Open Citadel

Progress

0%

Legal

Privacy Policy

Last updated: September 17, 2026

Open Citadel is built on a simple idea: your books, notes, and thinking are yours. This policy explains what data the app uses, where it lives, and what leaves your device when you choose to use Samwell Cloud.

Who We Are

Open Citadel is developed by Thamsanqa Ncube, an individual developer publishing on Google Play and the App Store. There is no separate company at this time. If that changes, this policy will be updated to name the responsible entity.

Summary

  • Your library, highlights, notes, chats, goals, and daily logs are stored in a local database on your device. We do not keep a copy of them on our servers.
  • You can read, highlight, and use on-device Samwell without an account.
  • Samwell Cloud and Compass need an account. When you use them, what you send and the context Samwell needs to answer is passed through our server to an AI provider to generate a reply.
  • Subscriptions are paid through Google Play or the App Store. We never see your payment details.
  • We do not sell data, show ads, or use advertising or analytics SDKs in the app.

What Stays On Your Device

Everything you create or add in Open Citadel is stored in a local SQLite database inside the app's private storage. That includes your books, reading progress, highlights, notes, collections, chat history with Samwell, Compass goals, and daily logs.

On-device Samwell runs an AI model on your phone. Conversations with it never leave your device.

Text-to-speech uses your device's built-in speech engine.

Your Account

To use Samwell Cloud and Compass you sign in or create an account. Sign-in is handled by Logto. Your account holds your email address and, if you give one, your name. The app keeps your sign-in session in your device's secure storage.

Signing out ends the session on your device. It does not delete anything stored on your device.

Samwell Cloud & Compass

Samwell Cloud answers through our server instead of running on your phone. Compass, the part of the app for goals, daily logs, and check-ins, works with Samwell Cloud.

When you send Samwell Cloud a message, the app sends our server:

  • your message and the rest of that conversation;
  • a short summary of your journey: books you are reading or have finished, the themes you highlight most, and your active goal, what you track for it, and how often you have logged lately;
  • anything Samwell looks up in the app to answer you, such as a passage from a book, your highlights and notes, or your goal history and logs.

The same applies when the app asks Samwell Cloud to suggest a title for a chat, suggest tags for a highlight, or write a takeaway when a goal ends, and to the optional setup conversation where Samwell introduces the app and helps you find free books.

Our server passes this to OpenRouter, which routes it to the AI model provider that generates the reply. OpenRouter's privacy policy and the policy of that model provider apply to how they handle it.

Our server does not store the content of your conversations. It stores what it needs to run your plan: your account ID, your plan, your credit balance, and a usage record for each request (the model used, the number of tokens, the cost, and the time). Like most servers, it also keeps technical logs of requests.

Subscriptions

Samwell Cloud plans are monthly subscriptions bought through Google Play or the App Store, which process the payment. We never see or store your card or payment details.

We use RevenueCat to manage subscriptions. RevenueCat receives your account ID and your purchase history from the store so we can tell which plan you are on.

Permissions We Request

The Android app requests the following:

  • Storage: to import books you pick into your library and to save images, such as highlight cards, to your device. Files are only accessed when you choose them.
  • Internet: to sign in, to use Samwell Cloud and Compass, to manage subscriptions, and to download free books and on-device AI models you choose.

On iOS, the app only reaches files you open or share into it.

Third-Party Services

  • Logto: sign-in and accounts.
  • OpenRouter and the AI model providers it routes to: generating Samwell Cloud replies.
  • RevenueCat: managing subscriptions.
  • Google Play and the App Store: processing payments, under Google's and Apple's own privacy policies.
  • Hugging Face: hosting the on-device AI models you choose to download. These are plain file downloads with no personal data attached.
  • Project Gutenberg: the source of the free public domain books the app can find and download for you.

Note: this website (the page you're reading now) uses Vercel Web Analytics to count anonymous, aggregated page views. This is separate from the app and does not use cookies or collect personal data.

Data Retention & Deletion

Your library, notes, chats, goals, and logs live on your device. You can delete books, highlights, notes, chats, and goals in the app, or remove everything by uninstalling Open Citadel. We have no copy to keep.

To delete your account and the records our server holds about it (your plan, credit balance, and usage records), open the app, go to Settings, and use DELETE ACCOUNT on the Cloud Account card. It takes effect immediately. If you no longer have the app, email us at the address below from the email on your account and we will do it within 30 days.

Cancel any active subscription in Google Play or the App Store first, since deleting your account does not cancel it. See Delete Your Account for the full steps and exactly what is deleted.

Children's Privacy

Open Citadel is not directed at children under 13, and we do not knowingly collect personal information from children.

Changes To This Policy

We may update this policy as the app changes. The "Last updated" date at the top of this page always shows the latest revision, and important changes will be called out in the app's release notes.

Contact

Questions about this policy or your data can be sent to thamsanqa.dev@gmail.com.