TMO BOOKS · PRIVACY
Privacy Policy
This policy explains when PDF text leaves your device and how TMO Books handles account, translation, purchase, advertising, and optional analytics data.
Effective: September 13, 2026
- PDF files
- Your library, reading position, and bookmarks stay on your device and are not synced to the TMO Books server.
- Online translation
- Only after consent, extracted text from the requested page and the target language travel through the TMO Books server to Google Gemini.
- Translation cache
- Successful results are encrypted with AES-256-GCM per account and remain valid in the app for up to 90 days.
- Sign-in
- A one-time code is sent by email. A server session normally expires after 30 days and may end sooner.
Operator and privacy contact
- Business name
- 티모지지
- Representative
- 백창명
- Business registration no.
- 523-21-02791
- Business address
- 서울특별시 관악구 승방길 27, 제A동 제B102호 6 (남현동, 한울 아파트)
- Contact
- [email protected]
1. Data we handle and why
| Area | Data | Purpose and handling |
|---|---|---|
| Local library | PDF file and name, library, reading position, bookmarks, and document search terms | Reading, search, and progress restoration. These remain in app storage on your device; the app does not provide server library sync. |
| Account and authentication | Email address, internal account ID, sign-in challenge records, HMAC of the session token, and expiry | Email OTP delivery and verification, account access, session continuity, and abuse prevention |
| Translation | Extracted page text, target language, model, translated result, usage balance, and a cache lookup hash | Online translation after express consent, duplicate-request prevention, encrypted caching, and usage accounting |
| Purchases | Account ID, App Store appAccountToken, product and transaction-chain IDs, status, expiry, and allowance ledger | Apple verification, subscription and ad-removal access, purchase restoration, refunds, disputes, and duplicate-benefit prevention. We do not receive your card number. |
| Security and operations | HMAC derived from network access information, request time and outcome, coarse error category, and basic app/device information | Rate limiting, abuse prevention, service protection, and fault diagnosis |
2. PDF and translation flow
- PDF files, file paths, the library, and bookmarks are not automatically uploaded to TMO Books. The app does not provide its own cross-device library sync.
- Before the first remote translation, the app names what will be sent and the recipients. Canceling or going back does not grant consent.
- After consent, extracted text and the target language for each requested page are sent through the TMO Books server to Google Gemini. Email and account ID are not deliberately added to the Gemini request, but the source text itself may identify a person.
- You can withdraw translation consent in settings. Withdrawal blocks future sends but cannot recall a completed request or automatically delete data already handled by a provider.
3. Service providers and equivalent protection
TMO Books uses Amazon Web Services for the API, database, operational logs, and email OTP delivery; Google Gemini for consented translation; Apple for App Store purchases; Google AdMob for eligible iOS library advertising; and Google Firebase for separately consented analytics. Depending on the provider, data may be processed outside your country over encrypted transport under that provider's contract and policy.
When a provider handles personal information for TMO Books, the operator requires confidentiality, purpose limitation, appropriate security safeguards, and a level of protection equivalent to this policy through the applicable contract and operational controls. The operator remains responsible for managing those providers within applicable law.
4. Advertising and analytics are separate choices
- The iOS app may show a non-personalized AdMob ad in the library when ad-removal access is inactive. Where required, an eligible ad request occurs only after Google's privacy flow permits it. Non-personalized ads can still involve IP-derived approximate location, ad interactions, app/device identifiers, and diagnostic information.
- Firebase Analytics starts off and initializes only after a separate opt-in. The app does not set an account user ID. Custom events exclude book title, path, original or translated text, search query, email, OTP, session token, and receipt.
- Advertising consent does not enable Firebase Analytics, and analytics consent does not grant advertising consent. Withdrawing analytics stops future collection and resets local analytics data, but does not automatically erase data already sent.
5. Retention and deletion
- An email OTP is valid for 10 minutes. Rate-limit records expire after 1 hour, and related aggregate counters expire after 2 days.
- A session normally expires 30 days after issue and can be invalidated sooner by sign-out, account deletion, or a security action.
- Pending translation records are physically deleted when account deletion is processed. Newly created failed rows expire after 1 hour, and a successful encrypted cache has a TTL of up to 90 days. TTL deletion is asynchronous, so physical removal is not guaranteed immediately at expiry.
- CloudWatch operational logs are configured for 30-day retention. The service is designed not to deliberately place source text or session tokens in those logs.
- Purchase, entitlement, and account-binding ledgers remain for as long as needed for restoration, payment integrity, refunds, disputes, and prevention of duplicate paid grants. After deletion, the minimal ledger retains a random former-account ID, deleted status, store transaction and original purchase binding identifiers, and purchase, subscription, grant, usage-balance, and period information. Email, source or translated text, and the cache keys used to locate or decrypt source or translated text are removed from this ledger.
Account deletion removes the active email HMAC index and invalidates every session. Email and the cache keys used to locate or decrypt source or translated text are removed from the former account, making old successful ciphertext unreadable by the live system. The retained minimal ledger contains the random former-account ID, deleted status, store transaction and original-purchase bindings, and the purchase, subscription, grant, usage-balance, and period details needed for legal or payment disputes and purchase restoration. A separate email-HMAC deletion marker contains no account ID and only the trial-used flag, deletion time, and expiry; it is configured to expire after 30 days and then be deleted asynchronously. If the same email registers again after that, trial eligibility may be evaluated anew under the product, store-verification, and anti-abuse rules then in effect; a new trial is not guaranteed. Local PDFs remain on the device until you remove them. Point-in-time backups and some older failed rows may temporarily contain earlier information; backup rotation and asynchronous TTL deletion mean immediate removal of every copy cannot be guaranteed, and deletion state must be reapplied after a restore. Deleting a TMO Books account does not cancel an App Store subscription, which must be canceled separately in Apple subscription management.
6. Your choices, security, and contact
You may request access, correction, deletion, or restriction through the account screen or [email protected]. Identity verification and lawful exceptions may apply. TMO Books uses encrypted transport, AES-256-GCM for translation caches, hashes or HMACs for secrets and lookup keys, and access controls. Material policy changes will be announced in the app or on this page before they take effect where required.