Overview
Bloox is an audiobook player for iOS. Your privacy is important to us. This policy explains what data the app accesses, how it is used, and what is shared with third parties.
Data Collection
All core app data (your library, playback progress, listening sessions, and transcriptions) is stored locally on your device. Bloox does not collect your name or Apple ID. Feedback is anonymous by default; if you choose to leave an email after submitting feedback, that email is used only for follow-up about that specific report. The exceptions to local-only storage are crash reporting, analytics, and the optional feedback feature described below.
Speech Recognition
Bloox offers an optional transcription feature that converts audiobook speech to text. This processing is performed entirely on your device using Apple’s on-device speech recognition. No audio is sent to any server. Transcription data is sent only when you submit recap feedback while Share recap details with Bloox is enabled, as described under Feedback below.
Google Drive Access — Overview
If you choose to import audiobooks from Google Drive, Bloox uses Google’s OAuth flow to request the drive.readonly scope. The three sections below describe exactly what Google user data the app accesses, how that data is protected, and how long it is kept.
How Bloox Uses Google User Data
With your permission, Bloox uses the drive.readonly scope to access:
- File and folder metadata — name, MIME type, size, parent folder, and shortcut targets — for the folders and files you choose to browse inside Bloox.
- File content — the audio files (e.g. M4B, MP3) and sibling files (cover image, CUE/NFO/metadata.json) belonging to the audiobooks you explicitly select to import.
This data is used solely to (a) display the folders and files you choose to browse, and (b) download the audiobooks you select onto your device for offline playback. Bloox does not modify, upload, sell, or transfer your Google Drive file contents, paths, or account identity to any third party. After import, Bloox may send the extracted audiobook title and author to Google Books to look up cover art, as described under Third-Party Services below. Google Drive access is read‑only: the app cannot create, edit, or delete files in your Drive.
How Google User Data Is Protected
- Direct, end‑to‑end transfer. Drive content is downloaded over HTTPS directly from Google to your iPhone. It does not pass through any Bloox server, and we do not operate any backend that stores, caches, or proxies your Drive files.
- On‑device storage. Imported audiobooks are stored in Bloox’s iOS Documents container and protected by iOS Data Protection. Other apps cannot access that container directly. Because Bloox supports Apple’s file‑sharing features, you can also access its Documents content through supported Files or Finder surfaces.
- Credentials. OAuth access and refresh tokens are managed by Google’s official Google Sign‑In SDK and stored in the iOS Keychain. The app never sees, copies, logs, or transmits your Google password.
- No human review. Bloox does not allow employees, contractors, or any third party to read your Google Drive data, except as required by law or with your explicit consent for a support request.
- Diagnostics. Crash and error logs sent to Firebase Crashlytics may include the title of the audiobook being processed at the time of an error, but never include Drive file IDs, file contents, OAuth tokens, or your Google account identity.
Retention and Deletion of Google User Data
- In your Google Drive: Bloox never writes, modifies, or deletes anything. Read‑only access only.
- On your device: Books you import are kept locally only as long as you choose to keep them. Deleting a book in Bloox immediately removes the audio files, cover image, sibling metadata, and any related transcription or character data from your device. There is no soft‑delete or recovery period.
- Sign‑out: Signing out of Google in Bloox clears the app’s OAuth session via Google’s SDK and prevents further Drive access. Books that you previously imported remain on your device until you delete them.
- Uninstall: Removing Bloox deletes its app sandbox, including all imported Drive content. iOS may preserve Keychain items after an app is removed, so sign out of Google Drive in Bloox before uninstalling to ensure the locally stored OAuth credentials are deleted.
- No server‑side copy. Because Drive content never leaves your device for our servers, there is no Bloox‑side copy of your Drive data to retain or delete.
Limited Use of Google User Data
Bloox’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Bloox uses Google Drive data only to provide and improve the in‑app audiobook import and offline playback features described above.
- Bloox does not transfer this data to others, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- Bloox does not use Google Drive data for serving advertisements, including personalized advertisements.
- Bloox does not allow humans to read this data, except (i) with your affirmative consent for a specific user‑initiated request, (ii) for security purposes (e.g. investigating abuse), (iii) to comply with applicable law, or (iv) where the data has been aggregated and anonymized.
- Bloox does not use Google Drive data to develop, improve, or train generalized AI/ML models.
Dropbox Access: Overview
If you choose to import audiobooks from Dropbox, Bloox uses Dropbox’s OAuth 2.0 flow (with PKCE) to request three read-only scopes: files.metadata.read, files.content.read, and account_info.read. The three sections below describe exactly what Dropbox data the app accesses, how that data is protected, and how long it is kept.
How Bloox Uses Dropbox Data
With your permission, Bloox uses these scopes to access:
- File and folder metadata (name, path, size, and type) for the folders and files you choose to browse inside Bloox.
- File content: the audio files (such as M4B or MP3) and sibling files (cover image, CUE/NFO/metadata.json) belonging to the audiobooks you explicitly select to import.
- Basic account information (your Dropbox account name or email) so the app can show you which account is connected.
This data is used solely to (a) display the folders and files you choose to browse, and (b) download the audiobooks you select onto your device for offline playback. Bloox does not modify, upload, sell, or transfer your Dropbox file contents, paths, or account identity to any third party. After import, Bloox may send the extracted audiobook title and author to Google Books to look up cover art, as described under Third-Party Services below. Dropbox access is read-only: the app cannot create, edit, move, or delete files in your Dropbox.
How Dropbox Data Is Protected
- Direct transfer. Dropbox content is downloaded over HTTPS directly from Dropbox to your iPhone using short-lived temporary links. It does not pass through any Bloox server, and we do not operate any backend that stores, caches, or proxies your Dropbox files.
- On-device storage. Imported audiobooks are stored in Bloox’s iOS Documents container and protected by iOS Data Protection. Other apps cannot access that container directly. Because Bloox supports Apple’s file-sharing features, you can also access its Documents content through supported Files or Finder surfaces.
- Credentials. OAuth access and refresh tokens (obtained via PKCE, so no app secret is embedded in the app) are stored in the iOS Keychain. The app never sees, copies, logs, or transmits your Dropbox password.
- No human review. Bloox does not allow employees, contractors, or any third party to read your Dropbox data, except as required by law or with your explicit consent for a support request.
- Diagnostics. Crash and error logs sent to Firebase Crashlytics may include the title of the audiobook being processed at the time of an error, but never include Dropbox file paths, file contents, OAuth tokens, or your Dropbox account identity.
Retention and Deletion of Dropbox Data
- In your Dropbox: Bloox never writes, modifies, or deletes anything. Read-only access only.
- On your device: Books you import are kept locally only as long as you choose to keep them. Deleting a book in Bloox immediately removes the audio files, cover image, sibling metadata, and any related transcription or character data from your device. There is no soft-delete or recovery period.
- Sign-out: Signing out of Dropbox in Bloox deletes the stored OAuth tokens from the iOS Keychain and prevents further Dropbox access. Books that you previously imported remain on your device until you delete them.
- Uninstall: Removing Bloox deletes its app sandbox, including all imported Dropbox content. iOS may preserve Keychain items after an app is removed, so sign out of Dropbox in Bloox before uninstalling to ensure the locally stored OAuth credentials are deleted.
- No server-side copy. Because Dropbox content never leaves your device for our servers, there is no Bloox-side copy of your Dropbox data to retain or delete.
Third-Party Services
Bloox uses the Google Books API to fetch cover art for your audiobooks. The book title, and the author name when known, are sent in these requests — no personal information is included.
Bloox also uses an external service to identify characters in your audiobooks. When this feature runs, the book title and author name are sent to a server to retrieve character data. No audio, transcription content, or personal information is included in these requests.
Feedback
Bloox includes an optional feedback feature that lets you send us comments, suggestions, or bug reports. When you submit feedback, the text you typed, your app version, the feedback source in the app, and a server timestamp are sent to Firebase Firestore (provided by Google). If you leave “Attach diagnostic logs” enabled, a recent app log excerpt may also be attached; that log can include recent app activity such as playback events and book titles.
When you rate a “What Did I Miss?” recap, Bloox records your thumbs choice, selected reason, and bounded technical details such as the prompt version, response timing, excerpt length, and whether the recap was cached. This ordinary analytics event does not include the book title, chapter title, transcript, recap, or anything you type. After a thumbs down, Share recap details with Bloox is on by default and can be turned off before submitting. When it is enabled, Bloox sends the generated recap, the short transcript excerpt and instructions used to create it, and any optional note you enter to Firebase Firestore so the problem can be reviewed. If you turn it off, a note you type is still sent as ordinary feedback, but the recap, transcript excerpt, and instructions remain on your device. No audiobook audio is shared.
After the report is saved, Bloox may ask whether you want to leave an optional email address. Leaving an email is not required, and skipped feedback remains anonymous. If you provide one, it is stored with that feedback report and may be used only to ask for more information or send updates about that specific report. We do not use feedback email addresses for marketing.
Crash & Error Reporting
Bloox uses Firebase Crashlytics (provided by Google) to collect crash reports and non-fatal error logs. This helps us identify and fix bugs quickly. The data sent to Crashlytics may include:
- Device model, OS version, and app version
- Stack traces and error messages generated at the time of a crash or error
- A random installation identifier (not tied to your identity)
- Audiobook titles associated with the error (e.g., which book was being processed when a failure occurred)
This data is used solely for diagnosing and fixing bugs. It is anonymous — Crashlytics does not collect your name, email, Apple ID, playback history, or any other information that identifies you personally. Book titles are included only to help us reproduce and fix errors affecting specific content. You can learn more about how Google handles Crashlytics data in Firebase’s privacy documentation.
Analytics
Bloox uses Firebase Analytics (provided by Google) to collect anonymous usage data that helps us understand how the app is used and improve it. The data collected includes:
- Feature usage patterns (e.g. which playback controls are used, import sources, transcription usage)
- Aggregate engagement metrics (session duration, screen flows)
- A random device identifier (IDFV — not tied to your identity or shared across apps)
This data is anonymous and aggregated. It does not include your name, email, Apple ID, audiobook content, transcription text, or any information that identifies you personally.
Analytics collection is enabled by default. You can disable it at any time in Settings → Privacy → Share Analytics. When disabled, no usage data is sent to Firebase Analytics.
Bloox does not include any advertising SDKs or cross-app tracking. You can learn more about how Google handles Analytics data in Firebase’s privacy documentation.
Data Sharing
We do not sell or trade user data. We use the service providers described in this policy (such as Firebase and the character lookup service) only to provide, secure, debug, and improve Bloox.
Children’s Privacy
Bloox does not knowingly collect any personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated effective date.
Contact
If you have questions about this privacy policy, please visit our Support page to submit a request.