LibraVault

Privacy First

Your data stays yours. Guaranteed.

Last updated: August 2026

Scoped Storage only. No broad file permissions. No accounts. No telemetry. No ads. No tracking. Optional client-side Encrypted Vaults for anything you want double-locked. Just you, your books, and your audiobooks — offline, private, secure.

Why This Matters

Most ebook and audiobook apps demand dangerous broad permissions: READ_EXTERNAL_STORAGE, MANAGE_EXTERNAL_STORAGE, INTERNET. They create accounts. They track your reading habits. They sync data to servers you don't control.

LibraVault is different.

The LibraVault Difference

Feature LibraVault Other Apps
File Permissions ✓ Scoped Storage ✗ Broad Access
Account Required ✓ None ✗ Yes
Analytics/Tracking ✓ None ✗ Yes
Ads ✓ None ✗ Yes
Offline Operation ✓ Yes ✗ No
Source Code Visible ✓ 100% FOSS ✗ Proprietary
Cloud Sync ✓ No ✗ Yes
Client-Side Encrypted Vaults ✓ AES-256-GCM, hardware-backed keys ✗ Not offered

What We Store on Your Device

✓ Reading Progress

Bookmarks, highlights, and position — stored only in a local database. Never leaves your phone.

✓ Library Folder Access

Folders you explicitly grant via Android's system folder picker (SAF). You control exactly what we see.

✓ Encrypted Vault Content

Files you choose to import into an Encrypted Vault are stored as chunked AES-256-GCM ciphertext, keyed by a PIN wrapped with your device's hardware-backed Keystore (or an independent recovery key) — never in the same database as your regular library, never in plaintext at rest.

✓ Optional Local Logging

Enable crash logs if you want — stored on your device only, never transmitted or shared.

What We Never Collect

Scoped Storage: The Technical Win

Android's Scoped Storage restricts app file access to specific folders you grant via the system picker. LibraVault cannot access your photos, messages, or other sensitive files — Android physically prevents it.

Most apps still use READ_EXTERNAL_STORAGE / MANAGE_EXTERNAL_STORAGE because they're easier to implement. We rejected that tradeoff.

Internet Access

F-Droid and Play builds — both no INTERNET permission

Neither build requests the INTERNET permission — the app makes zero network calls under any circumstances. Donations are handled entirely outside the app: a "Support the Project" button opens libravault.xyz/support in your system browser, where you can pay directly to a static BTC/XMR address or via a self-hosted BTCPay checkout. There is no in-app payment code, invoice polling, or Play Billing integration to make a network call in the first place.

100% Open Source (GPL-3.0)

Don't take our word for it — read the code yourself. Every claim on this page can be verified in the source.

Technical Details

Minimum SDK: Android 12 (API 31)

Permissions requested:

Permissions never requested, on any build: INTERNET, READ_EXTERNAL_STORAGE, MANAGE_EXTERNAL_STORAGE, CAMERA, CONTACTS, LOCATION.

Ready to take back your privacy?

Download LibraVault today. Your library, under lock and key.

Download LibraVault

All data is stored locally on your device. Uninstalling the app deletes everything. There is no server-side data to delete.

LibraVault does not knowingly collect any information from anyone, including children under 13.

If this policy changes materially, the updated date at the top of this page will reflect it. The policy will always be available at this URL.

privacy@libravault.xyz