Mark&Meter
GuidesPrivacy
Menu
GuidesPrivacy
Open reader

Privacy

Your books stay yours.

Last updated: September 19, 2026

Operator

This deployment is operated by David D. — contact: [email protected].

Local processing

Mark & Meter processes EPUB, TXT, and HTML files in your browser. Extracted text and progress are saved in IndexedDB. We do not operate an upload or book-content backend.

The app uses localStorage only for two small convenience values: an opaque last-opened book ID used for navigation and Focus session preferences. These values never contain book text, title/author metadata, reading progress, or stats. If browser policy blocks localStorage, reading and sessions continue, but those conveniences are not retained.

Public-page analytics and access logs

Static public pages use a self-hosted Umami tracker at analytics.daviddh.dev. The reviewed tracker is vendored in this release, so remotely mutable JavaScript is never loaded into this origin. It sends pageviews only from public pages: the page URL with query strings and hashes removed, page title, referrer, browser language, screen size, and information used to derive browser, operating system, device type, and country. The source IP is used by Umami to infer location and an anonymous session hash, but the raw IP is not stored. We do not assign a distinct or account-linked user ID. No cookies, custom events, session replay, or performance data are used. The tracker reads only the optional umami.disabled local-storage flag, and respects the browser’s Do Not Track setting. The reader under /app and /app/read, including history fallbacks, has no tracker tag, analytics request, or collector CSP permission.

Umami is self-hosted and retains analytics indefinitely by default; it has no built-in rolling 90-day TTL. This deployment makes no public 90-day retention claim until the operator has configured and evidenced a safe deletion procedure. The launch gate requires an operator review at least every 90 days; if no supported rolling deletion is available, the only approved fallback is an explicitly recorded manual full reset of the analytics database, which deletes all analytics rather than selectively deleting aged rows. The repository does not perform destructive cleanup.

Public access logs do not record reader paths under /app or /app/read. Public-page entries use the URI path without query strings and an anonymized client address. The production host/Dokploy log policy must be configured before launch to rotate and delete every copy within a maximum of 7 days. Subject to that deployment control, public logs are kept for up to 7 days; the repository cannot enforce host retention.

Backups and deletion

You control exports, restores, and deleting books in the app. Browser storage can also be cleared through your browser settings. Backup JSON contains metadata, settings, progress, and hashes—not the extracted words. There is no server-side user-data backup: service recovery is a redeploy of a known-good image, while copies of your library are your responsibility. We never promise to restore books.

Contact

Questions about this deployment: [email protected].

Mark & Meter · Find your mark. Set your pace.
PrivacyTermsAccessibilityContact