Buy once. Read forever.

ShelfPilot

A private reader for DRM-free books and documents on iPhone and iPad. Your library, under your control — no account, no tracking, no ads.

Support that stays human

Something broken, confusing, or missing? Email and a human (me) answers.

Please include

  • What you did, what you expected, what happened instead
  • Device and iOS/macOS version
  • Screenshots if they help — but never send account numbers or anything sensitive

Contact:

Clear answers

Is it really pay once?

Yes. One purchase on the App Store. No subscription, no in-app purchases, no account, no feature unlock. Every feature and every future update is included on iPhone and iPad.

Which formats are supported?

EPUB without DRM, PDF (including password-protected PDFs when you enter the password), CBZ comic archives, Markdown, HTML, and plain text. RAR/CBR archives and DRM-protected publications are not supported.

How do I import books?

Library → Add and pick files with Apple's document picker, or add a folder in Files, or connect an OPDS catalog or Calibre Content server from Sources. ShelfPilot copies publications into its managed library and never edits your originals.

How does iCloud sync work?

Sync is optional. It carries book metadata, reading positions, bookmarks, highlights, notes, tags and collections through your personal iCloud database. Publication files, source addresses and credentials stay on the device — import the same book on another device to read it there.

How do backups work?

Settings → Backup & Restore. Full backups include managed publications, covers, library data and preferences; metadata-only backups are smaller. Paths, sizes and SHA-256 checksums are validated before restore. Backups are integrity-checked but not separately encrypted — treat them like the books themselves.

Does read-aloud send my books anywhere?

No. Read-aloud uses Apple system voices on the device. Nothing is uploaded to any speech or AI service. Available voices depend on the voices installed in iOS Settings.

OPDS or Calibre will not connect — what do I check?

Confirm the server address opens from the same device and network. For Calibre, start its Content server and use the address it displays (ShelfPilot can add /opds when needed). Allow Local Network access when asked. Credentials are stored in the Apple Keychain and re-entered from Sources.

Privacy policy

The short version: ShelfPilot collects nothing. No analytics, no trackers, no ads, no accounts, no servers of mine. The App Store privacy label says "Data Not Collected" because that is literally true.

RouteWhat is usedWhere it livesWho can access it
Your libraryPublications, covers, positions, highlights, notes, tagsOn your deviceOnly you
iCloud sync (optional)Metadata, positions, annotations - never files, addresses or credentialsYour personal iCloud database (Apple)Only you, via your Apple account
OPDS / Calibre sources you addYour device talks directly to the server you chose; its operator may log requestsDirect connection, never proxied by usYou and that server's operator
App purchaseHandled entirely by AppleApple's systemsApple; I receive no personal data
Support emailWhatever you choose to writeMy mailboxMe, for answering you only

No accounts, no servers, credentials in Keychain

ShelfPilot has no login and no cloud of its own. Source credentials live in the Apple Keychain, excluded from sync, exports and backups.

Children

ShelfPilot is not directed at children and collects no data from anyone, children included.

Changes

If this policy ever changes, the new version appears here with a new effective date. It cannot get more private than "nothing is collected", so any change would only be clarifications.

Effective date: 1 August 2026

Terms of use

OnceBudget is sold under Apple's Standard EULA. These notes supplement it:

  • What it is: a reader for DRM-free publications you already own or may lawfully access. It is not a bookstore and hosts no content.
  • Your content, your responsibility: you are responsible for having the rights to publications you import or download from sources you configure.
  • Pricing: one-time purchase. No subscriptions, no in-app purchases. Future updates are included; features may evolve over time.
  • iCloud: sync depends on Apple's iCloud service and your account; outages there are outside my control.
  • Independence: ShelfPilot is an independent app. Calibre and other product names are trademarks of their owners; compatibility does not imply endorsement.
  • Contact: