Privacy Policy · Last updated September 22, 2026
Endpaper is a personal ereader app. It has no account system, no analytics, no advertising, and no server operated by the developer. This page explains, in full, everything the app does that touches your data.
Endpaper keeps a local database (on-device only, never transmitted to the developer) containing:
This data is excluded from iCloud backup where it's re-derivable (downloaded book files), and included where it's irreplaceable (your progress, highlights, and library index) — subject to your device's own iCloud/Backup settings. None of it is visible to, or accessible by, the developer.
Endpaper reads your book library from a folder in your Dropbox. You sign in directly with Dropbox, in Dropbox's own login screen, using the OAuth 2.0 standard — Endpaper never sees or stores your Dropbox password.
| Access scope | Read-only — account_info.read, files.metadata.read, files.content.read. Endpaper cannot create, modify, or delete anything in your Dropbox. |
|---|---|
| Folder scope | Restricted to Endpaper's own Dropbox App Folder — the app cannot see the rest of your Dropbox account. |
| What's stored | A refresh token, kept in the iOS Keychain (not UserDefaults, not iCloud-synced). It's used to reconnect without asking you to log in every time. |
| What's sent | Only the API calls needed to list and download the EPUB files in your library folder. |
You can disconnect Dropbox at any time from Settings, which removes the stored token from your device.
To fetch cover art, descriptions, and subject tags for books in your library, Endpaper can look them up against public book catalogues. The only information sent is the title, author, or ISBN already on the book file itself — never your reading history or personal information.
| Service | Purpose | Account needed? |
|---|---|---|
| Open Library | Primary catalogue lookup — descriptions, subjects, cover art | No — anonymous, no key |
| Google Books | Fallback lookup for titles Open Library doesn't have | Optional personal API key you provide, stored in Keychain |
Endpaper can suggest what to read next from books already in your library. This feature is off by default and requires you to choose a provider and enter your own API key in Settings. When you use it, the titles/authors used to build the suggestion are sent directly from your device to the provider you chose — never through a server run by Endpaper's developer — and billed to your own account with that provider.
| Provider | What happens |
|---|---|
| Anthropic (Claude) | Request sent directly to Anthropic's API using your personal API key |
| OpenRouter | Request sent directly to OpenRouter using your personal API key and chosen model |
| Cloudflare Workers AI | Request sent directly to your own Cloudflare account using your account ID and API token |
Each provider's own privacy policy governs how they handle that request. Endpaper does not log, store, or see the responses beyond displaying them to you.
Any API key you enter (Anthropic, OpenRouter, Cloudflare, Google Books) and your Dropbox refresh token are stored exclusively in the iOS Keychain, never in plain-text app storage, never synced to iCloud, and never transmitted anywhere except to the service the key belongs to.
Because everything lives on your device, deleting the app deletes your library index, reading progress, highlights, and stats along with it. Disconnecting Dropbox in Settings immediately removes the stored access token. There is nothing left behind on any server, because Endpaper's developer does not operate one.
If this policy changes, the "last updated" date at the top of this page will change with it. Since Endpaper has no way to contact you directly, please check back here if you have concerns.
Endpaper is an independent, personal project with no support inbox or company behind it. This page is the complete and current statement of its data practices.