Salon: Annotated Classics
Privacy Policy
Effective date: September 18, 2026. Questions: joeytowbin@gmail.com.
Salon is a reader for public-domain books with margin notes. This policy covers the Salon app and this website. In short: there is no account, most of what you do stays on your device, and the server keeps as little as it can while still running the daily allowance and Premium.
Anonymous identity
We do not require an account. The app identifies you through an anonymous customer identifier provided by RevenueCat, our subscription manager. This identifier is a random string and contains nothing that identifies you.
When the app first connects, our server checks that identifier with RevenueCat and creates a device session: a random session ID, your RevenueCat identifier, and when the session was created, last used, and signed out.
What stays on your device
Your name (if you enter one at setup), your reading place in each book, the lines you keep in your commonplace book, your settings, and the count of notes you have opened today are stored only on your device. They are not sent to our server, with one exception: if you subscribe to the Sunday letter inside the app, the name you entered is sent along with your email address (see below). Deleting the app removes them permanently.
Reading books and notes
Book text and margin notes are downloaded from our server without your identifier or session. The notes are prepared in advance for each chapter, not written from anything you do. Our server uses your IP address in short-lived counters to limit how many requests one address can make; those counters are deleted after about a day.
Explaining a paragraph
When you press and hold a paragraph, the app sends our server the paragraph's text, the book and chapter it comes from, any question you add, and your session. Before anything else, the text is checked by a content-safety classifier: OpenAI's moderation service, with Llama Guard through OpenRouter as a fallback and second opinion. It is then sent through OpenRouter to an AI model (currently from Meta, OpenAI, or Anthropic) to write the explanation. OpenRouter also receives your anonymous RevenueCat identifier as a usage tag. The explanation is checked by the same classifier before you see it.
We do not store the paragraph, your question, or the explanation. We keep only accounting for each explanation: your anonymous identifier, the model used, token counts, and cost. For free readers we also keep a count of explanations per identifier per day, so the daily allowance works across reinstalls. We do not use what you send to train models.
Safety records and reports
If the classifier flags text, we keep a record with your anonymous identifier, the categories and severity, and what we did. When text is blocked or warned about, the record includes up to 2,000 characters of it so it can be reviewed. Repeated or serious violations can restrict an identifier temporarily or permanently, and we keep that restriction state.
If you report a note, by email or from the app, the report and the chapter it came from may be reviewed by the developer. Content connected to a report about child safety, or to a legal request, is retained and may be disclosed to the National Center for Missing and Exploited Children or to law enforcement as required by United States law (18 U.S.C. 2258A).
Subscriptions
Premium subscriptions are processed entirely by Apple through the App Store. We never see your payment details. RevenueCat helps us verify your subscription status using the anonymous identifier, and our server keeps a copy of that status: whether Premium is active, when it expires, and the last subscription event.
Email, if you offer it
The app and this website invite you to subscribe to the Sunday letter, a weekly email. If you subscribe, we store your email address, your name if you give one, where you signed up, a record of your consent and confirmation, and any reading tastes you choose to share, such as favourite genres. Email is delivered through Resend, which receives your address, name, and tastes, plus the app moments described below.
Subscription is double opt-in: nothing is sent until you confirm from the first email, and every email carries a one-click unsubscribe link. Sign-ups that are never confirmed are deleted after seven days. If you subscribe from inside the app, your anonymous identifier is linked to your address, so moments in the app (for example, nearing the daily allowance or starting Premium) can shape which emails you get. When you unsubscribe, we stop sending and mark the address as unsubscribed; email us to have the record deleted.
Product analytics
Our server sends usage events to PostHog so we can see how the app is used: for example, that a session started, that an explanation was made (with the book, chapter, model, and length), that a reader neared or reached the daily allowance, that a purchase started, and newsletter events such as confirming, clicking a link, or unsubscribing. Events are keyed to your anonymous identifier; for newsletter events with no app link, they are keyed to your email address. Events never include the text of a paragraph, question, or explanation. The app itself contains no analytics or advertising SDK and does not track you across other apps or websites.
Data retention and deletion
The records above are kept until you request deletion, so the daily allowance and Premium keep working across reinstalls. To delete everything tied to your anonymous identifier or email address, email joeytowbin@gmail.com. We will remove your session records, usage and allowance counts, subscription status copy, safety records, and newsletter record. Signing out in Preferences ends your session on that device but does not by itself delete stored records; emailing us does. The only exception is content we are legally required to preserve after a safety report.
Changes
If this policy changes, we will update it here and change the effective date.
Contact
Questions about this policy: joeytowbin@gmail.com