Bunko · LazyingArt LLC · updated 26 September 2026
Reading remains local and does not require an account. Bunko has no analytics, advertising identifier, or crash reporting. Optional public discussions use GitHub. In versions with in-app posting, a small LazyingArt cloud service handles GitHub authorization and forwards the comments you choose to publish.
Which books and optional offline dictionaries you downloaded, where you stopped reading in each book, your private passage notes, unpublished comment drafts, hidden-reader preferences, recently viewed dictionary definitions, and your settings: languages shown, arrangement, readings, text size and theme. All of it is written to your device's local storage by the app itself. Deleting the app deletes it. Nothing is synchronised anywhere.
When you open the library or download a book or dictionary, the app fetches files from the public GitHub repository lachlanchen/bunko-books, through GitHub's own servers and the jsDelivr content network. A downloaded dictionary is searched entirely on your device. If you have not downloaded a dictionary, looking up a word requests its definition from Wiktionary. When you open a passage's public discussion, Bunko requests matching issues and comments from GitHub, directly or through its discussion service. Those services see ordinary web requests, including an IP address, a time, and the requested book file, dictionary pack, word, or discussion. Their handling is described by GitHub, jsDelivr, and Wikimedia. Book and dictionary downloads do not pass through the Bunko discussion service.
If you use “Request a book”, the app opens GitHub's issue form in your browser with the title you typed. Nothing is sent until you choose to submit it there, and what you submit is public.
If you use in-app GitHub sign-in, GitHub handles your password and consent in its secure browser. Bunko's cloud service receives your public GitHub user ID and username and an access token limited to Bunko's discussion repository. From version 1.0.6, access and refresh tokens remain encrypted on the server, and GitHub access tokens refresh automatically. An opaque Bunko session is stored in iOS/macOS Keychain or Android Keystore-protected storage; the web reader uses a Secure, HttpOnly cookie. Sessions remain active during normal use and expire after 90 days without authenticated use, or sooner if GitHub authorization expires or is revoked. Signing out deletes the server session and clears local sign-in storage; an offline sign-out clears native credentials immediately and the web cookie is cleared when the service is reachable. iOS Keychain entries can survive reinstalling the app. Version 1.0.5 keeps only an in-memory session for up to eight hours. You can revoke Bunko's authorization at any time in GitHub's application settings.
The service processes your IP address for short-lived rate limits, passage IDs to find conversations, and the excerpt and comment only when you press Post. Authorization attempts expire after ten minutes. Expired sessions are deleted automatically. A record of a submitted public comment may be kept for seven days to prevent duplicate posts; passage-to-issue mappings remain to locate conversations. Discussion responses may be cached briefly. Application logs exclude request bodies, credentials, and OAuth callback queries.
Your submitted post is public under your GitHub account. You can edit or delete your own posts on GitHub, report content there, or hide a reader locally in Bunko. Signing out does not delete public posts. Repository maintainers moderate discussions under GitHub's rules. Private notes and unpublished drafts never become public unless you explicitly submit them as a comment.
Bunko is a reading app for works of literature. Public passage discussions may contain user-generated text hosted by GitHub. GitHub requires an account to post and applies its own account rules. Bunko has no advertising and no purchases inside it.
LazyingArt LLC · lachlan.mia.chan@gmail.com