Phloem for iPad
Your papers. Your reading space.
Phloem for iPad is a paper reader made by Houfu Chen. This policy describes the iPad app. The Phloem website and browser extension have their own features and privacy information.
What stays in the app
Imported PDF and Word originals, extracted text, highlights, reading notes, reviewer comments, reading positions, and preferences are stored in the app on your iPad. Document rendering, text extraction, and the app’s OCR run on the device. Ordinary reading does not upload your library to a developer-operated service.
Phloem has no Phloem account, advertising, or integrated analytics service. GitHub sync is unavailable in the iPad app. Version 1.2 adds optional iCloud sync and optional Google Drive sync, described below. In version 1.1 and later, optional cloud AI is available only after you choose a provider and complete the setup described below.
Optional iCloud sync in version 1.2 and later
iCloud sync is off by default. If you turn it on, Phloem sends your library metadata, notes, highlights, handwriting, reading progress, PDF originals, and Word originals to a private CloudKit database in your iCloud account. The data counts against your iCloud storage. Phloem uses it to merge your reading library across compatible Apple devices; the local library remains available when iCloud is unavailable.
Apple provides iCloud and applies its iCloud terms and privacy practices. In China mainland, iCloud is operated by AIPO Cloud (Guizhou) Technology Co., Ltd. (GCBD), and iCloud content is subject to the terms and data handling for that service. Review Apple’s information about iCloud in China mainland and the iCloud operated by GCBD terms before enabling sync for sensitive material.
You can turn sync off without deleting either copy. Settings also provides Delete iCloud copy, which removes Phloem’s library record and original-document assets from its private CloudKit database while keeping the copies already stored on that iPad. iCloud recovery systems or backups may retain data for a period under the applicable iCloud terms.
Optional Google Drive sync in version 1.2 and later
Google Drive sync is off by default and is unavailable in the China mainland App Store. If you choose Connect Google Drive, you sign in to Google in a system sign-in sheet and allow Phloem to use its own hidden app-data folder in your Google Drive. Phloem asks only for that app-data permission; it cannot see or change your other Drive files.
When it is on, Phloem sends your library metadata, notes, highlights, handwriting, reading progress, PDF originals, and Word originals to that app-data folder, and reads them back to merge your library with the Phloem website and other devices signed in to the same Google account. The data counts against your Google storage. Google’s sign-in keeps a refresh token in this iPad’s Keychain with this-device-only protection; access tokens are kept only in memory. Google provides Drive and applies the Google Privacy Policy.
Choosing Turn off under Google Drive in Settings signs out, revokes Phloem’s Google access, and removes the token from this iPad, while keeping the local library. The copy in the app-data folder stays in your Google account until you delete it; in Google Drive on the web, open Settings › Manage apps, choose Phloem’s app, and select Delete hidden app data.
Optional AI in version 1.1 and later
Cloud AI is unavailable in the China mainland App Store. Phloem uses the current StoreKit storefront to hide these controls and to reject provider setup and network requests natively. If the storefront cannot be verified, cloud AI remains unavailable. Local reading, Apple Pencil tools, notes, OCR, imports and exports, and optional private iCloud sync remain available.
AI is off by default and is available only to people who confirm they are 18 or older. To turn it on, you choose one supported provider, review a provider-specific disclosure, give your affirmative consent, and enter your own provider API key in a native iOS secure prompt. The key is stored in this iPad’s Keychain with this-device-only protection. Phloem’s web interface cannot read it back, and Phloem does not include it in library backups or exports.
An AI request is made only when you deliberately use an AI feature. Depending on the action, Phloem sends the selected passage, current-page text, or guide context; your question and earlier turns in the same Phloem discussion; or extracted reviewer text and candidate excerpts chosen locally for reviewer assistance. Phloem does not send the original PDF or Word file, the rest of your library, unrelated highlights or notes, or keys for other providers.
The request goes directly from your iPad to the provider over HTTPS. Phloem does not operate an AI proxy and the developer does not receive your prompt or the provider’s response. The provider receives your API key and normal connection information, and the key can associate the request with your provider account.
You can choose:
- OpenAI API at
api.openai.com. OpenAI states that API data is not used to train its models unless the API customer opts in; default abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days, subject to exceptions. See OpenAI API data controls. - Anthropic API at
api.anthropic.com. Anthropic states that commercial API inputs and outputs are not used to train its models by default. Standard inputs and outputs are normally deleted within 30 days, but policy-flagged content, safety classifications, feedback, and legal, contractual, or feature-specific records can be retained longer. Data is stored in the United States and may be routed or processed in other supported regions. See Anthropic’s retention information, training information, and processing-region information. - DeepSeek API at
api.deepseek.com. DeepSeek’s published policy describes processing and storage in China, retention for service and other stated purposes, and possible model/technology improvement use. Phloem cannot guarantee no training or a fixed deletion period for API content. Review the DeepSeek privacy policy and Open Platform terms for your account before sending sensitive material. Those policies distinguish DeepSeek’s own services from downstream apps; this Phloem policy describes the app’s data flow.
Provider terms, eligibility, processing regions, retention, training choices, and deletion controls apply independently of Phloem and can change. Do not send confidential, sensitive, or unpublished material unless you are satisfied that your chosen provider and plan are appropriate for it.
Removing a saved key in Settings stops future requests to that provider and removes Phloem’s local consent receipt. It does not delete requests the provider already received. Use the provider’s account and privacy controls for those records.
When information leaves your iPad
- Define: requesting a definition can send the selected word or phrase to Wikipedia and a related search term to Wikimedia Commons. The app may also load images from Wikimedia. These services receive the requested term or resource and normal connection information, such as your IP address. Definitions are cached locally, but displaying a cached result’s image may still use the network. See the Wikimedia privacy policy.
- PDF links and external websites: importing a PDF URL or requesting another copy from its original link contacts that website. Opening an external link contacts its destination. The website receives the requested URL and normal connection information and applies its own privacy policy.
- Files and sharing: the system file picker gives Phloem the files you choose. A file provider may download them from your cloud storage. When you export, the iPad share sheet sends the chosen file to the destination you select, which may be another app, person, or cloud service.
- iCloud sync: if you turn it on, the reading library and original documents described above are sent to Apple iCloud or, for China-mainland iCloud accounts, the GCBD-operated iCloud service.
- Google Drive sync: if you connect it, the reading library and original documents described above are sent to the Phloem app-data folder in your Google Drive, and sign-in requests go to Google.
- Support: if you email us, we receive your email address, message, and any attachments you include. We use them to respond and troubleshoot. Do not include confidential papers or a full library backup unless you choose to share them.
Your backups and exports
The portable JSON library backup contains notes, highlights, reading progress, reviewer work, and document metadata. It does not contain the original PDF or Word files or AI API keys. The backup is not encrypted by Phloem, so anyone who receives it can read its contents. Keep your original documents separately. A review-layer export contains comments, linked excerpts, and revision notes; it does not include the original document.
Copies you save or share elsewhere remain under your control and the destination’s policies.
Retention, deletion, and your choices
Your library remains in the app until you remove papers or delete the app’s data. Removing a paper removes its local original and associated reading work from the active library. Recovery storage and device backups can retain earlier copies; this is not a secure-erasure feature.
Deleting the app removes its local app data, but does not automatically delete Phloem’s optional iCloud or Google Drive sync copies, files you exported, originals in Files, email attachments, or existing device backups. Use Delete iCloud copy before deleting the app if you want Phloem to request deletion of its CloudKit records. iPadOS may include app data in device backups according to your settings. Manage those copies in the relevant app or service. Keep an exported backup before deleting or reinstalling Phloem.
You can read locally imported papers without configuring AI or using Define, PDF links, or external websites. No Phloem account needs to be deleted. For a request about support correspondence, email us from the address used to contact us. Support messages remain in the support mailbox while needed to handle the conversation; you can request deletion of those messages, subject to any retention required by law.
Contact and updates
For privacy questions or requests, contact Houfu Chen at houfuchen0702@gmail.com.
Changes to the app’s data practices will be reflected in this policy and its updated date.