Privacy
What this site records
No accounts, no advertising, no cookies. Reading the pages records a visit count, never who you are. Last changed 27 September 2026.
Visits
Each page loads one small script from our own statistics service (kstats, run by the
same person as this site). It sends to this site's own address, /e, which
passes it on: the page path, the site that linked you here (its address without any
query string), utm_source and utm_campaign if the link carried
them, the page language, which outbound links you clicked (their address without a
query string), and how long the tab was visible.
The script stores nothing on your device and sets no cookie. It reads one setting,
k:self, which only we set on our own browsers so our visits are not
counted. Your IP address and browser name are used, on the server, to compute a one-way
code that changes every day, so a day's visitors can be counted without anyone being
followed across days. The IP address itself is not stored. Outside the EEA, the UK and
Switzerland a second code that does not change daily is kept, so "came back" can be
counted; it is never computed for visitors inside them, or when the country is
unknown. The country comes from Cloudflare's network.
Feedback
If you use the feedback form, it sends your message, the kind you picked, your email if you gave one, the page you came from, the quote or recommendation you were reporting, and a coarse device type such as “android/chrome”. It is stored in one private inbox shared by Eyal Levin's projects, and a copy of the message goes to his phone as a notification. The email is used only to reply to you.
The reader at /read
The book reader at ybooks.app/read keeps your place, likes, settings and reading streak in your browser's local storage, on your device only. It also stores a random device id there, and sends anonymous usage events (which book and card, swipes, settings changes, errors, how long a card's picture was looked at) with that id and your browser's user-agent, so we can see where the reader gets stuck. There is no account and no name attached.
When you press play, the text of that card (public-domain book text, nothing about you) is sent from our server to a text-to-speech provider (Google Gemini by default, or the one you picked: ElevenLabs, OpenAI or Groq), and the audio is saved for every reader. Card pictures are drawn by Cloudflare Workers AI from the card's text in the same way. Neither provider receives anything from your browser.
Who else sees the connection
The site runs on Cloudflare, which handles every request and keeps its own operational logs. The reader at /read loads its typeface from Google Fonts, so Google sees that request; the rest of the site loads no fonts. Our own error logs record the page address and, for automated crawlers we slow down, their network (the ASN). Links to sources open other sites, under their own rules.
Questions
Ask through the feedback form and leave an email for the answer.