Privacy Policy
Last updated 16 August 2026
This policy explains what personal data Umnis (“UmnisBooks”, “we”, “us”) collects when you use the UmnisBooks website and our mobile and desktop apps, why we collect it, who we share it with, and the choices you have. It applies to every platform we ship on: web, Android, iOS and macOS.
1. Information you give us
Account details. When you create an account we collect your name, email address, country and a password. Passwords are stored only as a salted hash — we never store or see the plaintext. If you sign in with Google instead, we receive your name and email address from Google; we never receive your Google password.
Payment details.To pay by mobile money we collect the mobile number you are paying from and the network it belongs to (MTN, Telecel or AirtelTigo). That number is passed to the mobile money operator to authorise the charge. For card payments on the web we use Stripe: your card number is entered directly into Stripe’s hosted fields and never reaches our servers.
Content you create. Highlights, annotations, notes and bookmarks you make while reading, together with your reading position, are saved to your account so they follow you between devices.
2. Information we collect automatically
Library and purchase history. The books, chapters, audiobooks, bundles and periodical subscriptions you buy, rent, sample or add to your library, and the transactions behind them.
Product analytics. We record a small, fixed set of events to understand how the product is used: account creation, opening a book, opening a sample, searching, and completing a purchase or rental. These events are linked to your account by email address.
Diagnostics. If the app crashes or errors we collect a crash report containing the error, a stack trace, your device model, operating system version and app version, so we can fix the fault.
3. How we use your data
We use it to run your account and library; to deliver the books and audiobooks you are entitled to and enforce those entitlements; to process payments, rentals and refunds; to sync your reading progress and annotations across devices; to personalise search results and recommendations; to diagnose crashes and improve performance; to answer support requests; and to detect fraud and abuse.
We do not sell your personal data, and we do not use it to serve third-party advertising. The apps contain no advertising SDKs and no cross-app tracking.
4. Who we share it with
We share data only with processors who help us run the service:
- Mobile money operators (MTN, Telecel, AirtelTigo) — the paying mobile number and amount, to authorise and settle a payment.
- Stripe — card payments on the web. Stripe acts as an independent controller for card data under its own privacy policy.
- PostHog — product analytics events, linked to your email address.
- Sentry — crash and error reports.
- Google — only if you choose to sign in with Google.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever sold or merged, account data may transfer to the acquirer under this policy.
5. Where your data is held
Our servers and our processors operate in Ghana, the European Union and the United States, so your data may be transferred outside your country of residence. Where such transfers involve personal data protected by the Ghana Data Protection Act, 2012 (Act 843) or the GDPR, we rely on standard contractual clauses or an equivalent safeguard with each processor.
6. How long we keep it
Account details, library entitlements, annotations and reading progress are kept for as long as your account exists. Transaction records are kept for seven years after the transaction, because tax and accounting law requires it — this applies even after you delete your account. Crash reports are kept for 90 days, and analytics events for 12 months.
7. Your rights, and deleting your account
You can access, correct, export or delete your personal data, object to or restrict how we process it, and withdraw consent at any time.
To delete your account and the personal data attached to it, follow the steps on our account deletion page, or email privacy@umnis.com from the address on the account, or use the contact form. We verify the request, then delete your account, library entitlements, annotations, reading progress and analytics profile within 30 days. Transaction records are retained for the statutory period described in section 6. Deletion is permanent — purchased and rented titles cannot be restored afterwards.
If you believe we have mishandled your data you can complain to the Ghana Data Protection Commission, or to your local supervisory authority if you are in the EU or UK.
8. Children
UmnisBooks is not directed at children under 13, and we do not knowingly collect data from them. Our catalogue includes textbooks used by school-age readers; where a school or family account is involved, the adult who set it up is responsible for the child’s use. If you believe a child has given us personal data, contact us and we will delete it.
9. Security
Traffic is encrypted in transit with TLS, passwords are salted and hashed, downloaded book content is stored encrypted on your device, and access to production data is restricted to staff who need it. No system is perfectly secure, but we will notify you and the relevant regulator without undue delay if a breach affects your data.
10. Changes to this policy
If we make a material change we will update the date at the top of this page and notify you in the app or by email before the change takes effect.
11. Contact us
Questions about this policy or your data: privacy@umnis.com, or via our support page.