Privacy

Why On-Device AI Matters for Your Reading Data

StoryCodex is designed local first, with optional cloud paths when you choose them. Here is what that means for privacy, cost, and reading.

ForgeAppsUpdated September 29, 20266 min read
A shield and lock protecting a reading device from remote processing

Many AI features in reader apps send books, reading positions, or highlights to a remote service. StoryCodex takes a local-first path: reading, library storage, and supported companion features are designed to work on the device, while cloud analysis is a separate opt-in route. You can read without an account, and the app makes the cloud choice visible instead of hiding it inside the reading flow. This article maps exactly what runs where, because local first only means something if the boundary is concrete.

What actually runs on your phone

The on-device stack

Story analysis

Chapter summaries and Codex extraction (characters, world entries, relationships, timeline events) run on a local language model you download once, currently the Gemma family: a roughly 2.6 GB build for most phones and a roughly 3.7 GB build for flagship hardware, both running on the GPU. CPU execution is offered for the smaller GGUF models; it works everywhere but is slow.

Narration

All three neural engines (Piper, Kokoro, and Supertonic) synthesize speech on the device itself. After the one-time voice download, narration works with the radio off. Nothing about the text being read leaves the phone.

Your library and history

Books, chapters, reading positions, Codex data, and stats live in the app's local database. There is no StoryCodex account quietly syncing them somewhere; there is no StoryCodex account at all unless you create one for cloud services.

What leaves the device, path by path

Every network path in the app

PathWhat leavesWhen
Reading and local CodexNothing beyond fetching chapters from the source siteContinuous, offline-capable
Model and voice downloadsA file download from a public model host or the StoryCodex mirrorOnce per model or voice
StoryCodex Cloud jobThe chapter text you submitted for analysisOnly when you confirm a credit-paid job
Bring your own keyChapter text to Claude, Gemini, or your OpenAI-compatible endpointOnly when you run a job on that provider
Google Drive syncYour library snapshot, into the app's private appData folderOnly if you enable it
Usage telemetryAnonymous usage events to analyticsOnly after you explicitly consent

Two things are worth noticing in that table. First, the local path has exactly one network touchpoint, and it is the same one a browser has: fetching the chapter you asked to read. Second, every row that does send data somewhere requires an action you took: confirming a credit job, entering your own API key, enabling sync, or consenting to telemetry. There is no row for ambient background upload, because there is none.

Myths about reader app privacy, checked

Myth

My books are processed in the cloud

Fact

The product is local first, while cloud jobs are a separate opt-in path, per chapter, and clearly labeled.

Myth

I need an account to use AI features

Fact

You can read and use the local-first path without an account. Accounts matter for optional services such as cloud credits or sync.

Myth

Local AI must be worse than cloud AI

Fact

A smaller local model can be a better fit for private, offline tasks. For heavier jobs, the app can offer a separate cloud route so you can choose the trade-off.

Myth

Privacy means giving up features

Fact

The local path includes summaries, the Codex, the Story Map, story insights, and offline neural narration. Privacy is the feature set, not a trade-off.

Myth

Analytics is mandatory

Fact

Telemetry is consent-gated. It defaults to off, the prompt appears after onboarding, and events recorded before consent stay buffered and are only ever sent if you say yes. Opting out changes nothing about features.

There is also a quieter benefit that rarely gets mentioned: portability without permission. Because your library is just data on your phone, StoryCodex can export the whole thing, books, Codex, and reading history, into a portable bundle that another device imports directly. Moving phones is a file transfer, not an account migration, and your reading life does not depend on a service staying in business.

The real costs, and how they're handled

Local AI has two real costs: storage and hardware. The on-device models are multi-gigabyte downloads, and the smaller one still wants a phone with enough memory headroom; on older hardware, a very long chapter simply takes longer on device than on a server. That is why StoryCodex Cloud exists as an optional, credit-based path with the cost shown before every job, and why Pro users can bring their own Claude, Gemini, or OpenAI-compatible keys, which are stored encrypted in the platform keystore rather than in plain preferences. Every cloud path is opt-in, and you can switch between local and cloud chapter by chapter.

What local-first does not protect you from

Local-first answers one threat well: the app vendor harvesting your library, positions, and highlights. It does not make you invisible. When you fetch a web novel, the source site still sees a request from your device. If you turn on Drive sync, your backup sits in Google's infrastructure, scoped to the app's private folder but still Google's. If you bring your own API key, the provider you chose sees the chapters you send it, under that provider's own policy. And anyone holding your unlocked phone can open your library. The short version: StoryCodex removes the app itself from your threat model, and stays out of the way of the rest.

This split between local work and an explicit, privacy-conscious cloud is becoming the industry pattern. Google's on-device AI documentation for Android makes the same case for processing data locally, and Apple's Private Cloud Compute draws the same line for the moments when a job genuinely needs a bigger model. The difference with StoryCodex is that local is not the fallback. It is the product.

Practical questions

Can I use every AI feature with no internet at all?

Almost. Reading, narration, summaries, and Codex analysis all work offline once the model and voice are downloaded. The only things that need a connection are fetching new web chapters and the opt-in cloud paths.

What exactly does a StoryCodex Cloud job send?

The chapter text you chose to analyze, nothing else, and only after you confirm the job and its credit cost. Your library, positions, and history are not part of the request.

If telemetry is consent-gated, what does consenting share?

Anonymous usage events, things like which features get used, so the app knows where to improve. It is off by default, asked once after onboarding, and refusing it costs you nothing.

Do my own API keys stay on the device?

Yes. Keys you add are stored in encrypted preferences backed by the platform keystore, and are only used to sign requests to the provider you configured.

What you control

  • Local vs cloud analysis, per chapter
  • Cloud credits: buy only when needed, no subscription
  • Google Drive sync: optional and scoped to the app's private data folder
  • Portable transfer: move your whole library without any cloud account
  • Usage telemetry: consent-gated, with sharing controlled by your choice

The reading experience is designed to stay useful either way, because the core product is local first. The important distinction is visible: local processing and optional cloud jobs are separate choices.

StoryCodex is free to try on Google Play and the App Store. Import a serial, pick a neural voice, and your library works fully offline, no account required.

Keep the story clear

Try StoryCodex for free.

Read, listen, and remember any long story with a private, spoiler-safe story memory that lives on your device.