Privacy Policy

Last updated: 24 August 2026

Earful is an audiobook player for iPhone. It has no accounts, no ads, and no tracking. Your books are yours and the files themselves never leave your device. A book’s title does leave, to look its chapters up, and that is explained below. Earful has two optional in-app purchases. This page explains the few exceptions, in plain terms.

What stays on your device

Your books, their audio files, cover art, bookmarks and playback positions are stored on your device, and none of those are ever uploaded to us. There is no Earful account, no sign-up and no password, and no server holding your library, because no such server exists. The one thing that does leave is a book’s title, author and runtime, sent to look its chapters up. That is described under “Book lookups” below.

If you buy anything, Earful needs some way to remember that you did. It uses a random identifier generated on your device, not an account. That identifier is described under “Your purchases” below.

If you connect a WebDAV server, its credentials are stored in the iOS Keychain on your device. Earful uses them to talk to the server you named. That connection is between your device and your server. We are not in the middle of it and we never see those files or those credentials.

What leaves your device

Book lookups. Earful looks a book up in three situations. Two of them you ask for: choosing “Look Up Metadata” on a book, and asking a book to re-check its chapters. The third one you do not. When you import a book, Earful automatically looks it up to find the chapter list that a file often does not carry, and it does this without asking you first.

All three send the same three things to the Earful metadata service: the book’s title, its author, and its total runtime in seconds. The runtime is sent because it is how the service tells two recordings of the same book apart. Nothing else about the book is sent, and the audio never is.

The automatic lookup can also happen again later. If Earful’s chapter settings change, the app re-checks a small number of already imported books at launch, up to ten at a time, and a re-check is another lookup. So the title of a book you imported long ago can be sent again without you doing anything. It is the same three fields every time.

Every lookup carries the random identifier described under “Your purchases”, so the service can check whether a metadata subscription is active. If there is no active subscription the service refuses to answer, but the title, author and runtime have already reached it by then. We would rather say that plainly than describe a refusal as though it undoes the request.

Put together, this means the Earful metadata service can see the titles of books in your library, tied to that random identifier. That is a fair description of it, and you should read it here rather than work it out later. The identifier is not connected to your name, your email address, or your Apple ID. The titles are not sold, not shared, and not used for anything except answering the lookup.

Most lookups are answered from a catalogue the service keeps its own copy of, so they reach nobody else. Details that catalogue does not hold, such as the narrator or a chapter listing, are filled in from third-party book and audiobook databases, so a lookup can reach those services too.

If you apply a match that has cover art, your device downloads that image directly from wherever the image is published. That is an ordinary image request: it carries no account identifier and nothing about your library beyond the image being asked for.

Crash and diagnostic reports. Earful uses Sentry to report crashes and performance problems. Our Sentry is self-hosted: reports go to a server run by the developer, not to a third-party analytics company, and they are not sold, shared or used for advertising.

A report can include:

  • The crash itself: the stack trace and the state of the app when it failed.
  • Your device model, iOS version, and the Earful version and build.
  • Performance traces from a sample of sessions, so slow screens can be found.
  • When chapter diagnostics are switched on, which they are not by default, a note that a book produced no chapter structure. That note carries the book’s random on-device identifier, how many files it has, how long it runs, and what went wrong. It deliberately does not carry the title.

Feature checks. Earful asks the developer’s service which optional features are switched on. This happens automatically at launch and at most once an hour while the app is in use, with no action from you. The request carries no information about you or your library.

Spotlight and Siri. Earful gives iOS the titles, authors and cover art of the books you have downloaded, so that they turn up in Spotlight search and so you can ask Siri to play one. That is handled by iOS on your device and goes to Apple, not to us, under Apple’s terms rather than this policy. We mention it because “stays on your device” should not quietly mean “except for the part the system gets”.

Your purchases. Earful uses RevenueCat to handle in-app purchases. RevenueCat is a third-party service that records what you have bought, so it works on your other devices and comes back if you reinstall.

When you make a purchase, or when Earful checks whether a purchase is still active, RevenueCat receives a random identifier generated on your device, the purchase itself as Apple reports it, your device model, and your iOS version. Like any service you connect to, it also sees the IP address the request came from. It does not receive your name, your email address, your Apple ID, or anything about your library.

Apple handles the payment. Earful never sees your payment details.

The Earful metadata service keeps one small record for each subscriber: the random identifier, that a metadata subscription exists, and when it expires. That is the whole record. It holds nothing about your library and nothing that identifies you.

Where that identifier lives. It is stored in the iOS Keychain on your device, and mirrored to your iCloud account so it survives moving to a new phone. It is deliberately kept when you delete the app, so that reinstalling restores what you paid for without asking you to sign in to anything. The same record holds a count of how many books you have imported, which is how the free tier’s limit works.

What Earful never collects

  • Your name, email address, or contacts.
  • Your location.
  • Advertising or tracking identifiers.
  • Your payment details. Apple handles payment; we never see a card number.
  • The contents of your books. We never see your audio files. The only things about a book that can leave your device are its title, author and runtime, sent by the lookups described above, and the request for a cover image you choose to apply.
  • Analytics of what you tap or listen to. A book lookup is not analytics: it exists to answer a question about one book, and it is described above rather than hidden here.

We do not store your IP address. Any server your device connects to can see it while the connection is open, including ours, RevenueCat’s, and whoever publishes a cover image you download. That is how the internet works rather than something Earful collects.

There are no advertising SDKs, no analytics SDKs, and no attribution SDKs in the app.

How long it is kept

Crash and diagnostic reports are kept for 90 days and then deleted automatically.

Book lookups are answered rather than recorded: the service keeps no per-subscriber history of what you looked up. Like any web service, its request logs do record the lookups it received, including the title in the request. Those logs are kept for a limited period and then deleted.

The subscriber record described under “Your purchases” is kept for as long as you have a subscription, and is not deleted automatically afterwards. You can ask us to delete it; see Contact below.

Nothing else is retained, because nothing else is collected.

Children

Earful is not directed at children under 13 and does not knowingly collect personal information from them.

Changes to this policy

If what Earful collects changes, this page changes with it, and the date at the top changes too. Material changes will also be noted in the app’s release notes.

Contact

Questions about privacy, a request to delete diagnostic data associated with your device, or a request to delete the subscriber record described above: support@earful.media.

Deleting the subscriber record while a subscription is active will stop metadata lookups working until it is recreated, which happens automatically the next time the app checks.