Last updated: August 13, 2026
Tomen is a local-first ebook reader, operated by Tomen LLC ("we"), an Idaho limited liability company in the United States, reachable at feedback@tomen.app. Your library lives on your device, not on our servers. This policy explains the little we do handle, and every service the app talks to. It is written to be read.
Everything the reader needs is stored in your browser's or app's storage (IndexedDB and local storage) on the device you use:
If you never sign in, none of this leaves your device. If you sign in and use sync, section 3 says exactly which parts are copied to our backend — and your book files are never among them.
An account is an email address. Sign-in works by a one-time "magic link" we email you — there is no password to create, or for us to store. We keep your email address and your entitlement status (whether you own Tomen Plus, and your trial dates). That's the whole account record.
Accounts run on Supabase, our backend provider, on servers in the United States. The sign-in and trial emails themselves are delivered through Resend, an email service.
Purchases of Tomen Plus are processed by Polar, our merchant of record. Polar (and its payment processor) handle your payment details — Tomen never sees or stores your card information. Polar tells us only that a purchase tied to your email succeeded, so we can unlock your license. See Polar's privacy policy for how they process payments.
If you're signed in with Tomen Plus (or on a trial), the app syncs your reading through our backend so your other devices stay in step. Here is everything that syncs:
To be plain about it: a highlight or a saved word carries a short excerpt of the book it came from. That excerpt is what makes it appear, in context, on your other devices. Your book files are never uploaded — sync moves your reading about your books, not the books.
This data is stored with Supabase in the United States, in your account's own rows, and is deleted when your account is deleted. If you never sign in, none of it exists.
Tomen can treat a folder in your Dropbox as your library. The connection is deliberately narrow:
Disconnect at any time in the app, or revoke Tomen's access from your Dropbox account settings. Either one ends it completely.
Some optional features send a small piece of data to a third party to work. Each is used only when you use that feature:
| Service | When it's used | What's sent |
|---|---|---|
| Wiktionary (Wikimedia) | Dictionary lookup | The word you look up |
| Wikipedia (Wikimedia) | The dictionary's Wikipedia tab | The term you look up |
| MyMemory | Translation | The text you translate |
| Open Library (Internet Archive) | Finding covers online, and looking up genres/subjects for your library (this runs automatically for books in your library) | The book's title and author |
| Supabase | Sign-in, license, and sync | Your email / session, and the sync data in section 3 |
| Resend | Delivering sign-in and trial emails | Your email address |
| Polar | Buying Tomen Plus | Handled by Polar at checkout |
| Dropbox | The cloud library (section 4) | Read-only requests for the folder you chose |
Two features talk to servers you choose, not ours. Connecting a book catalog (OPDS — your own Calibre server, for example) sends requests, and any username and password you enter, to that server. Importing a book from a pasted link fetches that link directly. In both cases the credentials and the address are stored on your device, and go only where you pointed them.
As with any web request, these services receive your device's IP address and basic request data. We don't control their data practices; please see their respective privacy policies.
If the app crashes or hits an unexpected error, it sends us an anonymized report so we can fix it: the error message, a stack trace scrubbed of anything personal (email addresses and usernames are stripped before it is sent), the app version, the page path, and a coarse browser and operating-system family — "Firefox on Windows", nothing finer. The report isn't tied to your account, and we neither want nor look for your reading data in it — but a crash message is text the app didn't author, so beyond the emails, usernames, and book filenames we strip, we can't absolutely guarantee a stray snippet never slips in. It is capped, de-duplicated, and goes to our own backend, not a third-party analytics service.
You can turn this off: Settings → System → Error reports. It is the only report the app ever sends on its own.
That is the whole list. No advertising, no profiling, no selling data, no "sharing with partners."
Tomen uses your device's local storage and IndexedDB to run the app and to keep you signed in. We do not use advertising or tracking cookies.
The data controller is Tomen LLC, an Idaho limited liability company in the United States, reachable at feedback@tomen.app.
Depending on where you live (e.g. the EU/UK under GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, delete, or export the personal data held about you, and to object to certain processing. What is held is your email address, your entitlement, and — only if you use sync — the reading data listed in section 3. Ask, and we'll act on it. We will not discriminate against you for exercising these rights.
Tomen is not directed to children under 13 (or the equivalent minimum age in your country), and we don't knowingly collect their personal information.
Account and entitlement data is processed in the United States. If you use Tomen from outside the US, you consent to that processing.
We may update this policy as Tomen evolves. We'll change the "last updated" date above, and significant changes will be noted in the app.
Questions, or a data request? Email feedback@tomen.app.