward to detect replay or fraud without retaining the token itself.

Your choices and deletion

You can stop using connected features, choose not to sign in, adjust applicable device permissions, or withdraw assistant consent by no longer sending connected requests. You may contact us to ask for access to or correction of your account data, object to or restrict processing where applicable, withdraw consent, or exercise other rights available under local law. Some requests require identity verification.

You can request account deletion in the app or through our account-deletion page. Deletion removes live account data, identities, session credentials, linked book metadata, assistant history, usage records, reports, and subscription records. Shared nonpersonal catalog metadata can remain. Deidentified blocked-content fingerprints and records required by law or app stores can remain. Your local library remains on your device unless you remove it there.

Security

We use access controls, authenticated service connections, credential protections, limited retention, and operational monitoring designed to protect the service. No system is completely secure; please keep device and account access protected and do not send passwords, tokens, or full book text to support.

International processing

Glossa is based in Brazil. Our providers and infrastructure may process information in other countries. Those countries may have data-protection rules that differ from yours; we use appropriate safeguards available for the service and providers involved.

Children

Weaver is not directed to children under 13. If you believe we collected a child’s personal information without appropriate consent, contact us so we can review and delete it where appropriate.

Changes and contact

We may update this policy as Weaver changes. We will post the new effective date here. For privacy questions or requests, email [email protected], or use Weaver Support.

© 2026 Glossa Apps

PrivacyTermsSupportHome

Glossa Apps is operated by Renato Moraes Pinheiro LTDA, Brazil.