Privacy Notice
Last updated: April 29, 2026
1. Who we are
Librythm is operated by YVY - DO BETTER, LDA ("we", "us", "our"), a company established in Portugal. We act as the data controllerfor personal data processed in connection with the Librythm service.
For privacy questions, contact us at privacy@librythm.com.
2. Data we collect
- Account data: name, email address, password hash, authentication identifiers.
- Profile data: avatar, reading goals, family/household membership.
- Library content: books you add, notes, highlights, reading sessions, page progress.
- Usage & telemetry: pages visited, features used, AI search queries, error logs.
- Device data: IP address, browser type, device identifiers, approximate location derived from IP.
- Support communications: messages you send to us.
3. Why we use your data and our legal basis
- Provide the service (account creation, syncing your library, AI search): performance of contract.
- Billing and subscription management: performance of contract and legal obligation. Payment data is collected and processed by Paddle (see Section 4).
- Security, fraud prevention, abuse detection: legitimate interests.
- Product improvement and analytics: legitimate interests.
- Customer support: performance of contract and legitimate interests.
- Marketing emails (if applicable): consent, which you can withdraw at any time.
- Legal compliance (tax, accounting, responding to lawful requests): legal obligation.
4. Sharing your data
We share personal data only with the following categories of recipients:
- Paddle.com Market Limited — our Merchant of Record. Paddle handles checkout, payments, tax compliance, invoicing, subscription management, and refunds. When you purchase Librythm, your order is processed by Paddle under their Buyer Terms and Privacy Notice.
- Hosting and infrastructure providers (cloud hosting, database, file storage, email delivery).
- Analytics and error-monitoring providers used to operate and improve the service.
- AI providers used to power features like AI search (queries are sent to the provider to generate a response).
- Professional advisers (legal, accounting, auditors).
- Authorities where required by law or to protect our rights.
We do not sell your personal data.
5. International transfers
Some of our service providers are located outside the European Economic Area (EEA). Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Retention
We retain personal data for as long as your account is active and for as long as needed to provide the service. After account deletion, we delete or anonymise your data within 90 days, except where we are required to keep it longer (e.g. tax and accounting records, typically up to 10 years under Portuguese law).
7. Your rights (GDPR)
You have the right to:
- Access the personal data we hold about you
- Request rectification of inaccurate data
- Request erasure of your data
- Restrict or object to certain processing
- Data portability
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your supervisory authority — in Portugal, the CNPD.
To exercise any of these rights, email privacy@librythm.com. We will respond within one month.
8. Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and row-level security in our database. No method of transmission or storage is fully secure, but we work to protect your data using industry best practices.
9. Cookies
We use essential cookies required to keep you signed in and to operate the service. We may use analytics cookies to understand how the service is used. You can manage cookie preferences through your browser settings.
10. Changes to this notice
We may update this notice from time to time. Material changes will be communicated by email or in-app notice.
YVY - DO BETTER, LDA · Portugal · privacy@librythm.com