Privacy Policy
Last updated: September 6, 2026
Overview
Acorny ("we", "our", "us") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use our services.
Information We Collect
Information You Provide
- Account Information — Email address and password when you create an account.
- Highlights & Notes — Text content you save through our browser extension.
- Kindle Notebook Data — When you click the Kindle sync button, book titles, authors, highlights, notes, and location labels from your Kindle Notebook.
- Review Data — Your spaced repetition progress and recall card responses.
Kindle sync is user initiated. We do not collect or transmit your Amazon password, cookies, or other login credentials, and we do not read Amazon store pages.
Information Collected Automatically
- Crash Diagnostics (mobile app only) — When the app crashes, we receive the error stack trace, device model, OS version, app version, and a random installation identifier generated by the crash reporting library. That identifier is not linked to your account and is regenerated if you reinstall the app. We do not collect screenshots, screen recordings, IP addresses, your search terms, your tags, or the contents of your highlights in crash reports. We do not collect performance traces, session health, or app-freeze reports.
- Failed-request Diagnostics (mobile app only) — When the app cannot load your account, your library, or your daily review, we send a short diagnostic note to the same error tracker so we can find out why. It contains a fixed label for which screen was loading (for example
me.profile), whether the failure was an HTTP error, a timeout, or a lost connection, and the HTTP status code. It does not contain the web address that was requested, your email, your search terms, your tags, or the contents of your highlights. This one is not a crash — the app keeps running and shows you a "couldn't load" message.
We do not use analytics, behavioural tracking, advertising identifiers, or device fingerprinting in any of our clients.
Mobile App Permissions & Local Data
The Acorny mobile app asks for the minimum it needs, and only when you use the feature that requires it.
- Notifications — Used only for the daily review reminder you turn on yourself. Reminders are scheduled entirely on your device; they do not go through our servers, and we do not store a push token. Turning the reminder off stops them immediately.
- Photo Library — Requested only when you tap "Save to Photos" on an exported highlight card. We ask for write-only access: the app saves one image and does not read your photo library.
- Google Sign-In — If you sign in with Google, we receive only an identity token used to verify who you are. We do not read your contacts, photos, or Drive files.
- On-Device Storage — Your session tokens and account identifier are kept in the operating system's secure storage; signing out clears them. A local cache holds your current review session (including highlight text) so the app works offline; it is cleared when you delete your account, and all of it is deleted when you uninstall the app. None of this local data leaves your device except as described above.
How We Use Your Information
- To provide and maintain the Acorny service.
- To sync your highlights and review progress across devices.
- To import the Kindle Notebook content you explicitly choose to sync into your Acorny account.
- To improve our spaced repetition algorithm based on aggregated, anonymized data.
- To send important service updates (you can opt out of non-essential emails).
Data Storage & Security
- Your data is stored on secure servers with encryption at rest and in transit.
- We do not sell, trade, or share your personal information with third parties for marketing purposes.
- You can export or delete your data at any time from the Settings page.
Third-Party Services
We use a small number of outside providers to run Acorny. Each receives only what the job below requires, and none of them receives your data for advertising or marketing.
- Railway (hosting) — Runs our backend service and our database, and therefore holds everything in your account: email address, highlights, notes and review progress.
- Resend (email delivery) — Receives your email address and the contents of the message, in order to send account verification and password-reset emails.
- DeepSeek (AI) — Receives the text of a single highlight, and returns question-and-answer recall cards made from it. This happens only when you ask for cards for that highlight — see below.
- Sentry (error tracking) — Receives the crash and failed-request diagnostics described under "Information Collected Automatically" above. It is Sentry's hosted service, not an instance we run ourselves.
About the AI recall cards. Acorny can turn one of your highlights into question-and-answer cards. This happens only when you ask for it, and only for the highlight you asked about. The text of that highlight — together with its source title, surrounding context and your own note, where those exist — is sent to DeepSeek, which returns the cards; we then store them in your account. Your email address, account identifier and login credentials are never sent. If you never use this feature, none of your highlights are sent to DeepSeek. The Acorny mobile app never sends anything to DeepSeek: generation is started from the browser extension or the web app, and the app only displays cards that already exist in your account.
Third-Party Accounts You Connect
Acorny lets you connect WeRead, Instapaper or Inoreader so their highlights sync in automatically. Connecting is entirely optional — one-time import and file import work without connecting any account.
When you connect, the credential you provide (an API Key for WeRead, account credentials for Instapaper, an OAuth token for Inoreader) is stored encrypted on our servers and used to periodically read your own highlights and notes on that platform. We only call read endpoints. We never modify, delete or publish anything in your account there.
What you should know about the WeRead API Key: it is bound to your WeRead account and carries no permission scopes. We only use it to call bookshelf, note and highlight read endpoints — but we cannot technically prove to you that it could not do more. If that is not acceptable to you, do not connect: manual import and file import remain available with identical functionality, they just need you to trigger them each time.
You can disconnect at any time on the Extensions & Apps page. Disconnecting deletes the credential from our database immediately.
Cookies
On the web, we use essential cookies only to maintain your login session. We do not use tracking or advertising cookies. The mobile app does not use cookies at all — it authenticates with a token held in the device's secure storage.
Your Rights
- Access — Request a copy of your personal data.
- Correction — Update inaccurate information.
- Deletion — Delete your account and all associated data.
- Export — Download your highlights and notes in standard formats.
Retention
We keep your account information, highlights, notes, and review progress for as long as your account exists. Deleting your account removes them.
For data stored only on your device: Signing out clears your session tokens and account identifier. The offline review cache is cleared when you delete your account or uninstall the app — signing out alone leaves it in place, so that signing back in on the same device does not have to re-download everything.
Deleting Your Acorny Account
You can delete your Acorny account and its data yourself, from either the mobile app or the web app. There is no waiting period and no need to contact us first.
How to delete your account
In the Acorny mobile app
- Open the Me tab.
- Tap Delete account.
- Confirm twice — the second step asks for your password, or for your email address if you signed up with Google.
In the Acorny web app
- Sign in at acorny.io and open Settings.
- Choose Delete account.
- Confirm with your password, or with your email address if you signed up with Google.
If you cannot sign in
Email us at hello@acorny.io from the address on the account and we will delete it for you.
What is deleted
Deletion is immediate and permanent — there is no grace period and no backup copy we can restore from. The following are erased from our servers:
- Your account record: email address, name, password hash, and Google account link.
- All highlights, notes, tags, and their sources.
- All review history, spaced repetition schedules, and recall cards, including AI generated ones.
- Any connected integration tokens and import history.
- All active sessions and sign-in tokens.
On your device, the offline review cache is cleared when you delete your account, and everything Acorny stored locally is removed when you uninstall the app.
What is kept
We keep security audit records — for example that a sign-in or a deletion happened, and when. These records let us investigate abuse and account takeover attempts, so we do not delete them.
They do not identify you after deletion. When you delete your account we clear the entire contents of those records — email address, IP address, device user agent, connected-service usernames, and every other detail — and the link between the records and your account is severed. All that remains is the type of event (for example "a sign-in happened") and its timestamp.
This also covers failed sign-in attempts made against your email address before you ever created an account. Going forward, when someone enters an email that has no Acorny account, we store only a one-way keyed hash of it, never the address itself.
We may also retain information where the law requires it, for as long as the law requires.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.
Contact
If you have questions about this Privacy Policy, please contact us at hello@acorny.io.