Litra

Privacy Policy

Effective September 4, 2026

Litra is a reading app for iPhone and iPad. It opens books and documents you already have, and it has an in-book assistant called Orb that answers questions about what you are reading. This policy explains, in plain terms, what data that involves, where it goes, and how to erase it.

The short version. Litra has no sign-up and never asks for your name, email or password. Your books, highlights, notes and chats live on your device and in your own private iCloud — not on our servers. When you ask Orb a question, the question and the passages of the book needed to answer it are sent to an AI provider for that single purpose. We do not sell your data, and we do not train any model on your books or your questions. Delete My Data in the app erases the account, its credits and the iCloud copy.

1. Who we are

"Litra", "we" and "us" mean the developer of the Litra iOS app and the operator of trylitra.app. You can reach us at serartinfo@gmail.com. For anything to do with your data, that address is the fastest route to a human.

This policy covers the Litra iOS app and this website. It does not cover Apple's App Store, or any website you reach by following a link out of the app.

2. No account, no login

Litra has no sign-up screen. We never ask for and never receive your name, email address, phone number, password, date of birth, or a social login.

Instead, the first time you launch the app it generates an anonymous identifier for you:

That identifier is a random-looking string. It is not derived from your name or email, and we cannot use it to learn who you are. It is what our server, our purchase provider and our analytics use to recognise a returning reader — nothing more. Because it lives in the Keychain and iCloud, it survives reinstalling the app; that is deliberate, so your subscription and credits come back without a login.

3. What stays on your device and in your iCloud

The content of your reading life does not go to our servers. This stays on your device, and syncs — if you have iCloud enabled — through your own private iCloud database, which is storage under your Apple ID that we cannot read:

Two features run entirely on the device and send nothing anywhere:

4. What our server stores

Litra's API runs on Cloudflare Workers. Its database holds the small amount of state that cannot honestly live on a device — money, mostly:

Usage records never contain your content. We store how many tokens a request cost, not what was in it. The text of your books, your questions and Orb's answers are not written to our database or to our analytics — that is a rule enforced in our own codebase, not a preference.

5. What goes to AI providers, and why

This is the part that matters most, so it is spelled out fully.

Orb cannot answer a question about your book without reading the relevant part of your book. Litra's API is a proxy in front of OpenRouter, which routes each request to the model that serves it. Four things travel that path:

Questions to Orb

When you ask Orb something, the app sends your question, the passages of the open document that Orb searched for and selected on your device, and the page you are currently on. Orb reads excerpts, not the whole book. Your conversation so far travels with the request, because that is what makes a follow-up question work.

Adding a book

When you add a book, Litra builds an index of it so Orb can find things later. To do that, the text of the book is sent, in chunks, to a Google Gemini model through OpenRouter. This is the one case where the whole text of a document passes through an AI provider. It happens once per book, in the background, and it is not charged to your credits.

Dictation

When you dictate instead of typing, the app records a short audio clip, sends it through our API to OpenRouter's transcription model, and inserts the returned text. The clip is not stored by us — it is forwarded, transcribed and dropped.

Cloud page recognition

If on-device recognition of a scanned page is not good enough and you choose to improve it, the page images are sent to a Google Gemini vision model through OpenRouter and returned as text.

The rules that apply to all four

6. Service providers

We use a small number of companies to run Litra. Each receives only what its job requires, and each is bound by its own agreement with us.

We may also disclose data if the law requires it, or to investigate fraud or abuse of the service. If Litra is ever acquired, this policy travels with the data and you will be told before anything changes.

7. Device permissions

Litra does not use your location, your contacts, your photo library, or your health data. It does not track you across other companies' apps and websites, and it contains no advertising or attribution SDKs.

8. Notifications

If you allow notifications, iOS gives the app a push token which we store against your anonymous identifier so we can send reading reminders. Turning notifications off in iOS Settings stops them; deleting your data (section 10) removes the token.

9. Retention

10. Deleting your data

Litra creates your account automatically, so it lets you delete it just as easily. In the app, open your profile and tap Delete My Data. After two confirmations, this:

It cannot be undone, and credits are not refunded. Two things survive on purpose, and neither is your account: an irreversible hash of the deleted identifier together with the last free credit period it claimed, and the device attestation key registration. Both exist so that deleting and recreating an account cannot be used as an unlimited source of free credits. Neither can be used to identify you or to restore anything.

Deleting your data does not cancel your subscription. Apple bills subscriptions, not us, and only you can cancel one — at apps.apple.com/account/subscriptions or in iOS Settings. The app reminds you of this before it deletes anything. If you prefer, you can also ask us at serartinfo@gmail.com and we will delete the account for you.

11. Your rights

Depending on where you live — for example under the GDPR in the EU and UK, or the CCPA in California — you may have rights to access, correct, export, restrict or erase the personal data a company holds about you, and to object to certain processing. We honour those rights.

Two practical notes. First, Litra holds no directly identifying data about you, so we usually cannot connect a request to an account without the identifier from the app itself. Second, the erasure right is already a button: Delete My Data (section 10) does more, and faster, than an emailed request. For anything else, write to serartinfo@gmail.com.

Where the GDPR applies, our legal bases are: performance of a contract for the account, credits, purchases and Orb answers you ask for; legitimate interests for security, abuse prevention, crash reporting and product analytics; and consent for notifications, the microphone and the camera, each of which you can withdraw in iOS Settings.

We do not sell or share personal information as those terms are defined by the CCPA, and we do not use it for cross-context behavioural advertising.

12. International transfers

Our providers operate in the United States and on globally distributed infrastructure, so data covered by this policy is processed outside your country, including in the United States. Where the GDPR applies, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism in each provider's data processing agreement.

13. Children

Litra is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has used Litra and you want the data removed, write to serartinfo@gmail.com.

14. Security

All traffic between the app and our API is encrypted with TLS. The API only answers requests from a genuine copy of Litra on real Apple hardware, verified with Apple's App Attest, and each session is authenticated with a signed token that carries the account identifier — so one reader cannot ask for another reader's data. The device's private attestation key never leaves its Secure Enclave. No system is perfect, and we do not claim otherwise; if you find a security problem, please tell us at serartinfo@gmail.com before disclosing it publicly.

15. Changes to this policy

If we change this policy we will update the effective date at the top, and for a material change — a new category of data, or a new purpose — we will tell you in the app before it takes effect. The current version always lives at trylitra.app/privacy.

16. Contact

Questions, requests, or anything about this policy: serartinfo@gmail.com. We answer in English.