Your data stays yours. Guaranteed.
Last updated: August 2026
Scoped Storage only. No broad file permissions. No accounts. No telemetry. No ads. No tracking. Optional client-side Encrypted Vaults for anything you want double-locked. Just you, your books, and your audiobooks — offline, private, secure.
Most ebook and audiobook apps demand dangerous broad permissions: READ_EXTERNAL_STORAGE, MANAGE_EXTERNAL_STORAGE, INTERNET. They create accounts. They track your reading habits. They sync data to servers you don't control.
LibraVault is different.
| Feature | LibraVault | Other Apps |
|---|---|---|
| File Permissions | ✓ Scoped Storage | ✗ Broad Access |
| Account Required | ✓ None | ✗ Yes |
| Analytics/Tracking | ✓ None | ✗ Yes |
| Ads | ✓ None | ✗ Yes |
| Offline Operation | ✓ Yes | ✗ No |
| Source Code Visible | ✓ 100% FOSS | ✗ Proprietary |
| Cloud Sync | ✓ No | ✗ Yes |
| Client-Side Encrypted Vaults | ✓ AES-256-GCM, hardware-backed keys | ✗ Not offered |
Bookmarks, highlights, and position — stored only in a local database. Never leaves your phone.
Folders you explicitly grant via Android's system folder picker (SAF). You control exactly what we see.
Files you choose to import into an Encrypted Vault are stored as chunked AES-256-GCM ciphertext, keyed by a PIN wrapped with your device's hardware-backed Keystore (or an independent recovery key) — never in the same database as your regular library, never in plaintext at rest.
Enable crash logs if you want — stored on your device only, never transmitted or shared.
Android's Scoped Storage restricts app file access to specific folders you grant via the system picker. LibraVault cannot access your photos, messages, or other sensitive files — Android physically prevents it.
Most apps still use READ_EXTERNAL_STORAGE / MANAGE_EXTERNAL_STORAGE because they're easier to implement. We rejected that tradeoff.
F-Droid and Play builds — both no INTERNET permission
Neither build requests the INTERNET permission — the app makes zero network calls under any circumstances. Donations are handled entirely outside the app: a "Support the Project" button opens libravault.xyz/support in your system browser, where you can pay directly to a static BTC/XMR address or via a self-hosted BTCPay checkout. There is no in-app payment code, invoice polling, or Play Billing integration to make a network call in the first place.
Don't take our word for it — read the code yourself. Every claim on this page can be verified in the source.
Minimum SDK: Android 12 (API 31)
Permissions requested:
FOREGROUND_SERVICE — Background audio playbackPOST_NOTIFICATIONS — Media controls on lock screen (Android 13+)Permissions never requested, on any build: INTERNET, READ_EXTERNAL_STORAGE, MANAGE_EXTERNAL_STORAGE, CAMERA, CONTACTS, LOCATION.
Download LibraVault today. Your library, under lock and key.
Download LibraVaultAll data is stored locally on your device. Uninstalling the app deletes everything. There is no server-side data to delete.
LibraVault does not knowingly collect any information from anyone, including children under 13.
If this policy changes materially, the updated date at the top of this page will reflect it. The policy will always be available at this URL.