← Back to Forge & Fable

PRIVACY POLICY

Forge & Fable privacy information

Last updated: 16 August 2026

Forge & Fable is a local-first Android application. It does not operate a central Forge & Fable user-account backend, and the project does not require an account for the core library.

Information kept on the device

The app stores the library and its metadata, reading and listening progress, bookmarks and highlights, collections, listening history, playback preferences, download state, and other settings in the app’s local Room database. Local imported files and app-managed downloads are stored in the app’s private storage. Listening and reading history is retained locally so that progress, resume, statistics, and history features work across app sessions.

The Kindle/Send-to-Kindle feature may store the Kindle email address entered in Settings locally. It is used only when the user explicitly starts an export.

Optional network services

Forge & Fable is not entirely offline. When a feature is used, it may communicate directly from the device with services such as:

Those services receive the network information needed to fulfil the request, such as the device’s IP address, request details, search terms, selected identifiers, and any information included in the request by the service. They operate under their own privacy policies, terms, retention rules, and security practices. Forge & Fable does not control those services.

Images, catalogue metadata, source results, stream resolution, and downloads may therefore involve third-party network requests. The app does not add a Forge & Fable analytics, advertising, or telemetry service. When a third-party provider is down, handling stays on the device; see provider-outages.md.

Credentials

TorBox and Real-Debrid credentials are kept in Android Keystore-backed encrypted preferences rather than the Room database. They are used to authenticate requests to the corresponding provider.

Custom API source definitions are kept separately from their secrets. API-key, bearer, and basic-auth credentials are moved to an Android Keystore-backed encrypted store. The Room configuration contains only the non-sensitive source definition and an opaque reference. Existing configurations that contain inline credentials are migrated when the app starts; if migration cannot safely complete, the inline value is removed from the persisted configuration and the source is marked as requiring the credential to be entered again. Credentials are not written to application logs.

Backups and exports

Manual Forge & Fable backups export local library metadata, progress, settings, collections, and related records so they can be restored on another installation. They do not intentionally include:

Authenticated source definitions may be restored as inactive or unhealthy until their credential is entered again. Backup files are created at a user-selected destination and should still be protected like any other personal export.

Android backup/device-transfer exclusions also exclude the local database, downloads, backup files, and encrypted credential stores.

Kindle sharing

When the user explicitly initiates Send-to-Kindle, Forge & Fable prepares URI-scoped attachments and hands the attachments, Kindle address, and email details to the user’s chosen email application. The email application and email provider then handle the message according to their own policies. Forge & Fable does not send the email silently from a Forge & Fable server.

Deletion and control

The user can remove library items, imported files, downloads, custom API source definitions, and stored provider credentials through the app’s available controls. Android’s app-data clearing and uninstall controls remove local app data according to Android’s behaviour. Third-party services retain or delete information under their own controls and policies.

This page is the public privacy policy for Google Play. For questions or privacy requests, use the support email listed on the Forge & Fable Play Store listing.