Privacy Policy
Version Pilot · effective 1 September 2026
1. Who this policy covers and what it applies to
This Privacy Policy explains what personal data Ains Reads (operated by AinsoftEdge Ltd, "we", "us", "our") collects when you use ainsreads.com, our Publish and Administrator portals, and our official Ains Reads mobile and desktop apps (together, the "Services"), why we collect it, who we share it with, and the choices and rights you have over it. It applies to readers, authors, and to people operating a Press, Publisher, or Transport business account on our marketplace.
2. Information we collect directly from you
Account information: your name, username, email address, and password (if you use our fallback sign-in) or your identity as provided by our secure sign-in system (see Section 4). We also record the country/location your account signs up from, frozen at the moment of signup, which we use for fraud prevention and never silently overwrite with later locations.
Profile information you choose to add: a display name, bio, avatar image, and social/website links.
Payment information: when you pay with a card, bank transfer, mobile money, or USSD through our payment processor Flutterwave, your card and bank details are collected and processed by Flutterwave directly — we never see or store your full card number, CVV, or bank login. We keep a record of the transaction itself (amount, currency, status, reference), not your payment instrument. Where you pay through an app store's in-app purchase system instead, that store processes your payment; we receive only a purchase confirmation, not your payment details.
Payout information (authors and business accounts): if you're owed money, you provide us a bank account, mobile money number, or crypto wallet address to be paid out to, verified with a one-time code sent to your registered email before we'll save or change it.
Identity and business verification information (KYC/KYB): where verification is required (see Section 5 of our Terms of Service), you provide a government-issued ID and complete a liveness (real-person) check through one of our verification partners — currently Dojah (Nigeria and Kenya), Smile ID (other African countries Smile ID supports), or Shufti Pro (all other territories, and as a fallback if Dojah or Smile ID is unavailable). These partners collect your ID document, a live selfie/video for liveness matching, and derive your date of birth from your ID; for a business (KYB), they collect the business's own registration and ownership documents. We store the verification outcome (passed/failed, verified date of birth where relevant, a reference to look the attempt back up) and the raw verification result for audit purposes; we do not store a raw copy of your ID document or liveness video ourselves beyond what our verification partner's own response includes.
Content you create: chapters, comments, reviews, reference notes, and any images or files you upload as an author, publisher, or business participant.
Support requests: anything you submit through a support ticket, including attached images or documents.
Communications: messages you send us, and the trusted contact an author may optionally designate (see Section 13 of our Terms of Service) — we collect that person's name and contact details for the sole purpose described there.
3. Information collected automatically
Device and session information: device type, operating system, app version, and a hashed (not raw) device identifier used to detect ban-evasion through repeated new accounts on the same device; a hashed identifier can be reset by reinstalling, so we treat it as one signal among several, not proof on its own.
Reading and usage activity: which titles/chapters you view, purchase, or unlock; how far you've read (so you can resume where you left off across devices); ratings you give a book's difficulty of use is not collected, only your own reviews/ratings you choose to leave; and general interaction events used to rank and recommend content.
Security and anti-piracy signals: every chapter you read carries a watermark unique to your account and reading session (see Section 4 of our Terms of Service) — this is not separate personal data we newly collect, but is derived from your existing account identity at the moment you read. If our apps detect an attempt to screenshot or otherwise capture a protected reading screen, we log that event (device, time, what was being viewed) as part of your account's security profile; this may lead to offline downloads on that device being deleted and to enforcement action as described in our Terms.
Location: only ever a coarse signal (such as the country implied by your network connection or a delivery address you choose to enter for a physical order) — we do not track precise device location in the background.
4. Sign-in and identity
We use Microsoft Azure Active Directory B2C to handle sign-in. When you sign in, Microsoft's service issues us a token confirming your identity; we do not receive or store your Microsoft/social sign-in password. The first time you sign in, we create a permanent, internal, cryptographically-derived identity record for your account (an "identity anchor") built from your account ID, your Microsoft identity reference, your join date, and your frozen signup location — this anchor is insert-only in our systems (it can never be edited after creation) and is the cryptographic root used to protect your coin ledger history and the content-encryption keys involved in your reading sessions. It is not shared with Microsoft or any third party, and it never leaves our systems.
We issue our own short-lived access token after B2C sign-in succeeds, which our apps use to talk to our servers; your coin balance is never included inside that token.
5. Who we share your data with
We share personal data only with the specific parties needed to provide the Services, never for unrelated advertising or resale of your data:
- Flutterwave — processes real-money payments and payouts; receives what's needed to charge or pay you (amount, currency, and — for payouts — your bank/mobile-money/crypto details).
- Apple, Google, and Microsoft — process in-app purchases and subscriptions made inside apps distributed through their stores, and receive what's needed to do that under their own respective privacy terms.
- Dojah, Smile ID, and Shufti Pro — process identity (KYC) and business (KYB) verification as described in Section 2, each for the territories described there.
- xAI (Grok) — receives uploaded chapter text and author-placed images for automated content screening (legal/harm review and an AI-generation likelihood signal) before or after publication.
- SendGrid and our SMTP provider — send transactional and account emails on our behalf.
- Termii — sends SMS messages for critical account and delivery notifications.
- Amazon Web Services (S3) — stores uploaded images and files (cover art, chapter illustrations, support attachments) securely.
- Verified Press, Publisher, and Transport business participants — receive the minimum information needed to fulfil a specific physical order you place (typically your delivery address and order contents), disclosed only for that order and visible to you in your own order history, as described in Section 9 of our Terms of Service. None of these business participants — nor any individual acting only in that business capacity — is ever given the ability to read the digital content itself.
- Law enforcement or regulators, where we are legally required to, or where necessary to protect the rights, property, or safety of Ains Reads, our users, or the public — including in cases of suspected fraud, leaked/pirated content traced through watermarking, or payment abuse.
We do not sell your personal data.
6. Coin ledger and financial records
Every coin transaction on your account is individually signed and chained to the one before it, so that your balance can always be independently verified and cannot be silently altered — including by us. We retain this ledger, and records of real-money payments and payouts, for as long as required by tax and accounting law, even after an account is otherwise deleted (see Section 8).
7. Cookies and similar technologies on the website
Our website uses essential cookies needed for you to stay signed in and for basic security protections. We do not use third-party advertising or cross-site tracking cookies.
8. Data retention and deletion
When you delete your account in good standing (no unresolved financial obligation or active fraud/abuse flag), we delete your active personal data and retain only anonymized financial records with nothing that identifies you — we do not keep anything that could link a later new account back to your old one. If your account has an unresolved financial obligation or an active flag at the time of deletion, we retain a hashed identifier together with that flag, solely so a later account created to evade the obligation can be recognized as connected to it; this is not done for accounts in good standing. Where applicable law gives you a right to erasure that overrides this, we honor it and retain only anonymized financial records as required by law.
Author earnings records are always retained in the author's own record regardless of any reader's account deletion or data-erasure request — a reader's privacy rights over their own data never remove an author's right to their own earnings history.
9. Age and parental responsibility
Our Services are intended for users 13 and older, self-declared at signup. We do not knowingly collect personal data from children under 13. Content our genre system marks as explicit is additionally restricted behind identity verification and a liveness check on both the author and the reader, as described in our Terms of Service; content with milder romantic content relies on age self-declaration alone. Parents and guardians who allow a minor to use a shared device with our apps installed are responsible for supervising that use; our content password-lock feature is available specifically so an account holder can restrict access to individual books or chapters on a shared device.
10. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, to object to or restrict certain processing, and to receive a copy of your data in a portable format. You can exercise most of these directly from your account settings (profile edits, account deletion) or by contacting support@ainsreads.com for anything else. We will respond to verified requests within a reasonable time and may need to verify your identity before acting on a request affecting your account.
11. International transfers
Because our verification, payment, hosting, and AI-screening partners operate internationally, your data may be processed in countries other than the one you live in, including Nigeria, other African countries our KYC/KYB partners cover, and countries where our cloud hosting and AI-processing partners operate. Where we transfer data internationally, we rely on our processors' own contractual and security safeguards.
12. Security
We encrypt purchased content both in storage and while it is being read, protect your account with a token-based sign-in system, and monitor for suspicious activity such as screenshot attempts and repeated new accounts from the same device. No system is completely secure, and we cannot guarantee absolute security, but we treat leaked or pirated content, and any compromise of user data, as serious incidents to be investigated and, where content is involved, traced through our watermarking system.
13. Changes to this policy
We may update this Privacy Policy from time to time. Every published version is kept on record and remains referenceable; a version, once published, is never edited in place — any change is published as a new version with its own effective date. When we publish a materially updated version, we email every account holder, and that email states the new version's effective date.
Questions about this policy, or requests concerning your personal data, can be sent to support@ainsreads.com.
This Privacy Policy explains what personal data Ains Reads (operated by AinsoftEdge Ltd, "we", "us", "our") collects when you use ainsreads.com, our Publish and Administrator portals, and our official Ains Reads mobile and desktop apps (together, the "Services"), why we collect it, who we share it with, and the choices and rights you have over it. It applies to readers, authors, and to people operating a Press, Publisher, or Transport business account on our marketplace.
2. Information we collect directly from you
Account information: your name, username, email address, and password (if you use our fallback sign-in) or your identity as provided by our secure sign-in system (see Section 4). We also record the country/location your account signs up from, frozen at the moment of signup, which we use for fraud prevention and never silently overwrite with later locations.
Profile information you choose to add: a display name, bio, avatar image, and social/website links.
Payment information: when you pay with a card, bank transfer, mobile money, or USSD through our payment processor Flutterwave, your card and bank details are collected and processed by Flutterwave directly — we never see or store your full card number, CVV, or bank login. We keep a record of the transaction itself (amount, currency, status, reference), not your payment instrument. Where you pay through an app store's in-app purchase system instead, that store processes your payment; we receive only a purchase confirmation, not your payment details.
Payout information (authors and business accounts): if you're owed money, you provide us a bank account, mobile money number, or crypto wallet address to be paid out to, verified with a one-time code sent to your registered email before we'll save or change it.
Identity and business verification information (KYC/KYB): where verification is required (see Section 5 of our Terms of Service), you provide a government-issued ID and complete a liveness (real-person) check through one of our verification partners — currently Dojah (Nigeria and Kenya), Smile ID (other African countries Smile ID supports), or Shufti Pro (all other territories, and as a fallback if Dojah or Smile ID is unavailable). These partners collect your ID document, a live selfie/video for liveness matching, and derive your date of birth from your ID; for a business (KYB), they collect the business's own registration and ownership documents. We store the verification outcome (passed/failed, verified date of birth where relevant, a reference to look the attempt back up) and the raw verification result for audit purposes; we do not store a raw copy of your ID document or liveness video ourselves beyond what our verification partner's own response includes.
Content you create: chapters, comments, reviews, reference notes, and any images or files you upload as an author, publisher, or business participant.
Support requests: anything you submit through a support ticket, including attached images or documents.
Communications: messages you send us, and the trusted contact an author may optionally designate (see Section 13 of our Terms of Service) — we collect that person's name and contact details for the sole purpose described there.
3. Information collected automatically
Device and session information: device type, operating system, app version, and a hashed (not raw) device identifier used to detect ban-evasion through repeated new accounts on the same device; a hashed identifier can be reset by reinstalling, so we treat it as one signal among several, not proof on its own.
Reading and usage activity: which titles/chapters you view, purchase, or unlock; how far you've read (so you can resume where you left off across devices); ratings you give a book's difficulty of use is not collected, only your own reviews/ratings you choose to leave; and general interaction events used to rank and recommend content.
Security and anti-piracy signals: every chapter you read carries a watermark unique to your account and reading session (see Section 4 of our Terms of Service) — this is not separate personal data we newly collect, but is derived from your existing account identity at the moment you read. If our apps detect an attempt to screenshot or otherwise capture a protected reading screen, we log that event (device, time, what was being viewed) as part of your account's security profile; this may lead to offline downloads on that device being deleted and to enforcement action as described in our Terms.
Location: only ever a coarse signal (such as the country implied by your network connection or a delivery address you choose to enter for a physical order) — we do not track precise device location in the background.
4. Sign-in and identity
We use Microsoft Azure Active Directory B2C to handle sign-in. When you sign in, Microsoft's service issues us a token confirming your identity; we do not receive or store your Microsoft/social sign-in password. The first time you sign in, we create a permanent, internal, cryptographically-derived identity record for your account (an "identity anchor") built from your account ID, your Microsoft identity reference, your join date, and your frozen signup location — this anchor is insert-only in our systems (it can never be edited after creation) and is the cryptographic root used to protect your coin ledger history and the content-encryption keys involved in your reading sessions. It is not shared with Microsoft or any third party, and it never leaves our systems.
We issue our own short-lived access token after B2C sign-in succeeds, which our apps use to talk to our servers; your coin balance is never included inside that token.
5. Who we share your data with
We share personal data only with the specific parties needed to provide the Services, never for unrelated advertising or resale of your data:
- Flutterwave — processes real-money payments and payouts; receives what's needed to charge or pay you (amount, currency, and — for payouts — your bank/mobile-money/crypto details).
- Apple, Google, and Microsoft — process in-app purchases and subscriptions made inside apps distributed through their stores, and receive what's needed to do that under their own respective privacy terms.
- Dojah, Smile ID, and Shufti Pro — process identity (KYC) and business (KYB) verification as described in Section 2, each for the territories described there.
- xAI (Grok) — receives uploaded chapter text and author-placed images for automated content screening (legal/harm review and an AI-generation likelihood signal) before or after publication.
- SendGrid and our SMTP provider — send transactional and account emails on our behalf.
- Termii — sends SMS messages for critical account and delivery notifications.
- Amazon Web Services (S3) — stores uploaded images and files (cover art, chapter illustrations, support attachments) securely.
- Verified Press, Publisher, and Transport business participants — receive the minimum information needed to fulfil a specific physical order you place (typically your delivery address and order contents), disclosed only for that order and visible to you in your own order history, as described in Section 9 of our Terms of Service. None of these business participants — nor any individual acting only in that business capacity — is ever given the ability to read the digital content itself.
- Law enforcement or regulators, where we are legally required to, or where necessary to protect the rights, property, or safety of Ains Reads, our users, or the public — including in cases of suspected fraud, leaked/pirated content traced through watermarking, or payment abuse.
We do not sell your personal data.
6. Coin ledger and financial records
Every coin transaction on your account is individually signed and chained to the one before it, so that your balance can always be independently verified and cannot be silently altered — including by us. We retain this ledger, and records of real-money payments and payouts, for as long as required by tax and accounting law, even after an account is otherwise deleted (see Section 8).
7. Cookies and similar technologies on the website
Our website uses essential cookies needed for you to stay signed in and for basic security protections. We do not use third-party advertising or cross-site tracking cookies.
8. Data retention and deletion
When you delete your account in good standing (no unresolved financial obligation or active fraud/abuse flag), we delete your active personal data and retain only anonymized financial records with nothing that identifies you — we do not keep anything that could link a later new account back to your old one. If your account has an unresolved financial obligation or an active flag at the time of deletion, we retain a hashed identifier together with that flag, solely so a later account created to evade the obligation can be recognized as connected to it; this is not done for accounts in good standing. Where applicable law gives you a right to erasure that overrides this, we honor it and retain only anonymized financial records as required by law.
Author earnings records are always retained in the author's own record regardless of any reader's account deletion or data-erasure request — a reader's privacy rights over their own data never remove an author's right to their own earnings history.
9. Age and parental responsibility
Our Services are intended for users 13 and older, self-declared at signup. We do not knowingly collect personal data from children under 13. Content our genre system marks as explicit is additionally restricted behind identity verification and a liveness check on both the author and the reader, as described in our Terms of Service; content with milder romantic content relies on age self-declaration alone. Parents and guardians who allow a minor to use a shared device with our apps installed are responsible for supervising that use; our content password-lock feature is available specifically so an account holder can restrict access to individual books or chapters on a shared device.
10. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, to object to or restrict certain processing, and to receive a copy of your data in a portable format. You can exercise most of these directly from your account settings (profile edits, account deletion) or by contacting support@ainsreads.com for anything else. We will respond to verified requests within a reasonable time and may need to verify your identity before acting on a request affecting your account.
11. International transfers
Because our verification, payment, hosting, and AI-screening partners operate internationally, your data may be processed in countries other than the one you live in, including Nigeria, other African countries our KYC/KYB partners cover, and countries where our cloud hosting and AI-processing partners operate. Where we transfer data internationally, we rely on our processors' own contractual and security safeguards.
12. Security
We encrypt purchased content both in storage and while it is being read, protect your account with a token-based sign-in system, and monitor for suspicious activity such as screenshot attempts and repeated new accounts from the same device. No system is completely secure, and we cannot guarantee absolute security, but we treat leaked or pirated content, and any compromise of user data, as serious incidents to be investigated and, where content is involved, traced through our watermarking system.
13. Changes to this policy
We may update this Privacy Policy from time to time. Every published version is kept on record and remains referenceable; a version, once published, is never edited in place — any change is published as a new version with its own effective date. When we publish a materially updated version, we email every account holder, and that email states the new version's effective date.
Questions about this policy, or requests concerning your personal data, can be sent to support@ainsreads.com.