OperaLibre Privacy Policy
Effective date: July 18, 2026
Last updated: September 3, 2026
OperaLibre is an audiobook player that can use audio files stored on your device or connect to an OperaLibre or Jellyfin server chosen by you. This Privacy Policy explains how the OperaLibre application (the “App”) handles information.
Summary
OperaLibre does not include advertising or tracking technology. The developer does not operate a central OperaLibre cloud service and does not receive your audiobook library, listening activity, account credentials, or server address through the App.
When you connect the App to a server, information is exchanged directly between your device and that server. The person or organization operating the server controls the information stored there and is responsible for its own privacy and security practices.
Information handled by the App
Depending on the features you use, the App may handle the following information.
Server and account information
When you connect to an OperaLibre or Jellyfin server, the App handles:
- the server address and server type;
- the username and password you enter during sign-in;
- an authentication or session token returned by the server;
- a locally generated Jellyfin device identifier when using Jellyfin; and
- basic account information returned by the server, such as a user ID, username, and account privileges.
Your sign-in information is sent directly to the server you select. The App stores the server address and authentication token on your device so that you can remain signed in. The App does not retain your password after the sign-in request is completed.
When an administrator adds an Audible account through the optional Libation integration, the Audible password and multi-factor authentication are entered on Amazon’s website rather than in OperaLibre. The final browser response URL is sent once to the selected OperaLibre server so its local Libation installation can finish authentication. OperaLibre does not persist that URL; Libation stores the resulting account tokens in the server’s private data directory.
Audiobook and listening information
When you connect a Libro.fm account for server imports, the email and password are sent through your selected OperaLibre server to Libro.fm. The server retains the resulting token and cached purchase list in its private data directory, not the password. These are scoped to your OperaLibre user through the API. Imported audio becomes part of the server library and follows its access rules. Disconnecting removes the connection and cached purchase list while keeping imported books. Purchase cover images may be loaded directly from Libro.fm’s image hosts.
When you choose This device in the native app, Libro.fm sign-in, catalog requests, and audio downloads go directly from the device to Libro.fm and its delivery hosts, without an OperaLibre server. The password is not saved. The token is stored in iOS Keychain or encrypted with an Android Keystore key in app-private, non-backed-up storage. Purchase metadata and import status are cached locally; native background jobs retain temporary signed download URLs. This device connection is shared by users of the app installation, not scoped to a server login. Disconnect removes the connection/cache while leaving imported audio and listening history. Device imports are not automatically uploaded to a server.
The App may receive or create:
- audiobook titles, authors, narrators, descriptions, chapters, cover artwork, and other library metadata;
- audio streams and audiobook files;
- playback position, listening progress, completion status, and related timestamps;
- a reading log recorded by the server: when each listening session started and ended, how long it lasted, which book it covered, the playback speed, the kind of client used, and the time zone offset reported by the device;
- a record of each book finished, including the date and a copy of that book’s title, author, narrator, runtime, and catalog identifiers, which the server keeps even after the audiobook itself is removed;
- playback preferences such as listening speed; and
- downloaded books and cached library information used for offline playback.
When you use a connected server, this information is exchanged directly with that server as necessary to browse your library, stream or download audio, display artwork, and synchronize playback progress. Some information is also cached on your device to provide the App’s features.
If the server owner installs and enables the optional follow-along sync generator, the selected OperaLibre server processes audiobook audio and EPUB text locally to create sentence timing maps. Audiobook contents are not sent to the developer or to a speech-recognition service. Installing the add-on and its first use download software and model files from their upstream hosts, which may receive ordinary request information such as the server’s IP address and request time.
Files selected from your device
If you choose the on-device library feature, the App lets you select supported audiobook files using the system file picker. Selected files are copied into the App’s private storage, and related library metadata and playback progress are stored locally. The developer does not receive these files or related listening information.
Local-network access
The App may request permission to access your local network so it can connect to an OperaLibre or Jellyfin server running on your home network. This access is used only to communicate with servers you select.
Technical network information
Whenever your device communicates with a server, that server may receive technical information ordinarily included in network requests, such as your IP address, request time, and device or client information. The server operator determines whether and for how long server logs are retained.
How information is used
Information handled by the App is used to:
- connect and authenticate with the server you choose;
- display and search your audiobook library;
- stream, download, and play audiobooks;
- save and synchronize listening progress;
- provide chapters, artwork, readalong material, and playback controls;
- remember your server and playback preferences; and
- diagnose connection or playback errors shown to you in the App.
The developer does not use information from the App for advertising, cross-app tracking, profiling, or sale to data brokers.
Storage and retention
On your device
Server settings, authentication tokens, playback preferences, cached metadata, listening progress, imported files, and downloaded media may remain on your device until you sign out, remove a download or imported book, clear the relevant App data, or uninstall the App. Some cached information may remain until the App’s storage is cleared or the App is removed.
On an OperaLibre server
An OperaLibre server may store usernames, password hashes, session tokens, library metadata, audiobook and readalong files, per-user listening progress, and a per-user reading log.
The reading log is more detailed than a playback position: it records when a reader was listening and for how long, which over time describes their daily routine. It is stored on the server the reader signs in to, is never sent anywhere else, and is readable only by that reader — an administrator’s own view of other readers remains limited to the optional shared-progress feature, which shows a percentage and a status by mutual opt-in.
The server operator controls retention. An OperaLibre administrator can remove a reader account, which deletes its progress and reading log. The server operator can remove library files and other stored data directly from the server.
On a Jellyfin server
When you connect to Jellyfin, account, library, session, and playback information is handled according to the configuration and privacy practices of that Jellyfin server and its operator.
Disclosure and third parties
The App sends information only as needed to services you choose or that are required to deliver the App:
- Your selected OperaLibre or Jellyfin server. Information described above is sent directly to that server for app functionality.
- Apple. Apple may process App Store, download, purchase, diagnostic, or device information independently under Apple’s own privacy policies. The developer does not control information Apple processes independently.
- Google Fonts. Current versions of the App may request font files from Google when network access is available. Those requests may reveal standard network information, including your IP address, to Google. Google processes that information under its own privacy terms.
The App does not integrate third-party advertising networks, data brokers, or behavioral analytics services. The developer does not sell or rent personal information.
Security
The App uses the connection method configured for the server you select. HTTPS encrypts information in transit and should be used for any server accessible over the public internet. A server configured with plain HTTP does not encrypt traffic; plain HTTP should be limited to trusted local or private networks.
Authentication tokens and offline media stored on your device are protected by the security features provided by your device and operating system. No method of electronic storage or transmission is completely secure.
Server operators are responsible for securing, updating, backing up, and controlling access to their servers.
Your choices and deletion
You can:
- decline local-network access in your device settings, although local servers may then be unavailable;
- sign out or change the selected server;
- delete downloaded books and imported on-device books in the App;
- uninstall the App to remove its locally stored data, subject to normal device backup behavior;
- ask the operator of an OperaLibre server to delete your reader account, listening progress, and reading log; or
- use the account and data-management options provided by your Jellyfin server or contact its operator.
Because the developer does not receive or centrally store your server account or listening data, requests concerning data held by a self-hosted server must be directed to that server’s operator.
Children’s privacy
OperaLibre is not directed to children under 13, and the developer does not knowingly collect personal information from children through a developer-operated service. A parent, guardian, or server operator who provides access to a child is responsible for configuring and supervising that account and server.
International use
The location in which connected data is processed depends on the location of the server you select and its operator. The developer does not centrally transfer App account or listening data between countries.
Changes to this policy
This policy may be updated when the App’s features or data practices change. The updated policy will be posted on this page with a revised “Last updated” date.
Contact
OperaLibre is developed by Donovan Montoya. For privacy questions about the App itself, open a request through the OperaLibre issue tracker. Do not include passwords, authentication tokens, audiobook files, or other sensitive information in a public issue.
For information stored on an OperaLibre or Jellyfin server, contact the person or organization that operates that server.